Security experts say 4.5 million embedded systems use public HTTPS and Secure Shell (SSH) keys that are not secret. The Vienna-based SEC Consult analyzes internet-connected embedded systems. The firm has released all 580 private HTTPS and SSH host keys via the code-sharing site GitHub. The report builds on research that involved analyzing cryptographic keys contained in the firmware used to run more than 4,000 embedded devices from more than 70 vendors. The consultancy began working with the U.S. Computer Emergency Response Team in August 2015 to notify 50 vendors and ISPs.”]
Source: https://www.cuinfosecurity.com/bad-crypto-key-hygiene-equals-internet-things-danger-a-9386