Live data from Hacker News

CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

troyhunt.com

11–20 of 175 posts

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#11
post #6

Oh god, it's a kids toy. It's meant to be something fun and cute. What a bunch of jerks to go messing around with that.

How about 'what a bunch of jerks to connect it to the internet and not secure it properly'?

The company was tanking and they were looking to make a quick buck. What market motivation would they have to spend extra time and money securing it properly? This is a fine example of why we need IOT regulation.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#12

For anyone who is coming straight to the comments before reading the article: the details are even worse than the headline suggests. Not only was a huge amount of information exposed through a public, unauthenticated MongoDB instance, and not only did CloudPets ignore multiple security researchers' attempts to alert them to the problem, but the database was actually held for ransom multiple times without customers be…

From what I've seen, a lot of of those MongoDB ransomwares actually just delete the data and leave a ransom note in the hope of getting free bitcoin. So in a sense they've done some good by removing it from the internet.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#13
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

> Hardly identity thief material.

True, but potentially very dangerous material in other ways. It's not hard to image kidnappers piecing together stolen audio clips to create fake messages as part of a ransom attempt. Or scammers creating audio clips to scare parents and extract money. A large bank of audio clips from a child could be used against that child's family in all sorts of ways, especially if the parents don't know the clips were stolen to begin with.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#14
post #11

Earlier quoted context omitted.

How about 'what a bunch of jerks to connect it to the internet and not secure it properly'?

The company was tanking and they were looking to make a quick buck. What market motivation would they have to spend extra time and money securing it properly? This is a fine example of why we need IOT regulation.

Hopefully this event will be 'market motivation' enough for them and any companies who will follow them. If this stuff is insecure it will be found and brought to light. The only question is will the good guys find it or the bad guys.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#15
post #11

Earlier quoted context omitted.

How about 'what a bunch of jerks to connect it to the internet and not secure it properly'?

The company was tanking and they were looking to make a quick buck. What market motivation would they have to spend extra time and money securing it properly? This is a fine example of why we need IOT regulation.

and people wonder why medical and aerospace companies are highly regulated :-)

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#16
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

>> our tolerances are very different when kids are involved > > Interesting. Why? The data is much less valuable

It's the why-do-I-care-about-my-privacy argument - but it's even more personal now, because it's not just you, it's your kids.

There's always that extra creep factor when it comes to children.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#17
post #15
post #11

Earlier quoted context omitted.

The company was tanking and they were looking to make a quick buck. What market motivation would they have to spend extra time and money securing it properly? This is a fine example of why we need IOT regulation.

and people wonder why medical and aerospace companies are highly regulated :-)

Security problems with medical devices have been in the news too.

The regulators have so far been focused on the health aspects of the devices.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#18
Companies have to get more involved in actually encrypting their data before entering it into the database. For every web app I create, especially when sensitive information is exposed, I try to encrypt as much data as possible. With all the leaks and hacks.. it only makes sense to add some encryption method in there.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#19
post #6

Oh god, it's a kids toy. It's meant to be something fun and cute. What a bunch of jerks to go messing around with that.

How about 'what a bunch of jerks to connect it to the internet and not secure it properly'?

That, too. Overwhelmingly that.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#20
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

The "S" in IoT stands for Security.
Post reply on HN