Your Smartwatch Could Be your Biggest Security Threat

Your Smartwatch Could Be Your Biggest Security Threat

Smartwatches are marketed as tools of convenience for improving everyday activities like shopping and fitness. The wristband technology allows the watch to record your daily movements, monitor your heart beat and can even recognize when you lift your arm to look at the time.

A student at the University of Copenhagen, Denmark has discovered another use for the wearable tech: stealing ATM pin codes and passwords from unsuspecting users.

In Troy Beltrameli’s thesis, titled “Deep-Spying: Spying Using Smartwatch and Deep Learning,” shows a hole in security that’s as clever as it is frightening. The student was able to create an app to capitalize on this gap.

Beltramelli built an app that records the movement data of the Sony Smartwatch 3 and then was able to sift through the data with an algorithm to find important inputs, gaining the ability to unlock a pin-protected phone or use an ATM’s keypad.

This ingenious hack does, however, have its limitations. Users can protect their ATM pin code by pressing it in with the hand that is not wearing the smartwatch. Also, the data needs to be collected by someone in close proximity to the smartwatch. For the student’s test, the data was transferred to a nearby Bluetooth device and then moved onto a server.

The last, and the most important, limitation is that the user has to willingly install the app that records this movement data. This is somewhat easy to overcome by burying such a function in an otherwise legitimate-looking  app.

Despite these limitations, this hack raises the question of how safe these smartwatches are. Recording movement data from the accelerometer and gyroscope is an invasion of privacy beyond the normal cybersecurity risks that people are used to.

The most troubling part about this is if a student could find this cyber security flaw, other less-wholesome types are probably making similar breakthroughs and aren’t publishing their findings in their thesis.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • Securing the Future

    Two security experts sit down with Security Today’s editor in chief Ralph C. Jensen to discuss what they see emerging and changing over the next several years along with how security stakeholders can harness these innovations into opportunities. Read Now

  • Collaboration Made Easy Using a Work Management Platform

    Effective collaboration between security operators, teams and other departments is critical to the smooth functioning of organizations. Yet, as organizations grow in complexity, it becomes more difficult for teams to coordinate with each other. This is compounded by staffing shortages, turnover and ineffective collaboration tools. Read Now

  • Creating a Safer World

    Managing and supporting locks and door hardware within a facility is a big responsibility. A building’s security needs to change over time as occupancy and use demands evolve, which can make it even more challenging. Read Now

  • Report: 78 Percent of CISOs Seeing Significant Impact from AI-Powered Cyber Threats

    Darktrace recently unveiled its 2025 State of AI Cybersecurity report. The findings reveal that 78% of Chief Information Security Officers (CISOs) surveyed say that AI-powered threats are having a significant impact on their organizations, a 5% increase1 from 2024. While an increasing number of CISOs report feeling a significant impact from AI threats, more than 60% now say that they are adequately prepared to defend against these threats, an increase of nearly 15% year-over-year. However, insufficient AI knowledge and skills and a shortage of personnel and talent continue to be listed as the two top inhibitors to a successful defense. Read Now

New Products

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.