Hackers Stalked Me by Hijacking a Smartwatch for Kids

1 month ago 26

Want Your Business Featured Here?

Get instant exposure to our readers

Chat on WhatsApp

The Dark Side of Smartwatches: Millions of Children's Devices Vulnerable to Hacking

A disturbing revelation has emerged about the security of smartwatches designed for children, with two researchers set to expose the alarming ease with which these devices can be hacked and used for malicious purposes. The investigation, to be presented at the Black Hat cybersecurity conference, reveals that tens of millions of GPS-enabled watches and car accessories are vulnerable to digital stalking, location disabling and spoofing, and even photo and video capture.

Background & Context

The research focuses on three Shenzhen-based platforms that provide the backbone for dozens of smartwatch and car accessory brands. These platforms, which are used by brands such as Wonlex and SETracker, have been found to have significant security flaws, including a lack of authentication that allows anyone to access any device. This vulnerability can be exploited to track the location of a child's watch, disable its GPS, and even intercept and spoof text and audio messages sent to the device.

The investigation's findings have significant implications for parents and guardians who rely on these devices to keep their children safe. With millions of children's devices vulnerable to hacking, the risk of exploitation is catastrophic. As one of the researchers notes, "Your criminal mind is the only limitation in exploiting those devices."

Key Details

According to the research, more than 30 brands of GPS-enabled watches and car accessories use the technology and backend servers of YiQingTeng, a Shenzhen-based company also known as Wonlex. Another 30-plus brands of tracking devices for cars and kids are run on the NewGPS2012 platform, also based in Shenzhen. The researchers found that all three platforms had significant security flaws, including a lack of authentication and server-side vulnerabilities that exposed consumer information.

The researchers were able to demonstrate the ease with which these devices can be hacked by accessing a child's watch and tracking its location. They also showed that the hackers could intercept and spoof text and audio messages sent to the device, and even capture photos and videos using the watch's camera. For some GPS-enabled car accessories, the researchers found that they could track the devices' locations or spoof messages to them that could potentially unlock or disable cars.

What Experts Say

The researchers' findings have significant implications for the cybersecurity community, highlighting the need for greater vigilance in the development and deployment of connected devices. As one expert notes, "This is a wake-up call for the industry to take security seriously and to invest in robust security measures to protect consumers."

The investigation's findings also raise questions about the accountability of companies that produce and distribute these devices. As one of the researchers notes, "We've been warning these companies about their vulnerabilities for months, but so far, we've seen no action."

Key Takeaways

  • More than 30 brands of GPS-enabled watches and car accessories use the technology and backend servers of YiQingTeng, a Shenzhen-based company also known as Wonlex.
  • Another 30-plus brands of tracking devices for cars and kids are run on the NewGPS2012 platform, also based in Shenzhen.
  • The researchers found that all three platforms had significant security flaws, including a lack of authentication and server-side vulnerabilities that exposed consumer information.
  • The researchers were able to demonstrate the ease with which these devices can be hacked by accessing a child's watch and tracking its location.

What This Means For You

If you're a parent or guardian who relies on a smartwatch or car accessory to keep your child safe, it's essential to take action to protect their device. First, check the device's manufacturer to see if it uses one of the vulnerable platforms. If it does, consider replacing the device or taking steps to secure it. Second, be aware of the potential risks of hacking and take steps to protect your child's device, such as setting up strong passwords and monitoring their activity regularly.

The investigation's findings also highlight the need for greater accountability from companies that produce and distribute connected devices. As consumers, we have the power to demand better from these companies. By speaking out and holding them accountable, we can create a safer and more secure digital world for everyone.

Read Entire Article
Chatroom