Nowadays, many parents use special devices (baby monitors) to monitor their babies when they are sleeping or generally when they are not in the same room as them. These devices are very useful. However, they can also become dangerousif misused by malicious hackers.
An investigation by PCMag and Bitdefender found that the iBaby Monitor M6S device has a serious vulnerability that allows hackers to steal stored videos and photos , monitor babies live, in real time , and collect personal information . Worse, however, is that anyone with an M6S baby monitor and the necessary networking skills can hack cloud -stored content from any device of the same type.
Every time your baby moves, the monitor records it and uploads it to the cloud before forwarding it to you. This data is protected with a secret key and an access ID key, but ultimately there is not much security. These keys give access only to your own data, but also to everyone else's.
However, this is not the only vulnerability in the baby monitor device.
“Using what’s called Indirect Object Reference (IDOR) , an attacker can steal personal details about the parent,” PCMag writes. “These details include email addresses , name, location, and even profile picture.”
Bitdefender had notified about the vulnerabilities in iBaby last May. But the manufacturer of the product has not responded. This means that the vulnerability still exists and can be exploited by hackers.
Despite the promise of a secure IoT, researchers are constantly finding vulnerabilities in smart devices. However, the fact that is at risk data of young children and babies In 2016, a survey by the New York Department of Consumer Protection found that four out of five baby monitors were vulnerable to breaches.

