A Brief History of ONEKEY: Securing the Internet of Things Since 2015

Since its initial development in 2015, the firmware analysis platform ONEKEY (formerly known as IoT Inspector) has analyzed tens of thousands of firmware images for vulnerabilities and compliance violations. Not only have we been able to identify countless misconfigurations and security issues. We have also detected many previously unknown security vulnerabilities for the first time.
Increasing Connectivity = Growing Security Risks
It is conductedby Nokia,IoT devices already accounted for one-third of all devices affected by security vulnerabilities in 2020. By comparison, the figure was only 16 percent in 2019. But the Internet of Things goes well beyond smart homes and personal gadgets such as hobby drones and fitness trackers. In over
Automated Analysis Tools for Efficient Security Checks
These numbers are startling, though unsurprising, as the vast majority of IoT devices operate under questionable security standards: 57% of them are “vulnerable to medium- or high-severity attacks, making IoT the low-hanging fruit for attackers.”
SEC Consult recognized the rapidly growing problem of insecure IoT devices early on and set the success story of IoT Inspector in motion as early as 2015. With the increasing demand for product testing of IoT and embedded devices (due tostricter regulatory requirements, particularly), the security consultants saw the need for an automated solution to support the relevant security checks. This laid the foundation for IoT Inspector.
House of Keys and the Tale of Black Widow
The first large-scale research project took place the same year. Security researcher. 580 security keys were reused and found ina large number ofdevices - making their encryption obsolete and exposing numerous devices to an increased security risk.
The brand "IoT Inspector" was first used in 2016, when a was uncovered in several devices from the American conference room equipment manufacturer AMX - whose products were used at the time in the White House, particularly. The devices had secret credentials(code name: black widow)thatallowthe manufacturer (and possibly others) to easily gain access to the devices and spy on its customers.This backdoor was discovered during a manual analysis and subsequently added to IoT Inspector's database.It isalsoworth mentioningthat the manufacturer has assured that it hadgotten rid ofthe backdoor during a security update. However, a new analysis by IoT Inspector showed the backdoor was not removed, only renamed...
In the same year, we achieved another brilliant success:Many companies use cameras to monitor their premises and protect themselves from intruders. Paradoxically, sometimes the cameras themselves are not sufficiently secured against external attacks. For example, a
A vulnerability of even greater magnitude was discovered in 2018 in the course of research around the automated detection of management protocols and supported cloud backends in IoT firmware at the Chinese OEM manufacturer Xiongmai. Its white-label components are used in products around the globe. Accordingly, over 9 million cameras were equipped with a remote monitoring feature enabled by default ("XMEye P2P cloud"), which was affected by critical security vulnerabilities. Of course, since then, vulnerable connections to the XMEye P2P cloud can be detected automatically by IoT Inspector, in addition to dozens of other management protocols.
An Overview of IoT Inspector in Action
To go into all the findings in detail would be beyond the scope here, but we can say this much: The research team of SEC Consult is always very ambitious in its fight for more cybersecurity.

To continuously develop IoT Inspector's analysis capabilities, we work with established security experts, including Red Alert Labs, QGroup, TÜV Rheinland, TÜV Hessen and VDE-Cert. Our analysis platform supports the security research of our research partners, and insights from their manual security analyses in turn migrate into the vulnerability modules of IoT Inspector. If you are also interested in a research partnership, we look forward to hearing from you.
#makeIoTsecure - IoT Security for Your Company
Our missionis to make the Internet of Things secure. That's why we developed IoT Inspector - the leading European solution for automated firmwaresecurity analysis and compliance checks. To make our technology accessible to the widest possible audience, in June 2020 we completely separated from by Atos).
Since then, IoT Inspector has been an independent company based in Bad Homburg, Germany. In September 2020,we received a

ONEKEY - How it Works
Whether you manufacture IoT products ourself, distribute them (e.g.as a telecommunications service provider), perform security audits for your customers, certify devices, or use them in your company: we can help. Don't ignore the security risk of your IoT devices and
Über Onekey
ONEKEY ist der führende europäische Spezialist für Product Cybersecurity & Compliance Management und Teil des Anlageportfolios von PricewaterhouseCoopers Deutschland (PwC). Die einzigartige Kombination der automatisierten ONEKEY Product Cybersecurity & Compliance Platform (OCP) mit Expertenwissen und Beratungsdiensten bietet schnelle und umfassende Analyse-, Support- und Verwaltungsfunktionen zur Verbesserung der Produktsicherheit und -konformität — vom Kauf über das Design, die Entwicklung, die Produktion bis hin zum Ende des Produktlebenszyklus.

KONTAKT:
Sara Fortmann
Senior Marketing Manager
sara.fortmann@onekey.com
euromarcom public relations GmbH
team@euromarcom.de
Bereit zur automatisierung ihrer Cybersicherheit & Compliance?
Machen Sie Cybersicherheit und Compliance mit ONEKEY effizient und effektiv.
.avif)