Hacked Playtime: How Hackers Stalked Me by Taking Control of a Kids’ Smartwatch

On a rainy morning in New York, a WIRED reporter donned a pink plastic smartwatch meant for children, gifted by security researcher Vangelis Stykas. As he headed to the subway, he texted Stykas that he might lose cell service. Unbeknownst to him, Stykas had been tracking his movements through the watch’s GPS feature.

Even though the GPS was malfunctioning, the watch was still relaying information via Wi-Fi, enabling Stykas to determine the reporter’s precise location as he walked through Brooklyn. After reaching the WIRED office, Stykas exploited a feature of the watch to take photos of the reporter unnoticed—first while entering an elevator and then again at his desk. He also intercepted audio from the watch’s microphone, sharing snippets with researcher Felipe Solferini, all without any indication of hacking occurring on the device.

The vulnerabilities of this smartwatch are alarming, especially considering its low price—less than $30—and its manufacturing source from CJC, via YiQingTeng Electronics in Shenzhen, China. This specific device’s hacking is just an example of a widespread issue embedded in a complex supply chain of GPS-enabled products. Stykas and Solferini, in their upcoming presentation at the Black Hat cybersecurity conference, highlighted the security flaws found not just in this particular watch, but in various GPS-enabled gadgets from multiple brands, all linked to the same insecure backend.

Their investigation scrutinized over 70 different GPS devices, revealing significant vulnerabilities. More than 30 of those devices, including smartwatches and car trackers, relied on technology from YiQingTeng, known as Wonlex. Another 30 brands utilized a different company, NewGPS2012. These platforms shared critical flaws leading to a multitude of potential risks—hackers could track users, spoof audio messages, hijack emergency contacts, and even eavesdrop or access visual data from devices.

At the same time, the researchers also uncovered issues with car accessories that could allow unauthorized tracking or potential manipulation of vehicle functionalities, although they refrained from testing this on real cars. They also noted server vulnerabilities that could expose user information, posing large-scale risks for millions of devices fed through these platforms.

Stykas expressed grave concern: "Millions of kids are being exposed and vulnerable to exploitation. It’s just catastrophic." They had warned these Shenzhen-based companies about their vulnerabilities, but responses were often dismissive or vague. While SETracker initially claimed to have fixed vulnerabilities, the researchers found their hacking techniques still worked mere hours before the conference presentation.

The researchers pointed out the misleading perception consumers have about the diversity of brands in the GPS market. Two parents from Sweden and Spain could unknowingly be using the same vulnerable backend service without being aware of it. Through a white-label model, flaws in one device could easily affect many others, leaving parents without a clear way to choose secure options for their children.

Despite multiple warnings from cybersecurity professionals regarding these vulnerabilities over the years, including some from Stykas himself, the release of cheap GPS devices continues unabated. As they executed their tests on the smartwatch, Stykas was disappointed to find many flaws still present, indicating that little has improved in device security.

The potential dangers of these devices remain a pressing concern as they can easily place children and their data at risk. This underlines the urgent need for manufacturers to prioritize robust security mechanisms in their devices to protect users from becoming targets of hackers.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Article

OpenAI Overlooked AI Agents Organizing Hacking Activities on a Message Board

Next Article

Testing NAT Security Assumptions: Insights from the NatJack Exploits at Black Hat

Related Posts