Sony Pixel Power calrec Sony

HP Study Reveals 70 Percent of Internet of ings Devices Vulnerable to Attack

29/07/2014

HP Study Reveals 70 Percent of Internet of Things Devices Vulnerable to AttackIoT devices averaged 25 vulnerabilities per product, indicating expanding attack surface for adversaries

PALO ALTO, Calif. - HP today released results of a study revealing 70 percent of the most commonly used Internet of Things (IoT) devices contain vulnerabilities, including password security, encryption and general lack of granular user access permissions.

With the rise of IoT, the number and diversity of connected devices is expected to increase exponentially. According to Gartner, the Internet of Things will include 26 billion units installed by 2020. IoT product and service suppliers will generate incremental revenue exceeding $300 billion, mostly in services, in 2020. (1)

This spike in demand is pushing manufacturers to quickly bring to market connected devices, cloud access capabilities and mobile applications in order to gain share. While this increase in IoT devices promises benefits to consumers, it also opens the doors for security threats ranging from software vulnerabilities to denial-of-service (DOS) attacks to weak passwords and cross-site scripting vulnerabilities.

While the Internet of Things will connect and unify countless objects and systems, it also presents a significant challenge in fending off the adversary given the expanded attack surface, said Mike Armistead, vice president and general manager, Fortify, Enterprise Security Products, HP. With the continued adoption of connected devices, it is more important than ever to build security into these products from the beginning to disrupt the adversary and avoid exposing consumers to serious threats.

HP leveraged HP Fortify on Demand to scan 10 of the most popular IoT devices, uncovering, on average, 25 vulnerabilities per device-totaling 250 security concerns across all tested products. The IoT devices tested-along with their cloud and mobile application components-were from manufacturers of TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.

The most common and easily addressable security issues reported include:

Privacy concerns: Eight of the 10 devices tested, along with their corresponding cloud and mobile application components, raised privacy concerns regarding the collection of consumer data such as name, email address, home address, date of birth, credit card credentials and health information. Moreover, 90 percent of tested devices collected at least one piece of personal information via the product itself, the cloud or its mobile application.

Insufficient authorization: 80 percent of IoT devices tested, including their cloud and mobile components, failed to require passwords of sufficient complexity and length, with most devices allowing password such as 1234. In fact, many of the test accounts HP configured with weak passwords were also used on the products' websites and mobile applications.

Lack of transport encryption: 70 percent of IoT devices analyzed did not encrypt communications to the internet and local network, while half of the devices' mobile applications performed unencrypted communications to the cloud, internet or local network. Transport encryption is crucial given that many of the tested devices collected and transmitted sensitive data across channels.

Insecure web interface: Six of the 10 devices evaluated raised security concerns with their user interfaces such as persistent XSS, poor session management, weak default credentials and credentials transmitted in clear text. Seventy percent of devices with cloud and mobile components would enable a potential attacker to determine valid user accounts through account enumeration or the password reset feature.

Inadequate software protection: 60 percent of devices did not use encryption when downloading software updates, an alarming number given that software powers the functionality of the tested devices. Some downloads could even be intercepted, extracted and mounted as a file system in Linux where the software could be viewed or modified.

To protect against security hazards that come along with the rise of IoT, it is imperative for organizations to implement an end-to-end approach to identify software vulnerabilities before they are exploited. Solutions like HP Fortify on Demand enable organizations to test the security of software quickly, accurately, affordably and without any software to install or manage-proactively eliminating the immediate risk in legacy applications and the systemic risk in application development.

Methodology

Conducted by HP Fortify and leveraging HP Fortify on Demand, the Internet of Things Security: State of the Union study tested 10 of the most commonly used IoT devices for vulnerabilities using standard testing techniques that combined manual testing along with the use of automated tools. Devices and their cloud, network and client application components were assessed based on the OWASP Internet of Things Top 10 list and the specific vulnerabilities associated within each category.

Additional information about application security and further details resulting from the study are available at hp.com/go/fortifyresearch/iot.

HP will be addressing the latest trends in enterprise security at the Black Hat USA 2014 conference, taking place Aug. 2-7 in Las Vegas. Visit the HP booth (No. 911) for an IoT product demo and Capture the Flag hacking contest. Additional information on HP's presence at the show can be found here.

(1) Gartner, Forecast: The Internet of Things, Worldwide, 2013, November 2013.

2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the e
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1744676...
See more stories from hp

Most recent headlines

06/10/2025

France Tlvisions Wins Prestigious 2025 EBU Technology & Innovation Award in Groundbreaking Collaboration with Dalet

France T l visions, France's leading broadcaster, has received the 2025 EBU ...

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

30/08/2025

FCC Slightly Raises Regulatory Fees for TV Stations

WASHINGTON The Federal Communications Commission has adopted its FY 2025 Regulatory Fees Order that establishes the regulatory fee rates for the broadcast stati...

29/08/2025

Australian Red Cross and SBS launch training to help workplaces in the fight against Modern Slavery

Australian Red Cross and SBS launch training to help workplaces in the fight aga...

