/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Study of 4000 embedded devices from over 70 vendors shows reused crypto keys leave millions of devices insecure, only 5 vendors known to have fixes on the way

Thomas Fox-Brewster / Forbes :

Forbes Thomas Fox-Brewster

Context & Ripple Effects

This Forbes report by Thomas Fox-Brewster is the opening entry in what became a multi-year documentation of embedded-device key hygiene: researchers scanned 4,000 devices from more than 70 vendors and found reused cryptographic keys, with only five vendors known to have fixes on the way. The finding matters because HTTPS and SSH trust depends on keys being unique per device.

Subsequent reporting validated and expanded the arc rather than contradicting it: a 2016 follow-up put the exposed population at over 4.5M network appliances and IoT devices reusing known private keys, and later studies found the same class of problem in four widely used open source TCP/IP stacks shipped in millions of embedded products — while a Fraunhofer survey showed 46 of 127 home routers had received zero updates in a year, explaining why such flaws persist in the field.

First-order effects

  • Owners of the affected embedded devices face immediate risk: a reused private key allows attackers to impersonate or decrypt the HTTPS and SSH services those devices present, and with only 5 of 70+ vendors preparing patches, most buyers currently have no remediation path.

Second-order effects

  • Vendors outside the five fixing now face pressure to audit their own key generation after the scan methodology proved reusable at fleet scale — a pressure realized when the same reuse pattern was measured across 4.5M appliances the following year.

Third-order effects

  • If the pattern holds, procurement and regulation will treat unique-per-device credentials and an update channel as baseline requirements for network-connected hardware, shifting liability toward vendors whose devices ship unpatchable — a shift already visible in later stack-level audits like Amnesia:33 and the router-patching gap studies.

The trend: Embedded and IoT security is moving from point-in-time vulnerability reports toward systemic scrutiny of shared components and update infrastructure, as repeated scans show the same key-reuse and patching failures across years and vendors.