Should we call this PetsBleed?
CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
121–130 of 175 posts
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#122Earlier quoted context omitted.
First, it's not just about "get [them] in trouble". Think about ten years later. Do we want adversaries to have logs of children's conversations? Also, It's not just recordings. Once an adversary has account access, they can talk to children. I can't imagine that being a good thing.
Additionally, what benefit do we have to gain by preserving these recordings? The whole thing seems massively risky for no reason other than to make a few bucks.
That's, unfortunately, the very reason why most of IoT stuff exists.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#123Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…
Someone steals the recording saying "Hello mommy and daddy, I love you so much."
They then manage to contact you, reporting that they have kidnapped your children. They play you the recording to prove they are in your custody and demand an immediate ransom payout.
Highly prone to error, not very likely to work, incredibly evil and likely to end up with the perpetrator in jail, but, unfortunately, the sort of thing that a desperate criminal might try, and even more unfortunately, it only needs to succeed once for someone to consider it a viable tactic.
I know this is stupidly unlikely occurrence, but extrapolate it with a bit more sophistication and you can start to see why this is actually quite nasty identity theft material.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#124Earlier quoted context omitted.
BearBleed.
I was gonna say "CloudBear", after Cloudflare, but it's basically already called that. Maybe just avoid anything with "cloud" in the name?
I do exactly that. I treat the word "cloud" in a product name (or feature list) as a huge negative indicator and steer clear.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#125Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#126Earlier quoted context omitted.
The corporation might be, but this seems like the level of gross criminal negligence that a person should be held liable for.
I'm not necessarily disagreeing but that seems fundamentally opposed to the way a LLC works.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#127Companies have to get more involved in actually encrypting their data before entering it into the database. For every web app I create, especially when sensitive information is exposed, I try to encrypt as much data as possible. With all the leaks and hacks.. it only makes sense to add some encryption method in there.
There is a German word for that. Datensparsamkeit.
https://martinfowler.com/bliki/Datensparsamkeit.html
Actually, and probably for the first time ever, I completely agree with Fowler:
"Datensparsamkeit isn't just about bad people stealing data, it's also about your relationship with the primary company themselves. The default attitude at the moment is that any data you generate is not just freely usable by the capturer but furthermore becomes their valuable commercial property. Privacy advocates, including me, think this assumption needs to be changed. Companies should only capture what they need and the burden of demonstrating need should fall on them. In addition, of course, they must be completely transparent about what they capture, what they store, and who they share their data with."
This, I believe, needs to be enforced by regulations, worldwide. Businesses won't do it themselves, because it's a clear case of conflicting social and monetary interests.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#128Earlier quoted context omitted.
and people wonder why medical and aerospace companies are highly regulated :-)
Security problems with medical devices have been in the news too. The regulators have so far been focused on the health aspects of the devices.
The point here was, there are always companies that are looking to make a quick buck and which will always refuse to "spend extra time and money securing it properly". Such companies have the market forces on their side - the less they give a shit, the faster and cheaper they can sell their products/services. Regulations in established industries ensure that the minimum level of giving a shit is still safe enough for people.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#129Earlier quoted context omitted.
The "S" in IoT stands for Security.
I like Apple's approach, where HomeKit certification requires that the device use some form of secure transport to communicate with iOS.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#130Who's the goto "freedom/privacy marketing" organization (EFF seems to be legal only)? This is an excellent propaganda for freedom opportunity. It involves a creepy invasion of privacy targeting children. Needs to be used in a massive campaign against (insecure) IoT ASAP.