Post

Ultra-cheap Smart Glasses Expose Australians' Data to Hackers

Ultra-cheap Smart Glasses Expose Australians' Data to Hackers

Ultra-cheap Smart Glasses Expose Australians’ Data to Hackers

The new generation of ultra-cheap smart glasses is exposing Australians’ sensitive data, images, and videos to hackers, an investigation by ABC News has found. 🕶️🔒 Independent testing by cybersecurity experts has revealed a suite of serious vulnerabilities. An attacker can gain control of the glasses and any stored images using only Bluetooth.

“Another person with the same app can log into the glasses without a password because there is no password,” said David Crees, the lead researcher in testing conducted for the ABC by NSB Cyber and Abstract Shield. He added, “It shouldn’t be possible. It is not possible in pretty much every other proper consumer electronic.”

The ability to hijack a stranger’s glasses with Bluetooth alone was one of more than a dozen flaws found in six days of testing the AI-enabled smart glasses, the phone app, and its website.

The findings have horrified legal experts, who stated that the security flaws were so serious that the product likely breached the privacy act, Australian consumer law, and the government’s new cybersecurity act. Kimberlee Weatherall, a tech regulation specialist from the University of Sydney, noted, “They don’t seem to have encrypted it, they don’t seem to have put passwords on it, they don’t seem to have put even basic protections on the information that’s on the website.” She concluded, “It’s a really clear breach [of the privacy act].”

Mr. Crees highlighted the lack of basic security: “If you think about AirPods or Samsung earbuds, you have to hold a button on the device for several seconds, and then you can pair it with a new phone. That protects the device, but this has nothing.”

Data Privacy Issues

Aside from the hacking risk, the testing also found that Australian user data was being sent to China in many instances. It revealed that anything spoken or typed to the in-built AI companion, along with any images submitted to AI, was sent first to a server in Shenzhen. Depending on the function being performed, the data might then be passed to another Chinese server belonging to a different company or to the US, although users are not explicitly informed.

Professor Weatherall observed, “It’s not at all clear to me why they couldn’t have put China into the privacy policy,” noting that the document only made specific mention of Singapore. Furthermore, the AI companion embedded in the glasses sometimes returned inaccurate answers or error messages when asked about topics the Chinese government considers sensitive.

Conclusion

Evan Vougdis from NSB Cyber, who oversaw the research, stated there is “a high degree of uncertainty when it comes to where the data is going.” He questioned, “Is it being used for further training of Chinese AI models? Is it being used for surveillance?” The developer of the HeyCyan app is Shenzhen Qingcheng Future Technology Co, based in mainland China.

It appeared that HeyCyan’s developers had attempted to patch some security flaws after the ABC shared the findings, but most vulnerabilities remained unaddressed. Mr. Crees asserted that the flaws were so many and substantial that a total fix was impossible. “The only real solution that I see is a recall,” he said. At least one Australian retailer, BDI Technology, confirmed it was no longer selling smart glasses because of the furore surrounding the devices.

Read full article

This post is licensed under CC BY 4.0 by the author.