29/08/2025

Call for entries is now open for the 19th Annual South African Film & Television Awards (SAFTAs19)

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

29/08/2025

L3Harris Launches Counter-Unmanned Systems Initiative

L3Harris Technologies has concentrated decades of expertise across the entire enterprise to develop affordable and reliable best-of-breed solutions to rapidly c...

29/08/2025

The CW Network Extends Pac-12 Deal Through 2030-31 Season

BURBANK, Calif. The CW Network and the Pac-12 Conference have announced a new media rights deal that will extend their broadcast partnership beginning with the ...

29/08/2025

Global FAST Channel Count Continues to Spike

NEW YORK Gracenote has released a new analysis of its global video dataset showing that the number of FAST channels grew nearly 14% from Q1 2025 and 76% since 2...

29/08/2025

Harmonic Unveils New Capabilities for Its Live Sports Streaming Solution

SAN JOSE, Calif. Harmonic has announced a series of improvements to its live sports streaming solution that the company said will improve fan engagement, protec...

29/08/2025

Youtube TV, Fox Settle Differences, Renew Carriage Agreement

NEW YORK and LOS ANGELES Fox Corp. and YouTube TV last night announced a renewal of the full portfolio of Fox networks, including Fox News Channel, Fox Business...

29/08/2025

Lightware MTR integration brings advanced flexibility and...

Budapest, Hungary, August 2025 - The integration of Microsoft Teams Rooms (MTR) with Lightware's Taurus universal matrix switchers delivers a new level of f...

29/08/2025

Frequency Launches Studio Live - a Unified Platform to Br...

Frequency, the engine behind many of the world's best-known streaming television channels, today announced it will launch Studio Live, a next-generation uni...

29/08/2025

Scality Day 2025 Celebrating 10 years of global innovatio...

In an era when AI and cyber resilience are essential, Scality will mark the 10th anniversary of Scality Day on October 16, 2025 in Paris. This flagship global e...

29/08/2025

Disguise Drives New Immersive Racing Experience - F1 Box

Disguise's In-House Creative and Technical Teams Pre-Visualised, Programmed and Delivered Content for the Experience, All Powered by EX 3+ Technology solu...

29/08/2025

Disguise Supports Fellow Entertainment Tech Leaders at IB...

Disguise will be demonstrating the latest workflows for TV, film and live events on a number of partner booths at the show Disguise, the industry-leading tech...

29/08/2025

Accedo to Highlight Compose AI-Agent Enhanced Orchestration Layer

STOCKHOLM, Sweden Accedo will showcase Accedo Compose, its AI agent-powered modular orchestration layer that assists streaming providers in transitioning client...

29/08/2025

Cineverse Launches Streaming Apps for In-Vehicle Video Streaming

LOS ANGELES Cineverse has announced that it is working with Xperi to bring four of its streaming channels to automobiles for the first time as part of the DTS A...

29/08/2025

Gray Media to Simulcast 17 Dallas Stars NHL Games

DALLAS & ATLANTA Gray Media has announced an agreement with the sports streaming service Victory+ to simulcast 17 Dallas Stars NHL games in 15 television market...

29/08/2025

Comcast NBCU and Amazon Ink New Distribution Agreements

NEW YORK AND CULVER CITY Comcast NBCUniversal and Amazon have announced new and extended distribution agreements that will expand the content available on their...

29/08/2025

RED Digital Cinema To Highlight Cine-Broadcast Module At IBC2025

FOOTHILL RANCH, Calif. RED Digital Cinema will feature its Cine-Broadcast Module supporting live broadcast workflows during IBC2025, Sept. 12-15, at the RAI Ams...

29/08/2025

Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and Highlighting Ukraine's Investment Case

29 Aug 2025 Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and ...

29/08/2025

Sky Sports to show more NFL games than ever as part of new rights agreement

More than half of all NFL games live on Sky for the first timeFriday 29 August 2025 Sky Sports has announced a new three-year deal with the NFL, extending its ...

29/08/2025

'RIV4LRIES': The Trailer of the New Series With Samuele Carrino Only on Netflix October 1

Back to All News RIV4LRIES: The Trailer of the New Series With Samuele Carrino ...

29/08/2025

Steps ahead: RT to air inspiring documentary on 12-year-old Irish dance star

Get ready for an inspiring and emotional insight into the world of competitive Irish dancing with My Story: Tomi Champion of the World airing on RT 2 this monda...

29/08/2025

TODAY WITH DAVID MCCULLAGH TO AIR ON RT RADIO 1 WEEKDAYS AT 10AM

RT has today announced that David McCullagh is to be the new presenter of RT Radio 1's flagship Today programme, which airs every weekday at 10am, replaci...

28/08/2025

Meet the 2025 Sundance Institute Documentary Edit Residency Artists

By Kristin Feeley, Director, Documentary Film & Artist Programs If you want to tell untold stories, if you want to give voice to the voiceless, you've got ...

