Some cheap smart glasses are a security disaster
Brief
Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all.
ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website.
The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation.
After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
Some cheap smart glasses are a security disaster
Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all.
ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website.
The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation.
After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone. An attacker could also make another device appear to be the victim’s glasses, allowing it to connect to the owner’s mobile app.
The testing also found that a Bluetooth-visible device identifier could allegedly be used with a weakness in the app’s website to retrieve a user’s email address and date of birth.
The research uncovered another privacy issue. ABC reports that voice or text submitted to the built-in AI, along with images sent to it, was first transmitted to a server in Shenzhen and could be forwarded elsewhere, depending on the function. The tests did not establish how the data was subsequently used.
The server locations, combined with some of the AI’s answers to specific questions, led researchers to conclude that the chatbot companion relied at least in part on Chinese sovereign AI models.
Some cheap smart glasses are a security disaster
Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all.
ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart glasses themselves, their app, and an associated website.
The main problem they uncovered was insecure Bluetooth pairing: If the glasses were powered on and not connected to their owner’s phone, an attacker could connect first, with no password or meaningful pairing confirmation.
After connecting, an attacker could reportedly control the glasses to capture photos or recordings, copy existing media, and intercept data moving between the glasses and the phone. An attacker could also make another device appear to be the victim’s glasses, allowing it to connect to the owner’s mobile app.
The testing also found that a Bluetooth-visible device identifier could allegedly be used with a weakness in the app’s website to retrieve a user’s email address and date of birth.
The research uncovered another privacy issue. ABC reports that voice or text submitted to the built-in AI, along with images sent to it, was first transmitted to a server in Shenzhen and could be forwarded elsewhere, depending on the function. The tests did not establish how the data was subsequently used.
The server locations, combined with some of the AI’s answers to specific questions, led researchers to conclude that the chatbot companion relied at least in part on Chinese sovereign AI models.
