Sony Pixel Power calrec Sony

HP Study Reveals Smartwatches Vulnerable to Attack

22/07/2015

HP Study Reveals Smartwatches Vulnerable to AttackHP Fortify finds 100 percent of tested smartwatches exhibit security flaws, provides guidance for secure device use

PALO ALTO, Calif., July 22, 2015 As part of an ongoing series looking at Internet of Things (IoT) security, HP today unveiled results of an assessment confirming that smartwatches with network and communication functionality represent a new and open frontier for cyberattack. The study conducted by HP Fortify found that 100 percent of the tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns1. In the report HP provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace.

As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities. As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps may soon enable physical access functions including unlocking cars and homes.

Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities, said Jason Schmitt, general manager, HP Security, Fortify. As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks.

The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built. HP leveraged HP Fortify on Demand to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns.

The most common and easily addressable security issues reported include:

Insufficient User Authentication/Authorization: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication and the ability to lock out accounts after 3-5 failed password attempts. Three in ten, 30 percent, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.

Lack of transport encryption: Transport encryption is critical given that personal information is being moved to multiple locations in the cloud. While 100 percent of the test products implemented transport encryption using SSL/TLS, 40 percent of the cloud connections continue to be vulnerable to the POODLE attack, allow the use of weak cyphers, or still used SSL v2.

Insecure Interfaces: Thirty percent of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30 percent also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.

Insecure Software/Firmware: A full 70 percent of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analyzed.

Privacy Concerns: All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.

As manufacturers work to incorporate necessary security measures into smartwatches, consumers are urged to consider security when choosing to use a smartwatch. It's recommended that users do not enable sensitive access control functions such as car or home access unless strong authorization is offered. In addition, enabling passcode functionality, ensuring strong passwords and instituting two-factor authentication will help prevent unauthorized access to data. These security measures are not only important to protecting personal data, but are critical as smartwatches are introduced to the workplace and connected to corporate networks. Additional guidelines for secure smartwatch use are outlined in the full report.

For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of 10 of the most common IoT devices. In addition, the 2015 HP Home Security Systems Report reviews the 10 of the most common Internet-connected home security systems.

Methodology

Conducted by HP Fortify, the HP Smartwatch Security Study used the HP Fortify on Demand IoT testing methodology which combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category.

All data and percentages for this study were drawn from the 10 smartwatches tested during this study. While there are certainly a fair number of smartwatch devices already on the market, and that number continues to grow, HP believes the similarity in results of the 10 smartwatches provides a good indicator of the current security posture of smartwatch devices.

1 HP Internet of Things Security Report: Smartwatches, HP, July 2015

About HP Security

HP enables organizations to take a proactive approach to security, disrupting the life
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=2037386...
See more stories from hp

Most recent headlines

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

29/04/2025

FCC Adopts New Licensing Framework for Lower 37-GHz Band

WASHINGTON The Federal Communications Commission has adopted a new licensing framework and new sharing rules for the lower 37-GHz spectrum band that the agency ...

29/04/2025

FCC Moves to Codify and Streamline Foreign Ownership Regulations

WASHINGTON The Federal Communications Commission has unanimously voted to pass a Notice of Proposed Rulemaking that the agency said would codify certain foreign...

29/04/2025

Deity Microphones Announces the Deity THEOS DXTX

Deity Microphones are excited to add the Deity THEOS DXTX Plug-On Transmitter to the THEOS family. The DXTX is packed full of advanced features designed to enha...

29/04/2025

April 28, 2025

Origin of life twist: New study challenges longstanding hypothesis on how first sugars formed Scripps Research and Georgia Institute of Technology scientists...

28/04/2025

From Audio to Video, Spotify's $100 Million Payout Fuels Creator Success Stories

Podcasts have become a cornerstone of the Spotify experience, evolving from a ni...

28/04/2025

Spotify Lends a Helping Hand to NYC Neighbors, the 9/11 Memorial & Museum

Each April, runners and walkers of all stripes gather together in Lower Manhattan for the 9/11 Memorial & Museum 5K. This race remembers those killed on Septemb...

28/04/2025

L3Harris to Present at Three Upcoming Investor Conferences

MELBOURNE, Fla., April 28, 2025 - L3Harris Technologies (NYSE: LHX) Chief Financial Officer and Aerojet Rocketdyne President Ken Bedingfield will present at Bar...

28/04/2025

LiveU Acquires Actus Digital

HACKENSACK, NJ LiveU, a global provider of live IP-video contribution, production and distribution solutions, has signed a definitive agreement to acquire Actus...

28/04/2025

LiveU Signs Definitive Agreement to Acquire the Business...

LiveU, the global leader in live IP-video contribution, production and distribution solutions, has signed a definitive agreement to acquire Actus Digital's ...

28/04/2025

Ikegami to Demonstrate IPX-100 Compact IP Base Station an...

Ikegami Electronics (Europe) will promote the latest additions to its range of broadcast-quality television production equipment at Broadcast Innovation Day (BI...

28/04/2025

Intinor Partners with Zest Technologies to Present Advanc...

Intinor is once again set to collaborate with its UK partner Zest Technologies at MPTS 2025 (Olympia, 14-15 May 2025). Following the recent launch of key update...

28/04/2025

CJP Broadcast Highlights Scalable Studio Solutions at MPT...

CJP Broadcast, the UK-based systems integrator specialising in virtual production and broadcast studio design, installation, commissioning and support, will ret...

28/04/2025

Interra Systems to Bring Comprehensive Suite of Video QC...

The media landscape in the Middle East continues to see a rise in OTT platforms, regional content creation, and expanding viewer expectations, which means the d...

28/04/2025

StreamPort Media Appointed as Official Distributor for Cl...

Clear-Com has announced the appointment of StreamPort Media as its authorized distributor in the Middle East. This partnership will expand access to Clear-Com&...

28/04/2025

nxtedition to Highlight AI Agents and Intuitive Productio...

nxtedition will showcase its unified production platform at CABSAT 2025, featuring advanced AI automation, open-source integrations and a seamless approach to l...

28/04/2025

nxtedition to Showcase Faster, Smarter, Seamless Storytel...

nxtedition will demonstrate its story-first production platform at MPTS 2025, highlighting integrated AI Agents, open-source language models, and frictionless c...

28/04/2025

Keepit and leading B2B platform company Ingram Micro anno...

Keepit has teamed with Ingram Micro, a leading business-to-business platform company for the global technology ecosystem, to expand access to Keepit's vendo...

28/04/2025

Ross Video to Showcase Hyperconverged Live Production Sol...

Ross Video, a global leader in video production technology, is participating in CABSAT 2025, taking place at the Dubai World Trade Center. CABSAT is the leadi...

28/04/2025

Disguise Appoints Media and Entertainment Leader Jake Sto...

Disguise, the leading platform and solutions provider driving the next generation of visual experiences, has appointed Jake Stone as its Senior Vice President o...

28/04/2025

Lightware Brings its Latest USB-C Innovation and Integrat...

Lightware, a global leader in connectivity and signal management solutions, is set to return to InfoComm 2025 with a dynamic showcase of industry-first innovati...

28/04/2025

EASY IP from arkona technologies Wins Futures Best of Sho...

arkona technologies GmbH, provider of cutting-edge IP core infrastructure solutions has announced that its EASY-IP platform is the recipient of Future's Bes...

28/04/2025

TMT Insights Wins Two Project of the Year Awards at NAB...

TMT Insights wrapped up an award-winning NAB 2025 with two of its high-profile customer engagements recognized with Project of the Year Awards: Content Acquisit...

28/04/2025

Fix Format Issues & Enhance Videos 80% Faster with VideoProc AI - Major Update

Fix Format Issues & Enhance Videos 80% Faster with VideoProc AI - Major Update Brie Clayton April 25, 2025 0 Comments VideoProc Converter AI just got ...

28/04/2025

New in Premiere Pro and After Effects at NAB 2025 - Larry Jordan with Kylee Pea of Adobe

New in Premiere Pro and After Effects at NAB 2025 - Larry Jordan with Kylee Pe a...

28/04/2025

The Text Selector Expression is arguably the most elusive Adobe After Effects Feature and yet it's its most powerful Text Feature

The Text Selector Expression is arguably the most elusive Adobe After Effects Fe...

28/04/2025

Master your music for free with a new desktop app from Brainworx

Master your music for free with a new desktop app from Brainworx Brie Clayton April 27, 2025 0 Comments bx_mastering studio promises free streaming-re...

28/04/2025

LiveU Inks Deal to Acquire Actus Digital, Boost Video Monitoring and Analytics Capabilities

LiveU Inks Deal to Acquire Actus Digital, Boost Video Monitoring and Analytics C...

28/04/2025

Small Van, Big Story: Changing the Game in Sports Broadcasting with Obvious C

Small Van, Big Story: Changing the Game in Sports Broadcasting with Obvious C By SVG Staff Monday, April 28, 2025 - 10:51 am Print This Story | Subscribe ...

28/04/2025

SVG Sit-Down: ESPN's Chris Calcinari on New Flagship Mobile Unit, Cloud and REMI Production, Early Prep for Super Bowl LXI

SVG Sit-Down: ESPN's Chris Calcinari on New Flagship Mobile Unit, Cloud and ...

28/04/2025

A Swiss Soccer Summer: Previewing UEFA Women's Euros 2025 with BBC Sport and Sunset+Vine

A Swiss Soccer Summer: Previewing UEFA Women's Euros 2025 with BBC Sport and...

28/04/2025

New research from Sky Sports looks at the role of Womens sport fandom in the future of sports

Monday 28 April 2025 New research from Sky Sports, released today, shows that w...

28/04/2025

Official trailer released for Sky Documentaries three-part series, Bibaa & Nicole: Murder in the Park, airing 11 May

Monday 28 April 2025 To view this content, please enable our use of cookies. To...

28/04/2025

Victory lap for A League of Their Own

After 20 Legendary Seasons Sky is Hanging Up The Boots of its BAFTA-winning Sports Show. Production of farewell series tees off this summerMonday 28 April 2025 ...

28/04/2025

Netflix Celebrates the Creative Tapestry of APAC Films at Tokyo Showcase

Back to All News Netflix Celebrates the Creative Tapestry of APAC Films at Tokyo Showcase Entertainment 28 April 2025 GlobalJapanSouth KoreaIndiaThailandInd...

28/04/2025

Get Ready for Netflix Tudum 2025: The Live Event! Watch the Trailer for Our Must-See Celebration

Back to All News Get Ready for Netflix Tudum 2025: The Live Event! Watch the Tr...

28/04/2025

NVIDIA Brings Cybersecurity to Every AI Factory

As enterprises increasingly adopt AI, securing AI factories - where complex, agentic workflows are executed - has never been more critical. NVIDIA is bringing ...

28/04/2025

How Agentic AI Enables the Next Leap in Cybersecurity

Agentic AI is redefining the cybersecurity landscape - introducing new opportunities that demand rethinking how to secure AI while offering the keys to addressi...

28/04/2025

Oracle Cloud Infrastructure Deploys Thousands of NVIDIA Blackwell GPUs for Agentic AI and Reasoning Models

Oracle has stood up and optimized its first wave of liquid-cooled NVIDIA GB200 N...

27/04/2025

A Tribute to Bruce Logan, Written By Steve Weiss

It's with deep regret that we share the passing of our dear friend Bruce Logan, ASC. Bruce was not just a collaborator-he was family. He worked with us at ...

27/04/2025

KAULITZ & KAULITZ - Launch date and first look for season 2

Back to All News KAULITZ & KAULITZ - Launch date and first look for season 2 Entertainment 27 April 2025 GlobalGermany Link copied to clipboard KAULITZ & ...

27/04/2025

'Senna' Wins Best Series Creator Category At The 2025 PLATINO Awards

Back to All News Senna Wins Best Series Creator Category At The 2025 PLATINO Awards Entertainment 27 April 2025 GlobalBrazil Link copied to clipboard This...

27/04/2025

Masterclass With Creative Team Behind 'Adolescence' Takes Filmmakers and Emerging Talent Behind the Scenes of Hit Show

Back to All News Masterclass With Creative Team Behind Adolescence Takes Filmma...

26/04/2025

Samsung Ads Launches New Interactive Ad Format

NEW YORK Samsung Ads has debuted a new interactive advertising format, Creative Canvas, that helps automate and deliver interactive ads....

26/04/2025

Sinclair Names Vincent J. Sollecito VP/GM of WPEC

WEST PALM BEACH, Fla. Sinclair has appointed Vincent J. Sollecito vice president and general manager of WPEC, serving the West Palm Beach, Florida market....

26/04/2025

Comcast Technology Solutions, AD-ID Join Forces to Advance Ad Standards

NEW YORK and DENVER AD-ID and Comcast Technology Solutions (CTS) have announced that they are working together to promote the adoption of industry standards in ...

26/04/2025

Cobalt Scores a Trifecta of Awards at NAB 2025

Cobalt Scores a Trifecta of Awards at NAB 2025 Brie Clayton April 25, 2025 0 Comments Company adds another Best of Show and two Product of the Year tr...

26/04/2025

FilmLight Colour Awards welcomes 2025 entries

FilmLight Colour Awards welcomes 2025 entries Brie Clayton April 25, 2025 0 Comments Entries open from 1 May 31 July to colourists on any grading pl...

26/04/2025

Blackmagic's Latest Products - Larry Jordan Guest Spots with Dan May at NAB Las Vegas 2025

Blackmagic's Latest Products - Larry Jordan Guest Spots with Dan May at NAB ...

25/04/2025

The Legend of Ochi Takes Families on an Adventure

Emily Watson, Isaiah Saxon, Helena Zengel, and Finn Wolfhard at The Legend of Ochi premiere (photo by Soul Brother/Shutterstock for Sundance Film Festival)...