
HP Study Reveals Smartwatches Vulnerable to AttackHP Fortify finds 100 percent of tested smartwatches exhibit security flaws, provides guidance for secure device use
PALO ALTO, Calif., July 22, 2015 As part of an ongoing series looking at Internet of Things (IoT) security, HP today unveiled results of an assessment confirming that smartwatches with network and communication functionality represent a new and open frontier for cyberattack. The study conducted by HP Fortify found that 100 percent of the tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns1. In the report HP provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace.
As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities. As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps may soon enable physical access functions including unlocking cars and homes.
Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities, said Jason Schmitt, general manager, HP Security, Fortify. As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks.
The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built. HP leveraged HP Fortify on Demand to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns.
The most common and easily addressable security issues reported include:
Insufficient User Authentication/Authorization: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication and the ability to lock out accounts after 3-5 failed password attempts. Three in ten, 30 percent, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.
Lack of transport encryption: Transport encryption is critical given that personal information is being moved to multiple locations in the cloud. While 100 percent of the test products implemented transport encryption using SSL/TLS, 40 percent of the cloud connections continue to be vulnerable to the POODLE attack, allow the use of weak cyphers, or still used SSL v2.
Insecure Interfaces: Thirty percent of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30 percent also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.
Insecure Software/Firmware: A full 70 percent of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analyzed.
Privacy Concerns: All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.
As manufacturers work to incorporate necessary security measures into smartwatches, consumers are urged to consider security when choosing to use a smartwatch. It's recommended that users do not enable sensitive access control functions such as car or home access unless strong authorization is offered. In addition, enabling passcode functionality, ensuring strong passwords and instituting two-factor authentication will help prevent unauthorized access to data. These security measures are not only important to protecting personal data, but are critical as smartwatches are introduced to the workplace and connected to corporate networks. Additional guidelines for secure smartwatch use are outlined in the full report.
For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of 10 of the most common IoT devices. In addition, the 2015 HP Home Security Systems Report reviews the 10 of the most common Internet-connected home security systems.
Methodology
Conducted by HP Fortify, the HP Smartwatch Security Study used the HP Fortify on Demand IoT testing methodology which combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category.
All data and percentages for this study were drawn from the 10 smartwatches tested during this study. While there are certainly a fair number of smartwatch devices already on the market, and that number continues to grow, HP believes the similarity in results of the 10 smartwatches provides a good indicator of the current security posture of smartwatch devices.
1 HP Internet of Things Security Report: Smartwatches, HP, July 2015
About HP Security
HP enables organizations to take a proactive approach to security, disrupting the life
Most recent headlines
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
29/04/2025
WASHINGTON The Federal Communications Commission has adopted a new licensing framework and new sharing rules for the lower 37-GHz spectrum band that the agency ...
29/04/2025
WASHINGTON The Federal Communications Commission has unanimously voted to pass a Notice of Proposed Rulemaking that the agency said would codify certain foreign...
29/04/2025
Deity Microphones are excited to add the Deity THEOS DXTX Plug-On Transmitter to the THEOS family. The DXTX is packed full of advanced features designed to enha...
29/04/2025
Origin of life twist: New study challenges longstanding hypothesis on how first sugars formed Scripps Research and Georgia Institute of Technology scientists...
28/04/2025
Podcasts have become a cornerstone of the Spotify experience, evolving from a ni...
28/04/2025
Each April, runners and walkers of all stripes gather together in Lower Manhattan for the 9/11 Memorial & Museum 5K. This race remembers those killed on Septemb...
28/04/2025
MELBOURNE, Fla., April 28, 2025 - L3Harris Technologies (NYSE: LHX) Chief Financial Officer and Aerojet Rocketdyne President Ken Bedingfield will present at Bar...
28/04/2025
HACKENSACK, NJ LiveU, a global provider of live IP-video contribution, production and distribution solutions, has signed a definitive agreement to acquire Actus...
28/04/2025
LiveU, the global leader in live IP-video contribution, production and distribution solutions, has signed a definitive agreement to acquire Actus Digital's ...
28/04/2025
Ikegami Electronics (Europe) will promote the latest additions to its range of broadcast-quality television production equipment at Broadcast Innovation Day (BI...
28/04/2025
Intinor is once again set to collaborate with its UK partner Zest Technologies at MPTS 2025 (Olympia, 14-15 May 2025). Following the recent launch of key update...
28/04/2025
CJP Broadcast, the UK-based systems integrator specialising in virtual production and broadcast studio design, installation, commissioning and support, will ret...
28/04/2025
The media landscape in the Middle East continues to see a rise in OTT platforms, regional content creation, and expanding viewer expectations, which means the d...
28/04/2025
Clear-Com has announced the appointment of StreamPort Media as its authorized distributor in the Middle East. This partnership will expand access to Clear-Com&...
28/04/2025
nxtedition will showcase its unified production platform at CABSAT 2025, featuring advanced AI automation, open-source integrations and a seamless approach to l...
28/04/2025
nxtedition will demonstrate its story-first production platform at MPTS 2025, highlighting integrated AI Agents, open-source language models, and frictionless c...
28/04/2025
Keepit has teamed with Ingram Micro, a leading business-to-business platform company for the global technology ecosystem, to expand access to Keepit's vendo...
28/04/2025
Ross Video, a global leader in video production technology, is participating in CABSAT 2025, taking place at the Dubai World Trade Center.
CABSAT is the leadi...
28/04/2025
Disguise, the leading platform and solutions provider driving the next generation of visual experiences, has appointed Jake Stone as its Senior Vice President o...
28/04/2025
Lightware, a global leader in connectivity and signal management solutions, is set to return to InfoComm 2025 with a dynamic showcase of industry-first innovati...
28/04/2025
arkona technologies GmbH, provider of cutting-edge IP core infrastructure solutions has announced that its EASY-IP platform is the recipient of Future's Bes...
28/04/2025
TMT Insights wrapped up an award-winning NAB 2025 with two of its high-profile customer engagements recognized with Project of the Year Awards: Content Acquisit...
28/04/2025
Fix Format Issues & Enhance Videos 80% Faster with VideoProc AI - Major Update
Brie Clayton April 25, 2025
0 Comments
VideoProc Converter AI just got ...
28/04/2025
New in Premiere Pro and After Effects at NAB 2025 - Larry Jordan with Kylee Pe a...
28/04/2025
The Text Selector Expression is arguably the most elusive Adobe After Effects Fe...
28/04/2025
Master your music for free with a new desktop app from Brainworx
Brie Clayton April 27, 2025
0 Comments
bx_mastering studio promises free streaming-re...
28/04/2025
LiveU Inks Deal to Acquire Actus Digital, Boost Video Monitoring and Analytics C...
28/04/2025
Small Van, Big Story: Changing the Game in Sports Broadcasting with Obvious C By SVG Staff
Monday, April 28, 2025 - 10:51 am
Print This Story | Subscribe ...
28/04/2025
SVG Sit-Down: ESPN's Chris Calcinari on New Flagship Mobile Unit, Cloud and ...
28/04/2025
A Swiss Soccer Summer: Previewing UEFA Women's Euros 2025 with BBC Sport and...
28/04/2025
Monday 28 April 2025
New research from Sky Sports, released today, shows that w...
28/04/2025
Monday 28 April 2025
To view this content, please enable our use of cookies. To...
28/04/2025
After 20 Legendary Seasons Sky is Hanging Up The Boots of its BAFTA-winning Sports Show. Production of farewell series tees off this summerMonday 28 April 2025
...
28/04/2025
Back to All News
Netflix Celebrates the Creative Tapestry of APAC Films at Tokyo Showcase
Entertainment
28 April 2025
GlobalJapanSouth KoreaIndiaThailandInd...
28/04/2025
Back to All News
Get Ready for Netflix Tudum 2025: The Live Event! Watch the Tr...
28/04/2025
As enterprises increasingly adopt AI, securing AI factories - where complex, agentic workflows are executed - has never been more critical.
NVIDIA is bringing ...
28/04/2025
Agentic AI is redefining the cybersecurity landscape - introducing new opportunities that demand rethinking how to secure AI while offering the keys to addressi...
28/04/2025
Oracle has stood up and optimized its first wave of liquid-cooled NVIDIA GB200 N...
27/04/2025
It's with deep regret that we share the passing of our dear friend Bruce Logan, ASC.
Bruce was not just a collaborator-he was family. He worked with us at ...
27/04/2025
Back to All News
KAULITZ & KAULITZ - Launch date and first look for season 2
Entertainment
27 April 2025
GlobalGermany
Link copied to clipboard
KAULITZ & ...
27/04/2025
Back to All News
Senna Wins Best Series Creator Category At The 2025 PLATINO Awards
Entertainment
27 April 2025
GlobalBrazil
Link copied to clipboard
This...
27/04/2025
Back to All News
Masterclass With Creative Team Behind Adolescence Takes Filmma...
26/04/2025
NEW YORK Samsung Ads has debuted a new interactive advertising format, Creative Canvas, that helps automate and deliver interactive ads....
26/04/2025
WEST PALM BEACH, Fla. Sinclair has appointed Vincent J. Sollecito vice president and general manager of WPEC, serving the West Palm Beach, Florida market....
26/04/2025
NEW YORK and DENVER AD-ID and Comcast Technology Solutions (CTS) have announced that they are working together to promote the adoption of industry standards in ...
26/04/2025
Cobalt Scores a Trifecta of Awards at NAB 2025
Brie Clayton April 25, 2025
0 Comments
Company adds another Best of Show and two Product of the Year tr...
26/04/2025
FilmLight Colour Awards welcomes 2025 entries
Brie Clayton April 25, 2025
0 Comments
Entries open from 1 May 31 July to colourists on any grading pl...
26/04/2025
Blackmagic's Latest Products - Larry Jordan Guest Spots with Dan May at NAB ...
25/04/2025
Emily Watson, Isaiah Saxon, Helena Zengel, and Finn Wolfhard at The Legend of Ochi premiere (photo by Soul Brother/Shutterstock for Sundance Film Festival)...