HomeSecurityHP identifies significant vulnerabilities in home security systems

HP finds major vulnerabilities in home security systems

An HP study of some of the most popular Internet-connected security devices reveals notable security gaps related to authentication and authorization, as well as cloud-based and mobile web interfaces.

HP found flaws - Connected Home Security Systems
Researchers from HP tested ten of the latest devices and discovered that, in many cases, inadequate integration of protection mechanisms could provide a third party with the ability to use them against their owner.

“The intent of these systems is to provide security and remote monitoring to a homeowner, but given the vulnerabilities we discovered, the owner of the home security system may not be the only one monitoring the home,” the researchers said in a recent report.

The series of vulnerabilities concerns the lack of two-factor authentication (2FA), which was detected in only one case, and issues related to the poor implementation of the SSL/TLS secure communication standard for mobile and the cloud-based interface, which allowed the exploitation of the POODLE.

A vulnerability found on all devices tested was the fact that weak passwords were allowed, with the lowest level recommended being six alphanumeric characters. This, combined with an insecure password recovery method or poorly protected log-ins, could lead to unauthorized access by third parties.

The possibility of brute-force attacks was also identified by the researchers, as some systems had no limit on the number of failed log-in attempts.

Account enumeration vulnerabilities were observed in seven cases. This would allow someone to gain knowledge about a target's user account from responses returned by different authorization services, such as feedback from a password reset action or from failed log-ins.

HP says that many of the systems under study raise concerns about the firmware, which relies on an unencrypted connection for transfer. Even more concerning is the fact that one of the systems was feeding the update file via FTP and allowing credentials to be recorded, which gave write permissions to the server.

Additionally, HP states that all devices collect various types of personal information, including payment card data and phone numbers along with the user's name, address and/or date of birth.

One of the best recommendations for consumers is to change the default username and password provided by the manufacturer. It is also a good idea to pay attention to the available security features of each device.

Businesses can isolate devices from the rest of the network to prevent intrusion.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS