Skip to main content

Teddy talk: Fisher-Price’s smart stuffed animals found to have security flaws

fisher price smart toys found to have security vulnerabilities
Just in time for Christmas last year, a security firm found that Hello Barbie, Mattel’s Wi-Fi-enabled doll with a sweet silver jacket and speech recognition, was vulnerable to hacking. Now Fisher-Price, which is owned by Mattel, has its own toy troubles. Its “Smart Toys” (Internet-connected stuffed animals), have a similar vulnerability, according to security researchers at Rapid7.

The “interactive learning friend,” aimed at kids aged 3-8, listens to and talks back to the child, tells stories and jokes, and knows the weather and news headlines. Whereas a beloved stuffed rabbit could only make a child vulnerable by becoming contaminated with scarlet fever germs, adding Wi-Fi could expose their identities. “It was determined that many of the platform’s web service (API) calls were not appropriately verifying the ‘sender’ of messages, allowing for a would-be attacker to send requests that shouldn’t be authorized under ideal operating conditions,” reports Rapid7. This means an attacker could have gotten the toy’s details (including its toy ID, name, type), accessed the child’s profile (which has data such as name, birthday, gender, and language), changed account details, and seen other information, such as game scores and customer purchases.

“While in the particular, names and birthdays are nominally non-secret pieces of data, these could be combined later with a more complete profile of the child in order to facilitate any number of social engineering or other malicious campaigns against either the child or the child’s caregivers,” Raipd7’s Mark Stanislav wrote in a post about the smart toys’ vulnerabilities.

After Rapid7 contacted Fisher-Price about the issues, the company addressed the problem. Smart watch hereO, meant to help families keep track of each other, also had a vulnerability, researchers found. The GPS platform had an authorization flaw since it was patched; one that could have allowed attackers to send an accept an authorization request. That authorization grants access to family members’ locations and location histories.

It’s a tough time to be a connected kid. Last week, the New York City Department of Consumer Affairs launched an investigation of connected baby monitors, thanks to a Rapid7 report raising security issues. 

Jenny McGrath
Former Digital Trends Contributor
Jenny McGrath is a senior writer at Digital Trends covering the intersection of tech and the arts and the environment. Before…
Nest Doorbell vs. Ring Battery Doorbell Plus: which is the better video doorbell?
The Ring Battery Doorbell Plus installed outside a front door.

Ring and Nest are responsible for some of the best video doorbells available. With easy-to-use smartphone apps, simple installation processes, and the ability to customize your motion alerts, the Ring Battery Doorbell Plus and Nest Doorbell have quickly established themselves as two of the best video doorbells money can buy.

But what exactly is the difference between these two popular gadgets? And which is better for your smart home?

Read more
The best Apple HomeKit devices for 2023
A person unlocking the Aqara U100 smart lock with their phone.

While not as widespread as Google Home or Amazon Alexa, Apple HomeKit remains one of the most popular smart home ecosystems of 2023. The software plays well with iOS devices, and several other gadgets such as smart lights, smart locks, thermostats, and cameras can be controlled using the fancy technology. If you’re looking to build your smart home around Apple’s ecosystem, here are the best HomeKit devices available today.
Locks

HomeKit doesn’t have the largest selection of smart locks, but that doesn’t really matter when you have something as well-rounded as the Aqara Smart Lock U100. Not only does it offer full HomeKit support, but you’ll even gain access to Apple home keys -- allowing you to unlock your door with your iPhone or Apple Watch. There’s also the standard keypad for entering a passcode, along with a fingerprint sensor that can store several dozen fingerprints (so your whole family can enter the home without worrying about forgetting their password or smartphone).

Read more
Secure your home with Ring Floodlight Cam Plus and save $80
Ring Floodlight Camera placed on a wall outside.

Best Buy has one of the best security camera deals at the moment with $80 off the Ring Floodlight Cam Plus Outdoor Wired Surveillance Camera. Usually priced at $200, it's down to $120 for a limited time only so if you're fast enough, you'll save a lot of cash. If you're looking to secure your home, keep reading while we tell you all about the advantages this security camera offers.

Why you should buy the Ring Floodlight Cam Plus
Considered to be one of the best floodlight cameras for someone seeking a hard-wired solution, the Ring Floodlight Cam Plus Outdoor Wired Surveillance Camera is a highly effective home security measure.

Read more