CIO Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
Daily Briefing for Technology's Top Decision-Makers
Saturday, April 19th 
Next Generation Data Center Is Here!
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Trending Topics:   Security Heartbleed Big Data Cloud Computing Windows XP Data Centers OS X Mavericks
Home
Enterprise Software
Enterprise Hardware
Big Data
Network Security
Cloud Computing
CRM Systems
Data Storage
Operating Systems
Communications
CIO Issues
Mobile Tech
Chips & Processors
World Wide Web
Business Briefing
After Hours
Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Mobile Tech

Security Firm Cracks Google Glass

Security Firm Cracks Google Glass
July 17, 2013 12:31PM

Bookmark and Share
"We analyzed how to make QR codes based on configuration instructions and produced our own 'malicious' QR codes," said Marc Rogers, principal security researcher at Lookout. When photographed by an unsuspecting Glass user, the code did its mischief successfully, making Glass connect to a "hostile" WiFi access point controlled by Lookout.

Neustar, Inc. (NYSE: NSR) is a trusted, neutral provider of real-time information and analysis to the Internet, telecommunications, information services, financial services, retail, media and advertising sectors. Neustar applies its advanced, secure technologies in location, identification, and evaluation to help its customers promote and protect their businesses. More information is available at www.neustar.biz.

San Francisco security firm Lookout revealed Wednesday that it was able to hack the Google Glass head-mounted system's earlier software and render it vulnerable to malicious code that could, in theory, seize control of data coming from that next big Internet of things.

Google Glass is where you literally just look up information, glancing into the screen and camera in this Web-connected device, to find the information you want. In this instance, Glass was hacked by the image of a malicious QR code.

In a Lookout blog posted on Wednesday, Marc Rogers, principal security researcher, revealed the exploit that his firm performed in May, and said it had immediately alerted Google to the problem.

The source of the hack was the Google Glass QR code. As Rogers put it, Glass looks for data it can recognize when the user takes a photo and the most obvious are QR codes, barcodes that can contain everything from instructions to send an SMS or browse a website to configuration information that change device settings. Google used this capability as an easy way for a user to configure his Glass without having to use a keyboard.

URL Mischief

The scenario that the exploit represents: The Google Glass wearer photographs something with a QR code or link, using the device. However, the code's command is also automatically executed. Without telling or asking the wearer for permission, the device can just open the URL. This is the door the hacker wants, injecting malicious code and links and gaining control of the device.

"We analyzed how to make QR codes based on configuration instructions and produced our own 'malicious' QR codes," he said. When photographed by an unsuspecting Glass user, the code did its mischief successfully, making Glass connect to a "hostile" WiFi access point controlled by Lookout.

The access point enabled the sleuths to spy on the connections Glass made, and it even allowed Lookout to divert Glass to a page on the access point with a known Android vulnerability that hacked Glass as it browsed the page.

Lookout alerted Google when the flaw was discovered in mid-May. Google responded quickly and the issue was fixed with the June 4 release of version XE6. Lookout recommended that Google limit QR code execution to points where the user solicited it.

"Google's changes reflected this recommendation," said Rogers. He credited Google's responsive turnaround as indication of the "depth of Google's commitment to privacy and security for this device."

Security in Post-PC Era

While the Google Glass flaw is fixed, the incident serves as a reminder of where we are in the post-PC era of an Internet of Things, and the new normal in security issues.

Everyday objects are being transformed by added sensors that enable them to interact with the world, processors that enable them to think about it and network interfaces that allow them to talk about it, he stated. New things can be hacked in new ways.

Rogers said, "As we change the nature of things, identifying vulnerabilities and managing updates quickly and efficiently will be paramount. Connected things need to be treated like software when it comes to security."

Tell Us What You Think
Comment:

Name:



 Mobile Tech
1. Cortana Fills Windows Phone Gap
2. Galaxy S5 Phone: Less Can Be More
3. Beware: Facebook Shares Your Locale
4. Android Gets Chrome Remote Desktop
5. Amazon 3D Smartphone Pics Leaked




 Most Popular Articles
1. BlackBerry Drops T-Mobile After Nasty Spat
2. Cisco, IBM Launch Internet of Things Consortium
3. Salesforce CRM Gets Industry Specific for Internet of Customers
4. IBM Applies Big Data Analytics To Fight Against Fraud
5. Intel Bets on Cloudera for Big Data Analytics


Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Galaxy S5 Phone: Less Can Be More
  Heartbleed Exploit Could Cost Millions
  Poll: A Mix of Feelings on Future Tech
  Google, Rockstar Suit Stays in Calif.
  Michaels: Nearly 3M Cards Breached

 Technology Marketplace

Business Intelligence
Get real-time, cloud-based information services with Neustar.
 
Cloud Computing
BMC's I.T. solutions unleash the power of your business
Next Generation Data Center Is Here! Vblock™ Systems from VCE
 
Contact Centers
HP delivers the future of the contact center with HP Qfiniti 10.
 
Data Storage
Next Generation Data Center Is Here! Vblock™ Systems from VCE
Barium Ferrite (BaFe) is the future of tape.
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
 
Enterprise Hardware
Barium Ferrite (BaFe) is the future of tape.
2.5" Enterprise-class SATA & SAS SSDs for server & storage applications
 
Enterprise I.T.
BMC's I.T. solutions unleash the power of your business
 
Hardware
Protect your network with APC Smart-UPS battery backup
 
Network Security
Protect your network with APC Smart-UPS battery backup
 

Network Security Spotlight
Heartbleed Could Cost Millions, Could Have Been Prevented
Early estimates of Heartbleed’s cost to enterprises are running in the millions. The reason: revoking all the SSL certificates the bug exposed will come at a very hefty price. Some say it all could have been avoided.
 
Michaels Says Nearly 3M Credit, Debit Cards Breached
Arts and crafts retail giant Michaels Stores has confirmed that a data breach at its POS terminals from May 2013 to Jan. 2014 may have exposed nearly 3 million customer credit and debit cards.
 
Google's Street View Software Unravels CAPTCHAs
The latest software Google uses for its Street View cars to read street numbers in images for Google Maps works so well that it also solves CAPTCHAs, those puzzles designed to defeat bots.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
The innovative headpiece may find its niche in markets where hands-free access to data can be a big advantage. Glass experiments for doctors are already under way, with some promising results.
 

Mobile Technology Spotlight
Review: Siri-Like Cortana Fills Windows Phone Gap
With the new Cortana virtual assistant, Windows catches up with Apple's iOS and Google's Android in a major way, taking some of the best parts of Apple's and Google's virtual assistants, with new tools too.
 
With Galaxy S5, Samsung Proves Less Can Be More
Samsung has produced the most formidable rival yet to the iPhone 5s: the Galaxy S5. The device is the fifth edition of the company's successful line of Galaxy S smartphones, and shows less can be more.
 
Facebook Rolls Out Potentially Intrusive Location-Sharing
Looking for friends? Facebook users in the U.S. will soon be able to see which of their friends are nearby, using a smartphone's GPS. Could be a cool feature in some cases, or way too much information.
 

Navigation
CIO Today
Home/Top News | Enterprise Software | Enterprise Hardware | Big Data | Network Security | Cloud Computing | CRM Systems
Data Storage | Operating Systems | Communications | CIO Issues | Mobile Tech | Chips & Processors | World Wide Web
Business Briefing | After Hours | Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 CIO Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.