Live data from Hacker News

CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

troyhunt.com

111–120 of 175 posts

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#111
post #94

Earlier quoted context omitted.

Very feasible -- don't plug it into the Internet.

At which point you have a brick with a microphone, and a pretty blue light, right?

"I'm having trouble understanding you right now."

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#112
post #61

IoT should die a swift and permanent death. Alas, that wont happen.

Seriously? That's a fairly aggressive comment to just throw out there without any backing arguments. You really can't think of anything valuable about hooking up small devices/sensors to the internet? Do you really believe the potential for stronger security is so low that it's not worth investigating? I work at an IoT company and we take security far more seriously than some would say is necessary or even reasonable…

But I do hear that self driving car has no idea to look for the traffic light if it was not informed beforehand it is here. That does not bring any confidence.

Also, I still don't know what problem is IoT supposed to solve.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#113
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

> Hardly identity thief material.

Audio messages can be used to train a system which then will be able to mimic the voice of the child, almost indistinguishable from the original. AI of this kind will be commodity (i.e. easily accessible by criminals) pretty soon if not today.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#114
post #20
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

The "S" in IoT stands for Security.

I like Apple's approach, where HomeKit certification requires that the device use some form of secure transport to communicate with iOS.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#116
Who's the goto "freedom/privacy marketing" organization (EFF seems to be legal only)? This is an excellent propaganda for freedom opportunity. It involves a creepy invasion of privacy targeting children. Needs to be used in a massive campaign against (insecure) IoT ASAP.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#117
post #42
post #13

Earlier quoted context omitted.

> Hardly identity thief material. True, but potentially very dangerous material in other ways. It's not hard to image kidnappers piecing together stolen audio clips to create fake messages as part of a ransom attempt. Or scammers creating audio clips to scare parents and extract money. A large bank of audio clips from a child could be used against that child's family in all sorts of ways, especially if the parents do…

If we assume that you can actually scare the parents into paying a ransom, in the end the impact is... a lot of stress + financial loss. And this assumes that the parents can't get in contact with the kid, the police can't get in contact with the kid and the scammers have enough savvy to accept untraceable money. All of which points to this being more of a movie plot than something that will happen in reality. And ev…

One of the typical scams in Russia is a message to the parents "mom, I out of money on my phone, please drom 20$ to this number" or "dad, I scratched someone's car need 2000$ right now".

In Germany it works with grandparents. They get calls from someone impersonating their grand-child in trouble. This works because in many families grandparents live separately and sometimes don't have much contact to their grandchildren (apart knowing that they exist). This threat is so real that there are police posters about this in community centers.

So this works over text messages or phone calls without much sophisticated mimicing. I just imagine a whole new spin of this when AI/DL tech becomes a commodity.

So I quite disagree with the "movie plot" estimation of the threat.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#118
I had a bear like that (not CloudPets, but looks like an exact clone). Thankfully, it was only used by my daughter with my supervision, so I know exactly what has been said. Unless the mic was enabled remotely, that is.

I assumed that the security issues might be bad, but placing the voice on unsecured Mongo facing public Internet is beyond shit.

Thankfully, I have disabled the bear long time ago. But now I worry about my NetAtmo station, which contains an always listening microphone to "measure the noise pollution". Yeah, right.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#119
post #83
post #55

Earlier quoted context omitted.

We do because we realize what the lack of it entails. So will the general public, eventually. And the only way to get there is if more cases like this start happening. It's a shame they have to learn the hard way but there's no other way. That, or we as an industry act up (in ways I can't even fathom).

The fact that you allude to it suggests you can fathom it in some way. Maybe you don't want to but clearly bad actors can exploit insecure systems and that's especially easy from the inside.

Sure I can, but they're all unrealistic so no point mentioning them. We could for example start boycotting companies that don't take security seriously. But I'm afraid we'd end up with a very, very long list.

Publicity can work wonders. You end-up with sensitive data for kids in the wild, possibly in the hands of perverts, nothing could work better than that in raising awareness for the general public. It's harsh, but it fucking works. So we'll stick with it for now, unless someone comes with a better idea.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#120
I'm working on an idea in the security space, that focusing on data breaches and attempting to identify them early. Keen to validate the idea, so if any fellow startups or businesses are interested, I'd love to talk and see what people think. Email is in my profile.
Post reply on HN