Children’s messages in CloudPets data breach
The BBC is reporting that a lack of cyber security on Cloudpets database could leave children’s messages vulnerable to hackers. The open database contains links to more than 2 million voice messages recorded on cuddly toys.
Cybersecurity researcher Troy Hunt has revealed in his blog that the messages recorded via a phone app and the toy itself were left exposed and that the password policy did not require the use of strong passwords, resulting in many people using the easily guessed word “cloudpets” as their password.
Troy Hunt wrote on his blog that the voice recordings were stored in the cloud and the database, which was left exposed on the net, reveals their exact location.
He also expressed concern that there were no password rules at all, meaning lots of people had selected passwords that were extremely easy to crack.
“Because there were no rules, lots of people created bad passwords,” he told the BBC.
“I did an exercise and found it was really easy to create them. Lots of people were using the password Cloudpets because that’s what people do.”
There appeared to be around 820,000 accounts visible.
Both Mr Hunt and British security researcher Ken Munro said the toy showed similar vulnerabilities to the Cayla doll, an internet-connected toy that was found to be easily breached and could even be hacked to spy on its owners.
Like Cayla, there is no Pin number required to sync CloudPets with other devices, Ken Munro explained.
“If you have a CloudPets bear, switch it off,” he said.
Read more at Children’s messages in CloudPets data breach

