'Disturbing' security flaw in cheap smart glasses - ABC News & Headlines – Australian Broadcasting Corporation
A new generation of ultra-cheap smart glasses is exposing Australians' sensitive data to hackers.
Basic testing has revealed stored videos and photos can be stolen from the controversial devices, using only bluetooth.
But there's a privacy risk for the person wearing the glasses too….
Security testing conducted for the ABC reveals the new wave of ultra cheap devices being sold in Australia… is shockingly hackable.
Yeah, so I have just recorded you and taken a photo with the glasses. You had no choice in the matter.
I would have expected to still have found some vulnerabilities // But in this case, there wasn't a single thing that they had done correctly.
He found more than a dozen serious security flaws - and was able to hijack the device using only bluetooth.
The second that these disconnect from your phone, Another person with the same app on their phone can log into the glasses without a password, there is no password, and just click download and get all of your photos and videos that are still on the glasses.
Several well known retailers have been selling similar devices in Australia, and all the models at that price point seem to rely on the same mobile phone app, called HeyCyan.
Thanks to a separate failure on that app's website, it's also possible to look up the owner's email address and date of birth using only the device ID number.
if they did any form of security audit whatsoever on any part of this, they would see the cascading failure that this is.
It's really disturbing to read just the extent of the, like just the failure to take even basic steps to protect personal data, to protect privacy.
it doesn't meet privacy standards. It doesn't meet the cyber security standards and it doesn't meet Australian consumer law from what I can see in the report and what's possible. So no, I wouldn't be selling them.
On top of the hacking risk, security testing found data was often being sent to China, via the in-built AI companion.
the act says if it's practical, you have to identify the country. It's not at all clear to me why they couldn't have put China into the privacy policy. So that also looks like a breach.
In return, the chatbot sometimes sends back inaccurate answers or error messages when asked about topics considered sensitive by the Chinese government.
It also declined to discuss the Tiananmen Square massacre and proposed "more positive topics" instead.
The ABC has made repeated attempts to contact HeyCyan and its parent company about the security flaws, but received no reply.
It appears the app's developers have tried to patch some of the issues since the ABC shared the findings, but most remain unaddressed.


