Security researchers remotely tracked a WIRED reporter through a child's GPS smartwatch, silently captured photos from its camera, and eavesdropped on conversations via its microphone without triggering any visible alerts, according to a demonstration published this week. The researchers, Vangelis Stykas and Felipe Solferini, presented their findings at the Black Hat cybersecurity conference, revealing that tens of millions of GPS tracking gadgets sold under dozens of brands share just three vulnerable supply chains based in Shenzhen, China. The watch showed no sign it was being hacked during the entire surveillance operation.

The researchers analyzed more than 70 GPS-enabled watches and car accessories and discovered that over 30 geolocation devices operate on the technology and backend servers of YiQingTeng, also known by the brand names Wonlex or the associated app SETracker. Another 30-plus brands of tracking devices for cars and children run on a separate Shenzhen-based platform called NewGPS2012. Combined with a third major GPS platform known as SinoTrack that sells car trackers and smartwatches, the researchers found that tens of millions of GPS tracker gadgets came from just three supply chains. All three platforms had significant security flaws that left children's watches vulnerable to tracking by hackers, location disabling and spoofing, interception and spoofing of text and audio messages, replacement of emergency contacts with ones chosen by attackers, silent audio eavesdropping, and photo and video capture for camera-enabled devices.

The researchers say they've been warning the companies behind all three Shenzhen-based GPS platforms about their vulnerabilities for months. Stykas characterizes the scope of the risk in stark terms: "Millions of kids are being exposed and vulnerable to exploitation. It's just catastrophic." He adds that "your criminal mind is the only limitation in exploiting those devices." In the case of YiQingTeng, the manufacturer of the watch WIRED tested, the researchers say an authentication security flaw would have allowed anyone to send commands to any SETracker-based device, letting hackers exploit devices at random or target specific watches if they can determine an identifier such as the parent's email address. For SinoTrack, they found that an account intended for demonstration purposes could be used to send commands to any of the platform's millions of devices, and a SQL injection vulnerability gave them access to tens of thousands of devices' locations, passwords, and vehicle records.

The security failures stem from what the researchers describe as an illusion of consumer choice: the white-label manufacturing model means a parent in Sweden buying a SafeKid watch and a parent in Spain buying a SaveFamily watch are both sending their child's location data to the same vulnerable backend on Alibaba Cloud in mainland China without knowing it. The researchers explain that a vulnerability in one backend affects dozens of consumer brands at the same time, and consumers have no way to tell which backend their product uses. Only hours before the Black Hat presentation did the researchers find that their hacking techniques against SETracker's platform stopped working, though they're still not sure if the flaws are fully fixed. SETracker later stated it had blocked certain ports on its servers used by a legacy version of its clients' systems, forcing a small subset of clients to upgrade. Meanwhile, Sinotrack and NewGPS2012 didn't respond to requests for comment, and the researchers say their hacking techniques against those systems still appear to work. For parents weighing convenience against privacy, the commodity electronics supply chain has effectively made informed purchasing impossible without reverse-engineering the device's network traffic.