MiSafes' child-tracking smartwatches are easy to hack
bbc.com
bbc.com
Just like we will "literally" never get the literal cat back in the bag.
I imagine many lawyer-hours would find that "this peon employed to ensure the device is secure" is found to be entirely responsible.
Edit: This ToS is hilarious
No Data Mining or Harmful Code.
You agree that you will not
(a) obtain or attempt to obtain any information from the Service;
(b) intercept, examine or otherwise observe any proprietary communications protocol used by the Service, whether through the use of a
network analyzer, packet sniffer or other device; or
(c) use any type of bot, spider, virus, clock, timer, counter, worm, software lock, drop dead device, Trojan-horse routing, trap door, time
bomb or any other codes, instructions or third-party software that is designed to provide a means of surreptitious or unauthorized
access to, or distort, delete, damage or disassemble the Site or the Service.I've always been told that judges are in fact humans who can see that for the no-op it is and are unlikely to be amused by such a stunt.
Seriously though, what the hell?
1. We desperately need to fix incentives for prosecutors. We as a people need to decide what we are trying to optimize for because I'm pretty sure we are not trying to optimize for a near 100% conviction rate. Prosecutors and attorney generals are humans and they react to incentives.
2. We must repeal the CFAA. While an appeals court has apparently ruled that a terms of services (TOS) violation is not a criminal offense, because we have not fixed 1 (above), this will continue to be a problem. As impossible it might seem to repeal, I think it is much easier than to do 1.
Some people might say that we need the CFAA in some form and that we just need to amend it. Say no to such calls for "moderation". You wouldn't pick the "middle road" between being alone and being dead. I want to be very much alive. The "middle way" of pleasing everyone doesn't always work.
Repeal the CFAA (and don't replace it with anything).
Someone wanting to abduct a specific child is, contrary to popular belief, multiple orders of magnitude more common than someone wanting to abduct an arbitrary child.
Trying to explain to them that it was more likely that a child would be kidnapped by a friend or family member - or to die in an auto or airplane accident - was seemingly impossible.
With this device there are a few problems:
1) Parents will have a false sense of security. They may let their child wander off a litter farther, possibly out of view.
2) The abductors can passively determine which kids are likely to be farther away from their parents and determine the safest path to extract their victim.
In terms of being silly: This could be a former (abusive) parent that is legally blocked from seeing their kid unsupervised. This is the most common scenario and many of the amber alerts are for this.
In my opinion, if parents are going to rely on something like this, it needs to use military grade encryption and military grade implementation / process and be pentested by numerous independent researchers and come with a multi-million dollar guarantee that it can not be compromised. If that is too difficult with current tech, then this device should not exist. Rather, parents will need to stay with their children until their children are able to defend themselves.
They banned these devices because they are essentially bugs/covert listening devices and are even marketed as such. Devices that look innocious (such as children's watches or teddy bears) but in reality are covert listening devices are banned in Germany by §90 TKG. [1]
This is why the Bundesnetzagentur banned the smartwatches in question. They even cited cases in which these watches were used to monitor teachers in classrooms. [2]
"Normal" smartwatches are NOT banned. "Normal" smartwatches for children are also NOT banned. Only watches with monitoring functions fall under the §90 TKG law. [3] Note that using an app to bring covert listening functionality to a phone or watch also converts that device into an illegal listening device.
[1] https://www.gesetze-im-internet.de/tkg_2004/__90.html (Just for reference)
[2] https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilung... (German, but google translate works sufficiently well)
[3] https://www.bundesnetzagentur.de/DE/Sachgebiete/Telekommunik... (German, use a translator)
These people would know what a child's routine is already, and would not need smartwatch info.
And we're talking about people to are also technically savvy enough to reverse engineer this software.
It seems more likely that even in this situation, the watch would be a help rather than a harm.
I'm not saying we shouldn't care about security, but people tend to over-react whenever children are involved.
Yes. You can turn on remote listening and spy on the wearer (and anyone else nearby).
If there's a real risk (and while it might be relatively rare, real risks do exist) then the regular routine is hopefully already set up to mitigate the risk. The value to the attacker is in being able to take advantage of deviations from routine that would apart from the watch be invisible to them.
And, you can enumerate all kids. Pretty much everything you need for a new app..."Kin-der".
People worry about chat rooms where you would have to social engineer any of that.
It's also very easy to spoof caller ID, so this opens up children to unsolicited calls.