FacebookInstagramTwitterContact

 

Hibiscus Tea Improves Blood Flow, Reduces Risk Of Cardiovascular Disease           >>           Beer Brewed To Music And A Crystal Castle — How To Have An A-List Getaway In Byron Bay           >>           Sleep Is Good For Your Heart, Reduces Risk Of CVD, According To Study           >>           Black Nightshade Reduces Growth Of Cancerous Tumors           >>           You Won't Be Able To Unsee Ryan Gosling's La La Land Confession           >>           Kate Middleton And Prince William’s Designer Friend Says They’re “Going Through Hell”           >>           Eta Aquarid Meteor Shower Peak Could Spawn Over 100 'Shooting Stars' Per Hour This Weekend           >>           Nintendo blitzes GitHub with over 8,000 emulator-related DMCA takedowns           >>           X Is Using Grok To Publish AI-Generated News Summaries           >>           Microsoft’s latest Windows security updates might break your VPN           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Connected Teddy Bears Leaked Kids' Voices Online


CloudPets

 


 February 28th, 2017  |  11:18 AM  |   1140 views

ENGADGETS.COM

 

The supposedly private messages were even held for ransom.

 

When Germany banned a connected doll over security concerns, it wasn't being overly cautious. As it turns out, there's a textbook example of what happens when toy data privacy goes horribly wrong. Security researchers have discovered that Spiral Toys' internet-savvy teddy bears, CloudPets, stored kids' voice messages to their parents (not to mention names and birthdays) in an insecure, misconfigured database that anyone could access online. While the passwords for the toys' accounts (over 821,000 of them) were stored in a cryptographic hash, there was no password strength limit -- it was trivial to crack many accounts and download voice data at will. And it gets worse.

 

Info security expert Niall Merrigan found evidence that the databases were compromised. Intruders copied the databases, deleted the originals and demanded a payment in bitcoin to get the data back. Given that the databases appeared to be completely gone by January 13th, it doesn't appear that Spiral gave into or acknowledged the demands.

 

As for Spiral's response? There is none, and might never be. Microsoft's Troy Hunt and others have tried reaching out to Spiral multiple times to no avail, and the company doesn't appear to have notified customers despite obvious signs that something was amiss. From all indications, the company is on life support or dead: its social media accounts have been silent for months, and its stock price is near worthless.

 

The kicker is that a lot of this would be entirely avoidable. Rapid7 security research director Tod Beardsley tells Engadget that all of the flaws have could been addressed, but that Spiral seems "uniquely uninterested" in taking them on. While Rapid7 tends to get responses from companies "about 70% of the time" and almost always sees them implement a fix or workaround when they get in touch, it's "increasingly rare" for a company to go completely silent.

 

Between this incident and revelations for other products, it's clear that connected toy makers are walking on glass when they decide to put kids' communications online. Even if a company doesn't do anything shady, such as passing the info along to irresponsible third-parties, it can only take a slip-up to expose extremely sensitive messages to the world. And that's assuming skilled hackers don't find it first, or that the company doesn't go belly-up without a firm plan to erase stored data. This doesn't mean that companies should abandon internet-capable toys altogether, but they need both weigh the merits of storing any info online and take very, very through precautions to make sure that leaks like this can't happen.

 


 

Source:
courtesy of ENGADGET

by Jon Fingas

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Myanmar Stops Men From Working Abroad As War Intensifies

 2024-05-04 00:38:42

Have The Wheels Come Off For Tesla?

 2024-05-04 07:51:07