Skip to content

Leadership1 publisher3 min readPublished

A solo developer built a Bluetooth app to detect nearby smart glasses

Meta disabled thousands of glasses whose recording LEDs had been tampered with, and a Polish developer's detector app picked up 5,000 users in a month, which together tell you how much weight the little light can carry.

The Board Room · Leadership desk

Photograph accompanying A solo developer built a Bluetooth app to detect nearby smart glasses
Photo: businessinsider.com

What happened

  • Pawel Szydlowski, a 30-year-old Polish software developer, launched an app called Zuckoff on Apple's App Store last month, and it has since picked up 5,000 users.
  • Meta bricked thousands of glasses this month after discovering that the built-in LEDs, which are supposed to light automatically while the glasses record, had been tampered with.
  • Szydlowski said European Union regulators have contacted him about the app, and that makers could adopt alerting like the Apple and Google standard for unknown Bluetooth trackers.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • contradiction Bosworth's design claim and the mass disablement cannot both bear weight: the second tells any venue that the indicator is a vendor promise policed after the fact, not a property of the device in the room.
  • capability Detection has moved off the device and into the room, since a bystander with a phone can now get a proximity read that no manufacturer has to authorise or supply.
  • decision Anyone drafting a wearables rule this quarter picks the object it names, conduct or tooling, and a rule built on detection inherits an accuracy question the record does not answer.
  • precedent If the tracker-alert model is what regulators pick up, the fight stops being about whether a light is lit and becomes about who must be notified, by whose standard, and on what radius.

The bricking is the more instructive of the two events, because of where it puts the consent signal. Meta's public position, stated by chief technology officer Andrew Bosworth in an Instagram video, is that the camera was designed to be noticed by the people around you [5]. The enforcement action says that being noticed is maintained by the vendor rather than guaranteed by the hardware: when the LED that should light automatically during recording had been tampered with, the remedy was remote disablement of thousands of units after discovery [4]. A rule that rests on "you will see the light" rests on a part that already failed at scale once and was repaired retroactively.

The app comes at the same problem from the other side of the room. Szydlowski built his fingerprints by physically buying various models and reading the Bluetooth signals they broadcast [6], then matching advertised identifiers, the UUID and the manufacturer ID, against that library [7]; some devices, he says, advertise services actually named "Meta" or "Ray Bans" [9]. Business Insider carries the detection capability as his own account rather than a tested result [2], and the reporting offers neither a false-positive rate nor an independent trial, and does not explain how the paid tier's notifications about nearby recording glasses separate recording from mere presence [10]. On the published record, what a user gets is a presence signal of unstated reliability.

Five thousand users in a month works out to roughly 165 sign-ups a day [11], on one app store, against a population of glasses in circulation that the reporting never quantifies, so the penetration ratio is not available here. The figure that carries weight is the build cost: one person, a few pairs of glasses, and data the devices give away by broadcasting it. Regulators in the European Union have already contacted him for more information [12], and his own suggestion is that makers adopt something like the Apple and Google standard that warns a phone's owner when an unknown Bluetooth tracker appears to be travelling with them [13].

Reading a privacy backlash into the existence of a detector app requires more than the app itself: the record here is consumer-side. It contains a developer's account of pickup artists filming women who could not always tell they were being recorded, subjects left unblurred, and commenters doxxing them [16], but no workplace incident, written policy, or employer's position appears alongside it. Whether unannounced recording of strangers is acceptable is an argument for this decade, and the evidence does not yet show it arriving through the HR file.

The choice worth making early is which object a rule names. A rule written about conduct (recording here requires saying so, and certain rooms are off limits) holds whether or not an indicator works and whether or not anyone in the room is scanning. A rule written about detection inherits an accuracy question the published record cannot settle, and carries the quiet implication that a device nothing flagged is a device nobody minds. Szydlowski's framing is that people have the right to at least know that someone is recording [14]; inside an organisation, the cheap way to satisfy that is to require the announcement and treat the light as evidence rather than permission.

What to watch

  • Whether EU regulators move from requesting information about the app to asking glasses makers for a broadcast and alerting standard.
  • Whether Meta alters what its glasses advertise over Bluetooth, which would break third-party fingerprinting, or Apple reconsiders hosting a detector aimed at another vendor's hardware.
  • Whether Meta publishes how many units it disabled, how the LED tampering was detected, and what happens to owners of modified glasses.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories