element14 Community
element14 Community
    Register Log In
  • Site
  • Search
  • Log In Register
  • Community Hub
    Community Hub
    • What's New on element14
    • Feedback and Support
    • Benefits of Membership
    • Personal Blogs
    • Members Area
    • Achievement Levels
  • Learn
    Learn
    • Ask an Expert
    • eBooks
    • element14 presents
    • Learning Center
    • Tech Spotlight
    • STEM Academy
    • Webinars, Training and Events
    • Learning Groups
  • Technologies
    Technologies
    • 3D Printing
    • FPGA
    • Industrial Automation
    • Internet of Things
    • Power & Energy
    • Sensors
    • Technology Groups
  • Challenges & Projects
    Challenges & Projects
    • Design Challenges
    • element14 presents Projects
    • Project14
    • Arduino Projects
    • Raspberry Pi Projects
    • Project Groups
  • Products
    Products
    • Arduino
    • Avnet & Tria Boards Community
    • Dev Tools
    • Manufacturers
    • Multicomp Pro
    • Product Groups
    • Raspberry Pi
    • RoadTests & Reviews
  • About Us
    About the element14 Community
  • Store
    Store
    • Visit Your Store
    • Choose another store...
      • Europe
      •  Austria (German)
      •  Belgium (Dutch, French)
      •  Bulgaria (Bulgarian)
      •  Czech Republic (Czech)
      •  Denmark (Danish)
      •  Estonia (Estonian)
      •  Finland (Finnish)
      •  France (French)
      •  Germany (German)
      •  Hungary (Hungarian)
      •  Ireland
      •  Israel
      •  Italy (Italian)
      •  Latvia (Latvian)
      •  
      •  Lithuania (Lithuanian)
      •  Netherlands (Dutch)
      •  Norway (Norwegian)
      •  Poland (Polish)
      •  Portugal (Portuguese)
      •  Romania (Romanian)
      •  Russia (Russian)
      •  Slovakia (Slovak)
      •  Slovenia (Slovenian)
      •  Spain (Spanish)
      •  Sweden (Swedish)
      •  Switzerland(German, French)
      •  Turkey (Turkish)
      •  United Kingdom
      • Asia Pacific
      •  Australia
      •  China
      •  Hong Kong
      •  India
      •  Japan
      •  Korea (Korean)
      •  Malaysia
      •  New Zealand
      •  Philippines
      •  Singapore
      •  Taiwan
      •  Thailand (Thai)
      •  Vietnam
      • Americas
      •  Brazil (Portuguese)
      •  Canada
      •  Mexico (Spanish)
      •  United States
      Can't find the country/region you're looking for? Visit our export site or find a local distributor.
  • Translate
  • Profile
  • Settings
Internet of Things
  • Technologies
  • More
Internet of Things
Blog New study shows 70 percent of home IoT devices vulnerable to attack
  • Blog
  • Forum
  • Documents
  • Quiz
  • Events
  • Polls
  • Members
  • Mentions
  • Sub-Groups
  • Tags
  • More
  • Cancel
  • New
Join Internet of Things to participate - click to join for free!
  • Share
  • More
  • Cancel
Group Actions
  • Group RSS
  • More
  • Cancel
Engagement
  • Author Author: Catwell
  • Date Created: 27 Mar 2015 4:08 AM Date Created
  • Views 2304 views
  • Likes 1 like
  • Comments 15 comments
  • research
  • security
  • hp
  • internet_of_things
  • study
  • cabeatwell
  • iot_security
  • iot
  • innovation
Related
Recommended

New study shows 70 percent of home IoT devices vulnerable to attack

Catwell
Catwell
27 Mar 2015

image

IoT seems so clean, safe, comfy even... but it isn't. (image via HP)


As technology continues to advance, some wonder if it’s becoming easier or more difficult to compromise personal information. That’s why HP decided to conduct a study that observed the vulnerabilities of home security systems managed by the Internet of Things; the results were horrifying.

 

HP took 10 IoT-connected Home Security Systems and tested them across various standards of network security, including assessing basic password strength, security posture variance and network vulnerabilities. The researchers did not reveal the names of the security systems tested, but they warned home owners to be mindful of security when choosing the right system for them, as all 10 of the units tested featured alarming security vulnerabilities.

 

All 10 of the home security systems tested easily enabled account harvesting using the Cloud. HP researchers were able to hack the Cloud and log into security systems fraudulently, giving them access to user information, location and security videos on home security units – and that’s not all. All 10 of the systems also allowed for incredibly weak passwords, such as “12345,” and did not exhibit account lockouts after failed login attempts. Other huge security weaknesses were observed as well, including the failure to encrypt software updates and inconsistency in network security strength across devices, exhibited by seven of the 10 systems. While these weaknesses may seem small, together, they allow for a significant increase in overall security risks. HP says it isn’t just a problem with IoT-connected Home Security Systems either, but in fact a bigger issue with the Internet of Things at large.

