IoT devices becoming an increasing security risk

IoT smart home security
(Image credit: Shutterstock.com) (Image credit: Shutterstock.com)

The rise in IoT devices may be leading to better connectivty and a boost in your Netflix consumption, but could also be putting your home at risk of cyberattack, new research has claimed.

A report from security firm Avast and Stanford University has found that about 40 percent of households across the globe now contain at least one IoT device

However many of these use outdated secuerity protocols or still have the default password in place, leaving households, offices and other workplaces at risk.

IoT security

In order to get its results, Avast scanned 83 million IoT devices across 16 million homes worldwide. It found that 94 percent of all IoT devices are manufatcured by just 100 vendors, with media and television-related devices the most common.

More worryingly, though, the study found that obsolete protocols like FTP and Telnet are still used by seven percent of total devices, meaning millions of devices are especially vulnerable. 

This was also the case for 15 percent of home routers, which is also worrying, as such devices can act as a gateway into the home network, opening up multiple devices to attack.

Surveillance devices such as security cameras were also found have the weakest Telnet profile, along with routers and printers - which again culd put them at rise of compromise, as seen in the hugely damaging Mirai botnet attacks. 

“The security community has long discussed the problems associated with emerging IoT devices,” said Zakir Durumeric, assistant professor of computer science at Stanford University.

“Unfortunately, these devices have remained hidden behind home routers and we’ve had little large-scale data on the types of devices deployed in actual homes. This data helps us shed light on the global emergence of IoT and the types of security problems present in the devices real users own.”

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions
Shure MoveMic 88+ lifestyle image
Shure's tiny MoveMic 88+ gives creators a cheap and easy way to record crystal clear audio on a smartphone
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April