Sony Pixel Power calrec Sony

HP Study Reveals Smartwatches Vulnerable to Attack

22/07/2015

HP Study Reveals Smartwatches Vulnerable to AttackHP Fortify finds 100 percent of tested smartwatches exhibit security flaws, provides guidance for secure device use

PALO ALTO, Calif., July 22, 2015 As part of an ongoing series looking at Internet of Things (IoT) security, HP today unveiled results of an assessment confirming that smartwatches with network and communication functionality represent a new and open frontier for cyberattack. The study conducted by HP Fortify found that 100 percent of the tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns1. In the report HP provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace.

As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities. As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps may soon enable physical access functions including unlocking cars and homes.

Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities, said Jason Schmitt, general manager, HP Security, Fortify. As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks.

The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built. HP leveraged HP Fortify on Demand to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns.

The most common and easily addressable security issues reported include:

Insufficient User Authentication/Authorization: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication and the ability to lock out accounts after 3-5 failed password attempts. Three in ten, 30 percent, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.

Lack of transport encryption: Transport encryption is critical given that personal information is being moved to multiple locations in the cloud. While 100 percent of the test products implemented transport encryption using SSL/TLS, 40 percent of the cloud connections continue to be vulnerable to the POODLE attack, allow the use of weak cyphers, or still used SSL v2.

Insecure Interfaces: Thirty percent of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30 percent also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.

Insecure Software/Firmware: A full 70 percent of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analyzed.

Privacy Concerns: All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.

As manufacturers work to incorporate necessary security measures into smartwatches, consumers are urged to consider security when choosing to use a smartwatch. It's recommended that users do not enable sensitive access control functions such as car or home access unless strong authorization is offered. In addition, enabling passcode functionality, ensuring strong passwords and instituting two-factor authentication will help prevent unauthorized access to data. These security measures are not only important to protecting personal data, but are critical as smartwatches are introduced to the workplace and connected to corporate networks. Additional guidelines for secure smartwatch use are outlined in the full report.

For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of 10 of the most common IoT devices. In addition, the 2015 HP Home Security Systems Report reviews the 10 of the most common Internet-connected home security systems.

Methodology

Conducted by HP Fortify, the HP Smartwatch Security Study used the HP Fortify on Demand IoT testing methodology which combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category.

All data and percentages for this study were drawn from the 10 smartwatches tested during this study. While there are certainly a fair number of smartwatch devices already on the market, and that number continues to grow, HP believes the similarity in results of the 10 smartwatches provides a good indicator of the current security posture of smartwatch devices.

1 HP Internet of Things Security Report: Smartwatches, HP, July 2015

About HP Security

HP enables organizations to take a proactive approach to security, disrupting the life
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=2037386...
See more stories from hp

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

02/05/2026

Dalet Flex LTS Delivers Smarter Search, Faster Editing, and an AI-Ready Foundation for Modern Media

Dalet, a leading technology and service provider for media-rich organizations, t...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

03/03/2026

LIV Golf, Beyond Sports Elevate Online Gaming Ecosystem with Launch of LIV Golf Fantasy and LIV X

Beyond Sports, a Sony group company, and LIV Golf, the world's golf league, ...

03/03/2026

Ilitch Sports + Entertainment Announces Launch of Detroit SportsNet

Ilitch Sports + Entertainment announces the launch of Detroit SportsNet (DSN), a year-round broadcast home for two of Detroit's franchises. With flexible op...

03/03/2026

Advanced Systems Group Promotes Gretchen Taipale to Vice President, Managed Services

Advanced Systems Group, LLC (ASG), a technology and services provider for media ...

03/03/2026

PGA of America, NBC Sports, and USA Sports Extend Media Rights Agreement Through 2033

The PGA of America, NBC Sports and USA Sports extend their media rights agreemen...

03/03/2026

HONOR, ARRI Announce Technical Collaboration to Bring ARRI Image Science into Next-Gen Consumer Devices

AI device ecosystem company HONOR enters into a strategic technical collaboratio...

03/03/2026

Telos Alliance Partners with College Radio Foundation to Support College Broadcasters

Cleveland's Telos Alliance, pioneers in broadcast technology for 30 years, l...

03/03/2026

Sennheiser Relaunches MD 9235 Wireless Mic Head

The MD 9235 microphone head for wireless handhelds has been a firm favorite with many engineers and artists for its ability to cut through high on-stage levels ...

03/03/2026

Haivision to Showcase Private 5G and Live Video Contribution Innovations at MWC 2026

Haivision Systems Inc. (Haivision), a global provider of mission-critical, real-...

03/03/2026

BMG Expands Washington Broadcast Center with 3 New TV Studios and Podcast Studio for Media Clients

Broadcast Management Group (BMG) announces the expansion of its 62,000-square-fo...

03/03/2026

Closing the Loop: Maroon 5 and the End of the Analog Era

Maroon 5's musical tour in 2025 marked a leap forward in live audio as Monitor Engineer Dave Rupsch utilized Sennheiser's all-digital Spectera wireless ...

03/03/2026

SVG in Indy: Pacers Sports & Entertainment Finds Production Sweet Spot in ST 2110-Based Control Center

Designed specifically for pro basketball, the renovated space at Gainbridge Fiel...

03/03/2026

Lawo Appoints Jamie Dunn CEO

As part of the move, former CEO Phillipp Lawo joins the broadcast-tech provider's Supervisory Board Lawo has announced appointment of Jamie Dunn as chief e...

03/03/2026

NBC Turns Back the Clock to 1990s for NBA Coast 2 Coast' Tuesday

A team of legendary announcers and analysts and a classic graphics look will bring the past to life NBC Sports and Peacock will return to yesteryear for tonigh...

03/03/2026

Sundance Film Festival: CDMX 2026 Returns for Its Third Edition

From April 30 to May 3, Sundance Film Festival: CDMX 2026 will offer a selection of exciting independent cinema. Mexico City, March 3, 2026 - At a moment of he...

03/03/2026

How Multi-Format Readers' Are Redefining Reading in the UK's National Year of Reading

For many, finding time or headspace to pick up a book can feel out of reach, but...

03/03/2026

Rohde & Schwarz and Realtek demonstrate first test solution for Bluetooth LE High Data Throughput (HDT)

Rohde & Schwarz and Realtek demonstrate first test solution for Bluetooth LE Hi...

03/03/2026

Sediba Scriptwriting Training Programme - Matatiele (Eastern Cape)

The National Film and Video Foundation (NFVF) invites aspiring and emerging filmmakers from Matatiele and surrounding areas to apply for the Sediba Scriptwritin...

03/03/2026

Clear-Com Supplies Cloud-based Communications System for SaxaVord Spaceport

eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({ content_source:......

03/03/2026

Magellan AI Integrates Nielsen DMA Data to Bring Local Market Measurement to Podcast Attribution

Nielsen's DMA data gives Magellan AI users a standardized way to measure th...

03/03/2026

Lawo Promotes Jamie Dunn to CEO

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Elements To Showcase Newly Unveiled GRID NAS Platform At 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Moments Lab To Feature Agentic AI For Video Workflows At 2026 NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Marshall Electronics Launches Compact CV356-10X Full HD C...

Marshall Electronics premieres the CV356-10X, its latest compact 10X camera that offers Full HD with simultaneous SDI and HDMI outputs, at NAB 2026 (Booth C8339...

03/03/2026

farmerswife and Cirkus to Showcase Smarter Media Workflow...

farmerswife, the industry-leading enterprise operations platform for broadcast and post-production, today announced it will exhibit at NAB Show 2026 in Las Vega...

03/03/2026

Manfrotto ONE Hybrid Tripod Wins iF Design Award 2026

Manfrotto has announced that the Manfrotto ONE Hybrid tripod has won the iF DESIGN AWARD 2026, one of the world's most respected design honours. Selected ...

03/03/2026

DHD to Introduce Latest Generation Broadcast Audio Mixers...

DHD is expanding the capabilities of its DX2, RX2, SX2 and TX2 broadcast audio mixers, RM1 portable production unit and XC3/XD3/XS2 processing cores with the in...

03/03/2026

Synamedia and MoMe launch first streaming CDN in Spain

Leading video software provider Synamedia and MoMe, a leading Spanish consultancy and systems integrator, today announced the launch of Spain's first stream...

03/03/2026

Long-Awaited ATSC 3.0 Rulemaking Overshadows NAB Show Expectations

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Audio Tech at NAB Show: Are We in the Second Wave' of IP?

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

IP's Impact on Imaging Tech on Full Display at NAB Show

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Live Production Over IP in 2026: Software-Defined Everything

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

NAB Show Leverages Revitalized LVCC To Reflect M&E Transformation

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Home Post Production Strengthens Factual and Natural Hist...

Home Post Production has further expanded its factual, unscripted, and entertainment capabilities with the acquisition of Picture Shop Bristol, a leading post h...

03/03/2026

Full Year 2025 Results

Luxembourg, 2 March 2026 -- SES S.A. fully consolidates Intelsat from 17 July 2025 and announces financial results for the year ended 31 December 2025 FY25 Pe...

03/03/2026

Iyuno Taps Dante AV to Sync Audio and Video Content

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

HBO Max and Paramount+ Streamers to Merge

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Survey: 70% of CTV Advertisers Plan to Boost Spending in 2026

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

XGN Global, X1 Mobile Show New 5G Broadcast Smartphone

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

Scripps Completes Sale of WFTX to Sun Broadcasting

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

HbbTV Association Formally Integrates DRM into Core Specification

Share Copy link Facebook X Linkedin Bluesky Email...

03/03/2026

VEON and MeetKai Expand Collaboration to Explore Sovereign AI Infrastructure Partnerships

03 Mar 2026 VEON and MeetKai Expand Collaboration to Explore Sovereign AI Infra...

03/03/2026

Ryan Reynolds and Rob Mac land first ever live commentary gig exclusively on Sky Sports for Wrexham vs Swansea

Tuesday 3 March 2026 Ryan Reynolds and Rob Mac land first ever live commentary ...

03/03/2026

The Dyers Caravan Park reopens for a second season after a hit launch on Sky

Tuesday 3 March 2026 The Dyers' Caravan Park reopens for a second season after a hit launch on Sky The Dyers' Caravan Park JPEG (510KB) Sky books a ...

03/03/2026

Kai Ko and Wang Po-chieh Unleash Divine Glory in Electrifying Agent from Above' Teaser

Back to All News Kai Ko and Wang Po-chieh Unleash Divine Glory in Electrifying ...