child smart watch

Millions of Children-Tracking Smartwatches Are At Risk Of Being Hacked

New findings by security firm Pen Test Partners reveal that 47 million devices worldwide could be exposed and tracked thanks to a strikingly insecure cloud platform.

Throughout 2019, security researchers have discovered striking flaws about child-tracking smartwatches that could be manipulated by hackers. But new findings reported by TechCrunch show that the smartwatches had a larger problem on their hands: a very insecure common cloud platform lacking basic cybersecurity protections.

Researchers found that the cloud platform, made by Chinese electronics company and location-tracking giant Thinkrace, puts at least 47 million devices at risk of being hacked. Because each device interacts with the cloud platform either directly or through a web domain set up by a reseller, cybersecurity firm Pen Test Partners was able to all commands for the devices back to the faulty cloud platform.

“It’s only the tip of the iceberg,” Ken Munro, the founder of the company, told TechCrunch.

The firm’s findings show that most of the commands that control the devices do not require authorization, allowing hackers to gain access to a device and track its location. There is also no randomization of account numbers, allowing the researchers to access devices in bulk by increasing each account number by one.

Disturbingly, researchers were also able to access voice messages recorded and stored in the insecure cloud that were meant to be exchanged between parents and children. The device, sold by a reseller of Thinkrace’s smartwatches, is used by some five million children and parents, according to TechCrunch.

Researchers compared their findings to CloudPets, a WiFi-enabled teddy bear that left its cloud unprotected and exposed the voice recordings of two million kids.

In 2015 and 2017, Pen Test Partners disclosed the vulnerabilities to electronic makers, including Thinkrace. Some resellers fixed their vulnerable “endpoints,” TechCrunch reported, but many companies ignored the warnings, which pushed the firm to go public with its discoveries.

While consumers may not think they own a Thinkrace smartwatch, many of its devices are sold to popular companies for resale. Some of those companies include Lenovo, Vodafone, Allianz and Huawei.

That’s why Munro recommends that consumers stay away from using the devices. Users can also contact the company selling the watch to ask if their watches are manufactured by Thinkrace, and if the business depends on Thinkrace’s cloud platform.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Cloud Adoption Gives Way to Hybrid Deployments

    Cloud adoption is growing at an astonishing rate, with Gartner forecasting that worldwide public cloud end-user spending will approach $600 billion by the end of this year—an increase of more than 21% over 2022. McKinsey believes that number could eclipse $1 trillion by the end of the decade, further underscoring the industry’s exponential growth. Read Now

  • AI on the Edge

    Discussions about the merits (or misgivings) around AI (artificial intelligence) are everywhere. In fact, you’d be hard-pressed to find an article or product literature without mention of it in our industry. If you’re not using AI by now in some capacity, congratulations may be in order since most people are using it in some form daily even without realizing it. Read Now

  • Securing the Future

    In an increasingly turbulent world, chief security officers (CSOs) are facing a multitude of challenges that threaten the stability of businesses worldwide. Read Now

    • Guard Services
  • Security Entrances Move to Center Stage

    Most organizations want to show a friendly face to the public. In today’s world, however, the need to keep people safe and secure has become a prime directive when designing and building facilities of all kinds. Fortunately, there is no need to construct a fortress-like entry that provides that high level of security. Today’s secured entry solutions make it possible to create a welcoming, attractive look and feel at the entry without compromising security. It is for this reason that security entrances have moved to the mainstream. Read Now

Featured Cybersecurity

Webinars

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3