Live data from Hacker News

CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

troyhunt.com

101–110 of 175 posts

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#101
post #98
post #94

Earlier quoted context omitted.

At which point you have a brick with a microphone, and a pretty blue light, right?

Not if it is configured to connect to a server in your home with all the data it needs to function.

Oh of course, but I wonder if by the time you'd created that system, you'd feel the result was worth it? Is what Echo offers really so valuable you'd go through the trouble? I wouldn't.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#102
post #54

Earlier quoted context omitted.

I'd love to see the INTERNET of Things be replaced by the INTRANET of Things. Remote access can be handled through a VPN, so there's no need for a remote server. I'm assuming that the device in question has computing hardware that's at least on par with a $9 CHIP. What's really needed is for secure and easy to set up VPNs (to connect back to your home network) to become a thing, then the remote access problems are ta…

So as a rough straw man sketch of how such a thing could work: 1. Consumer grade routers include a secure VPN endpoint. Whenever the router connects, it registers its internet-facing address with some vendor-specific DNS service under a name unique to that router but persistent at least until the router is factory-reset. 2. Devices on the local WiFi network can request a VPN access token. Optionally this requires a s…

I like this idea.

I honestly think most of the pieces are there. My old router, an ASUS RT-AC56U, has an OpenVPN server built in. It also supports dynamic DNS through an Asus-provided service. iOS (and probably Android) supports VPN-on-demand.

This is basically all of the infrastructure needed to do what you suggest.

The only piece missing is the easy-to-use provisioning/management piece.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#103

Earlier quoted context omitted.

Agreed. A bear that records voices and gives remote access should not need to store data on a server. Store the data in the bear. That's the way these types of bears have always been. The only thing new here is remote access... Storing my kid's private voice recordings on your server is just plain creepy even if you don't leave it wide open.

Sure! But in this case, part of the functionality was that friends and family could send voice messages to the bear, which are then approved by the parent in app, before being pushed to the bear. Based on how well the company is doing, it seems like this isn't really functionality that is deserved but it does sound like the justification for storing (some) messages is reasonable.

The bear could have something as powerful as a $9 CHIP inside that could handle all of the storage/playback/approval/etc needs. The only thing missing is the remote access, which should be solved at a different place in the network.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#104
post #91

Earlier quoted context omitted.

The VPN does introduce a lot of complication, what if we had publicly routable IP addresses from any network in the world and then just used default deny policies on our firewalls to secure networks and encrypted protocols to secure data? Someone should really get to work on developing such a technology stack. /s Sarcasm aside, I completely agree with you and as soon as someone offers iPhone/Siri level functionality…

Apple is in a good position to do this. Unfortunately, they keep paring down their product line and I could reasonably see them dropping the Airport products. Maybe the OpenVPN guys can do it? They've got clients for every platform and seem to be present in some consumer-grade routers. Infrastructure-wise, iOS has on-demand VPN capability and I'm sure Android does too. All the pieces are there, the only thing it need…

There are a lot of details that have to be done right. Backups in the cloud still make a lot of sense but there need to be serious guarantees on the security of the backed up data. Decentralized backups could be a solution to this but come with their own problems like can you trust your cousin and brother in law to run servers as reliably as Amazon?

I would love to see some of the features of iCloud moved into an Airport type device with expandable storage and modular hardware that I can simply swap out when it fails. I realize Siri level capabilities would take more hardware than the typical router contains but I feel like a Mac mini may even have the necessary horsepower to do the amount of cloud computing my iPhone requires in a day.

The hard parts are creating the map data to begin with and training the voice recognition but once those are complete why can't I just run them on local hardware?

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#105
post #94

Earlier quoted context omitted.

At which point you have a brick with a microphone, and a pretty blue light, right?

I have some ideas for a more strict but more user friendly household firewall device and corresponding UI, if something really really needs the Internet. But your lights, TV, etc. don't live in an Amazon datacenter.

You're right of course, but interesting sidenote: in the murder case I mentioned the police ended up looking at the suspect's smart water meter logs... which showed the use of about 140 gallons of water in the middle of the night. So... no, it doesn't all live in an Amazon datacenter, but it these days it might live somewhere.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#107
post #54

Earlier quoted context omitted.

So as a rough straw man sketch of how such a thing could work: 1. Consumer grade routers include a secure VPN endpoint. Whenever the router connects, it registers its internet-facing address with some vendor-specific DNS service under a name unique to that router but persistent at least until the router is factory-reset. 2. Devices on the local WiFi network can request a VPN access token. Optionally this requires a s…

I like this idea. I honestly think most of the pieces are there. My old router, an ASUS RT-AC56U, has an OpenVPN server built in. It also supports dynamic DNS through an Asus-provided service. iOS (and probably Android) supports VPN-on-demand. This is basically all of the infrastructure needed to do what you suggest. The only piece missing is the easy-to-use provisioning/management piece.

It's not totally secure, but why not just a physical button that enables a bluetooth device that transfers a token?

I think you could even have a BT pin, so it would require a little security (eg, neighbors don't have your pin). It should be relatively straightforward to have a BT profile for "token authority".

It certainly would be reasonably easy to use on most devices: just press button and connect to the token device.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#108
post #69

> The Germans had a good point: kids' toys which record their voices and send the recordings up to the web pose some serious privacy risks. It's not that the risks are particularly any different to the ones you and I face every day with the volumes of data we produce and place online (and if you merely have a modern phone, that's precisely what you're doing), it's that our tolerances are very different when kids are…

Yeah, I'm not worried about my kid saying things that will get him in trouble. However... he repeats literally everything that he hears, sometimes verbatim. Sometimes hours or days layer. To be honest, it's really creepy at times. Plus, he doesn't really have a filter, so he'll talk about everything he sees at school or on the playground, just chattering about all day to himself. So I'm worried about my kid saying th…

A common anecdote from East Germany is that teachers would ask children what the "sandman" looks like (an evening TV show for children). The seemingly harmless answer then revealed whether their parents secretly watched imperialist West-German television. So yeah, children are pretty good at implicating other people.

(No real source, but a random German article that quotes this anecdote: http://www.badische-zeitung.de/panorama/der-freundliche-herr...)

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#109
post #61

IoT should die a swift and permanent death. Alas, that wont happen.

Seriously? That's a fairly aggressive comment to just throw out there without any backing arguments. You really can't think of anything valuable about hooking up small devices/sensors to the internet? Do you really believe the potential for stronger security is so low that it's not worth investigating? I work at an IoT company and we take security far more seriously than some would say is necessary or even reasonable…

Just like you don't hear about all the miles an automated car drives safely.

Even if a self-driving car drives perfectly for 10,000,000 miles before swerving in to a crowd of people, no one is going to buy one.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#110
post #13
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

> Hardly identity thief material. True, but potentially very dangerous material in other ways. It's not hard to image kidnappers piecing together stolen audio clips to create fake messages as part of a ransom attempt. Or scammers creating audio clips to scare parents and extract money. A large bank of audio clips from a child could be used against that child's family in all sorts of ways, especially if the parents do…

Moving into the future only makes an audio bank more dangerous with technologies like Adobe VoCo which only require a modest amount of recordings to synthesize in the child's voice (~20m IIRC)
Post reply on HN