Apple’s smartwatch has full access to an iPhone: The Apple Watch shares almost everything with the phone, from communication (Messages app, telephony) and credit cards (Wallet app, though these must be added individually) to health data or iPhone camera control (remote triggering on the watch). Therefore, it is important that only an authorized Apple smartwatch connects to the iPhone. Apple has implemented a series of protocols and measures for this. However, at least the principle behind it is now public: Nils Rollshausen, a researcher specializing in wearable security, has successfully reverse-engineered the Apple Watch at the Seemoo lab of TU Darmstadt.
Fake Apple Watch says Hello
The hardware and software combination developed by Rollshausen, which was presented last year and has since been refined, goes through the security steps intended by Apple for the connection between the fake Apple Watch and the iPhone. However, the user must approve the connection, so an attacker would need access to the iPhone. Rollshausen did not find any specific device attestation or other function that would truly only allow genuine Apple watches to connect. “I was waiting for this wall the whole time, but it never came.” However, a specific attack was necessary, for which a paper is currently being worked on.
The findings from the reverse engineering of the Apple smartwatch are already available. In addition, Rollshausen has developed an app called WatchWitch, with which one can communicate with an Apple Watch from an Android device and request various data. This includes recorded health information, open apps, or alarms. WatchWitch can also be used to send notifications, forward notifications, and create and download screenshots. Apple is currently only preparing such interoperability measures towards third-party devices from the iPhone.
Replicated Watches as a Security Problem
With the successful reverse engineering of the watch protocols, the abundant Apple Watch fakes available in China and elsewhere pose a practical security problem for the iPhone.
The devices often look very similar to the original and could be used by malicious sellers to read sensitive iPhone data – because the user believes it to be a genuine Apple product and pairs it with their iPhone. However, corresponding incidents have not yet become publicly known. The technical possibility is now proven thanks to Rollshausen.
Empfohlener redaktioneller Inhalt
Mit Ihrer Zustimmung wird hier ein externer Preisvergleich (heise Preisvergleich) geladen.
Preisvergleich jetzt laden
(bsc)
Don’t miss any news – follow us on
Facebook,
LinkedIn or
Mastodon.
This article was originally published in
It was translated with technical assistance and editorially reviewed before publication.
Dieser Link ist leider nicht mehr gültig.
Links zu verschenkten Artikeln werden ungültig,
wenn diese älter als 7 Tage sind oder zu oft aufgerufen wurden.
Sie benötigen ein heise+ Paket, um diesen Artikel zu lesen. Jetzt eine Woche unverbindlich testen – ohne Verpflichtung!