Search

Lazy Encryption Practices Endanger Millions of Internet-Enabled Devices: Report

Advertisement
Lazy Encryption Practices Endanger Millions of Internet-Enabled Devices: Report

The Internet of things (IoT), the chip or sensor-equipped devices connected to each other over the Internet, continue to be a topic of concern among security researchers. A new report has found that a large number of well-known vendors continue to overlook security in their products, leaving their customers at risk. The list of vulnerable products stretches from IoT devices to networking equipment and mobiles.

According to a report by IT security consultancy SEC Consult, the cryptographic keys meant to certify connections are being made to official servers and devices are in fact easily extractable. Compounding the problem is that thousands of devices use the same 'unique' private keys, so once hackers get hold of one, they can potentially affect several more devices and connections.

The researchers at the firm analysed firmware images of over 4,000 embedded devices from over 70 companies, consisting of modems, routers, gateways, and VoIP phone vendors. The firm said that most of these vendors reuse the same cryptography keys. It was able to extract more than 580 unique private keys shared across systems. If attackers get access to these keys, they can impersonate any of the affected device servers, perform man-in-the-middle (MitM) attacks, and passive decryption attacks to obtain private information.

Of the total unique private keys, the firm said that at least 230 keys are actively used. Roughly 150 of the identified server certificates are used by a whopping 3.2 million HTTPS hosts, which to give some context, represent nine percent of all HTTPS hosts on the Web. Private keys for more than six percent of all Secure Shell (SSH) hosts on the Web are also uncovered during the research. An attacker with access to all these keys could monitor encrypted Web traffic, and spoof encrypted connections.

The firm further noted that most of cryptographic keys are hardcoded into the firmware of Internet-enabled devices, and vendors are found to be using the same keys across their product lineup, but on many occasions, the same keys were also found in products from different vendors. Best practices dictate random, unique keys are generated for each device at the factory stage, or on first boot of the device.

One certificate, for instance, which is found in Broadcom software development kit, is used by companies such as Actiontec, Aztech, Innatech, Comtrend, Smart RG, Zhone and ZyXEL to develop firmware. Because of this wide usage, the certificate is used in half a million devices. Another such certificate found in Texas Instruments SDK is used by many major vendors, shared across 300,000 devices.

SEC Consult notes that millions of the devices are directly accessible via the Internet due to these crippled configurations. More than 80,000 Seagate FoFlex NAS devices are accessible via the Internet, it has been found.

The study has found that Internet Service Providers (ISPs) including CenturyLink, TELMEX, Telefonica, China Telecom, VTR Globalcom, Chunghwa Telecom are also exposing their users to attacks with HTTPs and SSH remote administration features enabled by default.

(Also see: Mobile Locked Unless You Pay the Ransom? Could Happen to You in 2016)

The report said, "We found more than 900 products from about 50 vendors to be vulnerable. Of course our data is limited to the firmware we had access to. Affected vendors are: ADB, AMX, Actiontec, Adtran, Alcatel-Lucent, Alpha Networks, Aruba Networks, Aztech, Bewan, Busch-Jaeger, CTC Union, Cisco, Clear, Comtrend, D-Link, Deutsch Telekom, DrayTek, Edimax, General Electric (GE), Green Packet, Huawei, Infomark, Innatech, Linksys, Motorola, Moxa, NETGEAR, NetComm Wireless, ONT, Observa Telecom, Opener, Pace, Philips, Pirelli , Robustel, Sagemcom, Seagate, Seowon Intech, Sierra Wireless, Smart RG, TP-LINK, TRENDnet, Technicolor, Tenda, Tootling, unify, UPVEL, Ubee Interactive, Ubiquiti Networks, Vodafone, Western Digital, ZTE, Zhone and ZyXEL."

The firm says that it believes that even more devices could be affected by the aforementioned attacks. SEC Consult's findings once again underscore how vulnerable IoT devices are, and to the extent they are used by people. As Kaspersky had pointed out earlier this month, a vulnerable IoT device also compromises the security of the entire wireless network and devices connected to it.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Latest OTT Releases: When and What to Watch this Weekend
  2. Nvidia GeForce RTX 5060, GeForce RTX 5060 Ti Price in India Announced
  3. Infinix Note 50s 5G+ With 64-Megapixel Rear Camera Launched in India
  4. Moto Pad 60 Pro With 12.7-Inch Display, Quad JBL Speakers Launched in India
  5. PS5 Slim Models Discounted in Sony's 'Summer Sale' Offer: See Price
  6. Realme Buds Air 7 Pro Launch Date, Design, Key Features Confirmed
  7. WhatsApp Now Lets You Create, Organise and Share Custom Sticker Packs
  8. Oppo A5 Pro 5G India Launch Timeline Tipped; Price, Expected Specifications
  9. Realme GT 8 Pro Tipped to Feature Bigger Battery Than Realme GT 7 Pro
  10. Amazon's First Streaming Device Wiith Its Vega OS Could Launch This Year
  1. OnePlus 13T Chipset, Camera Details Teased; to Use Snapdragon 8 Elite Chipset
  2. Mario Kart World Direct Details New Courses, Characters and More
  3. Amazon's Vega TV OS Expected to Debut on First Streaming Device in 2025: Report
  4. WhatsApp Rolls Out New Feature Which Lets Users Create, Organise and Share Custom Sticker Packs
  5. Infinix Note 50s 5G+ With MediaTek Dimensity 7300 Ultimate SoC, 64-Megapixel Rear Camera Launched in India
  6. Perplexity AI Said to Be in Talks With Samsung, Motorola for Virtual Assistant Integration Deal
  7. Motorola Razr 60 Ultra Specifications Leaked; Said to Get Snapdragon 8 Elite, 7-Inch Main Display, More
  8. Realme Buds Air 7 Pro to Launch Alongside Realme GT 7 on April 23; Design, Key Features Revealed
  9. Nvidia GeForce RTX 5060, GeForce RTX 5060 Ti Price in India and Availability Announced
  10. Android 16 Beta 4 Rolling Out With Fixes for Developer and User-Reported Issues, Expanded OEM Support
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »