Firmware security has barely improved over last decade

(Image credit: Geralt / Pixabay)

A new survey of over 6,000 firmware images has found no improvement in firmware security over the last 15 years as well as lax security standards for the software running connected devices from Linksys, NETGEAR and other major hardware vendors.

The survey was carried out by chief scientist at the Cyber Independent Testing Lab (CITL), Sarah Zatcko who explained that firmware security is worse off than many thought, saying:

“We found no consistency in a vendor or product line doing better or showing improvement. There was no evidence that anybody is making a concerted effort to address the safety hygiene of their products.”

The CITL study surveyed firmware from 18 different vendors including ASUS, D-link, Linksys, NETGEAR, Ubiquiti and others. The team analyzed over 6,000 firmware versions created from 2003 to 2018 as part of the first logitudinal study of Internet of Things (IoT) safety.

Firmware security

Researchers at CITL studied publicly available firmware images to compile their study and evaluated them based on the inclusion of standard security features such as the use of non-executable stacks, Address Space Layout Randomization (ASLR) and stack guards which are used to prevent buffer overflow attacks.

CITL found that firmware from commonly used manufacturers failed to implement basic security features and this was also true when the researchers tested the most recent versions of the firmware.

There was some good news including the fact that almost all of Linksys and NETGEAR's recent router firmware included non-executable stacks. However, other common security features like ASLR or stack guards were not implemented according to CITL's data.

The researchers documented 299 positive changes in firmware security scores over the 15 years covered by the study but they also found 360 negative changes during the same period. Analyzing the entire data set actually showed that firmware security appeared to get worse over time. The poor scores these devices earned suggest that many companies making IoT devices have not adapted their practices to account for the increased risks that come with connected devices.

Cybercriminals are increasingly targeting connected devices because when compared to Microsoft's Windows, Apple's macOS and Google Chrome, they are easy prey.

Via The Security Ledger

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day