Sony Pixel Power calrec Sony

HP Study Reveals 70 Percent of Internet of ings Devices Vulnerable to Attack

29/07/2014

HP Study Reveals 70 Percent of Internet of Things Devices Vulnerable to AttackIoT devices averaged 25 vulnerabilities per product, indicating expanding attack surface for adversaries

PALO ALTO, Calif. - HP today released results of a study revealing 70 percent of the most commonly used Internet of Things (IoT) devices contain vulnerabilities, including password security, encryption and general lack of granular user access permissions.

With the rise of IoT, the number and diversity of connected devices is expected to increase exponentially. According to Gartner, the Internet of Things will include 26 billion units installed by 2020. IoT product and service suppliers will generate incremental revenue exceeding $300 billion, mostly in services, in 2020. (1)

This spike in demand is pushing manufacturers to quickly bring to market connected devices, cloud access capabilities and mobile applications in order to gain share. While this increase in IoT devices promises benefits to consumers, it also opens the doors for security threats ranging from software vulnerabilities to denial-of-service (DOS) attacks to weak passwords and cross-site scripting vulnerabilities.

While the Internet of Things will connect and unify countless objects and systems, it also presents a significant challenge in fending off the adversary given the expanded attack surface, said Mike Armistead, vice president and general manager, Fortify, Enterprise Security Products, HP. With the continued adoption of connected devices, it is more important than ever to build security into these products from the beginning to disrupt the adversary and avoid exposing consumers to serious threats.

HP leveraged HP Fortify on Demand to scan 10 of the most popular IoT devices, uncovering, on average, 25 vulnerabilities per device-totaling 250 security concerns across all tested products. The IoT devices tested-along with their cloud and mobile application components-were from manufacturers of TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.

The most common and easily addressable security issues reported include:

Privacy concerns: Eight of the 10 devices tested, along with their corresponding cloud and mobile application components, raised privacy concerns regarding the collection of consumer data such as name, email address, home address, date of birth, credit card credentials and health information. Moreover, 90 percent of tested devices collected at least one piece of personal information via the product itself, the cloud or its mobile application.

Insufficient authorization: 80 percent of IoT devices tested, including their cloud and mobile components, failed to require passwords of sufficient complexity and length, with most devices allowing password such as 1234. In fact, many of the test accounts HP configured with weak passwords were also used on the products' websites and mobile applications.

Lack of transport encryption: 70 percent of IoT devices analyzed did not encrypt communications to the internet and local network, while half of the devices' mobile applications performed unencrypted communications to the cloud, internet or local network. Transport encryption is crucial given that many of the tested devices collected and transmitted sensitive data across channels.

Insecure web interface: Six of the 10 devices evaluated raised security concerns with their user interfaces such as persistent XSS, poor session management, weak default credentials and credentials transmitted in clear text. Seventy percent of devices with cloud and mobile components would enable a potential attacker to determine valid user accounts through account enumeration or the password reset feature.

Inadequate software protection: 60 percent of devices did not use encryption when downloading software updates, an alarming number given that software powers the functionality of the tested devices. Some downloads could even be intercepted, extracted and mounted as a file system in Linux where the software could be viewed or modified.

To protect against security hazards that come along with the rise of IoT, it is imperative for organizations to implement an end-to-end approach to identify software vulnerabilities before they are exploited. Solutions like HP Fortify on Demand enable organizations to test the security of software quickly, accurately, affordably and without any software to install or manage-proactively eliminating the immediate risk in legacy applications and the systemic risk in application development.

Methodology

Conducted by HP Fortify and leveraging HP Fortify on Demand, the Internet of Things Security: State of the Union study tested 10 of the most commonly used IoT devices for vulnerabilities using standard testing techniques that combined manual testing along with the use of automated tools. Devices and their cloud, network and client application components were assessed based on the OWASP Internet of Things Top 10 list and the specific vulnerabilities associated within each category.

Additional information about application security and further details resulting from the study are available at hp.com/go/fortifyresearch/iot.

HP will be addressing the latest trends in enterprise security at the Black Hat USA 2014 conference, taking place Aug. 2-7 in Las Vegas. Visit the HP booth (No. 911) for an IoT product demo and Capture the Flag hacking contest. Additional information on HP's presence at the show can be found here.

(1) Gartner, Forecast: The Internet of Things, Worldwide, 2013, November 2013.

2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the e
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1744676...
See more stories from hp

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

06/09/2026

Dolby and MagentaTV Bring Fans Closer to the FIFA World Cup 2026 in Germany with Dolby Vision and Dolby Atmos

June 9 2026, 23:00 (PDT) Dolby and MagentaTV Bring Fans Closer to the FIFA Worl...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

27/06/2026

Through Their Lens: What Cinematographer Amy Vincent Saw at the 2026 Directors Lab

There's no doubt that you've seen the world through Amy Vincent's ey...

27/06/2026

UJAM release Retrocraft

Brings together saturation & lo-fi effects Following on from the release of their Voxcraft vocal-processing plug-in, UJAM have announced the launch of Retro...

27/06/2026

A record 4.84 million Australians choose SBS as the Socceroos advance at FIFA World Cup 2026

A record 4.84 million Australians choose SBS as the Socceroos advance at FIFA Wo...

27/06/2026

Apogee CRAS Symphony Mkii Education Feature Blog

Why CRAS Upgraded to Symphony I/O MK II When an audio school runs studios all day, every day, gear doesn't just need to sound good , it needs to survive rea...

27/06/2026

MultiDyne Acquires the Assets of MRMC

Share Copy link Facebook X Linkedin Bluesky Email...

27/06/2026

Spectrum Intelligence Ventures Launches Latis

Share Copy link Facebook X Linkedin Bluesky Email...

27/06/2026

Krotos Video to Sound Plugin Now Available for Adobe Premiere Pro

Krotos Video to Sound Plugin Now Available for Adobe Premiere Pro Brie Clayton June 26, 2026 0 Comments Editors can analyze footage, generate synchron...

27/06/2026

Mirai Media Elevates Digital and Broadcast Productions with Blackmagic Design

Mirai Media Elevates Digital and Broadcast Productions with Blackmagic Design Brie Clayton June 26, 2026 0 Comments Studio uses Ultimatte 12 HD and Po...

27/06/2026

Lutra Cafe & Bakery Opens At American Tobacco Campus

DURHAM, N.C. - JUNE 26, 2026 - Lutra Cafe & Bakery has opened its first brick-and-mortar location at American Tobacco Campus after owner Chris McLaurin operated...

26/06/2026

SVG GameDay, Ep. 21: Minnesota Vikings Allan Wertheimer - Large-Scale Shows in Minny

In-venue and creative video staffers at the professional and collegiate level ha...

26/06/2026

Strike Fighter League Announces Second Online Tournament, Set for July 25 in Las Vegas

Strike Fighter League (SFL), a professional air combat digital sport combining f...

26/06/2026

InfoComm 2026: Wisycom Announces MPR60 Firmware Update, MATF Antenna Matrix, and PFL RFoF Box

Wisycom has announced three new additions to its professional wireless ecosystem...

26/06/2026

Eurovision Services Inaugurates Expanded Master Control Room in Madrid

Eurovision Services inaugurated an expanded Master Control Room (MCR) in Madrid on June 1, 2026, building on a broadcast hub the company has operated in the cit...

26/06/2026

Midco Sports and University of North Dakota Renew Broadcast and Sponsorship Partnership

Midco Sports and the University of North Dakota (UND) have announced a two-year ...

26/06/2026

G&D and VuWall Appoint Vutec as Exclusive South Africa Distributor

Guntermann and Drunck (G&D) and VuWall, both part of the Panoptec Technologies Group, have appointed Vutec (Pty) Ltd as exclusive distributor for their KVM and ...

26/06/2026

Visit Seattle Launches Drone Scoreboard at Space Needle for FIFA World Cup 2026

Visit Seattle, the official destination marketing organization for Seattle and King County, has launched what it describes as the world's first drone scoreb...

26/06/2026

CP Communications Provides RF and Wireless Support for 2026 NBA Draft at Barclays Center

CP Communications provided RF video, audio, and crew communications support for ...

26/06/2026

Reimagined MoonPay X Games League Kicks Off With Three-Day Event in Sacramento

Produced by longtime partner Echo Entertainment, the action-sports property is now a team-based year-round league The inaugural season of the MoonPay X Games L...

26/06/2026

MultiDyne Acquires MRMC, Expands into Camera Robotics and Motion Control

The deal establishes MultiDyne Robotics and Motion Control, maintaining the well-known MRMC brand.MultiDyne Video & Fiber Optic Systems has acquired the assets ...

26/06/2026

TNT Sports Heads Into Year 2 of NASCAR Return With New NEP Truck, Expanded In-Car Experience

PX1 will debut at Sonoma as TNT leans into super-slo-mo, drones, SMT data integr...

26/06/2026

Ratings Roundup: USMNT-Australia Draws 23M Viewers; Mexico-South Korea Is Most-Watched Spanish-Language Soccer Match Ever

Ratings Roundup is a rundown of recent rating news and is derived from press rel...

26/06/2026

David Kuckhermann brings calabash to Celemony Tonalic

Virtual session musician plug-in gains new percussion options Celemony's latest update for their virtual session musician platform complements the exist...

26/06/2026

Softube unveil the Console 1 Compact

Half-size model joins Console 1 line-up Shortly after the release of their new Flow Studio controller, Softube have announced the launch of another new surf...

26/06/2026

ELT Group and Rohde & Schwarz sign a cooperation agreement to explore commercial opportunities in electromagnetic warfare and defense

ELT Group and Rohde & Schwarz sign a cooperation agreement to explore commercial...

26/06/2026

Lightware Powers Teddy Swims UK And Europe Tour With Adva...

For Teddy Swims sold-out I've Tried Everything But Therapy tour, event technology specialists, PRG, provided video, automation and lighting across 19 date...

26/06/2026

Taurus TPN powers AV workflows at NurnbergMesse

Modern exhibition and event venues face the challenge of seamlessly integrating traditional conference technology, professional broadcast workflows and IP-based...

26/06/2026

FCC Adopts New Cybersecurity Requirements for Alerting Systems

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Study: Roku Most Used But Not Highest Rated Streaming Platform

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Samsung Ads Announces First Shoppable CTV Partners

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Gray Media Names Annie Cordell General Manager of WMBF

Share Copy link Facebook X Linkedin Bluesky Email...

26/06/2026

Neko Oji: The Guy That Got Reincarnated as a Cat Edited with DaVinci Resolve Studio

Neko Oji: The Guy That Got Reincarnated as a Cat Edited with DaVinci Resolve Stu...

26/06/2026

Adobe to Acquire Topaz Labs

Adobe to Acquire Topaz Labs Brie Clayton June 25, 2026 0 Comments Adobe has seen strong demand for its AI products for creatives, including Adobe Fire...

26/06/2026

Berklee Students Earn Dedicated Section at Raindance Film Festival in London

Berklee Students Earn Dedicated Section at Raindance Film Festival in London Five documentary short films produced in the Africana Studies Department screen a...

26/06/2026

Keeping Pace with the Race

How IMS Productions and FOX Sports scaled coverage of the 109th Indianapolis 500. The last lap of this year's Indianapolis 500 delivered the kind of ending...

26/06/2026

Prison Wives of TikTok is Locked In for U and U&W

Flicker Productions to produce five-part docu-reality series following women who have fallen for men in prison and have become TikTok sensations, with brands an...

26/06/2026

Automating post-production workflows with Baselight, Daylight, Nara & FilmLight API. New York. 8 July 2026

Catch up on the latest developments across Baselight and Daylight v7, Nara and F...

26/06/2026

DFT installs second Polar HQ at China News Film Confirming Position as China's Leading 8K Film Preservation Partner

26. June 2026 News DFT is pleased to announce that a second Polar HQ film s...

26/06/2026

New documentary Freedom Founder: Thomas McKean and the American Revolution comes to RT

New documentary Freedom Founder: Thomas McKean and the American Revolution airs ...

25/06/2026

Launching a Career in Broadcast Engineering: Academic Paths and Essential Certifications

Launching a Career in Broadcast Engineering: Academic Paths and Essential Certif...

25/06/2026

SVG Students To Watch: Jude Kieffer, Ball State University

This superstar shooter/storyteller from Central Indiana hopes to make his mark in the blossoming sports-documentary and -features space In the live-sports-vid...

25/06/2026

Presidio and NHL Renew Multiyear North American Technology Partnership

Presidio and the National Hockey League have announced a multiyear renewal of their North American partnership. Presidio will remain an Official Technology Inno...

25/06/2026

Strike Fighter League Hits the Industry as First Professional Air Combat Sport

Strike Fighter League (SFL) is the world's first professional air combat digital sport that combines elite human performance and physical immersion with cut...

25/06/2026

Rise Reveals 2026 Worldwide Mentoring Cohorts to Support Future Industry Leaders

Rise, the award-winning advocacy group for gender diversity in the broadcast and media technology sector, is pleased to announce the global mentoring cohort for...

25/06/2026

MLB Network To Air American Association of Professional Baseball All-Star Game for First Time on July 15

The 2026 American Association of Professional Baseball (AAPB) All-Star Game will...

25/06/2026

Mediaproxy Partners with HVS for U.S. Broadcast Market

Mediaproxy has named Heartland Video Systems (HVS) as its exclusive partner for US television broadcasting. The Wisconsin-based systems integrator will represen...

25/06/2026

Backblaze Inks Five-Year Multi-Exabyte Data Storage Agreement with CoreWeave

Backblaze has formed an agreement with CoreWeave to create The Essential Cloud for AI. Under the multi-exabyte, $335 million agreement, Backblaze will provide...