HP study on 10 smartwatches finds ALL vulnerable to attack
By Digital News Asia August 10, 2015
- 100% of tested smartwatches exhibit security flaws
- Study provides guidance for secure device use
A STUDY by Hewlett-Packard Co’s Fortify security research unit found that 100% of tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption, and privacy concerns.
The report was part of an ongoing series looking at Internet of Things (IoT) security, HP said in a statement, adding that the results confirmed that smartwatches with network and communication functionality represent a new and open frontier for cyberattack.
In the report, HP also provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace, the company said.
READ ALSO: DNA Test: Chinese smartwatches – cheap, but any good?
As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities.
As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps, may soon enable physical access functions including unlocking cars and homes, HP said in its statement.
“Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities,” said HP Enterprise Security Products’ South-East Asia regional director Jeffrey Neo.
“As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks,” he added.
The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built.
The company made use of its Fortify on Demand managed application security testing service to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns.
The most common and easily addressable security issues reported include:
- Insufficient user authentication/ authorisation: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication (2FA) and the ability to lock out accounts after three to five failed password attempts. Three in 10, or 30%, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.
- Lack of transport encryption: Transport encryption is critical given that personal information is being moved to multiple locations in the cloud, HP said. While 100% of the test products implemented transport encryption using SSL/ TLS, 40% of the cloud connections continue to be vulnerable to the Poodle attack, allow the use of weak cyphers, or still used SSL v2.
- Insecure interfaces: 30% of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30% also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.
- Insecure software/ firmware: A full 70% of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analysed.
- Privacy concerns: All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.
As manufacturers work to incorporate necessary security measures into smartwatches, consumers are urged to consider security when choosing to use a smartwatch.
It’s recommended that users do not enable sensitive access control functions such as car or home access unless strong authorisation is offered, HP said.
In addition, enabling passcode functionality, ensuring strong passwords and instituting two-factor authentication will help prevent unauthorised access to data, the company added.
These security measures are not only important to protecting personal data, but are critical as smartwatches are introduced to the workplace and connected to corporate networks.
Additional guidelines for secure smartwatch use are outlined in the full report.
For more information, download the first report in this IoT series, 2014 HP Internet of Things Research Study, which reviews the security of 10 of the most common IoT devices.
In addition, the 2015 HP Home Security Systems Report reviews the 10 of the most common Internet-connected home security systems.
Conducted by HP Fortify, the HP Smartwatch Security Study used the HP Fortify on Demand IoT testing methodology which combined manual testing along with the use of automated tools.
Devices and their components were assessed based on the OWASP Internet of Things Top 10 and the specific vulnerabilities associated with each top 10 category.
All data and percentages for this study were drawn from the 10 smartwatches tested during this study. While there are certainly a fair number of smartwatch devices already on the market, and that number continues to grow, HP believes the similarity in results of the 10 smartwatches provides a good indicator of the current security posture of smartwatch devices.
Beware wearables and IoT: Kaspersky on security risks
Security the ‘elephant’ in the IoT/ smart city room: Frost
Smartwatches set for prime time: GfK
For more technology news and the latest updates, follow us on Twitter, LinkedIn or Like us on Facebook.