Hacker Exposes Gaping Hole in Google Glasses With Nasty QR Codes
July 17, 2013 4:45 PM
comment(s) - last by
Wearable electronics are undiscovered country in terms of security research
are still in their
very early stages
in terms of commercialization, but already there’s been a fascinating attack on their security, demonstrated by Marc Rogers, the principal researcher at
Lookout Mobile Security
Mr. Rogers took Google Inc.’s (
a rather gaping hole in the device’s security.
Glass Explorer when it spots special
(square shaped barcode-like stickers for smartphones and tablets) automatically can perform certain functions, such as visiting a URL. But the trouble began when Google allowed the QR codes to be used as a setup tool, connecting the devices to a network over Wi-FI or BlueTooth.
The idea seemed clever, given that setup would otherwise be onerous due to lack of a keyboard (the Glass Explorer can take voice input, input from a small trackpad on the side of the glasses, and input from glyphs such as QR codes,
which it “sees”
). The issue was that Google never secured these setup-driven connection commands, allowing you to trick the glasses into visiting a nasty network.
By posting a malicious QR code, Mr. Rogers tricked the Android glasses wearable computer into connecting to his attack network. He showed that such an attack could be used to monitor (using the software tool
) or even take complete remote control of the device exploiting
known Android vulnerabilities
(Mr. Rogers’ attack used an Android 4.0.4 vulnerability).
After revealing the vulnerability to Google on May 16, with information on the attack, Mr. Rogers was impressed to see Google cover the hole by June 4, with the
XE6 firmware update
. That update fights the attack in different ways, including improving warning when connecting to a network via QR command. More significantly the update turns off auto-scanning for QR codes. Thus similar future attacks would require the user to first be choosing to scan an unknowingly malicious code, rather than the attack launching from a mere accidental glance at a malicious QR stuck somewhere.
While Mr. Rogers says he expects more vulnerabilities to be found in Google Glass Explorer before its public release, he’s impressed with Google’s patching time of under a month. He remarks, "This responsive turnaround indicates the depth of Google’s commitment to privacy and security for this device and set a benchmark for how connected things should be secured going forward."
A mere stray glance at a malicious QR code could trigger the exploit, pre-patch.
[Image Source: Slashgear]
He says that the experience has convinced him that by the time the wearable – currently
only available to developers
– is launched at a lower cost to consumers (likely in 2014) – consumers will "be able to trust Glass … because it has been tested."
As for what’s next for Lookout, he plans to next investigate connected cars,
, and smartwatches (such as Sony Corp.'s (
) for exploits. He expects more vulnerabilities to be found in such devices as companies try to work around the logistical hurdles of limited user interfaces, often turning to novel but risky solutions. But he argues consumers shouldn’t fear the "internet of things" industry trend, remarking, "There’s a risk that we will get a little bit scared by new things, and there’s a risk that we could miss out on cool things [as a result]."
This article is over a month old, voting and posting comments is disabled
7/17/2013 9:01:31 PM
I for one hate staying in front my computer for a long time. Cannot imagine having glasses 24/7. Alzheimer's is gonna explode in the future.
7/17/2013 9:22:40 PM
What does the number of cases of alzheimers have to do with sitting in front of a computer or wearing google glass?
7/18/2013 7:01:13 AM
He's confusing sitting in front of a computer/glass 24/7 with sitting in front of soap operas & reality shows 24/7.
"This week I got an iPhone. This weekend I got four chargers so I can keep it charged everywhere I go and a land line so I can actually make phone calls." -- Facebook CEO Mark Zuckerberg
Dell Exploring Wearable Device Offering
July 5, 2013, 1:26 PM
Apple Looks to Trademark "iWatch" in Japan
July 1, 2013, 11:18 AM
Sony Announces 6.4" 2.2GHz Xperia Z Ultra Smartphone, SmartWatch 2
June 25, 2013, 8:37 AM
No Ogling With The Google Goggles: "Tits and Glass" App Banned
June 4, 2013, 2:30 PM
USPS Wants to be More Digital-Friendly
January 16, 2013, 9:52 AM
Sony's Xperia Z3 Gets Detailed in Leaked Photos
July 25, 2014, 2:30 PM
Heavy Users of Verizon’s “Unlimited” LTE Data Could Soon See Targeted Throttling
July 25, 2014, 1:52 PM
Motorola Moto X+1 Makes Appearance in Leaked Photos
July 25, 2014, 12:06 PM
Sony Finally Adds 3D Blu-ray Support to PS4
July 24, 2014, 3:44 PM
IDC: Although Apple Remains at Top of Tablet Market, Share Falls from 33% to 26.9%
July 24, 2014, 1:24 PM
Thanks in Part to Strong G3 Launch, LG Sells 14.5 Million Smartphones in Q2
July 24, 2014, 10:18 AM
Most Popular Articles
Microsoft Kills Entertainment Unit, May Shelve Flagship Lumia "McLaren"
July 18, 2014, 7:40 PM
JJ Abrams Unveils X-Wing Starfighter for New "Star Wars" Movie
July 21, 2014, 12:24 PM
Ford Details ’15 F-150’s 325hp, 2.7L EcoBoost V6; Demonstrates 732-lb Weight Loss
July 22, 2014, 6:55 PM
Comcast Memo: Harassing Customers During Retention Calls Actually IS Our Policy
July 22, 2014, 5:19 PM
Motorola Moto G Successor Reportedly Uncovered, Moto X Discounted by up to $75
July 21, 2014, 1:11 PM
Latest Blog Posts
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information