Share

Connected devices have huge security holes - study

Washington - The surge web-connected devices - TVs, refrigerators, thermostats, door locks and more - has opened up huge opportunities for cyber attacks because of weak security, researchers said.

A study by the Hewlett-Packard security unit Fortify found 70% of the most commonly used "Internet of Things" devices contain vulnerabilities, including inadequate passwords or encryption, or lax access restrictions.

"While the Internet of Things will connect and unify countless objects and systems, it also presents a significant challenge in fending off the adversary given the expanded attack surface," said Mike Armistead, vice president and general manager for Fortify's enterprise security.

"With the continued adoption of connected devices, it is more important than ever to build security into these products from the beginning to disrupt the adversary and avoid exposing consumers to serious threats."

The study comes amid recent security warnings about hacking of medical devices, cars, televisions and even toilets that have an internet connection.

Vulnerabilities

The researcher scanned the most popular devices and their cloud components and found on average 25 vulnerabilities per device. These products included TVs, webcams, home thermostats, remote power outlets, sprinkler controllers, hubs for controlling multiple devices, door locks, home alarms, scales and garage door openers.

The study said eight of 10 devices tests leaked private information that could include the user's name, e-mail address, home address, date of birth, credit card or health information.

Most of the devices lacked passwords, making it easier for hackers or others to gain access while some included simple default passwords such as "1234".

Some 70% of the devices analysed failed to use encryption for communicating with the internet and local network, another weakness that makes for easy outside access.

HP said that while demand for these devices is surging, security has failed to keep pace, and this "opens the doors for security threats" from a variety of sources.

The study said some estimates indicate as many as 26 billion devices will be connected to the internet by 2020.

"Fortunately, there's still time to secure devices before consumers are at risk," the report said.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.15
+0.0%
Rand - Pound
23.87
-0.2%
Rand - Euro
20.43
-0.2%
Rand - Aus dollar
12.30
+0.0%
Rand - Yen
0.12
-0.0%
Platinum
941.30
-1.0%
Palladium
1,025.00
-0.4%
Gold
2,380.85
+0.1%
Silver
28.34
+0.4%
Brent Crude
87.11
-0.2%
Top 40
66,936
-0.4%
All Share
72,968
-0.4%
Resource 10
62,929
-0.6%
Industrial 25
98,144
-0.3%
Financial 15
15,426
-0.4%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders