Earlier quoted context omitted.
They basically failed out of existence before this even happened (the article includes details on their share price sliding to nothing earlier last year), which is probably one reason they didn't bother telling customers about it. This is probably the best example I've ever seen of the dangers of trying to keep a service running once the company behind it has gone under.
Why did they fail aside from security issues?
CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
161–170 of 175 posts
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#162Earlier quoted context omitted.
How about 'what a bunch of jerks to connect it to the internet and not secure it properly'?
The company was tanking and they were looking to make a quick buck. What market motivation would they have to spend extra time and money securing it properly? This is a fine example of why we need IOT regulation.
This sort of thing almost (but not quite) always results in things that are no more secure, just more bureaucratic. Large companies keep building the same insecure crap they always have but can afford to hire an army of lobbyists and paper pushers to get "approval". Small innovators who could actually fix the issue are kept out by the high cost of useless paperwork. The industry stagnates at a dismal low point.
In short, prematurely regulating an industry is usually a fantastic way to strand an industry at a local maximum far below its potential.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#163Earlier quoted context omitted.
There are a lot of details that have to be done right. Backups in the cloud still make a lot of sense but there need to be serious guarantees on the security of the backed up data. Decentralized backups could be a solution to this but come with their own problems like can you trust your cousin and brother in law to run servers as reliably as Amazon? I would love to see some of the features of iCloud moved into an Air…
I wouldn't advocate getting rid of "the cloud" in general, but I'd advocate rationalizing it. For your examples: - Backups - Agreed, these make sense and need the appropriate security guarantees. - Siri - I can't think of anything it does that requires the voice recognition stuff to operate in the cloud. If this could all be done on-device, but with the ability to reach out to the cloud as required that would be cool…
I would rather none of my map usage or geolocation data ever went to the cloud. Yes, Google does aggregate a lot of valuable information but that could be consumed by personal devices directly instead of giving Google the ability to combine our travel habits with our eating habits and our browsing habits.
Bus arrival data isn't big or complex, Google just aggregates it which is why you go to maps but they don't actually put a GPS/Cellular device on every bus (excluding android phones >_>). They aggregate location data from the bus operator sources. I don't need to know where every bus in the United States is at every moment like Google does. I just need to know when my bus is reaching a stop near me. My home server could easily hit the same services Google does to get arrival data per stop or even just stay up to date on all the routes in my area or city.
Bus arrival data is public so there's no reason for me to store it locally but my usage of that data is personal and is something I want to own and control end to end.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#164Earlier quoted context omitted.
Not if it is configured to connect to a server in your home with all the data it needs to function.
Oh of course, but I wonder if by the time you'd created that system, you'd feel the result was worth it? Is what Echo offers really so valuable you'd go through the trouble? I wouldn't.
In a world where it is just expected that you have a personal cloud server in your home Alexa becomes an "app" on that server and the Echo continues life as a very nice speaker/microphone device you can place in a visible area in order to interact with that server.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#165Earlier quoted context omitted.
And they talk in real life to their kinds and not through a toy.
I can see a novelty use that would quickly die off. If you want to talk to your kids via a teddy bear instead of phone or Skype, then that is up to them. The Demo for the toy shows distant relatives using the toy to talk their kids/grand-kids. But the purpose of the device has nothing to do with the security of the device.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#166Earlier quoted context omitted.
I like this idea. I honestly think most of the pieces are there. My old router, an ASUS RT-AC56U, has an OpenVPN server built in. It also supports dynamic DNS through an Asus-provided service. iOS (and probably Android) supports VPN-on-demand. This is basically all of the infrastructure needed to do what you suggest. The only piece missing is the easy-to-use provisioning/management piece.
It's not totally secure, but why not just a physical button that enables a bluetooth device that transfers a token? I think you could even have a BT pin, so it would require a little security (eg, neighbors don't have your pin). It should be relatively straightforward to have a BT profile for "token authority". It certainly would be reasonably easy to use on most devices: just press button and connect to the token de…
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#167And now audio of children has been hacked, exposing kids voices. The future is here, and it's weird.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#168Massive negligence.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#169Put some CEOs in handcuffs, lock them in a cage like an animal, and see how quickly companies actually start doing crazy things like mentioning the word 'security' in job listings for software engineers or system administrators or even doing the unthinkable, hiring experienced expensive engineers.
Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages
#170Earlier quoted context omitted.
The fact that you allude to it suggests you can fathom it in some way. Maybe you don't want to but clearly bad actors can exploit insecure systems and that's especially easy from the inside.
Sure I can, but they're all unrealistic so no point mentioning them. We could for example start boycotting companies that don't take security seriously. But I'm afraid we'd end up with a very, very long list. Publicity can work wonders. You end-up with sensitive data for kids in the wild, possibly in the hands of perverts, nothing could work better than that in raising awareness for the general public. It's harsh, bu…