Some people consider dolls creepy enough,The Lust (2020) AMZN Hindi Short Film but what if that deceptively cute toy was listening to everything you said and, worse yet, letting creeps speak through it?
According to The Center for Digital Democracy, a pair of smart toys designed to engage with children in new and entertaining ways are rife with security and privacy holes. The watchdog group was so concerned, they filed a complaint with the Federal Trade Commission on Dec. 6 (you can read the full complaint here). A similar one was also filed in Europe by the Norwegian Consumer Council.
SEE ALSO: Microsoft's Home Hub aims to turn the PC into an Amazon Echo“This complaint concerns toys that spy,” reads the complaint, which claims the Genesis Toys’ My Friend Cayla and i-QUE Intelligent Robot can record and collect private conversations and offer no limitations on the collection and use of personal information.
Both toys use voice recognition, internet connectivity and Bluetooth to engage with children in conversational manner and answer questions. The CDD claims they do all of this in wildly insecure and invasive ways.
Both My Friend Cayla and i-QUE use Nuance Communications' voice-recognition platform to listen and respond to queries. On the Genesis Toy site, the manufacturer notes that while “most of Cayla’s conversational features can be accessed offline,” searching for information may require an internet connection.
The promotional video for Cayla encourages children to “ask Cayla almost anything.”
The dolls work in concert with mobile apps. Some questions can be asked directly, but the toys maintain a constant Bluetooth connection to the dolls so they can also react to actions in the app and even appear to identify objects the child taps on on screen.
The CDD takes particular issue with that app and lists all the questions it asks children (or their parents) up front during registration: everything from the child and her parent’s names to their school, and where they live.
While some of the questions children ask the dolls are apparently recorded and sent to Nuance’s servers for parsing, it’s unclear how much of the information is personal in nature. The Genesis Privacy Policy promises to anonymize information.
Nuance, a multibillion-dollar communication company, provides voice-recognition services across multiple industries and has reportedly served as the voice recognition technology behind Apple’s Siri. In fact, most digital voice assistants, like Amazon Alex and Google Assistant, employ some form of speech recognition and connect to the internet to find the answers to queries that have usually been converted to text.
The CDD also claims, however, that My Friend Cayla and i-Que employ Bluetooth in the least secure way possible. Instead of requiring a PIN code to complete pairing between the toy and a smartphone or iPad, “Cayla and i-Que do not employ... authentication mechanisms to establish a Bluetooth connection between the doll and a smartphone or tablet. The dolls do not implement any other security measure to prevent unauthorized Bluetooth pairing.”
These toys, which were released late last year, are still hot holiday items.
Without a pairing notification on the toy or any authentication strategy, anyone with a Bluetooth device could connect to the toys’ open Bluetooth networks, according to the complaint.
“Researchers discovered that by connecting one phone to the doll through the insecure Bluetooth connection and calling that phone with a second phone, they were able to both converse with and covertly listen to conversations collected through the My Friend Cayla and i-Que toys,” reads the FTC complaint.
In other words, someone might be able to use their own smartphone to speak to a child through one of these dolls. The CDD demonstrated this hack in the video above.
"[It's] significant that they went after a small company rather than Mattel for the Hello Dreamhouse, which is similar tech," wrote toy expert and Content Director for the toy recommendation site TTPM when contacted via email. Byrne added that while consumer toy complaints are relatively common, formal complaints are rare. This particular complaint "raises a whole lot of issues, particularly related to COPA and what that covers," wrote Byrne.
These toys, which were released late last year, are still hot holiday items. Mashablecontacted Genesis Toys and the CDD about the complaint and will update this post with their comments. The FTC could not comment directly on the filing but a spokesperson told us in an email, “All we can say about how complaints are handled and what might result is that every complaint is taken seriously.”
In the meantime, if these toys are on your holiday list, you might want to double check the Bluetooth setup -- there should always be a pairing authentication strategy -- and talk to your children about which conversations are appropriate to have with their robot toy friends.
Topics Cybersecurity Privacy
The first images of Earth are chillingSpain hands $146 million to Stellantis’s battery project with CATL · TechNodeiFLYTEK launches Spark Multilingual Model and Spark 4.0 Turbo · TechNodeIntel and Samsung explore foundry alliance to challenge TSMC · TechNodeSpain vs. Italy 2024 livestream: Watch Euro 2024 for freeNYT's The Mini crossword answers for June 20The first images of Earth are chillingNASA released wild footage of Mars helicopter flying over alien desertAfghanistan vs. India 2024 livestream: Watch T20 World Cup for freeBlack widows are vanishing. Scientists found out why.Mars scientists spent 6 years making the most detailed image of the planetDenmark vs. England 2024 livestream: Watch Euro 2024 for freeLi Auto ramps up chip making with new Hong Kong office: report · TechNodeVolkswagen may close Chinese joint plant · TechNodeAustralia vs. Bangladesh 2024 livestream: Watch T20 World Cup for freeByteDance releases Ola Friend, its first AI smart earbuds · TechNodeChina’s authority NPPA approves 109 new games licenses for September · TechNodeNASA's sciBlack widows are vanishing. Scientists found out why.Scientists find deep space radio signals all the time. Here's what they mean. “Marley Was Dead: to Begin With.” by Sadie Stein Oral Sadism and the Vegetarian Personality by Sadie Stein Unhinged Trump supporters harass the Biden campaign bus in viral clip Digital Silence by Alex Carp Happy 2013, From Mark Twain by Sadie Stein Kim Kardashian's birthday present from Kanye was this nightmarish hologram of her dead dad Leo Tolstoy, Emerging Author, and Other News by Sadie Stein Jack Dorsey's wild beard at the Senate hearing on Section 230 is being memed Here is a LEGO Scrooge for You by Sadie Stein Pornhub says it's reserved for voters only on Election Day Where Daisy Buchanan Lived by Jason Diamond 'The Birdcage's tale of queer love and drag queens is as timely as ever Gracie and Cyril: An Oral History by Emily Greenhouse Uber Eats will let you pick restaurants using less terrible packaging Freedom and Light by Brian Cullman Whoopi Goldberg urges Blizzard Entertainment to release 'Diablo 4' on Mac Kanye's birthday present to Kim Kardashian has gifted us with a holographic dad meme Street Scene by Jiayang Fan Water and Wonder by John Lingan Amazon might shove ads into Prime Video
2.6272s , 8224.8359375 kb
Copyright © 2025 Powered by 【The Lust (2020) AMZN Hindi Short Film】,Inspiration Information Network