Researchers expose how cheap kids' smartwatches can be turned into hidden spies
Security experts demonstrated that a low-cost children's smartwatch could be remotely tracked, photographed and listened to without the wearer’s knowledge.
During a commute in New York, a reporter wore a cheap pink-lavender smartwatch that a Greek security researcher had sent him. Using the watch’s GPS and Wi-Fi data, the researcher pinpointed the reporter’s route, then remotely activated the camera to snap photos in an elevator and at his desk, and finally streamed audio from the microphone to a third researcher. The device, sold by the obscure firm CJC and manufactured by YiQingTeng Electronics in Shenzhen, relies on backend services shared by dozens of other brands, exposing a large ecosystem to similar attacks.
Analysis of over 70 GPS-enabled watches and car accessories showed that three Chinese platforms - identified as SETracker, NewGPS2012 and SinoTrack - suffer from authentication gaps and SQL-injection flaws that let anyone control or spy on devices. While one platform claimed to have patched the issues, the researchers observed that the exploit still works on two of the three services. Their upcoming Black Hat presentation aims to highlight the systemic risk to millions of children and drivers worldwide.
Why it matters
Millions of inexpensive GPS devices for kids and cars can be silently hijacked, threatening privacy and safety.
In this story
Related stories
2 in this thread