Wearables Open Door to Many Security Vulnerabilities

Wearables Open Door to Many Security Vulnerabilities

The popularity of wearables is growing at a staggering rate, but at what cost?

The popularity of wearables, such as fitness trackers and smart watches, is growing at a staggering rate.  These devices offer convenient and fun platforms to track workouts, check emails, and pay for groceries.  But this all comes at a cost. The security of these wearables is not keeping up, and it provides hackers with another door to users’ accounts, enabling them to steal sensitive personal information, or worse, money from their banking accounts.  

Mike Lynch, the chief strategy officer from InAuth, which provides mobile device security to most of the largest banks in the world, says this may become one of the biggest security issues facing the industry in the coming months and years. These devices are exploding in popularity, and most consumers don’t give much thought to security for them. There is a perception that because it is tethered to a smartphone that the security is already built-in, but that often is not the case. It’s critical that security needs to be built-in to the wearable devices themselves.

Security Today connected with Lynch to get a better understanding of what vulnerabilities there are and how manufacturers can better protect their devices.

What are you expecting or witnessing as far as wearables growth in the market?

Wearable devices are growing in popularity around the world. Estimates from Statista place worldwide numbers to near 1 billion devices within the next few years.

Are there security concerns with wearables?

As app developers race to create wearable-optimized versions of productivity-enhancing tools for personal and business use, and as device manufacturers race to create the latest must-have wearable gadget, security may not keep up with innovation. The increase in the number of native applications available for smartwatches will create new opportunities for fraudsters to compromise wearable devices for access to highly valuable personal information.

What does InAuth do today in the security space, and how do you see future alignment with wearables technology?

InAuth is a leading provider of mobile device authentication solutions, which help organizations facilitate seamless digital transactions. Our technology is used to identify security threats by analyzing the mobile device itself. With wearable devices, there is a high risk for fraud because there has not been much of an industry emphasis on security for wearable devices, at least as compared with smartphones. InAuth can directly address a critical need for this growing market.

Potential threats range from exposure of details of people’s exercise activities (such as their walking paths or running speeds), to the potential compromise of financial information if a consumer is using a wearable device that is enabled to make payments.

What is the potential risk that wearables present for the enterprise environment?

Wearables linked to mobile devices, which are in turn linked to a corporate network, open organizations up to additional risks of attack. Even though the wearable itself may not be the primary target of an attack, its link to a mobile device creates another point of entry for cybercriminals to exploit—especially since wearables security is a relatively a new frontier. Information that can be stolen and exploited includes real-time geolocation information, emails, contacts, and other proprietary information on the device.

What are some of the risks for consumers that use wearables?

From simple fitness trackers that connect to a mobile phone, to stand-alone smartwatches, potentially sensitive personal and sometimes financial information is being passed to the app and to the manufacturer. Users may be asked for access to their files, location, contacts, camera and personal information (age, height, weight, and gender).

What could manufacturers do better to make wearables more secure?

Manufacturers of wearable devices should ensure their information security professionals remain vigilant about mobile device security and acknowledge the unique risks posed by wearable devices. When partnering with security vendors, they should work with those that specialize in both mobile and wearable application security.

To protect paired mobile devices from point-of-entry attacks that originate with wearables, organizations should implement authentication protocols that leverage biometric technology, versus an ID and password combination, which is more easily compromised in mass breaches and susceptible to phishing.

Manufacturers should also invest in digital authentication and fraud prevention solutions. Organizations should seek to authenticate at the device-level to offer the strongest level of identity verification. A mobile phone has thousands of attributes that are part of the device itself and can be used to uncover and analyze risk factors that could lead to potentially fraudulent activities.

What could the wearable user do to better protect themselves?

There are several simple steps that users can take:

  • Opt-in only for the information required for use of the app.
  • Leverage the highest level of security offered, such as biometrics.
  • Practice good password hygiene if passwords must be used, including not reusing passwords across multiple applications and changing passwords periodically.
  • Be knowledgeable about attempts to phish for information from those appearing as their manufacturer. Don’t click on links in emails or texts unless you are sure they are from a trustworthy source.
  • Download software updates when they are available, as many software updates patch known vulnerabilities.

Can you tell us what kind of wearable devices for which you are providing protection?

Those that are tied to major mobile platforms – IOS and Android. We also have wearables that operate independently from the mobile phone on our roadmap.

What specifically does InAuth do to protect wearables?

We provide intelligence on the mobile device itself. We look for the location of the device, whether there are any fraud tools on the device, is there any installed malicious software that is making the device appear to be another device/number (‘spoofing’), is there malware on it, and has the device been jailbroken, which makes them more vulnerable. That takes authentication to a new level and can result in less customer friction, fewer authentication steps, but stronger security and fewer "false positives".

Do you protect just the mobile device the wearable interacts with or do you also protect the wearable device itself?

Today we protect the mobile device, the mobile application data, the consumer, and the client organization using InAuth’s technology by detecting malware and providing intelligence that allows the organization to determine if a digital interaction is a fraudulent attempt or if a consumer’s data is at risk. In the future we may also protect certain wearables that are independent from the mobile device.

Where do you see wearable security going in the future?

There will be more wearables that are not paired with a mobile device. For many wearables that can operate independently from paired mobile devices, the same critical authentication measures are still possible. It is possible to permanently identify a type of wearable device the same way you would a mobile device. It is a matter of gathering the right factors to distinguish the type of device (e.g. smart watch or fitness tracker) and create a unique ID. In addition, other intelligence will be available to assess the risk of the transaction or interaction.

Featured

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

  • The Evolution of IP Camera Intelligence

    As the 30th anniversary of the IP camera approaches in 2026, it is worth reflecting on how far we have come. The first network camera, launched in 1996, delivered one frame every 17 seconds—not impressive by today’s standards, but groundbreaking at the time. It did something that no analog system could: transmit video over a standard IP network. Read Now

  • From Surveillance to Intelligence

    Years ago, it would have been significantly more expensive to run an analytic like that — requiring a custom-built solution with burdensome infrastructure demands — but modern edge devices have made it accessible to everyone. It also saves time, which is a critical factor if a missing child is involved. Video compression technology has played a critical role as well. Over the years, significant advancements have been made in video coding standards — including H.263, MPEG formats, and H.264—alongside compression optimization technologies developed by IP video manufacturers to improve efficiency without sacrificing quality. The open-source AV1 codec developed by the Alliance for Open Media—a consortium including Google, Netflix, Microsoft, Amazon and others — is already the preferred decoder for cloud-based applications, and is quickly becoming the standard for video compression of all types. Read Now

  • Cost: Reactive vs. Proactive Security

    Security breaches often happen despite the availability of tools to prevent them. To combat this problem, the industry is shifting from reactive correction to proactive protection. This article will examine why so many security leaders have realized they must “lead before the breach” – not after. Read Now

  • Achieving Clear Audio

    In today’s ever-changing world of security and risk management, effective communication via an intercom and door entry communication system is a critical communication tool to keep a facility’s staff, visitors and vendors safe. Read Now

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.