Sony Pixel Power calrec Sony

HP Study Finds Alarming Vulnerabilities with Internet of ings (IoT) Home Security Systems

10/02/2015

HP Study Finds Alarming Vulnerabilities with Internet of Things (IoT) Home Security SystemsHP Fortify OnDemand finds that 100 percent of top security systems studied display significant security deficiencies

PALO ALTO, Calif., February 10, 2015 HP today released results of a security testingstudy revealing that owners of Internet-connected home security systems may not be the only ones monitoring their homes. The study found that 100 percent of the studied devices used in home security contain significant vulnerabilities, including password security, encryption and authentication issues.

Home security systems, such as video cameras and motion detectors, have gained popularity as they have joined the booming Internet of Things (IoT) market and have grown in convenience. Gartner, Inc. forecasts that 4.9 billion connected things will be in use in 2015, up 30 percent from 2014, and will reach 25 billion by 2020.(1) The new HP study reveals how ill-equipped the market is from a security standpoint for the magnitude of growth expected around IoT.

Manufacturers are quickly bringing to market connected security systems that deliver remote monitoring capabilities. The network connectivity and access necessary for remote monitoring presents new security concerns that did not exist for the previous generation of systems that have no internet connectivity.

The HP study questions whether connected security devices actually make our homes safer or put them at more risk by providing easier electronic access via insecure IoT products. HP leveraged HP Fortify on Demand to assess 10 home security IoT devices along with their cloud and mobile application components, uncovering that none of the systems required the use of a strong password and 100 percent of the systems failed to offer two-factor authentication.

The most common and easily addressable security issues reported include:

Insufficient authorization: All systems that included their cloud-based web interfaces and mobile interfaces failed to require passwords of sufficient complexity and length with most only requiring a six character alphanumeric password. All systems also lacked the ability to lock out accounts after a certain number of failed attempts.

Insecure Interfaces: All cloud-based web interfaces tested exhibited security concerns enabling a potential attacker to gain account access through account harvesting which uses three application flaws; account enumeration, weak password policy and lack of account lockout. Similarly five of the ten systems tested exhibited account harvesting concerns with their mobile application interface exposing consumers to similar risks.

Privacy Concerns: All systems collected some form of personal information such as name, address, date of birth, phone number and even credit card numbers. Exposure of this personal information is of concern given the account harvesting issues across all systems. It is also worth noting that the use of video is a key feature of many home security systems with viewing available via mobile applications and cloud-based web interfaces. The privacy of video images from inside the home becomes an added concern.

Lack of transport encryption: While all systems implemented transport encryption such as SSL/TLS, many of the cloud connections remain vulnerable to attacks (e.g. POODLE attack). The importance of properly configured transport encryption is especially important since security is a primary function of these systems.

As we continue to embrace the convenience and availability of connected devices, we must understand how vulnerable they could make our homes and families, said Jason Schmitt (@raidschmitt), vice president and general manager, Fortify, Enterprise Security Products (@HPsecurity), HP. With ten of the top security systems lacking fundamental security features, consumers must be diligent about adopting simple and practical security measures when they're available, and device manufacturers must take ownership in building security into their products to avoid exposing their customers unknowingly to serious threats.

As IoT product manufacturers work to incorporate much needed security measures, consumers are urged to consider security when choosing a monitoring system for their home. Implementing secure home networks before adding insecure IoT devices, instituting complex passwords, account lockouts and two-factor authentication are only a few measures consumers can take to make their IoT experience more secure. Legislators are also getting involved, with the U.S. Federal Trade Commission releasing a recent report analyzing the balance between security and privacy concerns with development of the IoT devices.

For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of the top 10 most common IoT devices. Additionally, the most recent HP Security Briefing, Episode 20: The Internet of Things: A Security Overview looks at how the advent of millions of connected devices affects network security from a practical standpoint.

Methodology

Conducted by HP Fortify and leveraging HP Fortify on Demand, HP's Home Security Systems study tested 10 of the most commonly used home security IoT devices for vulnerabilities using standard security testing techniques that combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category. The resulting data and percentages in this report were drawn from the 10 IoT systems tested. Given the popularity and similarity among the 10 devices, HP Fortify believes the results provide a good indicator of where the market currently stands as it relates to security and the Internet of Things.

Additio
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1909050...
See more stories from hp

Most recent headlines

09/11/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

06/10/2025

France Tlvisions Wins Prestigious 2025 EBU Technology & Innovation Award in Groundbreaking Collaboration with Dalet

France T l visions, France's leading broadcaster, has received the 2025 EBU ...

13/09/2025

Cox Media Group's Misti Turnbull Inducted into the NATAS Silver Circle

ATLANTA Cox Media Group has announced that the company's vice president of news, Misty Turnbull has been inducted into the National Academy of Television Ar...

13/09/2025

Shotoku Debuts Swoop Cranes for Studio Robotics at IBC2025

AMSTERDAM Shotoku Broadcast Systems, a major developer of robotic systems, has announced plans to take studio robotics to the next level at IBC2025 by debuting ...

13/09/2025

Riedel Unveils Ultra-Light Bolero Mini Wireless Intercom...

At IBC2025 in Amsterdam, Riedel Communications unveiled Bolero Mini, the company's lightest and flattest wireless intercom beltpack to date. Designed to del...

13/09/2025

Shotoku Takes Studio Robotics to New Heights with IBC Deb...

Shotoku Broadcast Systems, the international developer of dependable, userfriendly robotic systems, is taking studio robotics to the next level at IBC 2025 with...

13/09/2025

The Bitmovin Video Developer Report 2025-26 Reveals Cost...

Bitmovin, a leading provider of video streaming solutions, today released the 9th annual Video Developer Report 2025/26, offering an in-depth look at the evolvi...

13/09/2025

Bitmovin and StreamShark Partner to Deliver High Quality...

Bitmovin, the leading provider of video streaming solutions, today announced a strategic partnership with StreamShark, the trusted video platform for enterprise...

13/09/2025

Ikegami Announces VFE-P711AD 7-inch OLED Multiformat On-C...

Ikegami has chosen IBC 2025 in Amsterdam as the launch venue for a major addition to its range of viewfinders. The new VFE-P711AD is a 7-inch high resolution OL...

13/09/2025

KitBash3D and Greyscalegorilla Announce Merger

Founder-led Merger to Fast Track R&D, Asset Library Upgrades, Tools and More; No Disruption to Pricing or Support for Users Today, KitBash3D, a pioneer in 3D a...

13/09/2025

Mavis Puts Itself at the Heart of Mobile Production

With NDI certification, Atomos integration, Grass Valley collaboration, and a new Monitor app, at this year's IBC, Mavis is showcasing a series of powerful...

13/09/2025

Creamsource Expands Vortex Family with Vortex24 Soft

Creamsource, maker of artisan LED lighting for film and television, has unveiled the Vortex24 Soft (V24S), a 1950W native soft light and the largest soft source...

13/09/2025

DAZN streams 2025 FIFA Club World Cup to billions of fans...

When international sports streaming service DAZN secured the global rights to the 2025 FIFA Club World Cup football tournament, it set out to deliver an unmatch...

13/09/2025

Riedel Communications Acquires hi human interface

Riedel Communications today announced the acquisition of hi human interface from Broadcast Solutions, bringing a powerful, vendor-agnostic control system to it...

13/09/2025

RTW chooses Calrec as technology partner for its AI ready...

Building on its long-term relationship with audio metering specialist RTW, Calrec has integrated the company's brand new TMxCore metering platform across it...

13/09/2025

Calrec unveils 48 fader Argo M at IBC2025 and demonstrate...

Calrec is expanding its family of future-ready self-contained Argo M control surfaces at IBC2025, with the addition of a brand new powerful 48-fader console. Co...

13/09/2025

Reaching Across the Isles: UK-LLM Brings AI to UK Languages With NVIDIA Nemotron

Celtic languages - including Cornish, Irish, Scottish Gaelic and Welsh - are the U.K.'s oldest living languages. To empower their speakers, the UK-LLM sover...

13/09/2025

SKY Perfect Modernizes Playout-to-Delivery with Harmonic

Harmonic's Software-Based XOS Advanced Media Processor Provides Unparalleled Efficiency and Unlocks New Business Models SAN JOSE, Calif. - Sept. 13, 2025 -...

13/09/2025

September 11, 2025

Researchers find brain region that fuels compulsive drinking Study by Scripps Research scientists shows how the brain learns to seek alcohol for relief, not jus...

12/09/2025

College Football Kickoff 2025: Fox Sports Ups Look as Canon, Sony Power Shallow Focus Coverage

College Football Kickoff 2025: Fox Sports Ups Look as Canon, Sony Power Shallow ...

12/09/2025

ABC/ESPN Excited For WNBA Postseason Coverage In Revamped Format

ABC/ESPN Excited For WNBA Postseason Coverage In Revamped FormatThe Finals moves to a best-of-seven series in 2025By Mark J Burns, SVG Contributor Friday, Sep...

12/09/2025

Rabbit Trap Pulsates With Folklore Dread

(L-R) Jade Croot, Rosy McEwen, and Bryn Chainey attend the 2025 Sundance Film Festival premiere of Rabbit Trap at Eccles Theatre on January 24, 2025, in Park ...

12/09/2025

Spotify's The Drop Weekly' Brings You the Week in New Releases, Straight From Our Editors

For fans, we know how important it is to stay plugged into music culture and dis...

12/09/2025

Agama and Consult Red announce RDK Accelerator integration

Link ping, Sweden and Shipley, United Kingdom, September 12, 2025 - Agama, the expert in video observability and analytics for service quality and customer expe...

12/09/2025

IBC2025 Opens for Business

IBC2025 began on Sept. 12, with exhibits and conferences running through Sept. 15 at the RAI Amsterdam Convention Center. Explore the full TV Tech coverage of t...

12/09/2025

The Best Fictional Bands (and the Artists Who Make Them Great)

The Best Fictional Bands (and the Artists Who Make Them Great) With Spinal Tap II: The End Continues hitting theaters and songs from KPop Demon Hunters ruling...

