CloudPets IoT Toys Leaked and Ransomed, Exposing Kids' Voice Messages (androidpolice.com)
"According to security researcher Troy Hunt, a series of web-connected, app-enabled toys called CloudPets have been hacked," reports Android Police. "The manufacturer's central database was reportedly compromised over several months after stunningly poor security, despite the attempts of many researchers and journalists to inform the manufacturer of the potential danger. Several ransom notes were left, demanding Bitcoin payments for the implied deletion of stolen data." From the report: CloudPets allow parents to record a message for their children on their phones, which then arrives on the Bluetooth connected stuffed toy and is played back. Kids can squeeze the stuffed animal's paw to record a message of their own, which is sent back to the phone app. The Android app has been downloaded over 100,000 times, though user reviews are poor, citing a difficult interface, frequent bugs, and annoying advertising. Hunt and the researchers he collaborated with found that the central database for CloudPets' voice messages and user info was stored on a public-facing MongoDB server, with only basic hashes protecting user addresses and passwords. The same database apparently connected to the stored voice messages that could be retrieved by the apps and toys. Easy access and poor password requirements may have resulted in unauthorized access to a large number of accounts. The database was finally removed from the publicly accessible server in January, but not before demands for ransom were left.
Heh, long ago I worked for a company that, as a part of its proprietary product, ran open mail relays. That's right! Open relays. It was "necessary" to make the software work correctly. The morons who built the custom solution knew nothing and I was a junior sysadmin back then so I didn't know to correct them. Needless to say we pumped out 100,000 spam emails a day compared to about 4,000 legitimate messages.
One day a new manager put his foot down and turned off the open relay. He was nearly fired. He was removed as my supervisor and put in charge of "special projects". Eventually we got listed on Spamhaus or RBL or one of those, which was very gratifying to report to management. Nothing was ever done though, it would have required rearchitecting the system. The open relay was still going strong when I left.
Shutting down free speech with violence isn't fighting fascism. It IS fascism!