Urgent.News

What's breaking now, across thousands of outlets.

Tech

Hackers Stalked Me by Hijacking a Smartwatch for Kids

Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.

Hackers Stalked Me by Hijacking a Smartwatch for Kids

Stykas informed the reporter of the situation, revealing that he had been monitoring his whereabouts through the GPS feature of the child's smartwatch. The gadget, despite its malfunction, was still transmitting identifiers of nearby Wi-Fi networks to a remote server, allowing Stykas to determine the reporter's exact location as he moved through Brooklyn.

When the journalist arrived at WIRED's headquarters, Stykas exploited a feature in the watch to secretly capture photos of him entering an elevator, then photographed him at his desk. He also utilized another function to intercept audio from the watch's microphone, transmitting it to a researcher, Felipe Solferini, who listened in on the reporter's coworker discussing his weekend visit to an art exhibition.

The watch's security flaws and the ease with which it was hacked were likely due to its origins: it was produced by an obscure Chinese manufacturer and sold by a lesser-known company. The online platform that enabled this hacking is utilized by numerous other smartwatch brands, potentially leaving them vulnerable to the same form of digital surveillance.

At the Black Hat cybersecurity conference, Stykas and Solferini plan to share their findings regarding the security issues of over 70 GPS-enabled watches and car accessories. They discovered that more than 30 of the devices they analyzed used the YiQingTeng technology and backend servers, while another 30+ brands relied on the Shenzhen-based NewGPS2012 and SinoTrack platforms.

Both researchers found significant security vulnerabilities in these platforms, including a lack of authentication, allowing unauthorized access to any device. These flaws could enable hackers to track children's watches, disable location services, intercept and spoof text and audio messages, replace emergency contacts, and even capture photos and videos from camera-enabled devices.

Some of the GPS-enabled car accessories also exhibited similar security issues, allowing hackers to track device locations or send spoofed messages potentially unlocking or disabling cars. Despite claims from SETracker, a company behind one of the compromised platforms, that the vulnerabilities had been resolved, the researchers found that their hacking techniques against SETracker's platform still functioned.

The researchers have been warning these companies about the security flaws for months, but identifying vulnerable devices among the vast array of options available to consumers has proven difficult.

Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at wired.com →

More in Tech

More from Thursday 6 August →