Connected Teddy Bears Leaked Kids' Voices Online

The supposedly private messages were even held for ransom.

By Jon Fingas

CloudPets via engadget

This story originally appeared on PCMag

When Germany banned a connected doll over security concerns, it wasn't being overly cautious. As it turns out, there's a textbook example of what happens when toy data privacy goes horribly wrong.

Security researchers have discovered that Spiral Toys' internet-savvy teddy bears, CloudPets, stored kids' voice messages to their parents (not to mention names and birthdays) in an insecure, misconfigured database that anyone could access online. While the passwords for the toys' accounts (more than 821,000 of them) were stored in a cryptographic hash, there was no password strength limit -- it was trivial to crack many accounts and download voice data at will. And it gets worse.

Info security expert Niall Merrigan found evidence that the databases were compromised. Intruders copied the databases, deleted the originals and demanded a payment in bitcoin to get the data back. Given that the databases appeared to be completely gone by Jan. 13, it doesn't appear that Spiral gave into or acknowledged the demands.

As for Spiral's response? There is none, and might never be. Microsoft's Troy Hunt and others have tried reaching out to Spiral multiple times to no avail, and the company doesn't appear to have notified customers despite obvious signs that something was amiss. From all indications, the company is on life support or dead: its social media accounts have been silent for months and its stock price is near worthless.

The kicker is that a lot of this would be entirely avoidable. Rapid7 security research director Tod Beardsley tells Engadget that all of the flaws have could been addressed, but that Spiral seems "uniquely uninterested" in taking them on. While Rapid7 tends to get responses from companies "about 70 percent of the time" and almost always sees them implement a fix or workaround when they get in touch, it's "increasingly rare" for a company to go completely silent.

Between this incident and revelations for other products, it's clear that connected toy makers are walking on glass when they decide to put kids' communications online. Even if a company doesn't do anything shady, such as passing the info along to irresponsible third-parties, it can only take a slip-up to expose extremely sensitive messages to the world. And that's assuming skilled hackers don't find it first, or that the company doesn't go belly-up without a firm plan to erase stored data.

This doesn't mean that companies should abandon internet-capable toys altogether, but they need both weigh the merits of storing any info online and take very, very through precautions to make sure that leaks like this can't happen.

Jon Fingas
Jon Fingas is an associate editor at Engadget.

Related Topics

Editor's Pick

This 61-Year-Old Grandma Who Made $35,000 in the Medical Field Now Earns 7 Figures in Retirement
A 'Quiet Promotion' Will Cost You a Lot — Use This Expert's 4-Step Strategy to Avoid It
3 Red Flags on Your LinkedIn Profile That Scare Clients Away
'Everyone Is Freaking Out.' What's Going On With Silicon Valley Bank? Federal Government Takes Control.
Leadership

How to Detect a Liar in Seconds Using Nonverbal Communication

There are many ways to understand if someone is not honest with you. The following signs do not even require words and are all nonverbal queues.

Celebrity Entrepreneurs

'I Dreaded Falling in Love.' Rupert Murdoch Is Getting Hitched for the Fifth Time.

The 92-year-old media tycoon announces he will wed former San Francisco police chaplain Ann Lesley Smith.

Business News

Carnival Cruise Wants Passengers to Have Fun in the Sun — But Do This, and You'll Get Burned With a New $500 Fee

The cruise line's updated contract follows a spate of unruly guest behavior across the tourism industry.

Starting a Business

Selling Your Business? Do These 6 Things Right Now.

If you want the maximum price you need to make these moves before you do anything else.

Leadership

5 Practical Strategies Founders Can Use to Improve Their Mental Health

Supporting your mental health is one of the most important investments you can make in your company. If you're unsure where to begin, choose one of these strategies and focus on implementing it in your everyday life.

Leadership

How Great Entrepreneurs Find Ways to Win During Economic Downturns

Recessions are an opportunity to recalibrate and make great strides in your business while others are unprepared to brave the challenges. Here's how great entrepreneurs can set themselves up for success despite economic uncertainty.