Sony Pixel Power calrec Sony

HP Study Reveals 70 Percent of Internet of ings Devices Vulnerable to Attack

29/07/2014

HP Study Reveals 70 Percent of Internet of Things Devices Vulnerable to AttackIoT devices averaged 25 vulnerabilities per product, indicating expanding attack surface for adversaries

PALO ALTO, Calif. - HP today released results of a study revealing 70 percent of the most commonly used Internet of Things (IoT) devices contain vulnerabilities, including password security, encryption and general lack of granular user access permissions.

With the rise of IoT, the number and diversity of connected devices is expected to increase exponentially. According to Gartner, the Internet of Things will include 26 billion units installed by 2020. IoT product and service suppliers will generate incremental revenue exceeding $300 billion, mostly in services, in 2020. (1)

This spike in demand is pushing manufacturers to quickly bring to market connected devices, cloud access capabilities and mobile applications in order to gain share. While this increase in IoT devices promises benefits to consumers, it also opens the doors for security threats ranging from software vulnerabilities to denial-of-service (DOS) attacks to weak passwords and cross-site scripting vulnerabilities.

While the Internet of Things will connect and unify countless objects and systems, it also presents a significant challenge in fending off the adversary given the expanded attack surface, said Mike Armistead, vice president and general manager, Fortify, Enterprise Security Products, HP. With the continued adoption of connected devices, it is more important than ever to build security into these products from the beginning to disrupt the adversary and avoid exposing consumers to serious threats.

HP leveraged HP Fortify on Demand to scan 10 of the most popular IoT devices, uncovering, on average, 25 vulnerabilities per device-totaling 250 security concerns across all tested products. The IoT devices tested-along with their cloud and mobile application components-were from manufacturers of TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.

The most common and easily addressable security issues reported include:

Privacy concerns: Eight of the 10 devices tested, along with their corresponding cloud and mobile application components, raised privacy concerns regarding the collection of consumer data such as name, email address, home address, date of birth, credit card credentials and health information. Moreover, 90 percent of tested devices collected at least one piece of personal information via the product itself, the cloud or its mobile application.

Insufficient authorization: 80 percent of IoT devices tested, including their cloud and mobile components, failed to require passwords of sufficient complexity and length, with most devices allowing password such as 1234. In fact, many of the test accounts HP configured with weak passwords were also used on the products' websites and mobile applications.

Lack of transport encryption: 70 percent of IoT devices analyzed did not encrypt communications to the internet and local network, while half of the devices' mobile applications performed unencrypted communications to the cloud, internet or local network. Transport encryption is crucial given that many of the tested devices collected and transmitted sensitive data across channels.

Insecure web interface: Six of the 10 devices evaluated raised security concerns with their user interfaces such as persistent XSS, poor session management, weak default credentials and credentials transmitted in clear text. Seventy percent of devices with cloud and mobile components would enable a potential attacker to determine valid user accounts through account enumeration or the password reset feature.

Inadequate software protection: 60 percent of devices did not use encryption when downloading software updates, an alarming number given that software powers the functionality of the tested devices. Some downloads could even be intercepted, extracted and mounted as a file system in Linux where the software could be viewed or modified.

To protect against security hazards that come along with the rise of IoT, it is imperative for organizations to implement an end-to-end approach to identify software vulnerabilities before they are exploited. Solutions like HP Fortify on Demand enable organizations to test the security of software quickly, accurately, affordably and without any software to install or manage-proactively eliminating the immediate risk in legacy applications and the systemic risk in application development.

Methodology

Conducted by HP Fortify and leveraging HP Fortify on Demand, the Internet of Things Security: State of the Union study tested 10 of the most commonly used IoT devices for vulnerabilities using standard testing techniques that combined manual testing along with the use of automated tools. Devices and their cloud, network and client application components were assessed based on the OWASP Internet of Things Top 10 list and the specific vulnerabilities associated within each category.

Additional information about application security and further details resulting from the study are available at hp.com/go/fortifyresearch/iot.

HP will be addressing the latest trends in enterprise security at the Black Hat USA 2014 conference, taking place Aug. 2-7 in Las Vegas. Visit the HP booth (No. 911) for an IoT product demo and Capture the Flag hacking contest. Additional information on HP's presence at the show can be found here.

(1) Gartner, Forecast: The Internet of Things, Worldwide, 2013, November 2013.

2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the e
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1744676...
See more stories from hp

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

12/02/2026

Spectrum News Acquires New England Cable News

Share Copy link Facebook X Linkedin Bluesky Email...

12/02/2026

Vizrt Unveils Campus Stadium Production Bundles

Share Copy link Facebook X Linkedin Bluesky Email...

12/02/2026

Hulu + Live TV Adds Fubo Sports Network to Channel Line-up

Share Copy link Facebook X Linkedin Bluesky Email...

12/02/2026

FCC To Hold Open Commission Meeting on Feb. 18

Share Copy link Facebook X Linkedin Bluesky Email...

12/02/2026

Ralph M. Oakley to Receive NAB's Chuck Sherman TV Leadership Award

Share Copy link Facebook X Linkedin Bluesky Email...

12/02/2026

February 11, 2026

TIME100 Health list features Scripps Research Professor Darrell Irvine Irvine is recognized for his work in empowering the immune system to fight disease, which...

11/02/2026

FYI: Phone Support Maintenance

FYI: Phone Support Maintenance One thing we pride ourselves on here at Utah Scientific is our 24-hour support included with our signature 10-year hardware warra...

11/02/2026

Bitmovin Appoints Ian Baglow as Co-Chief Executive Officer

Leading provider of video streaming solutions, Bitmovin, has appointed Ian Baglow as Co-CEO alongside existing CEO and Co-Founder Stefan Lederer. Under this str...

11/02/2026

Paramount and CBS Partner to Air UFC 326

Paramount and the CBS Television Network will partner to air UFC 326: HOLLOWAY vs. OLIVEIRA 2 live on Saturday, March 7, from T-Mobile Arena in Las Vegas, mar...

11/02/2026

MLB.TV Launches on ESPN Beginning February 10

Beginning February 10, fans can buy MLB.TV on ESPN, a new milestone in one of sports media's longest-standing partnerships. ESPN becomes the new streaming h...

11/02/2026

Fubo Sports Network Launches on Hulu + Live TV

Fubo Sports Network is available to Hulu's Live TV subscribers in the core $89.99 a month subscription plan, which also includes full access to the entire H...

11/02/2026

Rai Selects Imagine Selenio Network Processor for IP Migration

Following a competitive public tender process, Rai (Radiotelevisione Italiana), the national public broadcasting company of Italy, has awarded Imagine Communica...

11/02/2026

MLB Makes In-Market Streaming Subscriptions for 20 Clubs Available to Fans

Major League Baseball is making in-market streaming subscriptions for 20 Clubs available today for fans. Subscriptions for the following Clubs are available vi...

11/02/2026

5G Broadcast Trials Return to the Olympic Stage at Milano Cortina 2026

Building on successful demonstrations during the Paris Olympics 2024, Italian public service broadcaster Rai and the European Broadcasting Union (EBU) are condu...

11/02/2026

ESPN and Disney Launch We're Going, the First Marketing Campaign for ESPN's Inaugural Super Bowl

Following Sunday's Super Bowl LX, ESPN and Disney unveiled We're Going,...

11/02/2026

Stats Perform: 2026 Super Bowl Latency Report

Delayed streams are a growing source of frustration for sports fans. During the 2026 Super Bowl, some streams lagged up to 62 seconds behind the action on the f...

11/02/2026

NASCAR Channel and FloSports to Simulcast 16 Races Live

NASCAR and FloSports announces an expanded slate of racing events that will bring FloRacing coverage live throughout the 2026 season to the NASCAR Channel, furt...

11/02/2026

Manifold Expands Sales Presence in Europe

Manifold technologies GmbH announces the appointment of Nick Tucker as Sales Manager for Europe, reinforcing the company's continued growth across broadcast...

11/02/2026

Genies and MLB Players Inc. Team Up to Create AI Characters of MLB Players

Genies, the AI avatar technology company powering the next era of interactive digital identity, entered into a landmark collaboration with MLB Players, Inc., th...

11/02/2026

ICC, Google Partner for the First-Ever AI-Powered ICC Men's T20 World Cup fuelled by Gemini & Pixel

The International Cricket Council (ICC) and Google have joined forces for an AI-...

11/02/2026

Dolby Highlights From First Ever Super Bowl LX Innovation Summit

Dolby's CEO Kevin Yeaman and Giles Baker, SVP of Dolby Cloud Solutions, shared how the brand's latest innovations - Dolby Vision, Dolby Atmos, and Dolby...

11/02/2026

Detroit Tigers and Detroit Red Wings Enter Broadcast Partnership with MLB

Ilitch Sports + Entertainment has entered a first of its kind partnership with Major League Baseball, which will provide broadcast support to both the Detroit T...

11/02/2026

A Changing Landscape: MLB Local Media Brings Detroit Tigers, Los Angeles Angels Into the Fold; ESPN Begins Distribution of MLB.TV

Broadcasts of the NHL's Detroit Red Wings will also be produced by the leagu...

11/02/2026

DAM Los Angeles

Video moves fast can your DAM keep up? Join Blue Lucy in LA for the West Coast's leading Digital Asset Management event as we explore, celebrate, and acc...

11/02/2026

Super Bowl LX Delivers 124.9 Million Viewers

NEW YORK - February 10, 2026 - An estimated 124.9 million viewers watched Super Bowl LX on Sunday, February 8, according to Nielsen's Big Data Panel measu...

11/02/2026

Scripps Selling Court TV to Jellysmack

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

Schulze-Brakel Introduces Wireless Clip-On Branding For Mics

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

LiveU To Showcase Expanded IP-Video EcoSystem at 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

Clear-Com Powers TEDNext 2025 with Gen-IC Virtual Interco...

Clear-Com provided an advanced, IP-based communications infrastructure for TEDNext 2025, supporting production, media, and editorial teams with a highly flexib...

11/02/2026

Astera Releases QuikBeam - Versatile 200W Equivalent LED...

Astera introduces QuikBeam, the newest addition to its acclaimed Quik family of focusing LED Fresnels. This ultra-compact spotlight combines the equivalent powe...

11/02/2026

Rai Selects Imagine Selenio Network Processor for IP Migr...

Following a competitive public tender process, Rai (Radiotelevisione Italiana), the national public broadcasting company of Italy, has awarded Imagine Communica...

11/02/2026

DoPchoice to Intro SNAP RABBIT Octa 5 SNAPBAG

With Convertible Mount for NL Bowens & Aputure A Mounts See it at BSC Expo Stand #133 LCA DoPchoice continues to refine light shaping tools for professional LE...

11/02/2026

ZEISS Aatma -Contemporary Full Frame Primes with a Soulfu...

World Premiere at BSC Expo, Booth #319 Oberkochen/Germany, 10 February 2026 ZEISS introduces the new Aatma, set of nine high-end full frame T1.5 cinema primes ...

11/02/2026

NUGEN Audio Plug Ins Help Nick Fry Navigate the Demands o...

As Re-recording Mixer and Head of Sound at The Farm, one of UK's leading post-production facilities, Nick Fry has built his career on making stories sound a...

11/02/2026

iSpot Introduces Agentic AI Platform iSpot SAGE

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

NBC Sports Regional Sports Networks Taps Sportradar for NBA Coverage

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

MLB.TV Launches on ESPN

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

Super Bowl LX Attracts Nearly 125 Million U.S. Viewers

Share Copy link Facebook X Linkedin Bluesky Email...

11/02/2026

Graduate Spotlight: Gabrielle Rodriguez

Graduate Spotlight: Gabrielle Rodriguez The educator, who grew up in the Philippines, shares how shes bringing what she learned at Berklee back home. Februar...

11/02/2026

Sky brings together Netflix, Disney+, HBO Max and Hayu into one single subscription, exclusively on Sky

Wednesday 11 February 2026 Sky brings together Netflix, Disney , HBO Max and Ha...

11/02/2026

Netflix Confirms Production of Love O'Clock' From the Writers of Business Proposal' and True Beauty' Director

Back to All News Netflix Confirms Production of Love O'Clock' From the...

11/02/2026

Investing in Belgian Stories: A Commitment to Culture and Choice

Back to All News Investing in Belgian Stories: A Commitment to Culture and Choice From left to right: Undercover, Ang le, Rough Diamonds, Into the Night, John...

11/02/2026

Lisbon 2026

At the end of January, ICG headed off to the Portuguese capital, Lisbon, for our annual conference. An early flight gave us plenty of time to start exploring s...

11/02/2026

ABS Strengthens Ku-Band Capacity and Expands Regional Reach Through Strategic Partnership with Horizon Teleports

ABS Strengthens Ku-Band Capacity and Expands Regional Reach Through Strategic Pa...