HomeSecurityIoT is "growing" but security is still lagging behind!

IoT is growing but security is still lagging behind!

Four out of five Internet of Things (IoT) device manufacturers are failing basic cybersecurity practices by not providing users with a way to disclose security vulnerabilities in their products – which can put device users at risk of cyberattacks and privacy breaches.

See also: BadAlloc bugs expose millions of IoT devices to hijack

IoT

See also: Samsung: Software update turns old Galaxy smartphones into IoT devices

Research from the IoT Security Foundation (IoTSF) – a technology group aimed at encouraging Internet of Things security – analyzed hundreds of popular IoT product manufacturers and found that only one in five advertises a public channel for reporting security vulnerabilities so they can be fixed.

The 21% of vendors offering this type of channel has increased slightly since last year, which the IoT Security Foundation report describes as “glacial” progress in providing what it describes as a “core hygiene mechanism.”.

This is despite countries around the world, including the UK, US, Singapore, India and Australia, as well as the European Union, trying to emphasize the importance of cybersecurity in IoT devices and the ability to disclose vulnerabilities.

The report notes that part of the lack of vulnerability disclosure policies can be attributed to “non-traditional IT businesses” entering the IoT market for the first time, such as fashion houses launching connected products or kitchen appliance manufacturers adding smart capabilities to their products.

In these cases, it makes sense that the manufacturer doesn't have security in mind in the products themselves, so not only could vulnerabilities find their way into the devices, but there's also no set way to report them.

See also: Vulnerabilities put millions of IoT devices at risk - Update immediately!

However, the report points out how “best practice related to IoT has been freely available to anyone with an internet connection since 2017” and that the way four out of five companies fail to provide a mechanism that allows security vulnerabilities to be reported so they can be fixed is “unacceptably low” – and this could indicate wider problems.

Internet of Things devices are increasingly becoming part of home and office equipment. While many home brands are ensuring that their products are equipped with good security practices – the report cites tech companies such as Sony, Panasonic, Samsung, LG, Google, Microsoft, Dell, Lenovo, Amazon, Logitech and Apple among them – it is common for consumers to buy cheaper alternatives that do not place much emphasis on security.

The research paper paints a bleak picture of the IoT security landscape, but the IoT Security Foundation believes that eventually all of this will change and security will become a fundamental part of product design.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS