Attackers Can Track Kids' Locations Via Connected Watches
secwatcher shares a report from Threatpost: A gamut of kids' GPS-tracking watches are exposing sensitive data involving 35,000 children -- including their location, in real time. Researchers from Pen Test Partners specifically took a look at the Gator portfolio of watches from TechSixtyFour. The Gator line had been in the spotlight in 2017 for having a raft of vulnerabilities, called out by the Norwegian Consumers Council in its WatchOut research. "A year on, we decided to have a look at the Gator watch again to see how their security had improved," said Vangelis Stykas, in a Tuesday posting. "Guess what: a train wreck. Anyone could access the entire database, including real-time child location, name, parents' details etc. Not just Gator watches either -- the same back end covered multiple brands and tens of thousands of watches." "At issue was an easy-to-exploit, severe privilege-escalation vulnerability: The system failed to validate that the user had the appropriate permission to take admin control," reports Threatpost. "An attacker with access to the watch's credentials simply needed to change the user level parameter in the backend to an admin designation, which would provide access to all account information and all watch information."
It got AOC hot she likes trafficking.
Really? What statute?
you always know where your kid is. The bad news is, so does everyone else.
Shane does not let Chipmunk use Gator watches
They can also track kids using THEIR EYES
"A Randomized Trial of E-Cigarettes versus Nicotine-Replacement Therapy"
Want to track your kid like that? In the grand scheme of things a single person is extremely unimportant
I'd guess that 90% of things connected to the Internet today shouldn't be. But, people are lazy. So, nothing will change.
I don't respond to AC's.
Shouldn't that be Watch Test Partners?
How many actual stranger attacks on children are there? Seems like a lot because it sells news, so it is over reported. There was one around here about 30 years back, sad because the kid vanished at a baseball game, but the news still talks about it.
Most child kidnappings seem to be by their divorced other parent and even most molestation is by relatives, friends and trusted figures like the priest, coach or scout leader.
https://en.wikipedia.org/wiki/Inverted_totalitarianism
An attacker with access to the watch's credentials
They're already in the watch, so the user is screwed even without a escalation of privilege attack.
Guess what: a train wreck.
The product plan wasn't about keeping children safe: It was about selling crap to helicopter/neurotic/half-arsed parents every month.
The "are exposing sensitive data involving 35,000 children" link takes you to "A Randomized Trial of E-Cigarettes versus Nicotine-Replacement Therapy" study and not to anything related to GPS-watches.
Some editor should fix it.
- Peder
Easy to track someone when you're standing beside them.
First link points here:
https://www.nejm.org/doi/full/10.1056/NEJMoa1808779
A Randomized Trial of E-Cigarettes versus Nicotine-Replacement Therapy
Doesn't seem to have anything to do with kid tracking watches.
Even worse, your own government can track individual citizens with the same kind of devices. On top of that,all your interaction data is being sold to other people and companies, sometimes with complete profiles of you.
That seems equally as bad,if not worse. Why not fix the root problem rather than 'think of the children' lameisms
I don't want to be tracked or sold either. Child, adult, why should it matter?
This playground is afraid of me. I've seen it's true face.
I've been reading stories like this since at least 2012 with some VTech devices. When will the manufacturers be held accountable for the shit security in their devices?
It's not worse that attackers can do that than that the company can do that.