VTech Hack Gets Worse: Chat Logs, Kids' Photos Taken In Breach (vice.com)
An anonymous reader writes: The VTech hack just got a little worse. Reports say that in addition to the 4.8 million records with parents' names, home addresses, passwords and the identities of 227k kids, the hackers also have hundreds of gigabytes worth of pictures and chat logs belonging to children. ZDNet reports: "Tens of thousands of pictures — many blank or duplicates — were thought to have been taken from from Kid Connect, an app that allows parents to use a smartphone app to talk to their children through a VTech tablet. Motherboard was able to verify a portion of the images, and the chat logs, which date as far back as late-2014. Details about the intrusion are not fully known yet. The hacker, who for now remains nameless, told Motherboard that the Hong Kong-based company 'left other sensitive data exposed on its servers.'"
1156 W Shure Dr #200, Arlington Heights, IL 60004
(847) 400-3600
I keep seeing reports of this saying "4,800,000 parents" and "227,000 children". Can someone please explain this?
. . . who cares.
Expect fake lost kids emails and other much worse things.
There is evil. And then there's Evil.
This is the latter.
-- Tigger warning: This post may contain tiggers! --
Jared Fogle was just looking for new material.
I'm guessing that reactionary mommy bloggers everywhere are losing their minds about this non-story while every useful person on this planet continues with their lives.
The important question is why the data was stored on VTech's servers in the first place.
THIS ^^^^^^^^ THIS
This corporate culture of "store everything" needs to go away. At least in the past, we had storage limitations that made this infeasible. But dammit, as a software engineer, if the system requirements tell me to store something that would be bad if it was released, then I'm not storing it unless there is a damned good reason AND it is well encrypted.
My kids have some vtech stuff. I downloaded their app that lets the toy know the child's name, birthday, and favorite food. But that's it. It never occurred to me that they would have any reason to store that information. Let alone storing photos and chat logs from devices that have that capability.
WTF!!!!! I am anxious to hear about this. This is why I used to use a personal firewall years ago. Everything phones home. But now they are impractical.
https://www.thinkgeek.com/stuff/41/secrets-bear.shtml
Every day I read about zillion emails and other personal information is hacked. Like MobyDisk asks why are they storing this stuff? I think companies should be liable for loss of personal information so then they will first think is it necessary to gather information. Then if they do they better have some damn good methods of keeping it safe. Yes, I have personal firewall on all the time. I also have computers that are never put online. Then these places ask for name, birthdate and address. I may give them name and address, birthdates are different than my actual.
So now here's another hack and loss of data, ho hum, just another disaster in IT land, yawn. This can be serious. There might be a breach that will really screw things up and nobody will flinch.
mfwright@batnet.com
I don't get the issue...
I don't remember the registration asking for an address, just an email. If they did ask, it was "1234 fake st".
Omg they have my email address and name noooooo. And who cares about a pic of my kid, who looks like a million and one other kids out there.
If you want to see the interesting depths of a chat log of a kid, just fire up your favorite markov chain.
Wtf is everyone so worked up about?
Listen to Bruce Schneier make this important point:
http://feeds.cato.org/~r/CatoD...
My God, it's Full of Source!
OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
VTEC just kicked in yo!
Coren22 IMPERSONATES RESPECTED MEMBERS OF THE SECURITY COMMUNITY http://slashdot.org/comments.p...
---
"privilege escalation's a bad thing" - by Coren22 on Tuesday September 22, 2015
How else programmatically update it?
"requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it - hosts do vs. WFP/SFP not my ware. Users set it not programmatic impersonation. Security wares need it.
---
"secretary at MalwareBytes took a look at his source code & said it looked all good" - by Coren22 (1625475) on Wednesday November 18, 2015
Mr. Steven Burn of Malwarebytes
"yes I've seen the code & yes it is safe." FROM http://forum.hosts-file.net/vi...
---
"we should avoid your crap it looks like malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
60++ reputable sources say different:
64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl...
---
"MiTM... his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
Hardcoded favs users provide = REVERSE DNS verified & my ware filters 5,500++ false positives - security site hosts data = false positives filtered.
---
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Show us where I say it? Not illogic logic but where I say it. I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there.
APK
P.S.=>
"modding you down for trolling in your signature" - by Dog-Cow (21281) on Wednesday November 25, 2015
Dog-Cow's (old acc't. no new sockpuppet from you) thoughts of your signatures about me
... apk
Coren22 IMPERSONATES RESPECTED MEMBERS OF THE SECURITY COMMUNITY http://slashdot.org/comments.p...
---
"privilege escalation's a bad thing" - by Coren22 on Tuesday September 22, 2015
How else programmatically update it?
"requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it - hosts do vs. WFP/SFP not my ware. Users set it not programmatic impersonation. Security wares need it.
---
"secretary at MalwareBytes took a look at his source code & said it looked all good" - by Coren22 (1625475) on Wednesday November 18, 2015
Mr. Steven Burn of Malwarebytes
"yes I've seen the code & yes it is safe." FROM http://forum.hosts-file.net/vi...
---
"we should avoid your crap it looks like malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
60++ reputable sources say different:
64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl...
---
"MiTM... his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
Hardcoded favs users provide = REVERSE DNS verified & my ware filters 5,500++ false positives - security site hosts data = false positives filtered.
---
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Show us where I say it? Not illogic logic but where I say it. I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there.
APK
P.S.=>
"modding you down for trolling in your signature" - by Dog-Cow (21281) on Wednesday November 25, 2015
Dog-Cow's (old acc't. no new sockpuppet from you) thoughts of your signatures about me
... apk
Coren22 IMPERSONATES RESPECTED MEMBERS OF THE SECURITY COMMUNITY http://slashdot.org/comments.p...
---
"privilege escalation's a bad thing" - by Coren22 on Tuesday September 22, 2015
How else programmatically update it?
"requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it - hosts do vs. WFP/SFP not my ware. Users set it not programmatic impersonation. Security wares need it.
---
"secretary at MalwareBytes took a look at his source code & said it looked all good" - by Coren22 (1625475) on Wednesday November 18, 2015
Mr. Steven Burn of Malwarebytes
"yes I've seen the code & yes it is safe." FROM http://forum.hosts-file.net/vi...
---
"we should avoid your crap it looks like malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
60++ reputable sources say different:
64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl...
---
"MiTM... his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
Hardcoded favs users provide = REVERSE DNS verified & my ware filters 5,500++ false positives - security site hosts data = false positives filtered.
---
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Show us where I say it? Not illogic logic but where I say it. I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there.
APK
P.S.=>
"modding you down for trolling in your signature" - by Dog-Cow (21281) on Wednesday November 25, 2015
Dog-Cow's (old acc't. no new sockpuppet from you) thoughts of your signatures about me
... apk
Coren22 IMPERSONATES RESPECTED MEMBERS OF THE SECURITY COMMUNITY http://slashdot.org/comments.p...
---
"privilege escalation's a bad thing" - by Coren22 on Tuesday September 22, 2015
How else programmatically update it?
"requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it - hosts do vs. WFP/SFP not my ware. Users set it not programmatic impersonation. Security wares need it.
---
"secretary at MalwareBytes took a look at his source code & said it looked all good" - by Coren22 (1625475) on Wednesday November 18, 2015
Mr. Steven Burn of Malwarebytes
"yes I've seen the code & yes it is safe." FROM http://forum.hosts-file.net/vi...
---
"we should avoid your crap it looks like malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
60++ reputable sources say different:
64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl...
---
"MiTM... his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
Hardcoded favs users provide = REVERSE DNS verified & my ware filters 5,500++ false positives - security site hosts data = false positives filtered.
---
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Show us where I say it? Not illogic logic but where I say it. I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there.
APK
P.S.=>
"modding you down for trolling in your signature" - by Dog-Cow (21281) on Wednesday November 25, 2015
Dog-Cow's (old acc't. no new sockpuppet from you) thoughts of your signatures about me
... apk
Coren22 IMPERSONATES RESPECTED MEMBERS OF THE SECURITY COMMUNITY http://slashdot.org/comments.p...
---
"privilege escalation's a bad thing" - by Coren22 on Tuesday September 22, 2015
How else programmatically update it?
"requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it - hosts do vs. WFP/SFP not my ware. Users set it not programmatic impersonation. Security wares need it.
---
"secretary at MalwareBytes took a look at his source code & said it looked all good" - by Coren22 (1625475) on Wednesday November 18, 2015
Mr. Steven Burn of Malwarebytes
"yes I've seen the code & yes it is safe." FROM http://forum.hosts-file.net/vi...
---
"we should avoid your crap it looks like malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
60++ reputable sources say different:
64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl...
---
"MiTM... his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
Hardcoded favs users provide = REVERSE DNS verified & my ware filters 5,500++ false positives - security site hosts data = false positives filtered.
---
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Show us where I say it? Not illogic logic but where I say it. I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there.
APK
P.S.=>
"modding you down for trolling in your signature" - by Dog-Cow (21281) on Wednesday November 25, 2015
Dog-Cow's (old acc't. no new sockpuppet from you) thoughts of your signatures about me
... apk
Coren22 IMPERSONATES RESPECTED MEMBERS OF THE SECURITY COMMUNITY http://slashdot.org/comments.p...
---
"privilege escalation's a bad thing" - by Coren22 on Tuesday September 22, 2015
How else programmatically update it?
"requires elevation to write hosts" - by Coren22 (1625475) on Wednesday September 23, 2015
Hypocrite later admits it - hosts do vs. WFP/SFP not my ware. Users set it not programmatic impersonation. Security wares need it.
---
"secretary at MalwareBytes took a look at his source code & said it looked all good" - by Coren22 (1625475) on Wednesday November 18, 2015
Mr. Steven Burn of Malwarebytes
"yes I've seen the code & yes it is safe." FROM http://forum.hosts-file.net/vi...
---
"we should avoid your crap it looks like malware." - by Coren22 (1625475) on Monday November 02, 2015 @03:52PM (#50850445)
60++ reputable sources say different:
64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
MalwareBytes' hpHosts Admin (MalwareBytes employee) hosts & recommends it -> http://hosts-file.net/?s=Downl...
---
"MiTM... his software provides" - by Coren22 (1625475) on Wednesday November 18, 2015
Hardcoded favs users provide = REVERSE DNS verified & my ware filters 5,500++ false positives - security site hosts data = false positives filtered.
---
"Apk doesn't think DNS servers are worth running & believes Microsoft Active Directory can run w/out DNS." - by Coren22 (1625475) on Tuesday October 27, 2015
Show us where I say it? Not illogic logic but where I say it. I say AD needs internal DNS far back as 2007
http://forums.tweaktown.com/wi...
See "To warn users who have ActiveDirectory/AD LAN-WAN setups to NOT use external DNS servers" there.
APK
P.S.=>
"modding you down for trolling in your signature" - by Dog-Cow (21281) on Wednesday November 25, 2015
Dog-Cow's (old acc't. no new sockpuppet from you) thoughts of your signatures about me
... apk
"OH MY GOD THEY HAVE KIDS PICS AND CHATS! ARGH! IT'S PAEDO-GEDDON!!!"
C.T.F.D. now!
So what if they have the pictures of kids? Anyone can get pictures of anyone, including kids. I can stand in the middle of your local town, a public space, snapping pictures of anyone I please, there's no law against it providing I am not a nuisance or stopping you going about your business. I could then set up a stall and ask people to sponsor me to do some charity thing. I now have your name, phone number, maybe your address and your picture!
The chat logs? I cannot begin to imagine how banal the chat between two 8 year old's is.
