Friday, December 9, 2016

Dangerous toys NOT to get for Christmas

TL;DR: I strongly recommend that you do NOT buy the My Friend Cayla doll, the i-Que robot, or the Barbie Hello Dream House as gifts due to a grotesquely dangerous security flaw in the toy's design.

I often rant about poor security in products and how "security wasn't an afterthought, it wasn't thought of at all."  Mostly it's about something that is unlikely to effect most of all y'all.  This time is different - here are some toys that can endanger children, and I STRONGLY recommend that you do NOT buy these as gifts this holiday season.

My Friend Cayla is a doll with embedded voice recognition technology similar to Apple's Siri, that can interact with children.  It not only listens to what the child says but can respond appropriately.

While it's somewhat concerning that the doll "phones home" over the Internet for the voice recognition to work, the issue isn't that it's listening in on your kid.  Mind you, I find this more than a little creepy, but I remember when there were only 3 TV channels.

The danger is that the doll is Bluetooth enabled, and the Bluetooth is completely unprotected.  What this means is that anyone within Bluetooth range (which at 100 yards is actually further than many think) can connect to the doll and start talking to your child as she plays.

Let me say that again - Joe Shmoe in the park across from your house can connect to your little Princess' doll and have a chat.  There's a video of this, although they're wrong to call it a "hack".  It's simply use of the functionality as it was designed.

Also using the exact same technology with exactly the same flaw is the i-Que robot: this isn't just a threat to little girls.

Unconfirmed reports also include the Barbie Hello Dream House.  I don't know whether this is vulnerable to remote Bluetooth access, and it's almost certain that nothing definitive will be published on this before the holidays.  Given that I recommend that you don't buy this, either.


This seems to me to be bordering on criminal negligence by the companies involved (certainly My Friend Cayla and i-Que; possibly Mattel).  The idea that a child's toy could be released that would allow someone to remotely talk with your child his his or her own bedroom is mind bogglingly stupid.

To reiterate, I strongly recommend that you do NOT buy the My Friend Cayla doll, the i-Que robot, or the Barbie Hello Dream House as gifts due to a grotesquely dangerous security flaw in the toy's design.

5 comments:

George said...

Reminds me of:
http://www.hulu.com/watch/115713

Old NFO said...

Good info, thanks!!!

Lawrence Person said...

If I had the tools, it would be tempting do do a little wardriving until finding a My Friend Cayla, and have her intone: "Great Cthulhu is watching you, awaiting the great harvest! Watching you...ALWAYS!!!"

libertyman said...

Okay, it looks like you will not be getting any of these!!!

Brigid said...

Imagine - when I was that age we were able to entertain ourselves with a Daisy firearm, a tree, and mud.