frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MyFirst Kids Watch Hacked. Access to Camera and Microphone

https://www.kth.se/en/om/nyheter/centrala-nyheter/kth-studenten-hackade-klocka-for-barn-1.1461249
2•jidoka•1h ago

Comments

jidoka•1h ago
Title: KTH student hacked a popular children’s smartwatch, found 17 vulnerabilities and full remote access

A former student at KTH Royal Institute of Technology has demonstrated how a popular children’s smartwatch can be fully compromised over the internet. In his thesis, “Ethical Hacking of a Smartwatch for Kids: A Hacker’s Playground,” Gustaf Blomqvist conducted an ethical security assessment of a widely sold kids’ smartwatch and found what he describes as severe security flaws.

The device, identified in Swedish media as the MyFirst Fone R1s by MyFirst, exposed an insecure network service directly to the internet. By scanning for devices, an attacker could identify watches and take complete control of them remotely.

According to the findings, an attacker could access the camera and microphone, eavesdrop on surroundings, read and manipulate text messages, send arbitrary messages, and potentially use the device in denial-of-service attacks. In total, 17 vulnerabilities were discovered.

Blomqvist also found preinstalled malicious code on the watch. The device reportedly connected periodically to a remote server and transmitted detailed information about its contents. The update mechanism for that code was itself vulnerable, making it possible to install additional malicious software.

Children’s smartwatches are marketed primarily as safety devices so that parents can stay in contact with their children. However, the research suggests these products may introduce serious privacy and security risks instead.

Blomqvist says he reported the vulnerabilities to the manufacturer and initially received instructions on where to submit the details, but after that communication stopped. Pontus Johnson, professor of cybersecurity at KTH, commented that many software-based systems remain highly vulnerable and that smaller manufacturers may lack the resources to properly address security issues.

The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for connected products, but full enforcement will not take effect until 2027.

Sources: kth.se, expressen.se

Despite What You've Heard, AI Art Is Still Much Copyrightable

https://knifepoint.substack.com/p/despite-what-youve-heard-ai-art-is
1•kg•46s ago•0 comments

Building AI Agents non-technical teammates can improve without me

https://chainix.ai
1•JackFarrell•1m ago•1 comments

Google Account "Digital Execution" While Auditing a Chrome Store Vulnerability

1•NTT_Prime•1m ago•0 comments

Anthropic's AI tool Claude central to U.S. campaign in Iran, amid a bitter feud

https://www.washingtonpost.com/technology/2026/03/04/anthropic-ai-iran-campaign/
1•spenvo•2m ago•0 comments

Ask HN: Porting MIT CADR to RISC-V

1•lstevens14•2m ago•0 comments

Aigli: Photo and Video Editor – Now Available on the App Store

https://apps.apple.com/us/app/aigli-photo-video-editor/id6756179374
1•_janc_•2m ago•1 comments

How surprise discoveries and lizard venom led to a new class of weightloss drugs

https://biomedical-sciences.uq.edu.au/article/2024/04/rise-ozempic-how-surprise-discoveries-and-l...
1•thunderbong•3m ago•0 comments

AIPriceCompare – Instantly Compare AI API Pricing Across Models

https://aipricecompare.saposs.com/
1•powerwild•4m ago•1 comments

The one science reform we can all agree on, but we're too cowardly to do

https://www.experimental-history.com/p/the-one-science-reform-we-can-all
1•sito42•4m ago•1 comments

Show HN: O4DB – Intent-based M2M protocol without centralized APIs

https://github.com/dannythecountok/O4DB-protocol
1•dannythecount•4m ago•1 comments

"It Turns Out"

https://jsomers.net/blog/it-turns-out
1•Munksgaard•5m ago•0 comments

Show HN: AI Code Review CLI

https://github.com/kodustech/cli
1•eddelgado•6m ago•0 comments

Top HN: Daily summary of the top Hacker News stories

https://hn.alcazarsec.com/daily
1•alcazar•7m ago•1 comments

Senior Back End Engineer (Architecture and AI Systems)Vienna / Remote (Europe)

https://howiesystems.sharepoint.com/:w:/s/Howie/IQB9qE1nUjXER4YGyFc9GAuTAR--PsD5bDq0ZpVo0yo6PUM?e...
1•ewavonhowie•8m ago•1 comments

Show HN: I reverse-engineered car lease math against three real dealer documents

https://quotedefender.com/blog/verified-lease-math-three-deals
1•amirjavid•9m ago•2 comments

The Bizarro Team

https://k2xl.substack.com/p/the-bizarro-team
1•k2xl•10m ago•0 comments

AgenticROS is an open-source platform connecting ROS to OpenClaw for Physical AI

https://agenticros.com
1•cmatthieu•11m ago•1 comments

Show HN: I built a browser-based 3D modeler because I'm scared of Blender

https://app.topomaker.com/
1•whothatcodeguy•12m ago•0 comments

Show HN: CodeYam Memory – comprehensive memory management for Claude Code

1•nadis•14m ago•1 comments

The Death of Issue Tracking

https://twitter.com/danlovesproofs/status/2028890694837039202
1•stevenking86•15m ago•0 comments

The War in the Balkans (1912)

https://www.jstor.org/stable/25119890?seq=1
2•joebig•19m ago•0 comments

LeBron James Is President – Exploiting LLMs via "Alignment" Context Injection

https://github.com/skavanagh/lebron-james-is-president
2•PaulHoule•19m ago•0 comments

Show HN: GitPulse – stop buying dead software (and a timeline for your dev life)

https://www.gitpulse.dev/
1•bombashell•20m ago•1 comments

No Silver Bullet–Essence and accident in software engineering (1986) [pdf]

https://worrydream.com/refs/Brooks_1986_-_No_Silver_Bullet.pdf
1•vinhnx•22m ago•0 comments

Dating Profile Optimizer and AI Dating Coach – AskJoey

https://askjoey.io/
1•Luki1234•22m ago•0 comments

Show HN: Opacore – free Bitcoin tax reports and open-source portfolio OS (MIT)

https://opacore.com
1•jpsdtj•22m ago•1 comments

Show HN: CodePulse – Minimalist Online IDE Built with Vanilla JavaScript/Fastify

https://pklavc.github.io/codepulse-monorepo/
1•PkLavc•22m ago•1 comments

Swedish Government proposes real-time AI facial recognition for police use

https://www.regeringen.se/rattsliga-dokument/proposition/2026/03/prop.-202526150
1•JuliusLam•26m ago•0 comments

Ask HN: Why has ChatGPT disabled links to websites?

2•krschacht•26m ago•0 comments

Show HN: Open-sourced a web client that lets any device use Apple's on-device AI

https://github.com/Techopolis/perspective-intelligence-web-community
2•tayarndt•27m ago•0 comments