Cloud

7/17/2017
07:05 PM
100%
0%

FBI Issues Warning on IoT Toy Security

IoT toys are more than fun and games and can potentially lead to a violation of children's privacy and safety, the Federal Bureau of Investigation warned Monday.

Internet-connected toys carry the potential of violating children's privacy and safety, given the amount of information the toys can collect and store, the Federal Bureau of Investigation warned on Monday.

The sensors, microphones, data storage capabilities, cameras, and other multi-media features of IoT toys could potentially gather information on a child regarding their name, school, activity plans and physical location.

And if those toys are hacked, the information and data collected could potentially be used by attackers to do a child harm, the FBI warned. The FBI advisory offered advice on selecting an IoT toy, such as only connecting it to a secure and trusted WiFi network, research the toy to ensure it can receive firmware and software updates, and investigate where the information entered into the toy is stored.

Read more about the FBI advisory here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/18/2017 | 1:56:48 PM
IoToys
This issue has been gradually building up attention-getting for a while now -- particularly as hackers exploit the IoToys and IoBabyMonitors.

I'm mildly surprised that we're not seeing more about the FTC isn't coming down on manufacturers of these items regarding COPPA. Either the compliance is sublime (which I tend to doubt) or it's largely slipped under their radar because of the nonintuitive nature of the data gathering.
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12697
PUBLISHED: 2018-06-23
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
CVE-2018-12698
PUBLISHED: 2018-06-23
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
CVE-2018-12699
PUBLISHED: 2018-06-23
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
CVE-2018-12700
PUBLISHED: 2018-06-23
A Stack Exhaustion issue was discovered in debug_write_type in debug.c in GNU Binutils 2.30 because of DEBUG_KIND_INDIRECT infinite recursion.
CVE-2018-11560
PUBLISHED: 2018-06-23
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.