Live data from Hacker News

Hackers Stalked Me by Hijacking a Smartwatch for Kids

wired.com

41–46 of 46 posts

Re: Hackers Stalked Me by Hijacking a Smartwatch for Kids

#42
post #8

> made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China. Is this what is meant by "Shenzhen Speed"? Dump all safeguards and get any piece of crap out the door as soon as possible? This comment isn't directed specifically at Shenzhen, as other parts of the world do the same thing and call it "Move fast and break things." Dropping engineering standards may increase short term profits, but…

> Dump all safeguards and get any piece of crap out the door as soon as possible? Very few companies seem to get into trouble for knowingly releasing products that are either faulty, insecure, or actively dangerous

Is that something that can be backed by data?

If not, I have anecdotal counter info: saw a lot of work of a small team doing hardware testing/evaluation for a hardware reseller. Often using Chinese sources. Typical "our brand is good, but has to be slightly cheaper than competition". Some manufacturers are really good. But a lot of them send hardware so bad that it will electrocute you instantly. Which is wild in that profession - the whole point of sending samples to client is for them to disassemble it to asses quality. This is literally the only scenario, so any lie is instantly discovered.

One company asked for immediate return of a prototype because a client ordered a batch, but they don't know how was it made. They had zero documentation and had to check what was inside.

Re: Hackers Stalked Me by Hijacking a Smartwatch for Kids

#43

Earlier quoted context omitted.

The Law Of The Land in most lands nowadays is "Take whatever you can by swindling, lying, or cheating. Nobody is stopping you."

There's even a term for that in Hindi - Don't be a sucker (bhookha / bhole). Don't be the person that's naive, easily cheated, and left behind while others move ahead because you refuse to take the optimal course of action.

Might as well not have any kind of society or rule of law at that point at all then. Zero trust societies, that's definitely the way towards a better life for all of us

Re: Hackers Stalked Me by Hijacking a Smartwatch for Kids

#44
post #30
post #7

Until the Chinese government penalizes these Chinese companies for these insecure practices, they'll continue to be sold as is. China doesn't need to care about Chinese made products sold for export apparently.

I'm not sure this is uniquely a China problem

Cheap electronics with terrible software? Maybe not unique, but they dominate the market.

We could sure go a long way if China would start.

Re: Hackers Stalked Me by Hijacking a Smartwatch for Kids

#45
post #26

You think you're choosing between 20 different products, but underneath they may all be the same device talking to the same insecure backend. At that point "just research before you buy" isn't really useful advice

I found this true with security camera & dvr systems. If you're shopping on amazon, you're mostly looking at the same devices and software, sometimes with slightly different styling, versions, and capabilities.

Most of them use the same cloud software to connect to the cameras.

There's better solutions if you have a bigger budget, or the ability to roll your own DVR solution...but on the cheap end, you're just stuck with this terrible software, chinese cloud, and...at least for me...zero trust in privacy. (I keep mine offline)

Re: Hackers Stalked Me by Hijacking a Smartwatch for Kids

#46
post #26

You think you're choosing between 20 different products, but underneath they may all be the same device talking to the same insecure backend. At that point "just research before you buy" isn't really useful advice

Buyer Beware has always been a terrible way to live. It guarantees the shittiest products rise to the top because most people do not seriously beware for every purchase they make. As is always the case, regulation and enforcement is what's needed.

How are you even supposed to evaluate the security of a product before you buy it and have it in your hands? It's not like there's an ecosystem of outlets doing that kind of work for the hundreds of thousands of internet-connected devices out there.

And even when it's in your hands, who has the time and expertise to thoroughly review a product for security issues?

Post reply on HN