Sony Pixel Power calrec Sony

HP Study Reveals Smartwatches Vulnerable to Attack

22/07/2015

HP Study Reveals Smartwatches Vulnerable to AttackHP Fortify finds 100 percent of tested smartwatches exhibit security flaws, provides guidance for secure device use

PALO ALTO, Calif., July 22, 2015 As part of an ongoing series looking at Internet of Things (IoT) security, HP today unveiled results of an assessment confirming that smartwatches with network and communication functionality represent a new and open frontier for cyberattack. The study conducted by HP Fortify found that 100 percent of the tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns1. In the report HP provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace.

As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities. As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps may soon enable physical access functions including unlocking cars and homes.

Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities, said Jason Schmitt, general manager, HP Security, Fortify. As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks.

The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built. HP leveraged HP Fortify on Demand to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns.

The most common and easily addressable security issues reported include:

Insufficient User Authentication/Authorization: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication and the ability to lock out accounts after 3-5 failed password attempts. Three in ten, 30 percent, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.

Lack of transport encryption: Transport encryption is critical given that personal information is being moved to multiple locations in the cloud. While 100 percent of the test products implemented transport encryption using SSL/TLS, 40 percent of the cloud connections continue to be vulnerable to the POODLE attack, allow the use of weak cyphers, or still used SSL v2.

Insecure Interfaces: Thirty percent of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30 percent also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.

Insecure Software/Firmware: A full 70 percent of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analyzed.

Privacy Concerns: All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.

As manufacturers work to incorporate necessary security measures into smartwatches, consumers are urged to consider security when choosing to use a smartwatch. It's recommended that users do not enable sensitive access control functions such as car or home access unless strong authorization is offered. In addition, enabling passcode functionality, ensuring strong passwords and instituting two-factor authentication will help prevent unauthorized access to data. These security measures are not only important to protecting personal data, but are critical as smartwatches are introduced to the workplace and connected to corporate networks. Additional guidelines for secure smartwatch use are outlined in the full report.

For more information, visit the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of 10 of the most common IoT devices. In addition, the 2015 HP Home Security Systems Report reviews the 10 of the most common Internet-connected home security systems.

Methodology

Conducted by HP Fortify, the HP Smartwatch Security Study used the HP Fortify on Demand IoT testing methodology which combined manual testing along with the use of automated tools. Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category.

All data and percentages for this study were drawn from the 10 smartwatches tested during this study. While there are certainly a fair number of smartwatch devices already on the market, and that number continues to grow, HP believes the similarity in results of the 10 smartwatches provides a good indicator of the current security posture of smartwatch devices.

1 HP Internet of Things Security Report: Smartwatches, HP, July 2015

About HP Security

HP enables organizations to take a proactive approach to security, disrupting the life
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=2037386...
See more stories from hp

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

27/05/2026

Telestream Appoints Benjamin Desbois as CEO, Effective July 1

Telestream has announced that its Board of Directors has appointed Benjamin Desbois as Chief Executive Officer, effective July 1, 2026. Desbois, currently Teles...

27/05/2026

FOX MLB Leads Live-Event Categories; ESPN Is Tops Overall at 47th Annual Sports Emmy Awards

ESPN garnered 10 awards; NBC's Sunday Night Football received the Outstandin...

27/05/2026

Matrox Video Marks 50th Anniversary, Announces New Product Launch for June

Matrox Video is celebrating its 50th anniversary, marking five decades of operations from its headquarters in Montreal, Canada. Founded in 1976, the company has...

27/05/2026

MLB Announces Fan Engagement Initiatives for Americas 250th Anniversary

Major League Baseball has announced a series of initiatives tied to America's Semiquincentennial, including a national marketing campaign, Fourth of July br...

27/05/2026

Advanced Systems Group Hires Brian Gross as Account Manager for Audio Team

Advanced Systems Group (ASG) has announced that Brian Gross has joined the company as an Account Manager on its Audio team, based in the Burbank office. He will...

