The watch’s insecurity and the spying it enabled mightiness beryllium expected fixed the gadget’s pedigree: It’s sold by an obscure institution called CJC, costs little than $30, and was made by an arsenic obscure manufacturer, YiQingTeng Electronics, successful Shenzhen, China. More troubling, perhaps, is that the online level it’s built on—and the 1 that allowed Stykas and Solferini to truthful thoroughly hack it—is utilized by dozens of different brands of smartwatch, galore of which person apt been near susceptible to the aforesaid forms of integer stalking.
At the Black Hat cybersecurity league today, Stykas and Solferini program to contiguous their findings from analyzing the proviso concatenation and information of much than 70 GPS-enabled watches and car accessories. They recovered that much than 30 of those geolocation devices usage the exertion and backend servers of YiQingTeng, besides identified by the marque sanction Wonlex, the sanction of a spouse steadfast Shenzhen 3G Electronics, oregon their associated app, SETracker. Another 30-plus brands of tracking devices for cars and kids are each tally connected different Shenzhen-based level known arsenic NewGPS2012.
Combined with different large GPS level known arsenic SinoTrack that sells car trackers and smartwatches, the 2 researchers recovered that tens of millions of GPS tracker gadgets came from conscionable 3 proviso chains. All three, the researchers recovered successful their analysis, had important information flaws—in immoderate cases arsenic elemental arsenic a deficiency of authentication that allowed anyone to entree immoderate device—leaving children’s watches susceptible to tracking by a hacker, determination disabling and spoofing, interception and spoofing of substance and audio messages sent to them, replacement of exigency contacts with ones a hacker chose, soundless audio eavesdropping, arsenic good arsenic photograph and video seizure for camera-enabled devices. (Once the GPS started moving connected the smartwatch WIRED tested, the hackers showed that feature, too, could beryllium hijacked to travel the wearer’s each move.)
For immoderate GPS-enabled car accessories, the researchers recovered they could likewise way the devices’ locations oregon spoof messages to them that could perchance unlock oregon disable cars, though the researchers didn’t spell truthful acold arsenic to trial this retired connected existent vehicles. They besides accidental they recovered server-side vulnerabilities that exposed user information, would person allowed them to execute their ain codification connected the servers, oregon adjacent successful 1 lawsuit appeared to amusement that idiosyncratic other had already gained unauthorized entree to the system’s backend.
“Millions of kids are being exposed and susceptible to exploitation. It's conscionable catastrophic. It's truly low-hanging effect for a batch of atrocious actors,” Stykas says. “Your transgression caput is the lone regulation successful exploiting those devices.”
The Watches Watching Your Kids
The researchers accidental they’ve been informing the companies down each 3 Shenzhen-based GPS platforms astir their vulnerabilities for months. When WIRED reached a typical of SETracker, the idiosyncratic initially claimed successful an email that “the issues you mentioned person been resolved agelong before,” adding that “we connect large value to the information of Setracker and support strengthening its information continuously.” When WIRED pointed retired that researchers had been capable to hack a smartwatch moving connected SETracker conscionable this week, the idiosyncratic repeated their assertion that the issues had been fixed, past asked for grounds of the exploitation, which WIRED provided.
Only today, hours earlier the researchers’ speech astatine Black Hat, did the researchers find that their hacking techniques against SETracker’s level person stopped working—though they’re inactive not definite if the flaws they recovered are afloat fixed.
Sinotrack and the NewGPS2012 level didn’t respond to WIRED’s requests for comment, and the researchers accidental their hacking techniques against those systems inactive look to work.
For much than a decade, cybersecurity experts and privateness advocates person warned that cheap, GPS-enabled children’s smartwatches and aftermarket conveyance accessories are riddled with information vulnerabilities that permission kids and drivers susceptible to hacking and tracking. But the sheer fig of antithetic brands and models of those devices has often made identifying the genuinely insecure gadgets consciousness astir intolerable for consumers.











English (CA) ·
English (US) ·
Spanish (MX) ·