US National WireUS NATIONAL WIRE
TechOpinion

The 'Kid-Safe' Lie: Why Cheap Smartwatches Are Security Nightmares

Portrait of Jordan Wexler
Jordan Wexlerconsumer tech & gadgetsAug 7AI
The 'Kid-Safe' Lie: Why Cheap Smartwatches Are Security Nightmares

AI-generated image · US National Wire

A pink plastic gadget costing less than $30 proved to be a wide-open door for stalkers, exposing a catastrophic failure in the global GPS supply chain.

I've always said that if a spec sheet looks too good to be true for the price, the real cost is usually your privacy. But the latest reporting from Wired takes this from a theoretical concern to a waking nightmare.

In a recent experiment, as Wired first reported, security researchers Vangelis Stykas and Felipe Solferini used a lavender and pink plastic child's smartwatch to stalk a Wired reporter, Andy Greenberg, through the streets of New York. The device, sold by a company called CJC for less than $30, was essentially a beacon for anyone with the technical know-how to listen in. Even when the watch's GPS malfunctioned, Stykas could pinpoint Greenberg's exact location in Brooklyn by monitoring Wi-Fi network identifiers being transmitted to a remote server.

Once Greenberg reached the Wired Manhattan headquarters, the researchers shifted from tracking to active surveillance. They hijacked the watch's camera to silently snap photos of Greenberg in an elevator and at his desk. They then activated the microphone, allowing Solferini to eavesdrop on a conversation between Greenberg and a coworker. Throughout the entire ordeal, the watch provided no indication that it was being controlled remotely.

**Opinion: We need to stop pretending these 'kid-safe' gadgets are anything other than security nightmares. If a piece of pink plastic can be turned into a surveillance tool this easily, the industry is failing the very people it claims to protect.**

According to Wired, the danger isn't limited to one obscure brand. Stykas and Solferini analyzed more than 70 GPS-enabled car accessories and watches, discovering that tens of millions of these devices originate from just three Shenzhen-based supply chains. One chain involves YiQingTeng Electronics (also known as Wonlex), partner firm Shenzhen 3G Electronics, and the SETracker app. Another is the NewGPS2012 platform, and a third is SinoTrack.

The researchers found significant security flaws across all three, including a lack of authentication that could allow anyone to access any device. This opens the door for hackers to disable or spoof locations, intercept text and audio messages, and replace emergency contacts. For camera-enabled devices, it allows for silent photo and video capture. Stykas described the situation as "catastrophic," noting that these devices are "low-hanging fruit" for bad actors.

While SETracker initially told Wired that these issues had been resolved long ago, the researchers were still able to hack a device running on that platform just last week. It was only hours before the researchers presented their findings at the Black Hat cybersecurity conference that the specific hacking techniques used against SETracker stopped working.

This isn't just about a cheap toy; it's about a systemic failure. When the hardware is this insecure, the 'safety' features are just a marketing veneer for a surveillance tool.

Sources

More from Jordan Wexler