Connected Teddy Bears Leaked Kids' Voices OnlineThe supposedly private messages were even held for ransom.

ByJon Fingas

This story originally appeared onPCMag

CloudPets via engadget

When Germanybanned a connected dollover security concerns, it wasn't being overly cautious. As it turns out, there's a textbook example of what happens when toy data privacy goes horribly wrong.

Security researchers havediscoveredthat Spiral Toys' internet-savvy teddy bears, CloudPets, stored kids' voice messages to their parents (not to mention names and birthdays) in an insecure, misconfigured database that anyone could access online. While the passwords for the toys' accounts (more than 821,000 of them) were stored in a cryptographic hash, there was no password strength limit -- it was trivial to crack many accounts and download voice data at will. And it gets worse.

Info security expert Niall Merriganfound evidencethat the databases were compromised. Intruders copied the databases, deleted the originals and demanded a payment in bitcoin to get the data back. Given that the databases appeared to be completely gone by Jan. 13, it doesn't appear that Spiral gave into or acknowledged the demands.

As for Spiral's response? There is none, and might never be. Microsoft's Troy Hunt and others have tried reaching out to Spiral multiple times to no avail, and the company doesn't appear to have notified customers despite obvious signs that something was amiss. From all indications, the company is on life support or dead: its social media accounts have been silent for months and its stock price is near worthless.

The kicker is that a lot of this would be entirely avoidable. Rapid7 security research director Tod Beardsley tellsEngadgetthat all of the flaws have could been addressed, but that Spiral seems "uniquely uninterested" in taking them on. While Rapid7 tends to get responses from companies "about 70 percent of the time" and almost always sees them implement a fix or workaround when they get in touch, it's "increasingly rare" for a company to go completely silent.

Between this incident andrevelations for other products, it's clear that connected toy makers are walking on glass when they decide to put kids' communications online. Even if a company doesn't do anything shady, such as passing the info along to irresponsible third-parties, it can only take a slip-up to expose extremely sensitive messages to the world. And that's assuming skilled hackers don't find it first, or that the company doesn't go belly-up without a firm plan to erase stored data.

This doesn't mean that companies should abandon internet-capable toys altogether, but they need both weigh the merits of storing any info online and take very, very through precautions to make sure that leaks like this can't happen.

Wavy Line
Jon Fingas is an associate editor at Engadget.

Editor's Pick

Related Topics

Growing a Business

We're Now Finding Out The Damaging Results of The Mandated Return to Office — And It's Worse Than We Thought.

Companies knew the mandated return to the office would cause some attrition, however, they were not prepared for the serious problems that would present.

Business Solutions

Learn to Program an AI Chatbot for Your Business in This $30 Course

Get back-to-school savings on this AI coding course.

Money & Finance

Want to Become a Millionaire? Follow Warren Buffett's 4 Rules.

企业家是不能过度指狗万官方望太多a company exit for their eventual 'win.' Do this instead.

Business News

Netflix is Hiring an AI-Focused Role—and the Starting Salary is up to $900,000

The streaming giant is looking for a leader in its machine learning department.

Thought Leaders

Mark Cuban Says These are the Dumbest Things Entrepreneurs Do

Whatever you do, don't do the first thing on this list. Or the second. Definitely not the third.

Leadership

This Common Leadership Habit Will Harm Your Credibility. Are You Guilty of It?

As leaders, we're always looking for ways to build credibility among peers and employees. But this easy-to-make mistake can ruin it in an instant.