A WIRED reporter experienced firsthand just how insecure kids' smartwatches can be. During a security test, two researchers managed to track him, take photos of him, and even listen in on his conversations through a device that costs less than $30. All without any visible sign of intrusion on the wearable. This experiment, presented at the Black Hat conference, reveals systemic vulnerabilities affecting tens of millions of devices worldwide.
A silent attack starting in Brooklyn
Everything began when researcher Paul Stykas messaged the reporter to reveal his exact location. Stykas had been monitoring his movements through the watch's GPS, which, despite malfunctioning, transmitted identifiers of nearby Wi-Fi networks to a remote server. This allowed precise tracking along a Brooklyn street. Half an hour later, upon arrival at WIRED's Manhattan headquarters, Stykas exploited a feature to silently snap a photo from the watch's camera, capturing the moment the reporter stepped into an elevator. Shortly after, another shot showed him at his desk. Then, using the microphone, he enabled audio and a second researcher, Felipe Solferini, listened as a coworker described a weekend visit to an art exhibition. No visible indicator alerted the user that the device was under control.
Sponsored Protocol
An insecure supply chain
The device is sold by an obscure company called CJC and manufactured by YiQingTeng Electronics in Shenzhen, China. More troubling, the platform it relies on, named SETracker, is used by dozens of other brands. The researchers analyzed over 70 GPS-enabled devices and found that more than 30 of them share the same infrastructure by YiQingTeng, also known as Wonlex or Shenzhen 3G Electronics. Another 30-plus brands of car and kids' trackers run on the NewGPS2012 platform. Together with a third system, SinoTrack, these three supply chains feed tens of millions of devices.
Sponsored Protocol
Critical vulnerabilities and real risks
The security flaws discovered are extremely severe. In some cases, authentication is completely missing, allowing anyone to access any device. This means a malicious actor could track a child, disable location, intercept or alter messages, replace emergency contacts, eavesdrop on conversations, and even activate camera and microphone. For car devices, researchers found vulnerabilities that could potentially unlock or disable vehicles. Additionally, server-side issues exposed user data or allowed arbitrary code execution. Stykas emphasized the gravity: "Millions of kids are exposed and vulnerable to exploitation. It's catastrophic. It's really low-hanging fruit for a lot of bad actors."
Sponsored Protocol
The white-label problem
The diversity of brands on the market is illusory. Many seemingly different products share the same vulnerable backend. A parent buying a 'SafeKid' watch in Sweden and another buying a 'SaveFamily' watch in Spain are both sending their child's location data to the same myaqsh.com backend on Alibaba Cloud in mainland China. A single vulnerability in one backend affects dozens of consumer brands simultaneously, and consumers have no way to know which platform their product uses. This white-label model greatly amplifies the impact of any single flaw.
Company response and current status
The researchers have been warning the involved companies for months. A SETracker representative initially claimed that the issues had been resolved long before, but researchers demonstrated that hacking a device was still possible that same week. Only hours before the Black Hat presentation, their attacks against SETracker stopped working, but it remains unclear if all flaws have been fixed. SinoTrack and NewGPS2012 did not respond to requests for comment, and researchers say their attacks against these systems still work. They also found evidence of a previous compromise of NewGPS2012 systems.
Sponsored Protocol
This case highlights the need for greater awareness and regulation for IoT devices. Parents should check manufacturers' security policies before buying a smartwatch for their kids. For more on similar topics, see the article on AWS IoT Core vs Azure IoT Hub and Web3.js vs Ethers.js, which discuss security in emerging technologies. Additionally, for broader context on wearable vulnerabilities, you can consult Wikipedia.
Source: https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids