frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MyFirst Kids Watch Hacked. Access to Camera and Microphone

https://www.kth.se/en/om/nyheter/centrala-nyheter/kth-studenten-hackade-klocka-for-barn-1.1461249
37•jidoka•4h ago

Comments

jidoka•4h ago
Title: KTH student hacked a popular children’s smartwatch, found 17 vulnerabilities and full remote access

A former student at KTH Royal Institute of Technology has demonstrated how a popular children’s smartwatch can be fully compromised over the internet. In his thesis, “Ethical Hacking of a Smartwatch for Kids: A Hacker’s Playground,” Gustaf Blomqvist conducted an ethical security assessment of a widely sold kids’ smartwatch and found what he describes as severe security flaws.

The device, identified in Swedish media as the MyFirst Fone R1s by MyFirst, exposed an insecure network service directly to the internet. By scanning for devices, an attacker could identify watches and take complete control of them remotely.

According to the findings, an attacker could access the camera and microphone, eavesdrop on surroundings, read and manipulate text messages, send arbitrary messages, and potentially use the device in denial-of-service attacks. In total, 17 vulnerabilities were discovered.

Blomqvist also found preinstalled malicious code on the watch. The device reportedly connected periodically to a remote server and transmitted detailed information about its contents. The update mechanism for that code was itself vulnerable, making it possible to install additional malicious software.

Children’s smartwatches are marketed primarily as safety devices so that parents can stay in contact with their children. However, the research suggests these products may introduce serious privacy and security risks instead.

Blomqvist says he reported the vulnerabilities to the manufacturer and initially received instructions on where to submit the details, but after that communication stopped. Pontus Johnson, professor of cybersecurity at KTH, commented that many software-based systems remain highly vulnerable and that smaller manufacturers may lack the resources to properly address security issues.

The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for connected products, but full enforcement will not take effect until 2027.

Sources: kth.se, expressen.se

coredev_•1h ago
I'm very excited for EUs CRA, very promising for the future of digital security in the EU.
john_strinlai•18m ago
presumably, "CRA" in this comment stands for "Cyber Resilience Act" (https://digital-strategy.ec.europa.eu/en/policies/cyber-resi...)
defraudbah•1h ago
which smartwatch was that?

the source linked in the article is dead, and I only see that AI slop comment here

-- MyFirst Fone R1, singapore

funny that it's called my first, find my first upon your device, haha

pavel_lishin•54m ago
https://kth.diva-portal.org/smash/record.jsf?pid=diva2%3A203...

> In this thesis, welldocumented grey-box ethical hacking is conducted of the network service and firmware attack surfaces of the children’s smartwatch myFirst Fone R1s.

Lyrkan•42m ago
Reminded me of this recent talk from 39C3 regarding another company (Xplora) that also sells smartwatches for children: https://www.youtube.com/watch?v=VRQz9EX2Tl0
TazeTSchnitzel•15m ago
I guess some folks at KTH have been looking at this topic for a while now, there was a story about it on SVT (Swedish equivalent of the BBC) two years back: https://www.svt.se/nyheter/inrikes/sa-latt-hackas-ditt-barns...

Same professor, Pontus Johnson, is mentioned that story.

MacBook Neo

https://www.apple.com/newsroom/2026/03/say-hello-to-macbook-neo/
662•dm•3h ago•979 comments

Something is afoot in the land of Qwen

https://simonwillison.net/2026/Mar/4/qwen/
157•simonw•1h ago•60 comments

Nobody Gets Promoted for Simplicity

https://terriblesoftware.org/2026/03/03/nobody-gets-promoted-for-simplicity/
564•aamederen•6h ago•329 comments

You Bought Zuck's Ray-Bans. Now Someone in Nairobi Is Watching You Poop

https://blog.adafruit.com/2026/03/04/you-bought-zucks-ray-bans-now-someone-in-nairobi-is-watching...
27•ptorrone•20m ago•4 comments

“It turns out” (2010)

https://jsomers.net/blog/it-turns-out
145•Munksgaard•2h ago•57 comments

Welcome to the Wasteland: A Thousand Gas Towns

https://steve-yegge.medium.com/welcome-to-the-wasteland-a-thousand-gas-towns-a5eb9bc8dc1f
27•nop_slide•1h ago•29 comments

Glaze by Raycast

https://www.glazeapp.com/
133•romac•4h ago•76 comments

Motorola GrapheneOS devices will be bootloader unlockable/relockable

https://grapheneos.social/@GrapheneOS/116160393783585567
1097•pabs3•16h ago•440 comments

Qwen3.5 Fine-Tuning Guide – Unsloth Documentation

https://unsloth.ai/docs/models/qwen3.5/fine-tune
133•bilsbie•5h ago•38 comments

Libre Solar – Open Hardware for Renewable Energy

https://libre.solar
100•evolve2k•3d ago•26 comments

Government grant-funded research should not be published in for-profit journals

https://www.experimental-history.com/p/the-one-science-reform-we-can-all
189•sito42•2h ago•100 comments

Agentic Engineering Patterns

https://simonwillison.net/guides/agentic-engineering-patterns/
370•r4um•12h ago•208 comments

RFC 9849. TLS Encrypted Client Hello

https://www.rfc-editor.org/rfc/rfc9849.html
214•P_qRs•10h ago•103 comments

MyFirst Kids Watch Hacked. Access to Camera and Microphone

https://www.kth.se/en/om/nyheter/centrala-nyheter/kth-studenten-hackade-klocka-for-barn-1.1461249
38•jidoka•4h ago•7 comments

Emails to Outlook.com rejected due to a fault or overzealous blocking rules

https://www.theregister.com/2026/03/04/users_fume_at_outlookcom_email/
70•Bender•6h ago•43 comments

Medical journal says the case reports it has published for 25 years are fiction

https://retractionwatch.com/2026/03/03/canadian-pediatric-society-journal-correction-case-reports...
96•Tomte•2h ago•36 comments

Jiga (YC W21) Is Hiring

https://jiga.io/about-us
1•grmmph•5h ago

TikTok will not introduce end-to-end encryption, saying it makes users less safe

https://www.bbc.com/news/articles/cly2m5e5ke4o
318•1659447091•16h ago•317 comments

RE#: how we built the fastest regex engine in F#

https://iev.ee/blog/resharp-how-we-built-the-fastest-regex-in-fsharp/
148•exceptione•3d ago•53 comments

Greg Knauss Is Losing Himself

https://shapeof.com/archives/2026/2/greg_knauss_is_losing_himself.html
49•wallflower•2d ago•33 comments

A Visual Guide to DNA Sequencing

https://www.asimov.press/p/dna-sequencing
25•surprisetalk•4h ago•3 comments

A CPU that runs entirely on GPU

https://github.com/robertcprice/nCPU
195•cypres•13h ago•98 comments

Sea level much higher than assumed in most coastal hazard assessments

https://www.nature.com/articles/s41586-026-10196-1
29•jacquesm•1h ago•2 comments

Elevator Saga: The elevator programming game (2015)

https://play.elevatorsaga.com/index.html
70•xmprt•3d ago•13 comments

Show HN: Stacked Game of Life

https://stacked-game-of-life.koenvangilst.nl/
132•vnglst•4d ago•24 comments

SRGB↔XYZ Conversion (2021)

https://mina86.com/2019/srgb-xyz-conversion/
5•kqr•2d ago•3 comments

Better JIT for Postgres

https://github.com/vladich/pg_jitter
123•vladich•11h ago•55 comments

Modern Illustration: Archive of illustration from c.1950-1975

https://www.modernillustration.org
46•eustoria•4d ago•4 comments

Claude's Cycles [pdf]

https://www-cs-faculty.stanford.edu/~knuth/papers/claude-cycles.pdf
736•fs123•1d ago•309 comments

Charging a three-cell nickel-based battery pack with a Li-Ion charger [pdf]

https://www.ti.com/lit/an/slyt468/slyt468.pdf
21•theblazehen•1d ago•3 comments