Can drones steal what’s on your phone?

Sensepost drone
Sensepost drone

(CNNMoney) – We all know know we should protect our data, and most of us would never share our passwords.

But our mobile devices could be shouting out that information… and there are drones ready to listen.

A hacker using technology paired with a drone to grab cell phone information from people below.

This technology has been used on cell phones and laptops.

One day, it could be installed in larger aircraft think helicopters or small planes.

Security Researcher Glenn Wilkinson from Sensepost can also see your usernames, passwords, credit card information, and more.

The tech on the drone is called Snoopy. We took Snoopy out for a spin on the streets of London.

“It’ll fly within a relative close distance to a person with a phone tucked safely in their pocket, and if they’ve left their Wi-Fi on, which most people do in my experience, their phone will very noisily be shouting out the name of every network it’s ever connected to. They’ll be shouting out, Starbucks are you there?” Wilkinson said.

So you can protect yourself by turning off your Wi-Fi. But if you don’t, Snoopy can trick your phone and send back a signal pretending to be the network the phone is looking for.

Then the drone can intercept everything the phone sends and receives.

“Your phone is looking for Starbucks, and I pretend to be Starbucks. Your phone connects to me and then I can see all of your traffic, and see your passwords and things like that,” Wilkinson said.

We tested it out with some dummy accounts we created:

“And we can see here – logging into So Yahoo Mail, and I created an account, Angela Smith, and there’s the user name, and her password is ABC12. There’s Amazon. Here’s Amazon credentials, and also for PayPal. So PayPal email address, user name,” Wilkinson shows.

And Wilkinson hacked his own Facebook account, to demonstrate what that would look like:

“So let’s pick on my own Facebook account. So I can just say, fetch Facebook profile, and from there I can do something like, fetch all Facebook friends,” Wilkinson explains.

Wilkinson is an “ethical hacker” — he built the Snoopy drone to highlight insecurities in smart devices. Some of the things Snoopy can do, like steal usernames and passwords, are illegal.

Other features, like tracking location data, would probably not break any U.S. laws.

“If the technology got in the hands of criminals or bad hackers, which it may have done, there’s all kinds of things they could do: at the most basic level they can track people through space and time – say okay, this person’s at this location at this time,” Wilkinson said.

In a world where drones fly and tech enables them to potentially spy – it’s more important than ever to protect your data.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s