Sony Pixel Power calrec Sony

HP Study Reveals Smartwatches Vulnerable to Attack

22/07/2015

HP Study Reveals Smartwatches Vulnerable to AttackHP Fortify finds 100 percent of tested smartwatches exhibit security flaws, provides guidance for secure device use

PALO ALTO, Calif., July 22, 2015 As part of an ongoing series looking at Internet of Things (IoT) security, HP today unveiled results of an assessment confirming that smartwatches with network and communication functionality represent a new and open frontier for cyberattack. The study conducted by HP Fortify found that 100 percent of the tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns1. In the report HP provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace.

As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities. As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps may soon enable physical access functions including unlocking cars and homes.

Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities, said Jason Schmitt, general manager, HP Security, Fortify. As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks.

The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built. HP leveraged HP Fortify on Demand to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns.

The most common and easily addressable security issues reported include:

Insufficient User Authentication/Authorization: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication and the ability to lock out accounts after 3-5 failed password attempts. Three in ten, 30 percent, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.

Lack of transport encryption: Transport encryption is critical given that personal information is being moved to multiple locations in the cloud. While 100 percent of the test products implemented transport encryption using SSL/TLS, 40 percent of the cloud connections continue to be vulnerable to the POODLE attack, allow the use of weak cyphers, or still used SSL v2.

Insecure Interfaces: Thirty percent of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30 percent also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.

Insecure Software/Firmware: A full 70 percent of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analyzed.

Privacy Concerns: All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.

As manufacturers work to incorporate necessary security measures into smartwatches, consumers are urged to consider security when choosing to use a smartwatch. It's recommended that users do not enable sensitive access control functions such as car or home access unless strong authorization is offered. In addition, enabling passcode functionality, ensuring strong passwords and instituting two-factor authentication will help prevent unauthorized access to data. These security measures are not only important to protecting personal data, but are critical as smartwatches are introduced to the workplace and connected to corporate networks. Additional guidelines for secure smartwatch use are outlined in the full report.

For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of 10 of the most common IoT devices. In addition, the 2015 HP Home Security Systems Report reviews the 10 of the most common Internet-connected home security systems.

Methodology

Conducted by HP Fortify, the HP Smartwatch Security Study used the HP Fortify on Demand IoT testing methodology which combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category.

All data and percentages for this study were drawn from the 10 smartwatches tested during this study. While there are certainly a fair number of smartwatch devices already on the market, and that number continues to grow, HP believes the similarity in results of the 10 smartwatches provides a good indicator of the current security posture of smartwatch devices.

1 HP Internet of Things Security Report: Smartwatches, HP, July 2015

About HP Security

HP enables organizations to take a proactive approach to security, disrupting the life
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=2037386...
See more stories from hp

Most recent headlines

06/10/2025

France Tlvisions Wins Prestigious 2025 EBU Technology & Innovation Award in Groundbreaking Collaboration with Dalet

France T l visions, France's leading broadcaster, has received the 2025 EBU ...

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

30/08/2025

FCC Slightly Raises Regulatory Fees for TV Stations

WASHINGTON The Federal Communications Commission has adopted its FY 2025 Regulatory Fees Order that establishes the regulatory fee rates for the broadcast stati...

29/08/2025

Australian Red Cross and SBS launch training to help workplaces in the fight against Modern Slavery

Australian Red Cross and SBS launch training to help workplaces in the fight aga...

29/08/2025

Call for entries is now open for the 19th Annual South African Film & Television Awards (SAFTAs19)

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

29/08/2025

L3Harris Launches Counter-Unmanned Systems Initiative

L3Harris Technologies has concentrated decades of expertise across the entire enterprise to develop affordable and reliable best-of-breed solutions to rapidly c...

29/08/2025

The CW Network Extends Pac-12 Deal Through 2030-31 Season

BURBANK, Calif. The CW Network and the Pac-12 Conference have announced a new media rights deal that will extend their broadcast partnership beginning with the ...

29/08/2025

Global FAST Channel Count Continues to Spike

NEW YORK Gracenote has released a new analysis of its global video dataset showing that the number of FAST channels grew nearly 14% from Q1 2025 and 76% since 2...

29/08/2025

Harmonic Unveils New Capabilities for Its Live Sports Streaming Solution

SAN JOSE, Calif. Harmonic has announced a series of improvements to its live sports streaming solution that the company said will improve fan engagement, protec...

