跳到主体内容

Insecure Wearables: Kaspersky Lab Researcher Discovers Security Issue in His Fitness Wristband

2015年3月26日

Kaspersky Lab researcher has examined how a number of fitness wristbands interact with a smartphone and discovered some surprising results.

Fitness trackers of all kinds have become extremely popular, helping people to manage their physical activity and calorie intake and stay in shape. However, such devices also process important personal data about their owners and it is important to keep it secure. Kaspersky Lab researcher Roman Unuchek has examined how a number of fitness wristbands interact with a smartphone and discovered some surprising results.

According to his research findings, the authentication method implemented in several popular smart wristbands allows a third-party to connect invisibly to the device, execute commands, and – in some cases – extract data held on the device. In the devices investigated by the Kaspersky Lab researcher, such data was limited to the amount of steps taken by the owner during the previous hour. However, in the future, when next-generation fitness bands capable of collecting a greater volume of more varied data appear on the market, the risk of sensitive medical data about the owner leaking out could raise significantly.

The rogue connection is made possible because of the way in which the wristband is paired with a smartphone. According to the research, an Android-based device running Android 4.3 or higher, with a special unauthorized app installed can pair with wristbands from certain vendors. To establish a connection users need to confirm the pairing by pressing a button on their wristband. Attackers can easily overcome this, because most modern fitness wristbands have no screen. When the wristband vibrates asking its owner to confirm the pairing the victim has no way of knowing whether they are confirming a connection with their own device or someone else’s.

“This Proof of Concept depends on a lot of conditions for it to work properly, and in the end an attacker wouldn’t be able to collect really critical data like passwords or credit card numbers. However it proves that there is a way for an attacker to exploit mistakes left unpatched by the device developers. The fitness trackers currently available are still fairly dumb, capable of counting steps and following sleep cycles, but little more than that. But the second generation of such devices is almost here, and they will be able to gather much more information about users. It is important to think about the security of these devices now, and ensure that there is proper protection for how the tracker interacts with the smartphone,” - said Roman Unuchek, Senior Malware Analyst at Kaspersky Lab.

Kaspersky Lab experts advise users of smart wristbands who are concerned about the security of their device to check with the wristband’s vendors whether such a potential attack vector would be possible on their product.

Read more about the research performed by Roman Unuchek in his article on Securelist.com.

Insecure Wearables: Kaspersky Lab Researcher Discovers Security Issue in His Fitness Wristband

Kaspersky Lab researcher has examined how a number of fitness wristbands interact with a smartphone and discovered some surprising results.
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