27/05/2026

Nielsen Research: Hispanic Fans, Asian Markets Drive Global Soccer Audience Ahead of World Cup 2026

Nielsen has released new research on soccer fandom ahead of the FIFA World Cup 2...

27/05/2026

ESL FACEIT Group Debuts First Ever Esports Vertical Stream Co-Developed With TikTok

ESL FACEIT Group (EFG) has unveiled a new partnership with TikTok to bring broad...

27/05/2026

Two Weeks Away: FIFA Outlines Production Plans for Highly Anticipated North American-Based World Cup

FIFA's Oscar Sanchez gives a deeper look to how this tournament will be cove...

27/05/2026

SVG Students To Watch: Maggie Lynn, Virginia Tech

The soon-to-be senior from Charlottesville is building her skills in replay, TD, and even creative content for HokieVision and its ACC Network productions In t...

27/05/2026

A Global Festival of Football: FOX Sports Illustrates Strategy to Bring Every FIFA Mens World Cup Match to the U.S. Audience

FOX Sports' Mike Davies breaks down the vision for this summer's showcas...

27/05/2026

Top-Tier Storytelling: Host Broadcast Services Works at Capturing the Atmosphere of the FIFA Mens World Cup

HBS's Paul King, FIFA's Oscar Sanchez preview how the masses at home wil...

27/05/2026

Matt Gangl & Pete Macheska on FOX MLBs Huge Night and an Unforgettable Postseason Run

FOX's MLB coverage dominated the night at the 47th Annual Sports Emmy Awards...

27/05/2026

FOXs Mike Davies and Team on Outstanding Technical Team Win for 2025 World Series

One of the most memorable Postseasons in baseball history would have had no memo...

27/05/2026

NBC Sports Rob Hyland Reflects on an Unforgettable Sunday Night Football Season

NBC's Sunday Night Football is among the most decorated and most watched programs in the history of television. It added to its jam-packed trophy case on Tu...

27/05/2026

Prime Videos John Ward and Mike Francis on Groundbreaking NBA on Prime Video Studio

The 2026 Sports Emmys marked a watershed moment for Prime Video Sports. After bu...

27/05/2026

Countdown to FIFA World Cup 2026: SVG Launches SportsTechLive Blog in Lead-up to Winter Games

With the Opening Match just over two weeks away, the entire sports-production-te...

27/05/2026

Spotify Brings Long-Form Magazine Articles to Audio

Spotify already brings together listeners' favorite music, podcasts, and audiobooks in one place. Now, we're trialing a new format that expands the cont...

27/05/2026

Podcast Clips Make Your Favorite Moments Easier to Save and Share

The best podcast moments deserve more than just a mental note. That's why today, we're making those moments easier to save and share with clips. Whethe...

27/05/2026

Spotify and Netflix Partner With Jay Shetty to Bring On Purpose' to Video Across Both Platforms

On Purpose is one of the most popular podcasts in the world, known for conversat...

27/05/2026

Olivia Rodrigo Brings Billions Club Live to Barcelona: Watch the Concert Film Now

On May 8, 1,500 of Olivia Rodrigo's top fans gathered in Barcelona's Tea...

27/05/2026

JZ Microphones announce the MU-1

Hybrid design combines large-diaphragm capsule & ribbon JZ Microphones have teamed up with Grammy-winning producer and engineer Marc Urselli to develop a ne...

27/05/2026

Tape Effects Collection from AIR Music Tech

Three new plug-ins inspired by classic tape effects AIR Music Tech's latest release delivers a set of plug-ins that aim to capture the character, moveme...

27/05/2026

The Crow Hill Company's Absurdly Quiet Piano goes Pro

Piano played on the edge of silence The Crow Hill Company's Vaults collection offers a continual rotation of instruments that are given away for free fo...

27/05/2026

Arturia release Memory V

Recreates Moog's iconic Memorymoog polysynth Arturia's vast software instrument range offers a combination of new and old, with innovative modern so...

