Wednesday, April 14, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Cheap kids smartwatch exposes the location of 5,000+ children

November 26, 2019
in Internet Security
Cheap kids smartwatch exposes the location of 5,000+ children
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Image via SMA website

A cheap $35 kids’ smartwatch made in China was caught exposing the personal details and location information for more than 5,000 children and their parents.

In a report published today by the Internet of Things testing division of AV-TEST, researchers said they found egregious security measures put in place to protect the backend and mobile app of the M2 smartwatch, made by Chinese company SMA.

You might also like

Cybersecurity: Victims are spotting cyber attacks much more quickly – but there’s a catch

Samsung’s new Galaxy Quantum 2 uses quantum cryptography to secure apps

Brave browser disables Google’s FLoC tracking system

“The Chinese SMA-WATCH-M2 tops the security failures of other manufacturers by far,” said Maik Morgenstern, CEO and the Technical Director of AV-TEST, whose team has been testing kids smartwatches for more than two years.

The M2 smartwatch and its security flaws

The SMA W2 kids smartwatch has been around for years. It was designed to work with a companion mobile app. Parents would register an account on the SMA service, pair their child’s smartwatch to their phone, and use the app to track the kid’s location, make voice calls, or get notifications when the child would leave a designated area.

The concept is not new, as there are plenty of similar products on the market, varying in prices from $30 to $200-$300. However, Morgenstern suggests that SMA created one of the most insecure products on the market.

For starters, Morgenstern says anyone can query the smartwatch’s backend via a publicly accessible web API. This is the same backend where the mobile app also connects to retrieve the data it shows on parents’ phones.

Morgenstern says there’s an authentication token in place that’s supposedly there to prevent unauthorized access, but attackers can supply any token they like, as the server never verifies its validity.

An attacker can connect to this web API, cycle through all user IDs, and collect data on all kids and their parents.

Morgenstern says that using this technique, his team was able to identify more than 5,000 M2 smartwatch wearers and more than 10,000 parent accounts.

Most of the kids were located throughout Europe, in countries such as the Netherlands, Poland, Turkey, Germany, Spain, and Belgium, but the AV-TEST CEO says they’ve also found active smartwatches in China, Hong Kong, and Mexico.

sma-watch-m2-map.jpg

Image: AV-TEST

The data exposed via this Web API included the child’s current geographical location, device type, and SIM card IMEI.

Furthermore, a second vulnerability allowed access to even more creepy functions. Morgenstern says that the mobile app installed on parents’ phones is also very insecure.

An attacker can install it on their own device, change a user ID in the app’s main configuration file, and have their smartphone paired with a child’s smartwatch without ever having to enter a parent account email address or password.

Once attackers have paired their smartphone to a child’s smartwatch, they can use the app’s features to track the kid via a map, or even place calls and start voice chats with children.

Even worse, the attacker can change the mobile account’s password and lock the parent out from the app while they give a child wrong instructions.

Watch still on sale

Morgenstern says they’ve contacted SMA with their findings. He did not say how SMA reacted, but only mentioned that the watch is still being sold via the company’s website and via other distributors [1, 2].

Morgenstern says that German distributor Pearl has taken the M2 of their shelves after their report.

SMA did not return a request for comment before this article’s publication.

The AV-TEST CEO also contacted the Federal Office for Information Security (BSI), the country’s cyber-security agency. In 2017, the BSI banned the sale of kids smartwatches in Germany if the watch came with a remote listening feature.

Earlier this year in February, the EU recalled two kids’ smartwatch models because of similar security flaws that allowed attackers to contact and/or track children’s locations.

Credit: Zdnet

Previous Post

The Logjam in AI/ML Platforms is About to Complicate Your Life

Next Post

Acast Open launches to give brands an on-ramp to podcasting

Related Posts

Cybersecurity: Victims are spotting cyber attacks much more quickly – but there’s a catch
Internet Security

Cybersecurity: Victims are spotting cyber attacks much more quickly – but there’s a catch

April 14, 2021
Samsung’s new Galaxy Quantum 2 uses quantum cryptography to secure apps
Internet Security

Samsung’s new Galaxy Quantum 2 uses quantum cryptography to secure apps

April 14, 2021
Brave browser disables Google’s FLoC tracking system
Internet Security

Brave browser disables Google’s FLoC tracking system

April 13, 2021
These new vulnerabilities put millions of IoT devices at risk, so patch now
Internet Security

These new vulnerabilities put millions of IoT devices at risk, so patch now

April 13, 2021
Apple looking to close the gap between web and app privacy
Internet Security

Who do I pay to get the ‘phone’ removed from my iPhone?

April 13, 2021
Next Post
Acast Open launches to give brands an on-ramp to podcasting

Acast Open launches to give brands an on-ramp to podcasting

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Five Top Quality APIs
Learn to Code

Five Top Quality APIs

April 14, 2021
Cybersecurity: Victims are spotting cyber attacks much more quickly – but there’s a catch
Internet Security

Cybersecurity: Victims are spotting cyber attacks much more quickly – but there’s a catch

April 14, 2021
Detecting the “Next” SolarWinds-Style Cyber Attack
Internet Privacy

Detecting the “Next” SolarWinds-Style Cyber Attack

April 14, 2021
Weekly NFT roundup March 23-29: Circle, Klaytn, and more
Blockchain

Weekly NFT roundup April 7–13: Christie’s, Triller, and more

April 14, 2021
Machine learning can help keep the global supply chain moving
Machine Learning

Machine learning can help keep the global supply chain moving

April 14, 2021
Why I Think That Avengers: Age of Ultron is One of the Best Sci-Fi Movies About A.I | by Brighton Nkomo | Apr, 2021
Neural Networks

Why I Think That Avengers: Age of Ultron is One of the Best Sci-Fi Movies About A.I | by Brighton Nkomo | Apr, 2021

April 14, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Five Top Quality APIs April 14, 2021
  • Cybersecurity: Victims are spotting cyber attacks much more quickly – but there’s a catch April 14, 2021
  • Detecting the “Next” SolarWinds-Style Cyber Attack April 14, 2021
  • Weekly NFT roundup April 7–13: Christie’s, Triller, and more April 14, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates