Get the latest tech news
Bad Smart Watch Authentication
IDO based smart watches are a security nightmare, and there's likely millions of them out there
Investigating the Ryze Android app I quickly discovered that this is a white label of an IDO smart watch. I’m going to skip past dealing with authentication for the moment as that gets a little spicy and we don’t want to ruin the standard story telling plot framework. Turns out this probably just had the mac address on it or something because after several hours of getting device info and pulling activity data I realised that I had never performed any authentication step.
Or read this on Hacker News