Article URL: https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/ Comments URL: https://news.ycombinator.com/item?id=49204060 Points: 46 # Comments: 2…

On a rainy New York morning earlier this week, a WIRED reporter strapped to his wrist a lavender and pink plastic child’s smartwatch and headed to work. As he approached his nearby subway station to commute to WIRED’s office, he texted Vangelis Stykas, the Greek security researcher who had shipped him the watch via Amazon, to let him know that he was going into the station and might lose cell signal. In fact, Stykas had been monitoring the reporter’s location via the watch since the moment he left his apartment. The watch’s GPS feature, intended to let a parent track their child, was malfunctioning, but the wearable device was still picking up and transmitting to a faraway server identifiers from every nearby Wi-Fi network, which allowed Stykas to nonetheless pinpoint the reporter’s exact location as he walked down a particular Brooklyn block. A WIRED reporter wearing the GPS-enabled smartwatch while holding an umbrella and walking to the subway earlier this week. When the reporter arrived at WIRED’s Manhattan headquarters half an hour later, Stykas hijacked a feature in the watch that allowed him to silently take a photo from its camera, capturing the moment when the reporter stepped into an elevator. After a few minutes, he took another snap of the reporter at his desk, then used a different feature to pick up audio from the watch’s microphone, transmitting it to another researcher, Felipe Solferini, who listened as the reporter’s coworker described his weekend visit to an art exhibition. At no point did the watch show any sign that it was listening, taking photos, or otherwise being hacked. As WIRED reporter Andy Greenberg entered the elevator at WIRED's New York office, the hackers used the smartwatch to surreptitiously take a photo… The watch’s insecurity and the spying it enabled might be expected given the gadget’s pedigree: It’s sold by an obscure company called CJC, costs less than $30, and was made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China. More troubling, perhaps, is that the online platform it’s built on—and the one that allowed Stykas and Solferini to so thoroughly hack it—is used by dozens of other brands of smartwatch, many of which have likely been left vulnerable to the same forms of digital stalking. At the Black Hat cybersecurity conference today, Stykas and Solferini plan to present their findings from analyzing the supply chain and security of more than 70 GPS-enabled watches and car accessories. They found that more than 30 of those geolocation devices use the technology and backend servers of YiQingTeng, also identified by the brand name Wonlex, the name of a partner firm Shenzhen 3G Electronics, or their associated app, SETracker. Another 30-plus brands of tracking devices for cars and kids are all run on another Shenzhen-based platform known as NewGPS2012. Combined with another major GPS platform known as SinoTrack that sells car trackers and smartwatches, the two researchers found that tens of millions of GPS tracker gadgets came from just three supply chains. All three, the researchers found in their analysis, had significant security flaws—in some cases as simple as a lack of authentication that allowed anyone to access any device—leaving children’s watches vulnerable to tracking by a hacker, location disabling and spoofing, interception and spoofing of text and audio messages sent to them, replacement of emergency contacts with ones a hacker chose, silent audio eavesdropping, as well as photo and video capture for camera-enabled devices. (Once the GPS started working on the smartwatch WIRED tested, the hackers showed that feature, too, could be hijacked to follow the wearer’s every move.)