 

The aforementioned study was actually the second study executed by HP researchers testing the security of devices connected via the IoT. In a previous study, the researchers looked at 10 different devices and watched for network insecurity; once again, the results were unnerving. Each device exhibited roughly 20 network vulnerabilities, each. That’s a lot of opportunity for an average hacker to compromise the information of anyone relying on the newer technology.

 

The real issue with the IoT, according to HP, is the variance in network security across multiple devices. One household may have 10 various devices relying on one network. While it’s a dream come true for consumers, who can seamlessly use their devices with across-the-board connectivity, it’s also a dream realized for hackers looking for an easy target. Until the IoT can function as one secure, collective network, HP researchers argue it will continue to exhibit network insecurities that put consumers at risk of being hacked.

 

The prospective of keeping IoT networks secure is grim, according to HP researchers. Connecting hundreds of devices to the internet without strong security software to begin with is a ticking bomb, they argue. Hacking into home security systems allows for relatively untraceable home robbery. Uploading banking information and other personal information to the IoT may greatly increase the risk of identity theft as well. With any hope, HP’s recent studies will call developers to focus on enhanced network security in the face of a generation suffering from an insatiable thirst for instant gratification and ease-of-use. Until then, however, be careful in selecting a home security system that’s connected via the IoT, unless, of course, you like strangers watching you through your own security cameras. But, there’s no accounting for taste. 

 

C

See more news at:

http://twitter.com/Cabe_Atwell

  • Sign in to reply

Top Comments

  • johnbeetem
    johnbeetem over 11 years ago +3
    IMO there are two kinds of devices: devices with no network connection whatsoever and hackable devices.
  • gadget.iom
    gadget.iom over 11 years ago in reply to dougg +1
    I accept your position with regard to connecting to open public wifi , though users have the option of using these networks on a take-it-or-leave-it basis. I personally use VPN and/or mobile tethering…
  • DAB
    DAB over 11 years ago +1
    Now you all understand why I have been a wet blanket on the IoT technology. Yes it is easy to use, but you send your data to anyone who wants to tap in. I think it is up to the manufacturers to setup security…
  • xever
    xever over 11 years ago in reply to clem57

    That plus a secure RF protocol and a very secure cloud service without compromising user experience.

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • clem57
    clem57 over 11 years ago in reply to DAB

    The solution? A strong gateway in front that isolates the IoT in the home IMHO.

    Clem

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • DAB
    DAB over 11 years ago

    Now you all understand why I have been a wet blanket on the IoT technology.

     

    Yes it is easy to use, but you send your data to anyone who wants to tap in.

     

    I think it is up to the manufacturers to setup security in the devices, otherwise uninformed users will be at risk.

     

    DAB

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • gadget.iom
    gadget.iom over 11 years ago in reply to dougg

    I accept your position with regard to connecting to open public wifi , though users have the option of using these networks on a take-it-or-leave-it basis. I personally use VPN and/or mobile tethering when connecting to sensitive resources. Unfortunately the direction some of these devices are going in will mean that it can't/won't function without connecting to resources on the internet, and users won't have the same choices.


    I do agree though that articles such as this tend to scare monger, and offer no real information or risk mitigation approaches.

    • Cancel
    • Vote Up +1 Vote Down
    • Sign in to reply
    • More
    • Cancel
  • dougg
    dougg over 11 years ago in reply to gadget.iom

    Sure, there are risks involved when connecting devices. I worked on an IoT gateway for a company called Tendril. We improved the security quite a bit, but as a small embedded Linux system, there are limits to what can be done.

    Articles like this are aggravating. The security of the IoT has to be better, perfect or some combination. In the end, your selling a device to a consumer. The same person is worried about their electric meter or thermostat being a security risk will happily connect to an open WiFi network at Starbucks and login to Facebook. It just makes no sense and is self contradicting.

    Security of industrial devices needs to be held to a higher standard.

    • Cancel
    • Vote Up 0 Vote Down
    • Sign in to reply
    • More
    • Cancel
<>
element14 Community

element14 is the first online community specifically for engineers. Connect with your peers and get expert answers to your questions.

  • Members
  • Learn
  • Technologies
  • Challenges & Projects
  • Products
  • Store
  • About Us
  • Feedback & Support
  • FAQs
  • Terms of Use
  • Privacy Policy
  • Legal and Copyright Notices
  • Sitemap
  • Cookies

An Avnet Company © 2026 Premier Farnell Limited. All Rights Reserved.

Premier Farnell Ltd, registered in England and Wales (no 00876412), registered office: Farnell House, Forge Lane, Leeds LS12 2NE.

ICP 备案号 10220084.

Follow element14

  • X
  • Facebook
  • linkedin
  • YouTube