Your Smartwatch Could Be your Biggest Security Threat

Your Smartwatch Could Be Your Biggest Security Threat

Smartwatches are marketed as tools of convenience for improving everyday activities like shopping and fitness. The wristband technology allows the watch to record your daily movements, monitor your heart beat and can even recognize when you lift your arm to look at the time.

A student at the University of Copenhagen, Denmark has discovered another use for the wearable tech: stealing ATM pin codes and passwords from unsuspecting users.

In Troy Beltrameli’s thesis, titled “Deep-Spying: Spying Using Smartwatch and Deep Learning,” shows a hole in security that’s as clever as it is frightening. The student was able to create an app to capitalize on this gap.

Beltramelli built an app that records the movement data of the Sony Smartwatch 3 and then was able to sift through the data with an algorithm to find important inputs, gaining the ability to unlock a pin-protected phone or use an ATM’s keypad.

This ingenious hack does, however, have its limitations. Users can protect their ATM pin code by pressing it in with the hand that is not wearing the smartwatch. Also, the data needs to be collected by someone in close proximity to the smartwatch. For the student’s test, the data was transferred to a nearby Bluetooth device and then moved onto a server.

The last, and the most important, limitation is that the user has to willingly install the app that records this movement data. This is somewhat easy to overcome by burying such a function in an otherwise legitimate-looking  app.

Despite these limitations, this hack raises the question of how safe these smartwatches are. Recording movement data from the accelerometer and gyroscope is an invasion of privacy beyond the normal cybersecurity risks that people are used to.

The most troubling part about this is if a student could find this cyber security flaw, other less-wholesome types are probably making similar breakthroughs and aren’t publishing their findings in their thesis.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • 5 Tips to Improve Your Password Security

    Change Your Password Day is right around the corner. Observed every year on February 1, the day aims to raise awareness about cybersecurity and underscores the importance of keeping passwords strong and up to date. Read Now

  • Enhancing Port Security

    DP World Yarimca, one of the largest container terminals of the Gulf of İzmit and Turkey, is a strong proponent of using industry-leading technology to deliver unrivaled value to its customers and partners. As the port is growing, DP World Yarimca needs to continue to provide uninterrupted operations and a high level of security.To address these challenges, DP World Yarimca has embraced innovative technological products, including FLIR's comprehensive portfolio of security monitoring solutions. Read Now

  • Hot AI Chatbot DeepSeek Comes Loaded With Privacy, Data Security Concerns

    In the artificial intelligence race powered by American companies like OpenAI and Google, a new Chinese rival is upending the market—even with the possible privacy and data security issues. Read Now

  • Survey: CISOs Increasing Budgets for Crisis Simulations in 2025

    Today, Cyber Performance Center, Hack The Box, released new data showcasing the perspectives of Chief Information Security Officers (CISOs) towards cyber preparedness in 2025. In the aftermath of 2024’s high-profile cybersecurity incidents, including NHS, CrowdStrike, TfL, 23andMe, and Cencora, CISOs are reassessing their organization’s readiness to manage a potential “chaos” of a full-scale cyber crisis. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.