Ultra-cheap smart glasses leaving Australians' personal data exposed to hackers
Link:
The new generation of ultra-cheap smart glasses is exposing Australians' sensitive data, images and videos to hackers, an investigation by ABC News has found.
Independent testing by cybersecurity experts has revealed a suite of serious vulnerabilities, and found an attacker can gain control of the glasses and any stored images using only Bluetooth.
"Another person with the same app can log into the glasses without a password [because] there is no password," said David Crees, the lead researcher in testing conducted for the ABC by NSB Cyber and Abstract Shield.
"It shouldn't be possible. It is not possible in pretty much every other proper consumer electronic," he said.
The ability to hijack a stranger's glasses with Bluetooth alone was one of more than a dozen flaws he found in six days of testing the AI-enabled smart glasses, the phone app, and its website.
"I would have expected to have found some vulnerabilities … but in this case, there wasn't a single thing that they had done correctly," Crees said.
When the smart glasses are switched on but the owner is not connected, an attacker can "race" them to connect first, with no password or barrier to stop
Once inside, the attacker can control the device to take new photos and recordings, and copy any photos or videos that are already stored
Audio and images can be intercepted while they're being transmitted from the owner's glasses to their phone
An attacker can impersonate glasses they don't own and use them to connect to the owner's mobile app
The device ID number is visible to others within bluetooth range while the glasses remain unpaired, and can be used to look up the user's email address and date of birth via a separate failure on the app's website
The findings also horrified legal experts, who said the security flaws were so serious the product likely breached the privacy act, Australian consumer law, and the government's new cyber security act.
"It's really disturbing to read the extent of the failure to take even basic steps to protect personal data," said Kimberlee Weatherall, a tech regulation specialist from the University of Sydney.
"They don't seem to have encrypted it, they don't seem to have put passwords on it, they don't seem to have put even basic protections on the information that's on the website.
"It's a really clear breach [of the privacy act]."
There has been growing public backlash to the recent influx of cheap smart glasses to Australia, with calls for an import ban over privacy concerns their ability to record in secret.
The devices, which look like ordinary glasses, let the wearer capture images, video and audio with the press of a button, and they have attracted the nickname "pervert glasses" because it is not always clear when they are in use.
Now, revelations their security flaws raise a parallel set of privacy concerns for the glasses' owners.
The testing conducted for ABC News assessed two pairs of glasses - one costing (AU)$60 from the online retailer Temu, and another costing (AU)$110, bought from a Sydney-based importer called BDI Technology via Big W Marketplace.
Similar versions in a comparable price range have also been available in recent months from Dick Smith, Kmart, and Amazon, and all appear to rely on the same mobile phone app, called HeyCyan.
Like many ethical hackers, Crees first honed his skills as a cyber criminal, but now runs his own company called Abstract Shield, which is often hired by companies to detect security flaws before an attacker can.
"I'll spend anywhere from a week to a month going through a bit of software or a server or a website and finding everything that's wrong with it."
But he said it was clear straight away there was "no chance" these glasses were tested to a basic minimum standard before they hit Australian shelves.
"If you think AirPods or Samsung earbuds, you have to hold a button on the device for [several] seconds, and then you can pair it with a new phone," Crees said.
"That protects the device, [but] this has nothing."
Weatherall said the glasses also violated Australia's privacy laws and were likely to breach several sections of the yet-to-be-used cyber security act, which came into effect in March.
"The rules say that the password must be unique," she said.
"It doesn't even seem like they were applying a password, which might mean that their standards are so low they don't even technically breach that rule, which I find amazing."
Australian data in, Chinese propaganda out
Aside from the hacking risk, the testing also found Australian user data was being sent to China in many instances.
It revealed anything spoken or typed to the in-built AI companion, along with any images submitted to AI, was sent first to a server in Shenzhen.
Depending on the function being performed, the data might then be passed to another Chinese server belonging to a different company, or to the US, although users are not explicitly told.
"The [privacy] act says if it's practical, you have to identify the country," Weatherall said.
The AI companion embedded in the glasses sometimes returned inaccurate answers or error messages when asked topics the Chinese government considers sensitive.
In one instance, when asked China's well-documented persecution of millions of Uyghur Muslims in Xinjiang province, the chatbot said there was "no credible evidence".
It declined to the Tiananmen Square massacre and proposed "more positive topics" instead.
These findings, along with server locations, led researchers to conclude the chatbot companion relied at least in part on Chinese sovereign AI models.
"There is a high degree of uncertainty when it comes to where the data is going," Evan Vougdis, from NSB Cyber, who oversaw the research, said.
"Is it being used for further training [of Chinese AI models]? Is it being used for surveillance?"
The testing did not definitively determine how the data was being used, but Vougdis said any Australians considering buying the product should be aware of the risk they were taking.
"We're looking at data collection at a scale that we've never seen before due to the adoption of … products such as smart glasses that are readily available for a low price," he said.
The developer of the HeyCyan app is Shenzhen Qingcheng Future Technology Co, based in mainland China.
The ABC made repeated attempts to the company its security flaws and seek a response, but received no .
It appeared HeyCyan's developers had attempted to patch some security flaws after the ABC shared the findings, but most vulnerabilities remained unaddressed.
Crees said the flaws were so many and substantial that a total fix was impossible.
"You'd have to update 300 different brands of glasses and the app and the website… it'd take like a year to fix this. The only real solution that I see is a recall," he said.
The ABC understands at least one Australian retailer paused its supply because of the furore surrounding the devices.
BDI Technology, which is also listed as the supplier to Dick Smith and on Big W's Marketplace platform, said it was no longer selling smart glasses.
"I'm not surprised," privacy commissioner Carly Kind said.
"There has been a really extreme backlash to these technologies. Many of these companies really prize their reputation in the Australian community, and I think they [would] do well to listen to that community concern."
The ABC did not receive on-the-record responses from any other retailers.
Student opens fire outside school in Turkey, eight pupils wounded, NTV reports
Double murder-accused Beau Lamarre-Condon acted in 'self defence', court told
Australia joins global push for controls amid fears of runaway AI
Travel meltdown caused by ageing circuit and backup system failure, officials say
Nicky Hager's new book Dirty Work 'exposé' of Taxpayers' Union
RMA replacement laws pass in Parliament
Decision to send 12-year-old with 'safety plan' shortly before her death questioned
to continue for missing 1978 plane after inconclusive object found in Lake Moeraki
© RNZ, original at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