28/08/2025

Watch These 9 Sundance Institute-Supported Documentaries That Spotlight Workers' Rights

Directed by Steven Bognar and Julia Reichert, Sundance Institute-supported Amer...

28/08/2025

Motivational Corridos: The New Sound of Resilience in Msica Mexicana

Corridos have been a cornerstone of M sica Mexicana for generations, telling stories rooted in everyday life. Now, a new chapter is taking shape: motivational c...

28/08/2025

Corridos Motivadores: El Nuevo Sonido de la Resiliencia en Mxico

Los corridos han sido un pilar de la M sica Mexicana durante generaciones, contando historias enraizadas en la vida cotidiana. Ahora, un nuevo cap tulo est tom...

28/08/2025

Verano Forever Brings Myke Towers, Bele, Elena Rose, and More to Miami for an Unforgettable Latin Summer Celebration

Earlier this month, we promised our Verano Forever party would bring the heat, a...

28/08/2025

Poland Selects L3Harris Electronic Warfare System for F-16 Fleet

L3Harris will provide the Polish F-16V fleet with the Viper Shield electronic warfare system as part of an upgrade program....

28/08/2025

AgileTV consolidates its technological leadership with the development of Lowi TV in Spain

Bilbao, August 26, 2025 - AgileTV, an international television and video technol...

28/08/2025

Craft Interview: Ken Wilkinson, Audio Engineer

Ken Wilkinson is an Emmy Awards nominated New York audio engineer who specialises in production sound mixing for film, commercial, episodic and documentary work...

28/08/2025

Fubo to Launch Fubo Sports Skinny Bundle for $56 Per Month

NEW YORK FuboTV today announced that it will launch Fubo Sports, a skinny bundle that focuses on sports with a subscription price of $56 monthly....

28/08/2025

Telestream to Launch 'Global Ingest Workflow at IBC2025

NEVADA City, Calif. At IBC2025, Sept. 12-15 at the RAI Amsterdam, Telestream will debut its new Global Ingest strategy, introducing a next-generation ingest arc...

28/08/2025

Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Education

Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Educatio...

28/08/2025

TAG Strengthens Regional Presence with Appointment of Oli...

TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has named Oliver Gappa as Sales Di...

28/08/2025

DHD to Demonstrate AI-Based Voice Enhancement at IBC 2025

AI-based voice enhancement will be among a series of innovations making their IBC 2025 debut on the DHD stand B46 in Hall 8 at the RAI Amsterdam Convention Cent...

28/08/2025

Telefonica Servicios Audiovisuales Hit the Back of the Ne...

Telef nica Servicios Audiovisuales (TSA), the leading system integrator and service provider in the media sector in Spain, with the support of Appear, the globa...

28/08/2025

Optical Media Anchors LiveU IQ into its On site Productio...

To fully immerse sailing fans in the world's biggest offshore yacht race, production company, Optical Media turned to LiveU's On-site Production solutio...

28/08/2025

WNED Adopts Calrec Type R console to weather any storm an...

Working with Calrec on its most recent overhaul, radio and television broadcaster, WNED has migrated to a fully IP infrastructure with multiple Type R consoles,...

28/08/2025

Cleeng unveils first ever free D2C subscription platform...

Cleeng, the Subscriber Retention Management (SRM ) inventor, has unveiled Cleeng Pro, the first-ever direct-to-consumer (D2C) subscription management platform t...

28/08/2025

Zixi and OKAST Partner to Power Scalable Global FAST Chan...

Zixi, the industry leader in live broadcast-quality video over IP, today announced that French media distribution platform OKAST has selected Zixi to enable rel...

28/08/2025

Nixer to unveil CV1 AoIP monitoring tool to address evolv...

Solution offers a streamlined, speaker-free architecture to optimize integration with premium external loudspeakers and advanced loudness metering Nixer Pro Au...

28/08/2025

Cinegy Announces Strategic Partnership with One Touch Pro...

Cinegy, the premier provider of software-defined television technology, has announced a strategic partnership with Vision One Touch Film Production Services L.L...

28/08/2025

Telestream Global Ingest Workflow Powered by Vantage Open...

Telestream, a global leader in media workflow technologies, will debut its new Global Ingest strategy at IBC2025, introducing a next-generation ingest architect...

28/08/2025

Telenor partners with Broadpeak for multi-country content...

Tier 1 operator selects Broadpeak to power high-performance, unified CDN solution across Norway, Sweden and Finland Broadpeak, a leader in streaming and moneti...

28/08/2025

24 Frames Digital goes live with Synamedia Quortex Play f...

Leading video software provider, Synamedia, today announced that 24 Frames Digital, one of India's leading live event streaming service providers, has chose...

28/08/2025

VisualOn at IBC 2025 - Whats Next in AI Powered Video Str...

Meet VisualOn at IBC2025: See What's Next in AI-Powered Video Streaming Join VisualOn at IBC2025 and discover how our AI-driven Optimizer and advanced media...