Hackers Stalked Me by Hijacking a Smartwatch for Kids
Hackers Stalked Me by Hijacking a Smartwatch for Kids
黑客通过劫持儿童智能手表跟踪我
Save this story. On a rainy New York morning earlier this week, a WIRED reporter strapped to his wrist a lavender and pink plastic child’s smartwatch and headed to work. As he approached his nearby subway station to commute to WIRED’s office, he texted Vangelis Stykas, the Greek security researcher who had shipped him the watch via Amazon, to let him know that he was going into the station and might lose cell signal. 本周早些时候的一个雨天,一名《连线》(WIRED)记者在手腕上戴了一块淡紫色和粉色相间的塑料儿童智能手表,准备去上班。当他走向附近的地铁站前往《连线》办公室时,他给希腊安全研究员 Vangelis Stykas 发了条短信,告知对方自己即将进入地铁站,可能会失去手机信号。Stykas 是通过亚马逊将这块手表寄给他的。
“I know,” Stykas wrote back. “我知道,”Stykas 回复道。
In fact, Stykas had been monitoring the reporter’s location via the watch since the moment he left his apartment. The watch’s GPS feature, intended to let a parent track their child, was malfunctioning, but the wearable device was still picking up and transmitting to a faraway server identifiers from every nearby Wi-Fi network, which allowed Stykas to nonetheless pinpoint the reporter’s exact location as he walked down a particular Brooklyn block. 事实上,从记者离开公寓的那一刻起,Stykas 就一直在通过这块手表监控他的位置。虽然该手表旨在让家长追踪孩子位置的 GPS 功能出现了故障,但这款可穿戴设备仍在持续获取并向远端服务器传输附近所有 Wi-Fi 网络的标识符。这使得 Stykas 依然能够精准定位到记者在布鲁克林某条街道上行走的具体位置。
When the reporter arrived at WIRED’s Manhattan headquarters half an hour later, Stykas hijacked a feature in the watch that allowed him to silently take a photo from its camera, capturing the moment when the reporter stepped into an elevator. After a few minutes, he took another snap of the reporter at his desk, then used a different feature to pick up audio from the watch’s microphone, transmitting it to another researcher, Felipe Solferini, who listened as the reporter’s coworker described his weekend visit to an art exhibition. At no point did the watch show any sign that it was listening, taking photos, or otherwise being hacked. 半小时后,当记者抵达《连线》位于曼哈顿的总部时,Stykas 劫持了手表的一项功能,在不发出任何提示的情况下启动摄像头拍了一张照片,捕捉到了记者走进电梯的瞬间。几分钟后,他又在记者坐在办公桌前时拍了一张照片,随后利用另一项功能开启了手表的麦克风,并将音频传输给另一位研究员 Felipe Solferini。Solferini 听到了记者的同事在描述他周末参观艺术展的经历。整个过程中,手表没有任何迹象显示它正在监听、拍照或被黑客入侵。
The watch’s insecurity and the spying it enabled might be expected given the gadget’s pedigree: It’s sold by an obscure company called CJC, costs less than $30, and was made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China. More troubling, perhaps, is that the online platform it’s built on—and the one that allowed Stykas and Solferini to so thoroughly hack it—is used by dozens of other brands of smartwatch, many of which have likely been left vulnerable to the same forms of digital stalking. 考虑到这款设备的出身,其安全漏洞和由此引发的监视行为或许并不令人意外:它由一家名为 CJC 的名不见经传的公司销售,售价不到 30 美元,由中国深圳一家同样默默无闻的制造商——易青腾电子(YiQingTeng Electronics)生产。更令人担忧的是,它所依托的在线平台——即让 Stykas 和 Solferini 能够彻底攻破它的平台——还被数十个其他品牌的智能手表所使用,其中许多品牌很可能也面临着同样的数字跟踪风险。
At the Black Hat cybersecurity conference today, Stykas and Solferini plan to present their findings from analyzing the supply chain and security of more than 70 GPS-enabled watches and car accessories. They found that more than 30 of those geolocation devices use the technology and backend servers of YiQingTeng, also identified by the brand name Wonlex, the name of a partner firm Shenzhen 3G Electronics, or their associated app, SETracker. Another 30-plus brands of tracking devices for cars and kids are all run on another Shenzhen-based platform known as NewGPS2012. 在今天的 Black Hat 网络安全大会上,Stykas 和 Solferini 计划展示他们对 70 多款 GPS 手表和汽车配件的供应链及安全性分析结果。他们发现,其中 30 多款地理定位设备使用了易青腾的技术和后端服务器,这些设备也以 Wonlex 品牌、合作伙伴深圳 3G 电子的名义,或其关联应用 SETracker 的名义进行销售。另外 30 多个用于汽车和儿童的追踪设备品牌则全部运行在另一个名为 NewGPS2012 的深圳平台之上。
Combined with another major GPS platform known as SinoTrack that sells car trackers and smartwatches, the two researchers found that tens of millions of GPS tracker gadgets came from just three supply chains. All three, the researchers found in their analysis, had significant security flaws—in some cases as simple as a lack of authentication that allowed anyone to access any device—leaving children’s watches vulnerable to tracking by a hacker, location disabling and spoofing, interception and spoofing of text and audio messages sent to them, replacement of emergency contacts with ones a hacker chose, silent audio eavesdropping, as well as photo and video capture for camera-enabled devices. 加上另一个销售汽车追踪器和智能手表的主要 GPS 平台 SinoTrack,两位研究员发现,数以千万计的 GPS 追踪设备仅来自这三条供应链。研究人员在分析中发现,这三者都存在严重的安全漏洞——在某些情况下,漏洞简单到仅仅是缺乏身份验证,任何人都可以访问任何设备。这使得儿童手表极易受到黑客的追踪、位置禁用和欺骗、拦截并篡改发送给手表的短信和音频信息、将紧急联系人替换为黑客指定的号码、静默音频窃听,以及针对带摄像头设备的拍照和录像。
For some GPS-enabled car accessories, the researchers found they could similarly track the devices’ locations or spoof messages to them that could potentially unlock or disable cars, though the researchers didn’t go so far as to test this out on actual vehicles. They also say they found server-side vulnerabilities that exposed consumer information, would have allowed them to execute their own code on the servers, or even in one case appeared to show that someone else had already gained unauthorized access to the system’s backend. 对于一些具备 GPS 功能的汽车配件,研究人员发现他们同样可以追踪设备位置,或向其发送欺骗性信息,从而可能解锁或禁用车辆,尽管研究人员并未在实际车辆上进行测试。他们还表示,发现了服务器端的漏洞,这些漏洞不仅泄露了消费者信息,还允许他们在服务器上执行自己的代码,甚至在其中一个案例中,似乎显示已经有其他人获得了该系统后端的未经授权访问权限。
“Millions of kids are being exposed and vulnerable to exploitation. It’s just catastrophic. It’s really low-hanging fruit for a lot of bad actors,” Stykas says. “Your criminal mind is the only limitation in exploiting those devices.” “数百万儿童正处于暴露状态,容易受到侵害。这简直是灾难性的。对于许多不法分子来说,这简直是唾手可得的猎物,”Stykas 说,“利用这些设备,唯一的限制就是你的犯罪想象力。”
The researchers say they’ve been warning the companies behind all three Shenzhen-based GPS platforms about their vulnerabilities for months. When WIRED reached a representative of SETracker, the person initially claimed in an email that “the issues you mentioned have been resolved long before,” adding that “we attach great importance to the security of Setracker and keep strengthening its security continuously.” When WIRED pointed out that researchers had been able to hack a smartwatch running on SETracker just this week, the person repeated their claim that the issues had been fixed, then asked for evidence of the exploitation, which WIRED provided. 研究人员表示,他们几个月来一直在向这三家深圳 GPS 平台的背后公司发出漏洞警告。当《连线》联系到 SETracker 的一位代表时,对方最初在邮件中声称“你提到的问题很久以前就已经解决了”,并补充说“我们非常重视 Setracker 的安全性,并不断加强其安全防护”。当《连线》指出研究人员本周刚刚成功入侵了一款运行在 SETracker 上的智能手表时,该代表重复了问题已修复的说法,并要求提供入侵证据,《连线》随后提供了相关证据。
Only today, hours before the researchers’ talk at Black Hat, did the researchers find that their hacking techniques against SETracker’s platform have stopped working—though they’re still not sure if the flaws they found are fully fixed. 直到今天,在研究人员于 Black Hat 发表演讲的前几个小时,他们才发现针对 SETracker 平台的黑客攻击手段失效了——尽管他们仍不确定所发现的漏洞是否已完全修复。
Sinotrack and the NewGPS2012 platform didn’t respond to WIRED’s requests for comment, and the researchers say their hacking techniques against those systems still appear to work. Sinotrack 和 NewGPS2012 平台没有回应《连线》的置评请求,研究人员表示,他们针对这些系统的黑客攻击手段似乎仍然有效。
For more than a decade, cybersecurity experts and privacy advocates have warned that cheap, GPS-enabled children’s smartwatches and aftermarket vehicle accessories are riddled with security vulnerabilities that leave kids and drivers sus 十多年来,网络安全专家和隐私倡导者一直警告称,廉价的 GPS 儿童智能手表和售后汽车配件充斥着安全漏洞,使儿童和驾驶员处于……(原文截断)