27/05/2026

Accentize introduce free dxLevel plug-in

Offers loudness levelling for speech and dialogue Accentize have built up a solid reputation with their audio-restoration tools, and their latest plug-in is...

27/05/2026

10,000 units strong - The Rohde & Schwarz R&S M3SR Radio 4400

10,000 units strong - The Rohde & Schwarz R&S M3SR Radio 4400 Rohde & Schwarz celebrates a major manufacturing milestone, producing its 10,000th R&S M3SR Radi...

27/05/2026

L3Harris Introduces the XL Converge 300P Portable Public Safety Radio

The XL Converge 300P radio system emerges with a groundbreaking feature set enhancing the mission-critical communications of public safety, federal and critica...

27/05/2026

Modernizing Public Safety Communications

Pairing Two47 MCX software with existing LTE networks means tailored system upgrades that can save time, money and lives....

27/05/2026

L3Harris Strengthens Global Solid Rocket Motor Supply Chain With New PAC-3 Propulsion Supplier

PAC-3 MSE offers improved range, speed, and maneuverability, making it an effect...

27/05/2026

Brightcove Adds New Features to Its AI Suite for Video Advertising

Share Copy link Facebook X Linkedin Bluesky Email...

27/05/2026

Star Trek VFX: Recreating John Knoll's Iconic Warp Stars without a Slitscan Camera

Star Trek VFX: Recreating John Knoll's Iconic Warp Stars without a Slitscan ...

27/05/2026

Adventure World Uses Blackmagic Replay for Marine Live

Adventure World Uses Blackmagic Replay for Marine Live Brie Clayton May 27, 2026 0 Comments Large screen displays and slow motion replays dynamically ...

27/05/2026

Berklee Alumna and Assistant Professor Olivia Prez-Collellmir to Premiere Original Work at Gaud Centennial in Barcelona

Berklee Alumna and Assistant Professor Olivia P rez-Collellmir to Premiere Origi...

27/05/2026

Gravity Media Expands Into Creative Services With New Agency

Share Copy link Facebook X Linkedin Bluesky Email...

27/05/2026

Tegna Names Patrick Paolini as CEO

Share Copy link Facebook X Linkedin Bluesky Email...

27/05/2026

Telestream Taps Company Vet Benjamin Desbois as CEO

Share Copy link Facebook X Linkedin Bluesky Email...

27/05/2026

HDR10+ Technologies to Launch Eclipsa Video Certification Program

Share Copy link Facebook X Linkedin Bluesky Email...

27/05/2026

ATSC to Gather in Washington Next Week for Annual Meeting

Share Copy link Facebook X Linkedin Bluesky Email...

27/05/2026

Telestream Appoints Benjamin Desbois as Chief Executive O...

Co-founder Dan Castles to transition to Executive Chair; internal promotion reinforces continuity and long-term growth Telestream, a global leader in media wor...

27/05/2026

Big Blue Marble Announces First End-to-End 5G Broadcast S...

Big Blue Marble today announced that its Nakolos platform is the first end-to-end 5G Broadcast solution worldwide to implement the complete feature set introduc...

27/05/2026

Lightware Continues Its ESG Commitment Through Girls Day...

Lightware recently hosted the Girls' Day event in April at its headquarters in Budapest, welcoming students for an interactive introduction to engineering a...

27/05/2026

VEON's Kyivstar and Uklon Launch Ukraine's First Live Testing of Autonomous Vehicle Technology

27 May 2026 VEON's Kyivstar and Uklon Launch Ukraine's First Live Testi...

26/05/2026

Matrox Video Marks 50 Year Milestone

Share Copy link Facebook X Linkedin Bluesky Email...

26/05/2026

Roku Expands Premium Subscriptions With Fox One

Share Copy link Facebook X Linkedin Bluesky Email...

26/05/2026

Brian Gross Joins ASG's Audio Team as Account Manager

Share Copy link Facebook X Linkedin Bluesky Email...