Live data from Hacker News

CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

troyhunt.com

131–140 of 175 posts

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#131
post #56
post #20

Earlier quoted context omitted.

The "S" in IoT stands for Security.

I took a grad course last semester where one of the groups analyzed a Nest cam and the other analyzed the Mother sensor device. Both were surprisingly quite secure, especially the Mother, which had security features all the way down the stack.

One of my professors worked on the key exchange protocol [0], used in Nest. When discussing that particular point, he was very complimentary of Google's security practices, especially when it comes to Nest. [0] https://blogs.ncl.ac.uk/security/2015/07/28/j-pake-built-int...

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#132
post #61

IoT should die a swift and permanent death. Alas, that wont happen.

Seriously? That's a fairly aggressive comment to just throw out there without any backing arguments. You really can't think of anything valuable about hooking up small devices/sensors to the internet? Do you really believe the potential for stronger security is so low that it's not worth investigating? I work at an IoT company and we take security far more seriously than some would say is necessary or even reasonable…

It takes only one black sheep to trash the reputation of a whole sector.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#133

Earlier quoted context omitted.

I like Apple's approach, where HomeKit certification requires that the device use some form of secure transport to communicate with iOS.

Which totally would not have helped in this case: using https would still have left the DB exposed.

It doesn't help the server side data leak but at least you can't connect to it and make it say 'destroy all humans'

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#134
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

Wouldn't you say that as a parent it is your obligation to protect the child's privacy? The threat model doesn't even matter, there will be one eventually. All data can be used and combined (now or in the future). Is it that hard to imagine a future where recordings of a child can be used to recreate the voice of the same person as an adult...hardly. I find a "where's the harm" attitude towards privacy/data collection very troubling...doubly so if you are making that decision for someone else who can't protect themselves yet. Ethically it's probably a bigger problem than having such a lax attitude about your own privacy (which if perfectly fine/freedom of choice).

And yes I also rant and rave about parents who post pictures of their children everywhere.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#135

Earlier quoted context omitted.

Some of us do give a shit about security. It's just a shame that it feels like we are the exception to the rule.

And they talk in real life to their kinds and not through a toy.

I can see a novelty use that would quickly die off. If you want to talk to your kids via a teddy bear instead of phone or Skype, then that is up to them. The Demo for the toy shows distant relatives using the toy to talk their kids/grand-kids.

But the purpose of the device has nothing to do with the security of the device.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#136

Earlier quoted context omitted.

Yeah, I'm not worried about my kid saying things that will get him in trouble. However... he repeats literally everything that he hears, sometimes verbatim. Sometimes hours or days layer. To be honest, it's really creepy at times. Plus, he doesn't really have a filter, so he'll talk about everything he sees at school or on the playground, just chattering about all day to himself. So I'm worried about my kid saying th…

A common anecdote from East Germany is that teachers would ask children what the "sandman" looks like (an evening TV show for children). The seemingly harmless answer then revealed whether their parents secretly watched imperialist West-German television. So yeah, children are pretty good at implicating other people. (No real source, but a random German article that quotes this anecdote: http://www.badische-zeitung.d…

This was common in all Eastern Bloc countries. In Poland under Russian occupation UB/SB https://en.wikipedia.org/wiki/Służba_Bezpieczeństwa "secret police responsible for internal and external intelligence and counterintelligence to fight underground movements and the influence of the Catholic Church" would send its agents to schools to befriend children and try to get them to rat on the parents.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#137
post #70

"CloudPets can send and receive messages from anywhere in the world! Buy Now".[1] They delivered on that, all right. If you want one, they're now available for the low, low price of only $3.[2] Including WiFi. [1] https://cloudpets.com/ [2] https://www.hollar.com/products/as-seen-on-tv-cloudpet-dog

$3 is a great price for a stuffed animal, not to mention IoT BT/Wifi platform.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#138

Earlier quoted context omitted.

Some of us do give a shit about security. It's just a shame that it feels like we are the exception to the rule.

Computer/network security will never be important until governments start regulating this stuff through specialized agencies. It's the opposite of profitable to care, so businesses who do care are disadvantaged.

> Computer/network security will never be important until governments start regulating this stuff through specialized agencies.

Well I wouldn't say never, just needs some people determined to have it on the core of the team. Certs are free to low cost depending on the type you want. Compute needed for "Security" is minimal (Heck we can even do RootCA Validation on the the ESP8266 these days).

But this isn't directly connected to the internet and goes via Blue Tooth connection, issues like this are down to lax security practices.

> It's the opposite of profitable to care.

How much profit does it cut to not to put your mongoDB instance internet facing? Firewall off 27017 and Enable Auth shouldn't cut into their profits too much.

EDIT: Slapping a sig creation/check on the content urls shouldn't eat into profits either. This breach had nothing to do with the toy itself but was server side.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#139
post #69

> The Germans had a good point: kids' toys which record their voices and send the recordings up to the web pose some serious privacy risks. It's not that the risks are particularly any different to the ones you and I face every day with the volumes of data we produce and place online (and if you merely have a modern phone, that's precisely what you're doing), it's that our tolerances are very different when kids are…

Yeah, I'm not worried about my kid saying things that will get him in trouble. However... he repeats literally everything that he hears, sometimes verbatim. Sometimes hours or days layer. To be honest, it's really creepy at times. Plus, he doesn't really have a filter, so he'll talk about everything he sees at school or on the playground, just chattering about all day to himself. So I'm worried about my kid saying th…

Exactly. And give a kid any kind of recording devices chances are they'll also end up recording you at times you wouldn't expect to be recorded.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#140

IoT should die a swift and permanent death. Alas, that wont happen.

I'd love to see the INTERNET of Things be replaced by the INTRANET of Things. Remote access can be handled through a VPN, so there's no need for a remote server. I'm assuming that the device in question has computing hardware that's at least on par with a $9 CHIP. What's really needed is for secure and easy to set up VPNs (to connect back to your home network) to become a thing, then the remote access problems are ta…

A VPN could create a false sense of security. After all the device is still untrusted, and will need to connect to the internet even just to do security updates.

We have good security measures for connecting to servers (which is what IoT devices are) so why reinvent the wheel? Why not require devices to have normal TLS certificates and map the internal IP address to a subdomain of the manufacturer. That way browsers can access the device using CORS, and the normal XSS protections will apply. Authenticate and authorise using a well known standard like OpenID, OAuth or JWT.

Post reply on HN