Post

Some Cheap Smart Glasses Are a Security Disaster

Some Cheap Smart Glasses Are a Security Disaster

Some Cheap Smart Glasses Are a Security Disaster 🚨

Researchers have raised significant privacy concerns regarding smart glasses, particularly those from cheaper brands. A recent report by ABC Australia highlights findings from NSB Cyber and Abstract Shield, who tested two budget-friendly models priced at A$60 and A$110 (approximately US$42 and US$78). They discovered over a dozen security flaws in the smart glasses, their accompanying app, and the related website.

Key Findings 🔍

  • Insecure Bluetooth Pairing: The most alarming issue was the insecure Bluetooth pairing. If the glasses were powered on and not connected to their owner’s phone, an attacker could connect without any password or meaningful pairing confirmation. This vulnerability allowed attackers to control the glasses, capturing photos or recordings, copying existing media, and intercepting data between the glasses and the phone.
  • Device Impersonation: An attacker could also make another device appear as the victim’s glasses, enabling it to connect to the owner’s mobile app.
  • Data Exposure: The testing revealed that a Bluetooth-visible device identifier could be exploited alongside a weakness in the app’s website to retrieve sensitive user information, such as email addresses and dates of birth.
  • Privacy Issues: Furthermore, any voice or text submitted to the built-in AI, along with images sent to it, was initially transmitted to a server in Shenzhen and could potentially be forwarded elsewhere.

For more details, check out the full article here: Read full article

This post is licensed under CC BY 4.0 by the author.