Leaky child-tracking smartwatch maker hits back at bad PR

We're not convinced 'people who want to harm kids will follow the kid, not the watch' is a great comeback


Kids' smartwatch-pusher Enox, whose Safe-KID-One watch was pulled by the European Commission, has hit back against the bad PR – with some rather unusual arguments.

Citing an investigation by Icelandic infosec firm Syndis, the Commission this month outlined "serious" risks with the watch, which comes with GPS, a mic and a speaker so parents can make and receive calls from their kid or kids and keep an eye on where they are.

However, multiple studies found that such devices are prone to security flaws, with hackers being able to seize control of them to make calls to previously unknown numbers, eavesdrop and track the wearers.

kid

European Commission orders mass recall of creepy, leaky child-tracking smartwatch

READ MORE

"A malicious user can send commands to any watch making it call another number of his choosing, can communicate with the child wearing the device or locate the child through GPS," the Commission’s alert warned on Safe-KID-One.

When The Reg first reported the recall – which is thought to be the first of its kind – founder Ole Anton Bieltvedt unsurprisingly disputed Syndis's analysis.

Instead, he pointed to a one-page assessment from the German federal agency Bundesnetzagentur that the watch didn't violate that country’s Telecommunications Act.

However, rather than leaving it at that, Bieltvedt – who had to watch as a PR firm picked up on the story and pushed it out to multiple outlets – sought to put the watch's glitches into some kind of context. And that's when things got more than a little bizarre.

"If somebody wants to do harm to a kid, he will follow the kid, not a vague watch,” he told The Daily Star. Er, sure, that's one argument.

His reference to "vague" is because, apparently, the watch's GPS system "has an old construction from 2015" in which the antenna was "not strong" meaning the accuracy of the watch was only +/- 500m.

"The main function of the watch, was the clock and the telephone… The sales did stress this point, and the buyers didn't expect much from the GPS," he told The Reg. So that's fine then.

Next up is the risk associated with hacking into the server, with the founder suggesting that "regular" people wouldn't be able to do it, and if they did, it didn't really matter.

"We feel convinced that no regular person can misuse or break into our watches," Bieltvedt told The Register. "Besides, what will you find there? Just a few phone numbers, which can be mostly found in a telephone catalogue or on the internet."

Well, doesn't everyone put their family's mobe digits online?

Another complaint was that the press had latched onto the announcement (Bieltvedt said he'd had to deal with "dozens or hundreds" of journos) when there are plenty of unsecured systems out there.

"Recently, a student in Germany broke into the smartphones and/or computers of 1,000 of the leading political and commercial people in Germany," he said.

"This shows that the whole Internet system and the respective equipment is not safe, yet. So, we think this is a system problem more than an individual product problem."

Similarly, he argued to The Reg that since the Icelandic firm is a "high tech company, specialising in trying to protect banks and high-grade internet and computer systems", it could have broken into "any watch and any computer on the market, all brands and types included".

The news here, though, isn't that a security firm can hack into – as Bieltvedt put it – "a simple and cheap kids' watch"; it's that a product marketed to concerned guardians appears to be a privacy and security risk and has been recalled by the Commission.

More broadly, of course, he's not wrong: there's no end to reports of sophisticated hacks on even the supposedly most secure kit, and plenty of very dodgy connected devices at the opposite end of that scale.

And people concerned with security and privacy, especially in kids' toys, will no doubt hope that the Commission slaps more bans on them.

But just because other systems can be hacked doesn't mean it's OK to market an insecure product to parents as a child safety device – and El Reg reckons most punters would hope that companies recognise that.

When this point was put to him, Bieltvedt responded: "Of course any internet device, also our watch, needs maximum security. But, at this stage, this security is not 100 per cent available, neither for us nor others."

He added that Enox had "never experienced any misuse or problem with Safe-Kid-One", asking: "What are you and your colleagues trying to blame us for?"

Well, y'know, just marketing a watch that could expose kids’ locations (even if only within 500m) and that miscreants could hack into to call any number they fancy as a kids' safety device – and then failing to show it takes any criticisms seriously. ®

Similar topics

Narrower topics


Other stories you might like

  • VMware claims 'bare-metal' performance from virtualized Nvidia GPUs
    Is... is that why Broadcom wants to buy it?

    The future of high-performance computing will be virtualized, VMware's Uday Kurkure has told The Register.

    Kurkure, the lead engineer for VMware's performance engineering team, has spent the past five years working on ways to virtualize machine-learning workloads running on accelerators. Earlier this month his team reported "near or better than bare-metal performance" for Bidirectional Encoder Representations from Transformers (BERT) and Mask R-CNN — two popular machine-learning workloads — running on virtualized GPUs (vGPU) connected using Nvidia's NVLink interconnect.

    NVLink enables compute and memory resources to be shared across up to four GPUs over a high-bandwidth mesh fabric operating at 6.25GB/s per lane compared to PCIe 4.0's 2.5GB/s. The interconnect enabled Kurkure's team to pool 160GB of GPU memory from the Dell PowerEdge system's four 40GB Nvidia A100 SXM GPUs.

    Continue reading
  • Nvidia promises annual datacenter product updates across CPU, GPU, and DPU
    Arm one year, x86 the next, and always faster than a certain chip shop that still can't ship even one standalone GPU

    Computex Nvidia's push deeper into enterprise computing will see its practice of introducing a new GPU architecture every two years brought to its CPUs and data processing units (DPUs, aka SmartNICs).

    Speaking on the company's pre-recorded keynote released to coincide with the Computex exhibition in Taiwan this week, senior vice president for hardware engineering Brian Kelleher spoke of the company's "reputation for unmatched execution on silicon." That's language that needs to be considered in the context of Intel, an Nvidia rival, again delaying a planned entry to the discrete GPU market.

    "We will extend our execution excellence and give each of our chip architectures a two-year rhythm," Kelleher added.

    Continue reading
  • Now Amazon puts 'creepy' AI cameras in UK delivery vans
    Big Bezos is watching you

    Amazon is reportedly installing AI-powered cameras in delivery vans to keep tabs on its drivers in the UK.

    The technology was first deployed, with numerous errors that reportedly denied drivers' bonuses after malfunctions, in the US. Last year, the internet giant produced a corporate video detailing how the cameras monitor drivers' driving behavior for safety reasons. The same system is now apparently being rolled out to vehicles in the UK. 

    Multiple camera lenses are placed under the front mirror. One is directed at the person behind the wheel, one is facing the road, and two are located on either side to provide a wider view. The cameras are monitored by software built by Netradyne, a computer-vision startup focused on driver safety. This code uses machine-learning algorithms to figure out what's going on in and around the vehicle.

    Continue reading

Biting the hand that feeds IT © 1998–2022