HP Study Reveals Smartwatches Vulnerable to Attack

Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to threats to sensitive information.

As part of an ongoing series looking at Internet of Things (IoT) security, HP has unveiled results of an assessment confirming that smartwatches with network and communication functionality represent a new and open frontier for cyberattack. The study conducted by HP Fortify found that 100 percent of the tested smartwatches contain significant vulnerabilities, including insufficient authentication, lack of encryption and privacy concerns1. In the report HP provides actionable recommendations for secure smartwatch development and use, both at home and in the workplace. As the IoT market advances, smartwatches are growing in popularity for their convenience and capabilities. As they become more mainstream, smartwatches will increasingly store more sensitive information such as health data, and through connectivity with mobile apps may soon enable physical access functions including unlocking cars and homes. “Smartwatches have only just started to become a part of our lives, but they deliver a new level of functionality that could potentially open the door to new threats to sensitive information and activities,” said Jyoti Prakash, Country Director, India and SAARC countries, HP Enterprise Security Products (ESP). “As the adoption of smartwatches accelerates, the platform will become vastly more attractive to those who would abuse that access, making it critical that we take precautions when transmitting personal data or connecting smartwatches into corporate networks.” The HP study questions whether smartwatches are designed to store and protect the sensitive data and tasks for which they are built. HP leveraged  HP Fortify on Demand to assess 10 smartwatches, along with their Android and iOS cloud and mobile application components, uncovering numerous security concerns. The most common and easily addressable security issues reported include:

  • Insufficient User Authentication/Authorization: Every smartwatch tested was paired with a mobile interface that lacked two-factor authentication and the ability to lock out accounts after 3-5 failed password attempts. Three in ten, 30 percent, were vulnerable to account harvesting, meaning an attacker could gain access to the device and data via a combination of weak password policy, lack of account lockout, and user enumeration.
  • Lack of transport encryption:Transport encryption is critical given that personal information is being moved to multiple locations in the cloud. While 100 percent of the test products implemented transport encryption using SSL/TLS, 40 percent of the cloud connections continue to be vulnerable to the POODLE attack, allow the use of weak cyphers, or still used SSL v2.
  • Insecure Interfaces:Thirty percent of the tested smartwatches used cloud-based web interfaces, all of which exhibited account enumeration concerns. In a separate test, 30 percent also exhibited account enumeration concerns with their mobile applications. This vulnerability enables hackers to identify valid user accounts through feedback received from reset password mechanisms.
  • Insecure Software/Firmware:A full 70 percent of the smartwatches were found to have concerns with protection of firmware updates, including transmitting firmware updates without encryption and without encrypting the update files. However, many updates were signed to help prevent the installation of contaminated firmware. While malicious updates cannot be installed, lack of encryption allows the files to be downloaded and analyzed.
  • Privacy Concerns:All smartwatches collected some form of personal information, such as name, address, date of birth, weight, gender, heart rate and other health information. Given the account enumeration issues and use of weak passwords on some products, exposure of this personal information is a concern.
Recommendations HP has the following recommendations for those looking to use or produce smartwatch devices in a more secure manner: Consumer
  • Do not enable sensitive access control functions (e.g., car or home access) unless strong authentication is offered (two-factor etc).
  • Enable passcode functionality to prevent unauthorized access to your data, opening of doors, or payments on your behalf.
  • Enable security functionality (e.g., passcodes, screen locks, two-factor and encryption). • For any interface such as mobile or cloud applications associated with your watch, ensure that strong passwords are used.
  • Do not approve any unknown pairing requests (to the watch itself).
Enterprise Technical Teams
  • Ensure TLS implementations are configured and implemented properly.
  • Protect user accounts and sensitive data by requiring strong passwords.
  • Implement controls to prevent man-in-the-middle attacks.
  • Build mobile applications (specific to each ecosystem) into the device – in addition to any vendor-provided or recommended apps.
 


Tags assigned to this article:
hp insights internet of things iot

Advertisement

Around The World