Security and privacy concerns affect Fisher-Price's IoT Smart Toys and hereO's line of children's GPS watches, Rapid7 researchers have discovered.
The Fisher-Price Smart Toy is a relatively new line of plush toys that can interact with children based on dynamic assignment, even learning from their experiences. The toy can be connected to the internet to speed up the learning process, but parents can also monitor the situation using a mobile app via their local WiFi .
Rapid7 researchers discovered that the smart toys were using an insufficiently secure APIwhen communicating with Fisher-Price servers while connected to the Internet.
"The platform's Web Service (API) calls did not properly authenticate the sender of messages, allowing a would-be attacker to send requests that should not be allowed under ideal operating conditions," the researchers explain.
This would allow an attacker to challenge the API and receive responses they shouldn't have. The attackers could have exposed a list of all of the manufacturer's customers, all of the child profiles, and the type of game associated with each account and each child.
Personal information, such as the child's name, date of birth, gender, language, and was also available, along with the current status of the game (whether the child was playing it or not).
Additionally, attackers could delete game profiles and switch games from one account to another, swapping their behavior and confusing children with incorrect answers.
The issues came to Fischer-Price's attention in mid-November and were corrected in mid-January of this year.
The second issue the researchers discovered was in the GPS platform of hereO, a project funded by Indiegogo, which began shipping its products to backers of the project just a month ago.
hereO is a family of GPS-enabled children's watches that come with a range of mobile apps that allow parents and other family members to track their child's location across the city.
hereO mobile apps use the concept of “circles” to manage which family members are allowed and trusted to GPS-locate a child or group.
Rapid7 researchers discovered that the API contained an authentication bypass issue that allowed attackers to request and then grant access to the family circle themselves.
In this way, the attacker should have had access to data such as the child's real-time location, their previous locations, and the location of other family members via the GPS of their smartphones.
The hereO project was patched from these issues on December 15, 2015, after Rapid7 researchers informed their security team about the issue in late October.
[su_youtube url=”https://www.youtube.com/watch?v=hlFH_bdrGMs” width=”580″ height=”380″]

