Tens of millions of GPS devices exposed to hacking risks
EUR/MDL - 20.05 0.2309
USD/MDL - 17.37 0.3228
VMS_91 - 3.03%
VMS_364 - 9.54%
BONDS_2Y - 7.40%
GOLD - 4,265.81 4.73%
EURUSD - 1.15 0%
BRENT - 83.76 1.92%
SP500 - 768.56 0.16%
SILVER - 62.14 4.53%
GAS - 2.89 8.25%

Tens of millions of GPS devices were found to be vulnerable to hacking

GPS watches for children and other tracking devices designed for safety can themselves become a source of danger. Researchers have discovered vulnerabilities that allow attackers to track users’ locations, access cameras and microphones, and remotely control the devices.
Natasha Kim Reading time: 2 minutes
Text size
Link copied
GPS device for children

Photo blog.kaspersky.kz

In a study presented at the Black Hat USA conference, Vangelis Stikas and Felipe Solferini hacked a children’s smartwatch costing less than $30 that was being used by a WIRED journalist. The researchers were able to track his movements, take photos with the built-in camera, and activate the microphone. Meanwhile, the device showed no signs that the owner was being monitored.

The problem turned out to be much broader than just this one watch model. The researchers tested more than 70 GPS devices, including children’s watches and car trackers, and found that more than 60 brands use the infrastructure of the Chinese platforms SETracker and NewGPS2012. Another major system—SinoTrack—also serves a large number of similar devices. Collectively, this amounts to tens of millions of gadgets.

The main cause of the risk was flaws in the security of the device management systems. In some cases, attackers could gain access to the gadgets’ functions without proper user authentication. This allowed them to track and spoof locations, intercept messages, change emergency contacts, and remotely activate the camera and microphone.

Researchers also discovered serious issues in the infrastructure that supports these devices. In certain systems, they found ways to access user data, including location information, passwords, and vehicle details. The experts also noted signs of a possible previous breach of some platforms.

SETracker stated that it had addressed the identified issues, but the researchers were unable to confirm that all vulnerabilities had been patched. According to their findings, issues in SinoTrack and NewGPS2012 persisted at the time of the study.

The study showed that devices purchased to protect children and monitor vehicles can, if inadequately secured, become tools for surveillance. Instead of enhancing security, they can expose data on users’ movements and surroundings to attackers.


Follow our updates


РекламаРеклама
Related*
More from author*

We always appreciate your feedback!

Latest news
Popular now*
Must Read*