Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, March 3, 2017

Dolls Keep Getting More And More Nosy. And Scary

 Could hackers access voice messages left by kids
on this internet-connected cute toy?
Security experts say yes. 
Since when have toys gotten so nefarious?

In December, I told you about Cayla, the doll that collects information from chatty kids. This information could be used to target advertising, or worse, scam the kid or their family.

Now, we're learning about more dolls and toys that are just as cavalier about privacy.

There's a group of toy animals, made by an outfit called CloudPets, that can store and replay voice messages sent to them via the internet, says the Huffington Post. 

Often families buy these toys for things like sending hearfelt messages to and from dad or mom who might, say, by deployed in the military overseas.

The problem is, the personal information of more than 800,000 customers is now out there. These include some two million voice recordings, many of them made by children, the Huffington Post says. 

What's worse is CloudPets appears to some to have a pretty cavalier attitude toward the data breach.

Information like customers' login and password information and voice recordings, was in a database there for anyone who knew how to find the information.

Security experts like Troy Hunt ried to contact CloudPets about the issue, but never heard back from the company, the Huffington Post reports. 

The head of toy maker, Mark Meyers, denied that the voice recordings were stole, says Network World. 

The security threat isn't huge, espeically if the passwords for CloudPets products aren't the same as users' other devices.

But the data could be used to push messages to children, and there are a lot of creepy people out there.

I really think we should just go back to old fashioned dolls that have no connection to the internet.

According to The Guardian:

"John Madelin, CEO at IT security experts Reliance ACSN, echoes Hunt's warnings. "Connected toys that are easily accessible by hackers are sinister. The CloudPets issue highlights the fact tht manufactuers of connected devices really struggle to bake security in from the start."

Madelin called the accessibility of the CloudPets data "unforgivable."

Time to haul out the internet-free teddy bears we got when we were kids, I guess.

Tuesday, January 19, 2016

People Are Hacking Baby Monitors To Terrify Infants, Families

Is somebody checking out the baby besides
mom, dad and the bsbysitter? Baby monitors
might not be very secure. 
Now this is scary.

It turns out baby monitors are often incredibly easy to hack, and a lot of people know this.

It also turns out there are a number of sickos out there who like to terrorize babies - and their families.

A married couple, identified only as Jay and Sarah, said their three year old kid kept saying he was scared to go to sleep at night because the "phone" kept talking to them, said television station KDVR in Denver. 

Jay and Sarah could NOT figure out what was going on with their boy until Sarah walked by the baby monitor and heard a stranger's voice coming out of it.

The voice said, "Look out little boy, daddy's looking for you," KDVR reported. 

When Sarah walked into the room, the camera's night vision lens turned to examine her and the voice added, "Look, someone's coming into view."

This wasn't an isolated case. A Minnesota family learned their baby monitor had been hacked when they found photos of their baby online, probably taken via the monitor from somebody controlling it remotely.

Foscam, the company that made Jay and Sarah's baby monitor, said it might have been hacked and controlled by someone using a smartphone app or laptop.

Obviously, this whole thing freaked out Jay and Sarah enough to take a lot of safety measures around their house, because who knows what the hackers were really up to.

Last year, when a security firm named Rapid 7 tested nine widely available Internet connected baby monitors and found security on all of them lacking, reportedWired magazine.

Says Wired:

"'Eight of the nine cameras got an F and one got a D minus,' security researcher Mark Stanislav told Fusion's Kashmir Hill. Security flaws included issues such as lack of encryption, the use of default passwords, and access to Internet portals with the device's serial number or account number. Rapid 7 disclosed the vulnerabilities to the companies, who will hopefully all take the information to heart."

Yeah, we hope they did.

It's probably better at this point to go back to the old fashioned way and going in yourself to check on Baby John Or Baby Sue, rather than glancing at the baby monitor.

Because maybe a lot of other people are glancing at it, too.







Sunday, January 19, 2014

Low Paid, Put-Upon Airport Workers A Security List

OK: Now I've got yet another thing to worry about.

I'm guessing the NSA, in its relentless combing of phone and database records, is probably looking for some Middle Eastern terrorists who might be a threat to our country.
Could bad airport working conditions and wages
lead to crime or terrorism? Workers want
higher wages. Photo by Dave Sanders/SEIU  

That threat might be real, but the New York Times and other news agencies might have indirectly uncovered another threat to our security, especially at airports.

Airports have substantially cut the pay of already low paid airport workers, deny them vacation time or days off, all in the name of cost cutting, according to the Times.

Upon reading this Dan Savage in his blog   raised a good point. The Powers That Be, who slash airport workers' wages, who make them work without breaks or time off, who willfully lower there standards of living because, Profits! might be opening the door to a domestic attack.

Some of these workers will get so resentful, goes Savage's reasoning, that they might resort to illegal activities. Drug running, even helping terrorists.

I think Savage is right.

Of course the airport workers, no matter how lousy their pay and working conditions, have a moral responsibility to not help criminals or terrorists.  But resentment sometimes overcomes morals, like it or not.

Airlines might be saving some cash for their bottom lines (not to mention their executive pay) But are they increasing the threats to our security at the same time?

Yeah, we can't all be millionaires, but maybe treat the workers a teensy, tiny bit better, and maybe give them an occasional pay raise, especially if they do a good job?

It could be a better investment than you'd think.

Sunday, August 25, 2013

Feel Safe? Homeland Security Official Wants To Start Homophobic Race War

On Gawker,  we have news of a U.S. Homeland Security official who apparently would just love to start a race war and has a website to promote this idea. 
Does this probably soon to be ex Homeland Security
employee want to start a race war?  


I'm not sure how a race war would enhance the nation's security but maybe the Homeland Security employee, whose name is Ayo Kimathi, has some idea.

According to Gawker, Kimathi wants the mass murder of whites and the ethnic cleansing of "black skinned Uncle Tom race traitors."

The Southern Poverty Law Center says fellow employees are afraid of Kimathi, saying one day he will go postal and kill a bunch of people.

Homeland Security supervisors say if any employee wants to run a web site, they have to get approval for it first. He apparently told his supervisors that the web site would have entertainment content and sell concert tickets, which sounded benign enough and was approved.

Guess they should have checked the content of the site a little more extensively.

In any event, I  think Kimathi's job at Homeland Security is just about done.  I also hope there's no other people in the agency like this guy. We'd have to rename it Homeland Insecurity.