Hackers Stalked Me by Hijacking a Smartwatch for Kids
The watchâs insecurity and the spying it enabled might be expected given the gadgetâs pedigree: Itâs sold by an obscure company called CJC, costs less
The watchâs insecurity and the spying it enabled might be expected given the gadgetâs pedigree: Itâs sold by an obscure company called CJC, costs less than $30, and was made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China. More troubling, perhaps, is that the online platform itâs built onâand the one that allowed Stykas and Solferini to so thoroughly hack itâis used by dozens of other brands of smartwatch, many of which have likely been left vulnerable to the same forms of digital stalking. At the Black Hat cybersecurity conference today, Stykas and Solferini plan to present their findings from analyzing the supply chain and security of more than 70 GPS-enabled watches and car accessories. They found that more than 30 of those geolocation devices use the technology and backend servers of YiQingTeng, also identified by the brand name Wonlex, the name of a partner firm Shenzhen 3G Electronics, or their associated app, SETracker. Another 30-plus brands of tracking devices for cars and kids are all run on another Shenzhen-based platform known as NewGPS2012.
Combined with another major GPS platform known as SinoTrack that sells car trackers and smartwatches, the two researchers found that tens of millions of GPS tracker gadgets came from just three supply chains. All three, the researchers found in their analysis, had significant security flawsâin some cases as simple as a lack of authentication that allowed anyone to access any deviceâleaving childrenâs watches vulnerable to tracking by a hacker, location disabling and spoofing, interception and spoofing of text and audio messages sent to them, replacement of emergency contacts with ones a hacker chose, silent audio eavesdropping, as well as photo and video capture for camera-enabled devices. (Once the GPS started working on the smartwatch WIRED tested, the hackers showed that feature, too, could be hijacked to follow the wearerâs every move.) For some GPS-enabled car accessories, the researchers found they could similarly track the devicesâ locations or spoof messages to them that could potentially unlock or disable cars, though the researchers didnât go so far as to test this out on actual vehicles.
They also say they found server-side vulnerabilities that exposed consumer information, would have allowed them to execute their own code on the servers, or even in one case appeared to show that someone else had already gained unauthorized access to the systemâs backend. âMillions of kids are being exposed and vulnerable to exploitation. It's just catastrophic. It's really low-hanging fruit for a lot of bad actors,â Stykas says. âYour criminal mind is the only limitation in exploiting those devices.â The Watches Watching Your Kids The researchers say theyâve been warning the companies behind all three Shenzhen-based GPS platforms about their vulnerabilities for months. When WIRED reached a representative of SETracker, the person initially claimed in an email that âthe issues you mentioned have been resolved long before,â adding that âwe attach great importance to the security of Setracker and keep strengthening its security continuously.â When WIRED pointed out that researchers had been able to hack a smartwatch running on SETracker just this week, the person repeated their claim that the issues had been fixed, then asked for evidence of the exploitation, which WIRED provided.
