/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Study of 4000 embedded devices from over 70 vendors shows reused crypto keys leave millions of devices insecure, only 5 vendors known to have fixes on the way

‘Worrying’ 9 Per Cent Of Encrypted Web Vulnerable To Private Key Attacks  —  Getting encryption right can be hard.

Forbes Thomas Fox-Brewster

Context & Ripple Effects

A scan of 4,000 devices from more than 70 vendors found that many ship with reused cryptographic keys for their HTTPS and SSH servers, meaning an attacker who extracts one private key can impersonate a whole class of appliances — and only five vendors are known to have fixes underway. The finding puts a number on a problem that keeps resurfacing in embedded security research.

It was not a one-off: within a year researchers counted over 4.5 million network appliances, IoT devices, and embedded systems vulnerable to known-key reuse, and by 2023 the same class of flaw had matured into demonstrated complete compromise of SSH-protecting keys. The 2015 study is an early data point in a pattern spanning at least eight years.

First-order effects

  • Owners of the affected routers, appliances, and IoT devices face immediate exposure to man-in-the-middle attacks that can decrypt or forge their encrypted sessions, while most of the 70-plus vendors have no patch available — leaving the five with fixes as the exception, not the rule.

Second-order effects

  • Enterprise buyers gain leverage to demand per-device key generation and signed firmware from appliance vendors, and rivals who fix quickly can turn the disclosure into a differentiator against the laggards — the same dynamic later seen when chip and OS vendors raced patches after the Bluetooth encryption bug hit Apple, Broadcom, Intel, and Qualcomm.

Third-order effects

  • If key reuse persists as studies keep confirming it, embedded cryptography shifts from a vendor implementation detail to a procurement and regulatory question — with certification schemes and buyer checklists treating unique key provisioning as a baseline requirement rather than a feature.

The trend: Embedded and IoT security keeps failing at its weakest shared layer — cryptographic keys and TCP/IP stacks, as Amnesia:33 later showed — because firmware is copied across millions of devices faster than it is fixed.