12/09/2025

Tom Baldassare Joins Advanced Systems Group

Industry veteran Tom Baldassare has joined Advanced Systems Group, LLC (ASG), a technology and services provider for media creatives and content owners, as a Se...

12/09/2025

Maxon Unveils a Brand New Look for its Growing Family of...

Maxon, maker of powerful, approachable software solutions for creators working in 2D and 3D design, motion graphics, visual effects, and more, today announced a...

12/09/2025

PlayBox Neo US Partners with AI-Media to Deliver Scalable...

PlayBox Neo, a leading provider of media playout solutions, has partnered with AI-Media, pioneering developers of AI-powered captioning technology, to integrate...

12/09/2025

Dalet Unveils Agentic AI Media Workflows at IBC2025

Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...

12/09/2025

Keepit and Ingram Micro launch strategic sales agreement...

New alliance strengthens the IT channel in Germany and Switzerland in protecting business-critical SaaS data. Keepit, the world s only independent, cloud-nativ...

12/09/2025

Mediaset selects Fincons Group AllRights to evolve rights...

Fincons Group, an international IT business consultancy and systems integrator company with more than 40 years of experience in the market, is proud to announce...

12/09/2025

EVS Acquires XD motion

Following its acquisition of Telemetrics, EVS continues its push into robotics with an announcement at IBC2025 that it is acquiring XD motion....

12/09/2025

Televisa Executive Joins NABA Board

TORONTO The North American Broadcasters Association (NABA) has announced the appointment of Eduardo Ruiz Sanchez, deputy director, broadcast operations at Telev...

12/09/2025

Ed Miller, Former SBE President, Has Died

Ed Miller, a longtime broadcast engineer in Ohio and a former national president of the Society of Broadcast Engineers, has died....

12/09/2025

IBC2025: Dynamic HDR Gains Traction

AMSTERDAM At this year's IBC2025, the Advanced HDR by Technicolor initiative will be pushing broadcasters to adopt a more dynamic, frame-by-frame conversion...

12/09/2025

Granville opens up one last time for U&GOLD in Open All Hours: Inside Out

Feature-length retrospective from Studio Crook to air in 2026 Sir David Jason returns to the nation's favourite comedy channel, U&GOLD, for Open All Hours:...

12/09/2025

Bob Geldof to receive Lifetime Achievement Award at the Sky Arts Awards 2025

Friday 12 September 2025 The Boomtown Rats, Nyah Grace, Soweto Kinch, Royal Ballet and Madness also announced to perform at the ceremony on Tuesday Sky today ...

12/09/2025

Riedel Unveils Ultra-Light Bolero Mini Wireless Intercom Beltpack

Wuppertal September 12, 2025 Riedel Unveils Ultra-Light Bolero Mini Wireless Intercom BeltpackAt IBC2025 in Amsterdam, Riedel Communications unveiled Bolero M...

12/09/2025

Riedel Communications Acquires hi human interface

Wuppertal September 12, 2025 Riedel Communications Acquires hi human interfaceRiedel Communications today announced the acquisition of hi human interface fro...

12/09/2025

New International Crime Series Road (WT)' Explores Twisted Murders Across Borders

Back to All News New International Crime Series Road (WT)' Explores Twiste...

12/09/2025

First Look: Thai Crime Drama Everybody Loves Me When I'm Dead' Premieres October 14

Back to All News First Look: Thai Crime Drama Everybody Loves Me When I'm ...

12/09/2025

Netflix Marks 10 Years in Japan, Announces Three New Series That Will Keep You Hitting The Next Episode

Back to All News Netflix Marks 10 Years in Japan, Announces Three New Series Th...

12/09/2025

What Is CORE+ Technologyand How Does It Elevate Church Sound?

CORE+ virtually removes distortion, setting a new standard for church sound and giving worship teams the clarity and confidence they need. Read the full artic...

12/09/2025

Margot Robbie, Colin Farrell, Mary Robinson and Conor Murray amongst guests on Late Late Show season opener

The Late Late Show is back with a bang after the summer break, and Patrick Kielt...

12/09/2025

Another jam-packed weekend of live, free-to-air Sport across RT

The World Athletics Championships, Ireland v France in the Women's Rugby World Cup quarter-final, the Irish Champions Festival, and two Sports Direct Men...

12/09/2025

Katie Hannon explores the shelves of Ireland's National Archives in new series

The Records Show starts Sunday at 6.30pm on RT One and RT Player. Katie Hanno...

11/09/2025

Report: Busy Live Sports Streaming Execs Have Low-hanging Fruit' in Front of Them

Report: Busy Live Sports Streaming Execs Have Low-hanging Fruit' in Front o...

11/09/2025

Inside Game Creek Video's Big Week as Ovation, Flagship Make NFL Debuts

Inside Game Creek Video's Big Week as Ovation, Flagship Make NFL DebutsBy Ken Kerschbaumer, Editorial Director Thursday, September 11, 2025 - 7:00 am Pr...