Jump to content

TLDR

basically pairing the watch to ur phone only uses a short 6 digit code which is very easy to bruteforce

a longer key would defeat this

 

http://www.tomsguide.com/us/smartwatch-encryption-cracked,news-19998.html

 

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
https://linustechtips.com/topic/267625-android-based-smartwatches-hacked/
Share on other sites

Link to post
Share on other sites

ok... i guess google will fix this in 5.0.2?

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to post
Share on other sites

I'm not too sure if increasing the digits would even work that well either. Why not just allow all characters to work? Then the possibilities are even more endless than 10^n.

dude, a 64b int is more than enough, or if youre scared get a 128b number and you wont have any computer realistically bruteforce it

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to post
Share on other sites

ok... i guess google will fix this in 5.0.2?

i think is easier if they just patched the android wear app and the OS in the watch IIRC android wear updates are fully in control of google instead of the manufacture since wear is pretty much the same exact build in different devices no mods by OEM's, is more like windows in that aspect

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to post
Share on other sites

i think is easier if they just patched the android wear app and the OS in the watch IIRC android wear updates are fully in control of google instead of the manufacture since wear is pretty much the same exact build in different devices no mods by OEM's, is more like windows in that aspect

aaah i figured it was like android. then yeah, they really should patch this... a 6 digit code isnt really stronh

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to post
Share on other sites

dude, a 64b int is more than enough, or if youre scared get a 128b number and you wont have any computer realistically bruteforce it

It's not really a 64b integer though. Its an array of numbers from 0-9. Doing what I suggest is 6 characters of upper/lower cased letters plus numbers. Which is actually far less than the max 64b integer... A true 64b integer would only allow 18 digits of 0-9, which is a lot more numbers to press...

Link to post
Share on other sites

Not really hacked though, is it.

I mean bruteforcing a pairing password is pretty pointless if you can't initialise the pairing in the first place.

Its like knowing the code to the secret door without knowing where the door actually is.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×