Security Vulnerabilities in Top Christmas Gifts

Security Vulnerabilities in Top Christmas Gifts

Internet connected devices might be the hot item for Christmas this year, but are they secure?

Smart devices are on everyone Christmas list this year. From smart assistants to connected toys, everyone wants an Internet of Things device under the tree. But before you go gifting these top gifts this holiday season, it might be worth it to check whether or not it is one of the good ones.

Mozilla has produced a ranking of 70 top gifts this holiday season based on its security risk level. Each device was graded on a number of measures including the data it collects, is the data encrypted and when is it transmitted. Mozilla also looked at who the data is shared with and what is the worst-case scenario if something did go wrong. 

Here are just a few products that received the lowest scores on the list, a few might surprise you.

FREDI Baby Monitor

The FREDI Baby Monitor was on Mozilla's list as one of the "creepier" devices. The product, made to help parents check in on their little ones has a camera and microphone with connected app. According to Mozilla, the product does not use encryption and does not require the user to change the default password of "123," easily making the camera hackable. The camera also does not have automatic security updates, a way to fill in any holes that are vulnerable.

Mozilla says that the "product does a seemingly poor job protecting privacy and security." Potentially, someone could, and it has been proven before that they can, access the video feed and spy on the user and its family. 

Dobby Pocket Drone

This drone is one of the smallest and cheapest drones on the market this holiday season. The device touts HD video, 360-degree views and a size that will literally fit in your pocket. However, without a minimum security standard and privacy policy, it doesn't matter if this drone can fit in your pocket. 

Mozilla says this product doesn't fit the bill for their security standards and the relaxed security of the device could lead to videos being taken by someone else or your location data stolen by someone you don't know.

Petzi Treat Cam

This camera designed to allow pet owners peek in on their pets when they are not home seems like a good idea. The device allows you to see, talk and fling treats at your pet through a connected app. It's wide-angle lens, high quality audio and app might make you think this is the perfect gift for your friend who is obsessed with their dog, but alas, this device did not meet Mozilla's minimum security standards.

The device does use encryption, but the right kind of hacker can, and will, use the device to spy on you and your dog. With the trendy functionality of the smartphone application, the hacker can also post pictures of your and your dog on social media. Creepy.

Click here to browse through all the products evaluated by Mozilla.


About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now

  • Report: AI is Supercharging Old-School Cybercriminal Tactics

    AI isn’t just transforming how we work. It’s reshaping how cybercriminals attack, with threat actors exploiting AI to mass produce malicious code loaders, steal browser credentials and accelerate cloud attacks, according to a new report from Elastic. Read Now

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.