29/08/2025

Youtube TV, Fox Settle Differences, Renew Carriage Agreement

NEW YORK and LOS ANGELES Fox Corp. and YouTube TV last night announced a renewal of the full portfolio of Fox networks, including Fox News Channel, Fox Business...

29/08/2025

Lightware MTR integration brings advanced flexibility and...

Budapest, Hungary, August 2025 - The integration of Microsoft Teams Rooms (MTR) with Lightware's Taurus universal matrix switchers delivers a new level of f...

29/08/2025

Frequency Launches Studio Live - a Unified Platform to Br...

Frequency, the engine behind many of the world's best-known streaming television channels, today announced it will launch Studio Live, a next-generation uni...

29/08/2025

Scality Day 2025 Celebrating 10 years of global innovatio...

In an era when AI and cyber resilience are essential, Scality will mark the 10th anniversary of Scality Day on October 16, 2025 in Paris. This flagship global e...

29/08/2025

Disguise Drives New Immersive Racing Experience - F1 Box

Disguise's In-House Creative and Technical Teams Pre-Visualised, Programmed and Delivered Content for the Experience, All Powered by EX 3+ Technology solu...

29/08/2025

Disguise Supports Fellow Entertainment Tech Leaders at IB...

Disguise will be demonstrating the latest workflows for TV, film and live events on a number of partner booths at the show Disguise, the industry-leading tech...

29/08/2025

Accedo to Highlight Compose AI-Agent Enhanced Orchestration Layer

STOCKHOLM, Sweden Accedo will showcase Accedo Compose, its AI agent-powered modular orchestration layer that assists streaming providers in transitioning client...

29/08/2025

Cineverse Launches Streaming Apps for In-Vehicle Video Streaming

LOS ANGELES Cineverse has announced that it is working with Xperi to bring four of its streaming channels to automobiles for the first time as part of the DTS A...

29/08/2025

Gray Media to Simulcast 17 Dallas Stars NHL Games

DALLAS & ATLANTA Gray Media has announced an agreement with the sports streaming service Victory+ to simulcast 17 Dallas Stars NHL games in 15 television market...

29/08/2025

Comcast NBCU and Amazon Ink New Distribution Agreements

NEW YORK AND CULVER CITY Comcast NBCUniversal and Amazon have announced new and extended distribution agreements that will expand the content available on their...

29/08/2025

RED Digital Cinema To Highlight Cine-Broadcast Module At IBC2025

FOOTHILL RANCH, Calif. RED Digital Cinema will feature its Cine-Broadcast Module supporting live broadcast workflows during IBC2025, Sept. 12-15, at the RAI Ams...

29/08/2025

Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and Highlighting Ukraine's Investment Case

29 Aug 2025 Kyivstar Rings Opening Bell at Nasdaq Marking Landmark Listing and ...

29/08/2025

Sky Sports to show more NFL games than ever as part of new rights agreement

More than half of all NFL games live on Sky for the first timeFriday 29 August 2025 Sky Sports has announced a new three-year deal with the NFL, extending its ...

29/08/2025

'RIV4LRIES': The Trailer of the New Series With Samuele Carrino Only on Netflix October 1

Back to All News RIV4LRIES: The Trailer of the New Series With Samuele Carrino ...

29/08/2025

Steps ahead: RT to air inspiring documentary on 12-year-old Irish dance star

Get ready for an inspiring and emotional insight into the world of competitive Irish dancing with My Story: Tomi Champion of the World airing on RT 2 this monda...

29/08/2025

TODAY WITH DAVID MCCULLAGH TO AIR ON RT RADIO 1 WEEKDAYS AT 10AM

RT has today announced that David McCullagh is to be the new presenter of RT Radio 1's flagship Today programme, which airs every weekday at 10am, replaci...

28/08/2025

Meet the 2025 Sundance Institute Documentary Edit Residency Artists

By Kristin Feeley, Director, Documentary Film & Artist Programs If you want to tell untold stories, if you want to give voice to the voiceless, you've got ...

28/08/2025

Watch These 9 Sundance Institute-Supported Documentaries That Spotlight Workers' Rights

Directed by Steven Bognar and Julia Reichert, Sundance Institute-supported Amer...

28/08/2025

Motivational Corridos: The New Sound of Resilience in Msica Mexicana

Corridos have been a cornerstone of M sica Mexicana for generations, telling stories rooted in everyday life. Now, a new chapter is taking shape: motivational c...

28/08/2025

Corridos Motivadores: El Nuevo Sonido de la Resiliencia en Mxico

Los corridos han sido un pilar de la M sica Mexicana durante generaciones, contando historias enraizadas en la vida cotidiana. Ahora, un nuevo cap tulo est tom...

28/08/2025

Verano Forever Brings Myke Towers, Bele, Elena Rose, and More to Miami for an Unforgettable Latin Summer Celebration

Earlier this month, we promised our Verano Forever party would bring the heat, a...

28/08/2025

Poland Selects L3Harris Electronic Warfare System for F-16 Fleet

L3Harris will provide the Polish F-16V fleet with the Viper Shield electronic warfare system as part of an upgrade program....

28/08/2025

AgileTV consolidates its technological leadership with the development of Lowi TV in Spain

Bilbao, August 26, 2025 - AgileTV, an international television and video technol...

28/08/2025

Craft Interview: Ken Wilkinson, Audio Engineer

Ken Wilkinson is an Emmy Awards nominated New York audio engineer who specialises in production sound mixing for film, commercial, episodic and documentary work...

28/08/2025

Fubo to Launch Fubo Sports Skinny Bundle for $56 Per Month

NEW YORK FuboTV today announced that it will launch Fubo Sports, a skinny bundle that focuses on sports with a subscription price of $56 monthly....

28/08/2025

Telestream to Launch 'Global Ingest Workflow at IBC2025

NEVADA City, Calif. At IBC2025, Sept. 12-15 at the RAI Amsterdam, Telestream will debut its new Global Ingest strategy, introducing a next-generation ingest arc...

28/08/2025

Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Education

Dr. Rhoda Bernard Releases Groundbreaking Debut Book on Accessible Arts Educatio...

28/08/2025

TAG Strengthens Regional Presence with Appointment of Oli...

TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has named Oliver Gappa as Sales Di...

28/08/2025

DHD to Demonstrate AI-Based Voice Enhancement at IBC 2025

AI-based voice enhancement will be among a series of innovations making their IBC 2025 debut on the DHD stand B46 in Hall 8 at the RAI Amsterdam Convention Cent...

28/08/2025

Telefonica Servicios Audiovisuales Hit the Back of the Ne...

Telef nica Servicios Audiovisuales (TSA), the leading system integrator and service provider in the media sector in Spain, with the support of Appear, the globa...

28/08/2025

Optical Media Anchors LiveU IQ into its On site Productio...

To fully immerse sailing fans in the world's biggest offshore yacht race, production company, Optical Media turned to LiveU's On-site Production solutio...

28/08/2025

WNED Adopts Calrec Type R console to weather any storm an...

Working with Calrec on its most recent overhaul, radio and television broadcaster, WNED has migrated to a fully IP infrastructure with multiple Type R consoles,...

28/08/2025

Cleeng unveils first ever free D2C subscription platform...

Cleeng, the Subscriber Retention Management (SRM ) inventor, has unveiled Cleeng Pro, the first-ever direct-to-consumer (D2C) subscription management platform t...

28/08/2025

Zixi and OKAST Partner to Power Scalable Global FAST Chan...

Zixi, the industry leader in live broadcast-quality video over IP, today announced that French media distribution platform OKAST has selected Zixi to enable rel...

28/08/2025

Nixer to unveil CV1 AoIP monitoring tool to address evolv...

Solution offers a streamlined, speaker-free architecture to optimize integration with premium external loudspeakers and advanced loudness metering Nixer Pro Au...

28/08/2025

Cinegy Announces Strategic Partnership with One Touch Pro...

Cinegy, the premier provider of software-defined television technology, has announced a strategic partnership with Vision One Touch Film Production Services L.L...

28/08/2025

Telestream Global Ingest Workflow Powered by Vantage Open...

Telestream, a global leader in media workflow technologies, will debut its new Global Ingest strategy at IBC2025, introducing a next-generation ingest architect...

28/08/2025

Telenor partners with Broadpeak for multi-country content...

Tier 1 operator selects Broadpeak to power high-performance, unified CDN solution across Norway, Sweden and Finland Broadpeak, a leader in streaming and moneti...

28/08/2025

24 Frames Digital goes live with Synamedia Quortex Play f...

Leading video software provider, Synamedia, today announced that 24 Frames Digital, one of India's leading live event streaming service providers, has chose...

28/08/2025

VisualOn at IBC 2025 - Whats Next in AI Powered Video Str...

Meet VisualOn at IBC2025: See What's Next in AI-Powered Video Streaming Join VisualOn at IBC2025 and discover how our AI-driven Optimizer and advanced media...