Hello hackable Barbie
Toys that talk back are some of the hottest holidays gifts in 2015. And they may soon be hot items for hackers, too. Cybersecurity researchers uncovered a number of major security flaws in systems behind Hello Barbie, an Internet-connected doll that listens to children and uses artificial intelligence to respond. Vulnerabilities in the mobile app and cloud storage used by the doll could have allowed hackers to eavesdrop on even the most intimate of those play sessions, according to a report released Dec 4 by Bluebox Security and independent security researcher Andrew Hay.
Martin Reddy, co-founder and chief technology officer of ToyTalk -- the company behind the voice features in Hello Barbie -- said that the company has been working with Bluebox and has “already fixed many of the issues they raised.” The researchers say that they informed ToyTalk about the issues in mid-November and that the company was very responsive. But the news comes on the heels of a major breach at VTech, a Hong Kong-based seller of toys for toddlers and young children, which exposed profiles on more than 6 million children around the world. And Hello Barbie's security issues are yet another sign that Internet-connected devices are making their way into children's hands with problems that leave privacy at risk.
Hello hackable Barbie