Wearables in the hands of hackers!
The authentication method implemented in several popular models allows third parties to invisibly connect to the device, execute commands and – in some cases – extract data, Kaspersky Lab warns.
Wearable fitness devices are becoming increasingly popular. However, they process important personal data, which is important to keep secure.
Kaspersky Lab researcher Roman Unuchek examined how various wearables with smartphones. According to his findings, the authentication method implemented in several popular “smart” wristbands allows third parties to invisibly connect to the device, execute commands, and – in some cases – extract data.
On the devices tested by the researcher, such data was limited to the number of steps the owner had taken during the previous hour. However, in the future, when next-generation fitness trackers appear on the market, which will be able to collect a larger amount of information from wider databases, the risk of sensitive medical data being leaked could increase significantly.
The malicious connection is made possible by the way wearables connect to smartphones. According to the research, a device running Android 4.3 or later with a specially crafted, unauthorized app installed can connect to certain manufacturers’ wristbands. To connect, users must confirm the pairing by pressing a button on their smart bracelet.
Attackers can easily bypass this step because most fitness bracelets lack a screen. When the peripheral vibrates, prompting its owner to confirm the connection, the victim has no way of knowing whether they are confirming the connection with their own device or with someone else’s device.
«The experiment depends on various conditions and generally shows that an attacker is not able to collect truly critical data, such as passwords or credit card numbers. However, it shows that there is a way for attackers to exploit some vulnerabilities that have not been fixed by the developers of a device. The fitness trackers available today on the market are not yet «smart», being able only to count steps and follow sleep cycles and not much more than that. However, the next generation of these devices is almost ready and will be able to gather much more information about users. Therefore, it is important to think about the security of these devices now and ensure that appropriate protection is in place in their interaction with smartphones», said Roman Unuchek, senior malware analyst at Kaspersky Lab.
Οι ειδικοί της Kaspersky Lab συμβουλεύουν τους χρήστες των «έξυπνων» περιβραχιόνιων που ανησυχούν για την ασφάλεια της συσκευής τους, να ελέγξουν – σε συνεργασία με τους παρόχους των συσκευών – αν μια τέτοια δυνητική επίθεση, θα μπορούσε να συμβεί και στο προϊόν τους.
Source: protothema.gr/

