3 More Hackable Toys NOT to Buy Your Kids This Holiday Season

3 More Hackable Toys NOT to Buy Your Kids This Holiday Season

The clock is ticking on gift-buying this holiday season, but that’s no excuse not to do some research before you buy connected toys.

The clock is ticking on gift-buying this holiday season, but that’s no excuse not to do some research before you buy connected toys. The wave of new WiFi and Bluetooth-enabled gadgets for kids means more possibilities that a toy with looser security standards could be hacked, leaving you and your child vulnerable.

We previously covered three hackable toys as investigated by Mashable. Since then, groups like Which?, a U.K.-based consumer products safety testing firm, and the U.S. Public Interest Research Group have issued their own lists of unsafe toys for 2017. Here are three of their worst offenders:

My Friend Cayla

Cayla is a smart, interactive doll that can chat with children. Her Bluetooth capability works with her app and blocks pre-loaded “bad” words and subjects, but some consumers are concerned that she may violate the Children’s Online Privacy Protection Act. Cayla was classified by the German Federal Network as an “illegal espionage apparatus” and was banned in the country after concerns that access to the doll was unsecured and she could be used to “illegally spy” on children. It’s possible to connect to Cayla even without her app installed because smartphones identify her as a hands-free headset.

Furby Connect

The latest update to Furby connects to the Furby Connect World App to provide more physical and digital ways to interact. It also has LCD-screen animated eyes and can say more than 1,000 phrases. Unfortunately, researchers found that anyone within range of its Bluetooth can connect to the toy when it’s switched on without physically interacting with it due to a lack of security features when pairing with the device. You can also connect to the Furby with a laptop, and some researchers were able to upload and play a custom audio file through the toy, which means anyone with the know-how could upload inappropriate material to play for a child.

I-Que Intelligent Robot

i-Que is an interactive robot who can talk, tell jokes and quiz children. It uses Bluetooth to pair with its app, but smartphones can identify it as a hands-free headset without even installing the app. Anyone within Bluetooth range of the toy can pair with it and use a text field in the app to make the toy say whatever they want in the robot’s own voice. Which? demonstrates a worst-case scenario of someone taking advantage of this vulnerability in the video below.

In a consumer notice about internet-connected toys released in July, the FBI suggested parents take the following steps before purchasing a “smart” toy:

  1. Research any known security issues with the toy.
  2. Only connect smart toys to trusted and secured Wi-Fi.
  3. Look into the toy’s internet and device connection security measures.
  4. Use authentication when pairing the device with Bluetooth, such as a pin or password.
  5. Stay up to date with any manufacturer security update or patches.
  6. Investigate where the user data is stored, with the company, a third party source or both.

About the Author

Jessica Davis is the Associate Content Editor for 1105 Media.

Featured

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

  • Access Control Technology

    As we move swiftly toward the end of 2024, the security industry is looking at the trends in play, what might be on the horizon, and how they will impact business opportunities and projections. Read Now

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3