Live data from Hacker News

CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

troyhunt.com

51–60 of 175 posts

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#52
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

How about the kids who don't leave cutesy messages and saw disturbing or threatening things? How about the parent who sits on the thing and says something?

Voice data was once safe in its obscurity... now I have a $2 app on my phone that can do decent voice transcription.

It's just one more thing to worry about.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#53
post #44

Earlier quoted context omitted.

I do agree that lots of IoT products have terrible security, but is having insecure bluetooth or the likes really a terrible thing for most of these types of products? I understand that this leak is related to mongodb... and that is terrible, but mostly referring to your bluetooth example. I mean take bluetooth headphones they are notoriously insecure, but the range in which eavesdropping could take place is pretty s…

> Seems reasonable that they save bandwidth on secure transmission of data for higher audio quality. Encrypting a compressed audio stream does not add to the bandwidth, aside from the initial key negotiation. Furthermore, the bandwidth required for audio of a quality that's indiscernible from the original is negligible when compared to the bandwidth of Bluetooth radios. Ridiculously good audio is 320 kbps, and Blueto…

Yea I was thinking the bandwidth limitations would be on the CPU because of data decryption... your points are valid though even with that. It's not a great example. I still think that varying degrees of security are fine with these types of things.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#54

IoT should die a swift and permanent death. Alas, that wont happen.

I'd love to see the INTERNET of Things be replaced by the INTRANET of Things. Remote access can be handled through a VPN, so there's no need for a remote server. I'm assuming that the device in question has computing hardware that's at least on par with a $9 CHIP. What's really needed is for secure and easy to set up VPNs (to connect back to your home network) to become a thing, then the remote access problems are ta…

So as a rough straw man sketch of how such a thing could work:

1. Consumer grade routers include a secure VPN endpoint. Whenever the router connects, it registers its internet-facing address with some vendor-specific DNS service under a name unique to that router but persistent at least until the router is factory-reset.

2. Devices on the local WiFi network can request a VPN access token. Optionally this requires a separate password set in the router, or pressing a physical button on the router a la WPS. As part of provisioning the token, the vendor-specific DNS name is also provided to the device. The provisioning process requires connecting back to a listening socket on the client device.

3. Devices (eg your mobile phone / tablet) provisioned with a VPN access token can then connect back in to your local network remotely. Each VPN access token is time-limited, configurable on the router but generally something in the range of 7 to 60 days. After the token expires you must connect back locally to the local network to renew it - renewal is blocked over the VPN connection itself.

4. The router interface can be used to list and manually revoke access tokens.

5. The client device can automatically connect to the VPN, eg when requested by an app for one of these IoT devices. On operating systems like Android and IOS, access to the VPN should be restricted to a specific granted permission.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#55
post #20

Earlier quoted context omitted.

The "S" in IoT stands for Security.

Some of us do give a shit about security. It's just a shame that it feels like we are the exception to the rule.

We do because we realize what the lack of it entails. So will the general public, eventually. And the only way to get there is if more cases like this start happening. It's a shame they have to learn the hard way but there's no other way. That, or we as an industry act up (in ways I can't even fathom).

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#56
post #20
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

The "S" in IoT stands for Security.

I took a grad course last semester where one of the groups analyzed a Nest cam and the other analyzed the Mother sensor device. Both were surprisingly quite secure, especially the Mother, which had security features all the way down the stack.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#57

Earlier quoted context omitted.

I'd love to see the INTERNET of Things be replaced by the INTRANET of Things. Remote access can be handled through a VPN, so there's no need for a remote server. I'm assuming that the device in question has computing hardware that's at least on par with a $9 CHIP. What's really needed is for secure and easy to set up VPNs (to connect back to your home network) to become a thing, then the remote access problems are ta…

Agreed. A bear that records voices and gives remote access should not need to store data on a server. Store the data in the bear. That's the way these types of bears have always been. The only thing new here is remote access... Storing my kid's private voice recordings on your server is just plain creepy even if you don't leave it wide open.

Sure! But in this case, part of the functionality was that friends and family could send voice messages to the bear, which are then approved by the parent in app, before being pushed to the bear.

Based on how well the company is doing, it seems like this isn't really functionality that is deserved but it does sound like the justification for storing (some) messages is reasonable.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#59
post #44
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

I do agree that lots of IoT products have terrible security, but is having insecure bluetooth or the likes really a terrible thing for most of these types of products? I understand that this leak is related to mongodb... and that is terrible, but mostly referring to your bluetooth example. I mean take bluetooth headphones they are notoriously insecure, but the range in which eavesdropping could take place is pretty s…

If your threat model for your Bluetooth keyboard doesn't involve, say, an abusive spouse sniffing traffic to see if you're reaching out for help, your threat model is probably biased in favour of wankery like the NSA and not real threats ordinary people face.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#60
post #42
post #13

Earlier quoted context omitted.

> Hardly identity thief material. True, but potentially very dangerous material in other ways. It's not hard to image kidnappers piecing together stolen audio clips to create fake messages as part of a ransom attempt. Or scammers creating audio clips to scare parents and extract money. A large bank of audio clips from a child could be used against that child's family in all sorts of ways, especially if the parents do…

If we assume that you can actually scare the parents into paying a ransom, in the end the impact is... a lot of stress + financial loss. And this assumes that the parents can't get in contact with the kid, the police can't get in contact with the kid and the scammers have enough savvy to accept untraceable money. All of which points to this being more of a movie plot than something that will happen in reality. And ev…

Do you know how many calls you can get in a year of scammers pretending to have kidnapped members of your family in some developing countries? The only real difference from that to this is the added tech-savyness of obtaining real recordings instead of bad acting, which some scammers are actually likely to have by virtue of purchasing this data the way they currently purchase phone numbers, names and CC numbers. The police in those places won't bother going after a phone scammer that only took money (say, in the form of a non-cryptocurrency digital cash transfer that was quickly exchanged for cash), even if the criminal is fairly traceable in theory. When the rule of law is such that only about 2% of murders ever get investigated, this sort of thing just becomes the background noise of un-safety.
Post reply on HN