Breaking News

Gigabyte announces X870 and B850 AORUS STEALTH ICE Samsung Launches Odyssey G6 World’s First 500Hz OLED Gaming Monitor Samsung Galaxy S25 Edge Features New Corning Gorilla Glass Ceramic 2 for Enhanced Durability Razer announces Clio Chair Accessory for Audio Immersion Razer Unveils Ergonomic Gaming Mouse and Keyboard for Gaming on the Go

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Discover Flaws in Smartwatches For Kids

Researchers Discover Flaws in Smartwatches For Kids

Gadgets Dec 11,2019 0

Security researchers discovered vulnerabilities in smartwatches for children that make it possible for strangers to override parental controls and track kids.

Cybersecurity firm Rapid7 Inc. identified vulnerabilities in a number of children's GPS-enabled smart watches under the guidance of the company's IoT Research Lead Deral Heiland. The researchers purchased three different brands of watches from Amazon: Children's SmartWatch, G36 Children's Smartwatch, and SmarTurtles Kid's Smartwatch. During the investigation, the researchers determined that all three products shared nearly identical hardware and software, so all of the described findings affect all three watches.

While only one of these issues is a technical vulnerability—the lack of functional SMS filtering—two other issues that the researchers identified were equally troubling: an undocumented default password used to associate with the devices, and a lack of transparency and communication with the retail vendors of these devices.

For two of the devices, the vendors appear to exist solely as Amazon storefronts, and any attempts to contact these vendors privately proved impossible. The third, SmarTurtles, does have an associated website, but there appears to be no mechanism to contact this vendor, nor is there a published privacy policy.

The lack of a privacy policy is especially troubling in this age of CCPA and GDPR, and doubly so when it comes to technology marketed to parents of small children.

All three models of GPS watches use either SETracker or SETracker2 as the backend cloud service and mobile application for the iPhone and Android platforms. Both versions of SETracker are provided by the developer "wcr." The application indexing service AppBrain indicates that wcr is the developer account associated with 3G Elec, a Chinese company based in Shenzhen. As far as the hardware is concerned, all three devices appear to be white-label rebrands of 3G Elec's offering.

None of the retail vendors were identifiable or contactable. While an email address was identified for 3G Elec, any attempts to contact and discuss these issues were foiled by technical issues with that email address.

Aside from the communications issues described above, two technical issues were uncovered across the three GPS smart watches:

The products under test have a SMS-based interface to view and change configuration details by texting the watch directly with certain commands. The documentation states that only certain configured numbers may communicate with the watch, and those numbers are entered on a whitelist on the associated mobile app. However, in practice, this filter did not appear to be functional at all—unlisted numbers could also interact with the watch.

Incidentally, SMS filtering is a weak control even in the best of circumstances, as this originating phone number is trivially spoofable, and is therefore not recommended as a security control.

So, armed with the knowledge of a watch's assigned phone number and the configuration password (see below), unauthenticated attackers can read and write configuration details, up to and including pairing the watch with the attacker's own smartphone.

The watches have a default configuration password of "123456" and each of the three watches under test treat this information differently. One manual does not mention the password at all, another mentions it in a translated blog about the product (but not in the printed material), and a third doesn't characterize the string as a password nor provides any instruction on how to change it.

Given an unchanged default password and a lack of SMS filtering, it is possible that an attacker with knowledge of the smart watch phone number could assume total control of the device, and therefore use the tracking and voice chat functionality with the same permissions as the legitimate user (typically, a parent).

Unfortunately, there does not appear to be any mechanism to address the SMS filtering issue without a vendor-supplied firmware update, and such an update is unlikely to materialize given that the provider of these devices are difficult to impossible to locate.

The researchers urge current users of these devices who wish to continue to use the device to investigate how to update the SMS control password.

Tags: smartwatchesprivacyCybersecurity
Previous Post
The Story of Spotify to Become a Netflix Series
Next Post
New AMD Radeon Pro W5700X GPU Available For the Apple Mac Pro

Related Posts

  • EU Privacy Watchdog Accused of Delaying Probe Procedures Against Facebook

  • Realme India Announces Smartwatch and TVs

  • Electrocardiogram Monitoring Cleared for Galaxy Watch Active2 by South Korea

  • Apple Watch Nike Pride Edition Sport Band Released

  • Intel Confirms "Thunderspy" Risk in Thuerbolt Devices

  • Facebook Users Accept $550 Million Privacy Deal Over Facebook's “Tag Suggestions”

  • Global Smartwatch Shipments Grow 20 Percent in Q1 2020, Apple Maintains 1st Position

  • Xiaomi Updates Its Browsers After Alleged Privacy Vulnerabilities

Latest News

Gigabyte announces X870 and B850 AORUS STEALTH ICE
PC components

Gigabyte announces X870 and B850 AORUS STEALTH ICE

Samsung Launches Odyssey G6 World’s First 500Hz OLED Gaming Monitor
Gaming

Samsung Launches Odyssey G6 World’s First 500Hz OLED Gaming Monitor

Samsung Galaxy S25 Edge Features New Corning Gorilla Glass Ceramic 2 for Enhanced Durability
Smartphones

Samsung Galaxy S25 Edge Features New Corning Gorilla Glass Ceramic 2 for Enhanced Durability

Razer announces Clio Chair Accessory for Audio Immersion
Consumer Electronics

Razer announces Clio Chair Accessory for Audio Immersion

Razer Unveils Ergonomic Gaming Mouse and Keyboard for Gaming on the Go
PC components

Razer Unveils Ergonomic Gaming Mouse and Keyboard for Gaming on the Go

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Rock 5

be quiet! Dark Rock 5

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed