Sony Pixel Power calrec Sony

HP Study Reveals 70 Percent of Internet of ings Devices Vulnerable to Attack

29/07/2014

HP Study Reveals 70 Percent of Internet of Things Devices Vulnerable to AttackIoT devices averaged 25 vulnerabilities per product, indicating expanding attack surface for adversaries

PALO ALTO, Calif. - HP today released results of a study revealing 70 percent of the most commonly used Internet of Things (IoT) devices contain vulnerabilities, including password security, encryption and general lack of granular user access permissions.

With the rise of IoT, the number and diversity of connected devices is expected to increase exponentially. According to Gartner, the Internet of Things will include 26 billion units installed by 2020. IoT product and service suppliers will generate incremental revenue exceeding $300 billion, mostly in services, in 2020. (1)

This spike in demand is pushing manufacturers to quickly bring to market connected devices, cloud access capabilities and mobile applications in order to gain share. While this increase in IoT devices promises benefits to consumers, it also opens the doors for security threats ranging from software vulnerabilities to denial-of-service (DOS) attacks to weak passwords and cross-site scripting vulnerabilities.

While the Internet of Things will connect and unify countless objects and systems, it also presents a significant challenge in fending off the adversary given the expanded attack surface, said Mike Armistead, vice president and general manager, Fortify, Enterprise Security Products, HP. With the continued adoption of connected devices, it is more important than ever to build security into these products from the beginning to disrupt the adversary and avoid exposing consumers to serious threats.

HP leveraged HP Fortify on Demand to scan 10 of the most popular IoT devices, uncovering, on average, 25 vulnerabilities per device-totaling 250 security concerns across all tested products. The IoT devices tested-along with their cloud and mobile application components-were from manufacturers of TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.

The most common and easily addressable security issues reported include:

Privacy concerns: Eight of the 10 devices tested, along with their corresponding cloud and mobile application components, raised privacy concerns regarding the collection of consumer data such as name, email address, home address, date of birth, credit card credentials and health information. Moreover, 90 percent of tested devices collected at least one piece of personal information via the product itself, the cloud or its mobile application.

Insufficient authorization: 80 percent of IoT devices tested, including their cloud and mobile components, failed to require passwords of sufficient complexity and length, with most devices allowing password such as 1234. In fact, many of the test accounts HP configured with weak passwords were also used on the products' websites and mobile applications.

Lack of transport encryption: 70 percent of IoT devices analyzed did not encrypt communications to the internet and local network, while half of the devices' mobile applications performed unencrypted communications to the cloud, internet or local network. Transport encryption is crucial given that many of the tested devices collected and transmitted sensitive data across channels.

Insecure web interface: Six of the 10 devices evaluated raised security concerns with their user interfaces such as persistent XSS, poor session management, weak default credentials and credentials transmitted in clear text. Seventy percent of devices with cloud and mobile components would enable a potential attacker to determine valid user accounts through account enumeration or the password reset feature.

Inadequate software protection: 60 percent of devices did not use encryption when downloading software updates, an alarming number given that software powers the functionality of the tested devices. Some downloads could even be intercepted, extracted and mounted as a file system in Linux where the software could be viewed or modified.

To protect against security hazards that come along with the rise of IoT, it is imperative for organizations to implement an end-to-end approach to identify software vulnerabilities before they are exploited. Solutions like HP Fortify on Demand enable organizations to test the security of software quickly, accurately, affordably and without any software to install or manage-proactively eliminating the immediate risk in legacy applications and the systemic risk in application development.

Methodology

Conducted by HP Fortify and leveraging HP Fortify on Demand, the Internet of Things Security: State of the Union study tested 10 of the most commonly used IoT devices for vulnerabilities using standard testing techniques that combined manual testing along with the use of automated tools. Devices and their cloud, network and client application components were assessed based on the OWASP Internet of Things Top 10 list and the specific vulnerabilities associated within each category.

Additional information about application security and further details resulting from the study are available at hp.com/go/fortifyresearch/iot.

HP will be addressing the latest trends in enterprise security at the Black Hat USA 2014 conference, taking place Aug. 2-7 in Las Vegas. Visit the HP booth (No. 911) for an IoT product demo and Capture the Flag hacking contest. Additional information on HP's presence at the show can be found here.

(1) Gartner, Forecast: The Internet of Things, Worldwide, 2013, November 2013.

2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the e
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1744676...
See more stories from hp

Most recent headlines

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

19/04/2025

SDVI Earns Both Product and Project of the Year Awards at...

SDVI, the leading platform provider for cloud-native media supply chains, today announced that the company earned multiple awards at the 2025 NAB Show, with two...

19/04/2025

Ateliere Announces CEO Transition

Ateliere Creative Technologies, a leading GenAI media software solutions company, today announced that Dan Goman has stepped down as CEO and David Bortis, Ateli...

19/04/2025

Marshall CV574 Miniature 4K UHD Camera Revolutionizes Off...

As Director of Media and Aerial Production at Terrible Herbst Motorsports, Bryan Moore is setting new standards in off-road racing media coverage thanks to his ...

19/04/2025

Lightware Launches Dual Screen Extended Desktop Taurus

A next-generation collaboration device that redefines connectivity for meeting environments Lightware, an industry-leading manufacturer of signal management so...

19/04/2025

Calrec Wins 2025 NAB Show Product of the Year Award for N...

Calrec is today announcing that its True Control 2.0 is a Remote Production winner in the 2025 NAB Show Product of the Year Awards. This official awards program...

19/04/2025

Appear and NBCUniversal Win Project of the Year at NAB Sh...

Appear, a global leader in live production technology, proudly announces it has been recognised alongside NBCUniversal with the prestigious NAB Show Delivery Pr...

19/04/2025

Deity Microphones Announces The Deity THEOS DIFB at NAB 2...

Deity Microphones, a leader in innovative audio equipment, is proud to announce the expected release of our Ultra-Wide Band IFB to the market. The THEOS DIFB wi...

19/04/2025

LiveU IQ Technology Delivers Breakthrough Network Perform...

A world renowned broadcaster and long-standing LiveU customer has successfully completed a series of live connectivity tests using LiveU's revolutionary, aw...

19/04/2025

BitFire Wins 2025 NAB Show Project of the Year and Produc...

BitFire (bitfire.tv), a longtime leader in live video transport, today announced dual NAB Show award wins at the 2025 NAB Show in Las Vegas. The company's M...

19/04/2025

BitFire Wins Three Top Awards at 2025 NAB Show

BitFire (bitfire.tv), a longtime leader in live video transport, today announced three major award wins at the 2025 NAB Show, April 5-9, in Las Vegas. The compa...

19/04/2025

Moments Lab and Satisfaction Group Form Unique Strategic...

AI video discovery company Moments Lab and Satisfaction Group, a leading independent unscripted television production company, are proud to announce a unique st...

19/04/2025

The Infrastructure of Creative Flow DigitalGlues creative...

As the media industry navigates the triple challenge of AI-driven production, distributed teams, and skyrocketing content demand, DigitalGlue s creative.space h...

19/04/2025

Miri Technologies Wins Two Prestigious Awards for X510 Bo...

Network technology startup Miri Technologies Inc. capped off its tremendously successful NAB Show debut by winning two prestigious industry awards for its cutti...

19/04/2025

Tablo Adds 45 New FAST Channels From Warner Bros. Discovery

CINCINNATI Scripp's Nuvyyo USA has concluded a deal with Warner Bros. Discovery to bring 45 FAST channels to Nuvyyo's Tablo TV device....

19/04/2025

Court Overrules FCC's $57 Million Fine Against AT&T

In a ruling that could have broader implications on the legality of regulatory agencies levying fines through administrative proceedings, the 5th U.S. Circuit C...

19/04/2025

FCC Chair Carr Blasts Comcast Over MSNBC Coverage

WASHINGTON Federal Communications Commission chair Brendan Carr has blasted Comcast over MSNBC's coverage of the deportation of Kilmar Abrego Garcia in a so...

19/04/2025

Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC

Berklee NYC and NYC Media Launch Season 3 of Inside Power Station @BerkleeNYC This season features faculty member Arun Pandian as the new host and interviews ...

18/04/2025

Everyone Is Cordially Invited to Celebrate Queer Joy in The Wedding Banquet

Director Andrew Ahn, alongside actors Youn Yuh-jung and Joan Chen, takes a photo of the audience after the premiere of his film The Wedding Banquet at Eccles ...

18/04/2025

U.S. Judge Rules Google Illegally Monopolized Ad Technologies

In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...

18/04/2025

TV News Outlets See March Spike in Social Media Usage

Broadcast and cable TV news outlets saw strong social media growth in March, according to new data from the social video analytics company Tubular Labs ....

18/04/2025

Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist

Berklee Student Yukai Yang Named 2025 Yamaha Young Performing Artist The drummer secured a spot among the elite winners in this years competition. By Maddie...

18/04/2025

Boston Conservatory Alums Bring Real Women Have Curves to Broadway

Boston Conservatory Alums Bring Real Women Have Curves to Broadway The Latin American immigrant community takes center stage in a new musical featuring Tatian...

18/04/2025

UPDATED: Broadcasters Urge FCC to Hit the Delete Button on Antiquated Regs

WASHINGTON The FCC's call for public comments and suggestions on outdated regulations that it should be eliminated, has prompted a slew of fillings from bro...

18/04/2025

Federal Judge Rules Google Illegally Monopolized Ad Technologies

In a ruling that could have a major impact on the digital advertising market, a federal judge has ruled that Google has monopolized some types of advertising te...

18/04/2025

AMS, VideoAmp Collaborate on Cross-Channel Targeting and Measurement

PEARL RIVER, N.Y. Global media solutions company Active Media Services (AMS) has formed a new relationship with VideoAmp, a measurement company for linear TV, c...

