Security Vulnerabilities in Top Christmas Gifts

Security Vulnerabilities in Top Christmas Gifts

Internet connected devices might be the hot item for Christmas this year, but are they secure?

Smart devices are on everyone Christmas list this year. From smart assistants to connected toys, everyone wants an Internet of Things device under the tree. But before you go gifting these top gifts this holiday season, it might be worth it to check whether or not it is one of the good ones.

Mozilla has produced a ranking of 70 top gifts this holiday season based on its security risk level. Each device was graded on a number of measures including the data it collects, is the data encrypted and when is it transmitted. Mozilla also looked at who the data is shared with and what is the worst-case scenario if something did go wrong. 

Here are just a few products that received the lowest scores on the list, a few might surprise you.

FREDI Baby Monitor

The FREDI Baby Monitor was on Mozilla's list as one of the "creepier" devices. The product, made to help parents check in on their little ones has a camera and microphone with connected app. According to Mozilla, the product does not use encryption and does not require the user to change the default password of "123," easily making the camera hackable. The camera also does not have automatic security updates, a way to fill in any holes that are vulnerable.

Mozilla says that the "product does a seemingly poor job protecting privacy and security." Potentially, someone could, and it has been proven before that they can, access the video feed and spy on the user and its family. 

Dobby Pocket Drone

This drone is one of the smallest and cheapest drones on the market this holiday season. The device touts HD video, 360-degree views and a size that will literally fit in your pocket. However, without a minimum security standard and privacy policy, it doesn't matter if this drone can fit in your pocket. 

Mozilla says this product doesn't fit the bill for their security standards and the relaxed security of the device could lead to videos being taken by someone else or your location data stolen by someone you don't know.

Petzi Treat Cam

This camera designed to allow pet owners peek in on their pets when they are not home seems like a good idea. The device allows you to see, talk and fling treats at your pet through a connected app. It's wide-angle lens, high quality audio and app might make you think this is the perfect gift for your friend who is obsessed with their dog, but alas, this device did not meet Mozilla's minimum security standards.

The device does use encryption, but the right kind of hacker can, and will, use the device to spy on you and your dog. With the trendy functionality of the smartphone application, the hacker can also post pictures of your and your dog on social media. Creepy.

Click here to browse through all the products evaluated by Mozilla.


About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.