Granted the breach of a supposedly secure system is a serious issue, yes the data should have been protected but simply having the pictures, chat logs and contact details of people is not top secret and civilization will not cease. It probably means the internet now has more shit dumped on it that almost everyone will ignore!
YOU BLEW IT BADLY HERE especially -> http://slashdot.org/comments.p...
See subject & my last post you replied to Coren22: BIND doesn't come w/ Windows, the most used OS there is by the most folks on the desktop!
(LMAO - I own you... YOU, have been DOMINATED!)
APK
P.S.=> You're efficiency is poor - Less IS truly MORE in using what you already have (hosts + firewalls) as I do, & to do more with less... apk
Reply to This
YOU BLEW IT BADLY HERE especially -> http://slashdot.org/comments.p...
See subject & my last post you replied to Coren22: BIND doesn't come w/ Windows, the most used OS there is by the most folks on the desktop!
(LMAO - I own you... YOU, have been DOMINATED!)
APK
P.S.=> You're efficiency is poor - Less IS truly MORE in using what you already have (hosts + firewalls) as I do, & to do more with less... apk
Reply to This
YOU BLEW IT BADLY HERE especially -> http://slashdot.org/comments.p...
See subject & my last post you replied to Coren22: BIND doesn't come w/ Windows, the most used OS there is by the most folks on the desktop!
(LMAO - I own you... YOU, have been DOMINATED!)
APK
P.S.=> You're efficiency is poor - Less IS truly MORE in using what you already have (hosts + firewalls) as I do, & to do more with less... apk
YOU BLEW IT BADLY HERE especially -> http://slashdot.org/comments.p...
See subject & my last post you replied to Coren22: BIND doesn't come w/ Windows, the most used OS there is by the most folks on the desktop!
(LMAO - I own you... YOU, have been DOMINATED!)
APK
P.S.=> You're efficiency is poor - Less IS truly MORE in using what you already have (hosts + firewalls) as I do, & to do more with less... apk
YOU BLEW IT BADLY HERE especially -> http://slashdot.org/comments.p...
See subject & my last post you replied to Coren22: BIND doesn't come w/ Windows, the most used OS there is by the most folks on the desktop!
(LMAO - I own you... YOU, have been DOMINATED!)
APK
P.S.=> You're efficiency is poor - Less IS truly MORE in using what you already have (hosts + firewalls) as I do, & to do more with less... apk
Computer Associates != a reputable source. They were caught in Accounting scandalshttp://www.bing.com/search?q=computer+associates+accounting+scandal&qs=n&form=QBLH&pq=computer+associates+accounting+scandal&sc=1-38&sp=-1&sk=&ghc=1&cvid=08487390E8064B75BDFA2D327BECEB4D & HAD TO SELL THEIR GARBAGE PC SECURITY SUITE too!
HOWEVER: Before they did? They lowered the 'threat' level on that old simple app of mine to ZERO (no threat, as I passed all 21 of their removal questions with flying colors on it to be cleared as safe... lol!)
THOR SCHMUCK? LOL @ HIM - he had to eat my dust like the fat chump he is.
APK
P.S.=> It's a shame you're such "ne'er-do-wells" & aren't able to code apps that even the likes of Malwarebytes folks HOST & RECOMMEND for me... lol! apk
Computer Associates != a reputable source. They were caught in Accounting scandals http://www.bing.com/search?q=c... & HAD TO SELL THEIR GARBAGE PC SECURITY SUITE too!
HOWEVER: Before they did? They lowered the 'threat' level on that old simple app of mine to ZERO (no threat, as I passed all 21 of their removal questions with flying colors on it to be cleared as safe... lol!)
THOR SCHMUCK? LOL @ HIM - he had to eat my dust like the fat chump he is.
APK
P.S.=> It's a shame you're such "ne'er-do-wells" & aren't able to code apps that even the likes of Malwarebytes folks HOST & RECOMMEND for me... lol! apk