18/04/2025

Netflix Reports Strong Q1 Revenue, Operating Income

Netflix reported generally positive results for first-quarter 2025, with revenue up 13% year-over-year to $10.543 billion and operating income growing by 27% to...

18/04/2025

NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile Units from NEP Group, Game Creek Video

NHL Playoffs 2025: TNT Sports Hits the Road for Onsite Productions With Mobile U...

18/04/2025

EVS's Sbastien Verlaine on U.S. Expansion, Next-Generation Products

EVSs S bastien Verlaine on U.S. Expansion, Next-Generation Products Beyond replay, offerings also target asset management and media infrastructure By Ken Kersc...

18/04/2025

ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC

ESPN Unleashes 4DREPLAY as NCAA Women's Gymnastics Championships Hit ABC Men's championships to follow Saturday night on ESPN2 By Brandon Costa, Direct...

18/04/2025

Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports

Visualizing Victory: The Latest in AR, XR, and Virtual Production in Live Sports This panel discussion featured leaders from ESPN, CBS Sports, Warner Bros. Disc...

18/04/2025

NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remote-Production Models in U.S., Canada

NHL Playoffs 2025: With 16 Games in First Six Days, ESPN Deploys Variety of Remo...

17/04/2025

The Ugly Stepsister: A Cinderella Body Horror Story That Will Leave a Crowd in Shambles

Emilie Blichfeldt attends the 2025 Sundance Film Festival premiere of The Ugly ...

17/04/2025

Why Resilient GPS (R-GPS) Matters for US Military Superiority: We Must Address GPS Vulnerabilities

R-GPS gives warfighters a decisive battlefield advantage by punching through adv...

17/04/2025

What NAB told us about the future of media tech

This year's NAB Show in Las Vegas marked a noticeable shift in the priorities of media and broadcast organisations. Gone are the days of chasing flashy, or ...

17/04/2025

Changing Sustainable Production in Wales and Beyond

class=attachment-thumbnail size-thumbnail f-align-center alt= decoding=async data-lazy-srcset=https://www.antonbauer.com/wp-content/uploads/2024/12/Amy-Daniel-1...

17/04/2025

Roku to Collaborate with Adobe on Real-Time Customer Data

SAN JOSE, Calif. Roku and Adobe have announced that they are collaborating on a real time data platform made possible by a a new integration of the Roku Data C...

17/04/2025

IAB: Digital Ad Revenue Surges 14.9% YoY to $259 Billion in 2024

NEW YORK Internet advertising revenues demonstrated strong growth in 2024, increasing 14.9% year-over-year to $258.6 billion, according to the IAB Internet Adv...

17/04/2025

SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show

SDVI Earns Both Product and Project of the Year Awards at 2025 NAB Show Brie Clayton April 17, 2025 0 Comments Left to right, Geoff Stedman, CMO, SDVI...

17/04/2025

Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions with AJA

Singapore Polytechnic Readies Aspiring AV Professionals for Live IP Productions ...

17/04/2025

Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0

Calrec Wins 2025 NAB Show Product of the Year Award for True Control 2.0 Brie Clayton April 17, 2025 0 Comments Image: The Calrec True Control 2.o on ...

17/04/2025

In Return to Berklee, Lucius Looks Back and Moves Forward

In Return to Berklee, Lucius Looks Back and Moves Forward From mood boards to live demos, the alumni band gave students an exclusive look at the process behin...

17/04/2025

MyFree DirecTV Adds 8 NBCU Channels

DirecTV's free streaming service MyFree DirecTV has just added another eight channels from NBCUniversal....

17/04/2025

GameChanger Launches in the U.S.

LOS ANGELES The virtual production company GameChanger has announced that it is expanding its global footprint by bringing its virtual production technology to ...

17/04/2025

IBCAP Launches Automated VOD Monitoring and Takedown System

DENVER The International Broadcaster Coalition Against Piracy (IBCAP) has announced that it has developed a proprietary, automated software-based system to iden...

17/04/2025

Pixalate: Roku Continues to Dominate U.S. CTV Device Market

Pixalate's new CTV Device Market Share report for Q1 2025 shows that Roku has the highest open programmatic CTV device market share in the United States, wi...

17/04/2025

Edward J. Lewis III Named Senior Vice President of Institutional Advancement

Edward J. Lewis III Named Senior Vice President of Institutional Advancement Lewis has more than 20 years of industry experience, leading fundraising initiati...

17/04/2025

The Curling Group Puts On Inaugural Curling All-Star Game in Nashville

The Curling Group Puts On Inaugural Curling All-Star Game in Nashville The location in Music City is intended to broaden the sport's appeal By Dan Daley, ...

17/04/2025

Tribeca Festival 2025 Announces TV and NOW Lineup

April 17th, 2025 Press Materials Available Here Tribeca Festival 2025 Announces TV & NOW Lineup World Premieres and Exclusive Cast Panels with Apple TV '...

17/04/2025

SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clients, How Industry Trends Impact Workflows

SVG Sit-Down: Cisco's Bryan Bedford on Providing End-to-End Support for Clie...