{"id":62102,"date":"2024-03-14T11:25:05","date_gmt":"2024-03-14T03:25:05","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=62102"},"modified":"2024-03-14T11:25:08","modified_gmt":"2024-03-14T03:25:08","slug":"smart-toy-vulnerabilities-could-let-cybercriminals-video-chat-with-kids","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2024\/03\/14\/smart-toy-vulnerabilities-could-let-cybercriminals-video-chat-with-kids\/","title":{"rendered":"Smart toy vulnerabilities could let cybercriminals video-chat with kids"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Vulnerabilities in a popular smart toy robot could make children potential targets for cybercriminals, Kaspersky researchers have\u00a0discovered.\u00a0The weaknesses could enable hackers to take control of the toy\u2019s system and misuse it to secretly communicate with kids through video chat without parental consent. The risks associated with the robot system\u2019s application extend to dangers that sensitive details such as users\u2019 names, genders, ages and even their locations may be compromised.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An Android-based robot designed for kids is equipped with a built-in video camera and microphone. It harnesses artificial intelligence to recognize and interact with children by name and to adjust its responses based on the child\u2019s mood, gradually getting acquainted with them over time. To unlock the full potential of the toy, parents are required to download the application to their mobile device. Through this app, parents can track the child&#8217;s progress with their learning activities and even initiate a video call with the child via the robot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During initial setup, parents are instructed to connect the toy to a Wi-Fi network, link it to their mobile device, then provide the child\u2019s name and age. During this phase, Kaspersky experts have uncovered a concerning security issue: the responsible API (Application Programming Interface) for requesting this information lacks authentication enforcement, a step that confirms who can access your network resources. This potentially allows cybercriminals to intercept and access various types of data \u2013 including the child\u2019s name, age, gender, country of residence, and even their IP address \u2013 by intercepting and analyzing the network traffic.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What\u2019s more, this flaw enables cybercriminals to exploit the robot\u2019s camera and microphone, initiating direct calls to e users, bypassing the required authorization from the guardians\u2019 account. If a child accepts this call, an attacker can communicate covertly, without parents\u2019 consent. In such cases, the attacker could manipulate the user, potentially luring them out of the safety of their home or influencing them into engaging in risky behaviors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, security issues of the parent\u2019s mobile application may enable an attacker to remotely take control over the robot and gain unauthorized access to the network. Using brute-force methods to recover the six-digit one time-password (OTP), and with no enforced limit on failed attempts, an attacker could remotely link the robot to his own account, effectively taking the device out of its owner\u2019s control.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhen purchasing smart toys, it becomes imperative to prioritize not only their entertainment and educational value but also their safety and security features. Despite the common belief that a higher price tag implies enhanced security, it is essential to understand that even the most expensive smart toys may not be immune to vulnerabilities that attackers can exploit. Hence, parents must carefully examine toy reviews, remain vigilant about updating smart device software, and closely supervise their child&#8217;s activities during playtime,\u201d comments Nikolay Frolov, senior security researcher at Kaspersky\u2019s ICS CERT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The findings from the team&#8217;s thorough research were presented during the panel&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.mwcbarcelona.com\/agenda\/sessions\/4310-how-can-we-empower-the-vulnerable-in-the-digital-environment\">session<\/a>&nbsp;titled \u201cEmpowering the Vulnerable in the Digital Environment\u201d at Mobile World Congress (MWC) 2024.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Kaspersky team reported all the vulnerabilities they discovered to the vendor, who promptly patched them. Learn more on&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/smart-robot-security-research\/111938\/\">Securelist.com.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To keep all smart devices, secure and protected, Kaspersky experts compiled the following tips:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keep your devices updated: Regularly update the firmware and software of all your connected devices, including smart toys. These updates often contain crucial security patches that address known vulnerabilities.<\/li>\n\n\n\n<li>Research before purchase: Before buying a smart toy or any connected device, research the manufacturer&#8217;s reputation for security and privacy. Choose devices from reputable brands that prioritize security and provide regular updates.<\/li>\n\n\n\n<li>Be cautious with app permissions: Review and limit the permissions granted to mobile apps associated with your smart device. Only provide necessary access to features and data, and avoid granting excessive privileges.<\/li>\n\n\n\n<li>Power it off when not used: Switch off the smart toy when not in use to prevent data collection. If the device has a microphone, store it in a hard-to-reach place when not active, and cover or redirect any cameras when not in use.<\/li>\n\n\n\n<li>Use reliable security solutions: Employ a dependable <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/premium\">security solution<\/a> to help secure and protect your entire smart home ecosystem.&nbsp;<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The risks associated with the robot system\u2019s application extend to dangers that sensitive details such as users\u2019 names, genders, ages and even their locations may be compromised.<\/p>\n","protected":false},"author":6,"featured_media":62103,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-62102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/62102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=62102"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/62102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/62103"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=62102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=62102"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=62102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}