Homeinet2015: Hacking targeting children and toys

2015: Hacking targeting children and toys

Hacking children's toys: In early December 2015, we learned that a hacker managed to breach the servers of the Chinese toy manufacturer VTech and obtained personal data from almost five million parents and more than 200,000 children.hacking

The data from the hack included home addresses, names, dates of birth, email addresses, and passwords. The data also included photos and chat logs of parents with their children.

The exploit raised the obvious question: which of the games connect to the Internet, and how many of them have lax security?

How many millions or hundreds of millions of children are at risk for this?

We got a partial answer in November, when Bluebox Security discovered serious vulnerabilities in Mattel's Hello Barbie, an Internet-enabled doll.

Hello Barbie: keep Mattel's new doll away from children

It is very likely that the majority of games connected to the Internet games have serious weaknesses and there are many reasons for this:

It's new to the market and hackers have a head start in a virgin space. The Internet of Things – devices that connect to each other and to the Internet, isn't just for games. The Internet of Things includes every device you can imagine: cars, refrigerators, televisions, kettles, a whole bunch of digital and semi-analog devices.

The Internet of Things is not secure, mainly because companies don't feel obligated to invest the time, money, and effort required to secure their devices. International security standards or guidelines range from lax to nonexistent.

To make matters worse, companies are not required to tell consumers what kind of information they collect and how they will protect it.

Fiat's recall of Chrysler cars in July 2015, when 1.4 million Chrysler, Dodge, Jeep and Ram were recalled, demonstrated the extent of the problem.

The company had known about the vulnerabilities in its Uconnect systems for some time, but did not report them (and of course did not fix them) until Wired magazine demonstrated in a publication that all vehicles using them were vulnerable and that the driver could even lose control of the steering wheel.

Protecting children from hacking attacks is extremely important. They are vulnerable and innocent. This makes them emotionally charged targets for extortion attacks.

Imagine if a really bad hacker had access to VTech's systems and was stealing data taken from the cameras to extort money from parents by threatening to harm their children.

Last year, Fox 19 reported  that a hacker hacked into the baby monitoring system at a home in Cincinnati, Ohio, and began screaming “Baby Wake Up!” at a 10-month-old girl.

Shock! Sick hacker hacked baby monitor camera

It's possible that the cost of product recalls is driving incentives for greater security. But victims are rarely compensated for the loss of their identity data. VTech makes $2 billion a year and says that connected products for children are one of the fastest-growing industries.

What will happen next?

The solutions are not easy and require not only incentives, but also regulations, coordination and control mechanisms. The Internet of the Internet looks set to launch on millions of devices in 2016, without basic security settings. Security standards should have already been set before the devices reach our homes, for a safer online world that is also used by our children.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS