Study of 4000 embedded devices from over 70 vendors shows reused crypto keys leave millions of devices insecure, only 5 vendors known to have fixes on the way
Thomas Fox-Brewster / Forbes :
Context & Ripple Effects
This Forbes report by Thomas Fox-Brewster is the opening entry in what became a multi-year documentation of embedded-device key hygiene: researchers scanned 4,000 devices from more than 70 vendors and found reused cryptographic keys, with only five vendors known to have fixes on the way. The finding matters because HTTPS and SSH trust depends on keys being unique per device.
Subsequent reporting validated and expanded the arc rather than contradicting it: a 2016 follow-up put the exposed population at over 4.5M network appliances and IoT devices reusing known private keys, and later studies found the same class of problem in four widely used open source TCP/IP stacks shipped in millions of embedded products — while a Fraunhofer survey showed 46 of 127 home routers had received zero updates in a year, explaining why such flaws persist in the field.
First-order effects
- Owners of the affected embedded devices face immediate risk: a reused private key allows attackers to impersonate or decrypt the HTTPS and SSH services those devices present, and with only 5 of 70+ vendors preparing patches, most buyers currently have no remediation path.
Second-order effects
- Vendors outside the five fixing now face pressure to audit their own key generation after the scan methodology proved reusable at fleet scale — a pressure realized when the same reuse pattern was measured across 4.5M appliances the following year.
Third-order effects
- If the pattern holds, procurement and regulation will treat unique-per-device credentials and an update channel as baseline requirements for network-connected hardware, shifting liability toward vendors whose devices ship unpatchable — a shift already visible in later stack-level audits like Amnesia:33 and the router-patching gap studies.
The trend: Embedded and IoT security is moving from point-in-time vulnerability reports toward systemic scrutiny of shared components and update infrastructure, as repeated scans show the same key-reuse and patching failures across years and vendors.