Live data from Hacker News

CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

troyhunt.com

21–30 of 175 posts

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#21
post #13
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

> Hardly identity thief material. True, but potentially very dangerous material in other ways. It's not hard to image kidnappers piecing together stolen audio clips to create fake messages as part of a ransom attempt. Or scammers creating audio clips to scare parents and extract money. A large bank of audio clips from a child could be used against that child's family in all sorts of ways, especially if the parents do…

Or worse, they could train a neural network to mimic the child's voice and create a fake message to send to the police alleging child abuse, with a ransom note at the end - in the child's voice.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#22
post #20
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

The "S" in IoT stands for Security.

Hahaha i spent a good 3 minutes looking for where the S was, until the joke hit me

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#23
post #20
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

The "S" in IoT stands for Security.

shouldn't that be 'SH' ?

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#24

IoT should die a swift and permanent death. Alas, that wont happen.

I'd love to see the INTERNET of Things be replaced by the INTRANET of Things.

Remote access can be handled through a VPN, so there's no need for a remote server. I'm assuming that the device in question has computing hardware that's at least on par with a $9 CHIP.

What's really needed is for secure and easy to set up VPNs (to connect back to your home network) to become a thing, then the remote access problems are taken care of. After this, each IoT device's app just needs to look for the device and possibly give the user a gentle VPN reminder if it can't find it.

Of course, a VPN introduces a lot of extra work for the user. Even the steps to connect/disconnect from the VPN add enough friction that some people won't bother.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#25
post #6

Oh god, it's a kids toy. It's meant to be something fun and cute. What a bunch of jerks to go messing around with that.

I'd be surprised if the script kiddies attacking world-writable MongoDB instances know or care who owns them. Destroying the data and then lying is a lot less effort than actually copying and examining it.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#27
post #26

> As you can see by loading the image, all that's required to access the file is the path which is returned by the app every time my profile is loaded. How else would you do it?

Put it behind the webapp's authentication and access control layer - so only logged in users with relevant connection/permission to the requested image can get it.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#28
post #13
post #5

Okay, first of all: >the average parent.. is technically literate enough to know the wifi password but not savvy enough to understand how the "magic" of daddy talking to the kids through the bear (and vice versa) actually works [or] that every one of those recordings... is stored as an audio file on the web. If it is not considered amazingly stupid, or at least ignorant to not understand that the magic talking bear h…

> Hardly identity thief material. True, but potentially very dangerous material in other ways. It's not hard to image kidnappers piecing together stolen audio clips to create fake messages as part of a ransom attempt. Or scammers creating audio clips to scare parents and extract money. A large bank of audio clips from a child could be used against that child's family in all sorts of ways, especially if the parents do…

Of course, when somebody releases a proof of concept, it'll be called RansomBear.

Re: CloudPets teddy bears leaked and ransomed, exposing kids' voice messages

#30
post #20
post #4

A guy I work with did a presentation on this product, he is big into reverse engineering bluetooth devices. I can assure you the toys themselves are just as insecure as apparently their infrastructure is. Seeing it light up and say "destroy all humans" was pretty funny, moreso because there is pretty much zero authentication on them so you could do it from anywhere from your mobile, and the mic can turn on and record…

The "S" in IoT stands for Security.

Some of us do give a shit about security. It's just a shame that it feels like we are the exception to the rule.
Post reply on HN