Abstract
Transport Layer Security (TLS) is commonly used to secure communications over the Internet. However, since the rise of Internet of Things (IoT) devices, there have been concerns regarding the security practices adopted in the development of these devices. In particular, the study IoTLS (IMC'21) analyzed TLS practices in consumer IoT devices and revealed widespread use of insecure protocol versions, weak cipher suites, and improper certificate validation.
Our work reproduces the IoTLS analysis on a new set of 22 comparable consumer IoT devices to assess the advancement of security practices five years later. Our findings indicate significant improvements; for example, support for deprecated TLS versions has decreased from 45% to 9.1%. However, insecure configurations remain prevalent: 86.4% of devices still accept weak cipher suites. These results indicate that while manufacturers have made progress in adopting secure TLS practices, further efforts are needed to achieve a consistently secure IoT landscape.
Our work reproduces the IoTLS analysis on a new set of 22 comparable consumer IoT devices to assess the advancement of security practices five years later. Our findings indicate significant improvements; for example, support for deprecated TLS versions has decreased from 45% to 9.1%. However, insecure configurations remain prevalent: 86.4% of devices still accept weak cipher suites. These results indicate that while manufacturers have made progress in adopting secure TLS practices, further efforts are needed to achieve a consistently secure IoT landscape.
| Original language | English |
|---|---|
| Title of host publication | EuroSec '26 |
| Subtitle of host publication | Proceedings of the 19th European Workshop on Systems Security |
| Place of Publication | New York, NY |
| Publisher | Association for Computing Machinery (ACM) |
| Pages | 53-59 |
| Number of pages | 7 |
| ISBN (Electronic) | 9798400726033 |
| ISBN (Print) | 979-8-4007-2603-3 |
| DOIs | |
| Publication status | Published - 26 Apr 2026 |
Keywords
- IoT security
- TLS
- IoT Networks
Fingerprint
Dive into the research topics of 'IoTLS 2.0: How Far Has IoT Industry Come in Securing Communications with TLS?'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver