词条 | CloudPets |
释义 |
Security researchers demonstrated that the toy itself was insecure and could be trivially accessed via Bluetooth. The personal records of over 820,000 owners of the toy[4] were stored in an insecure MongoDB database. Attackers also replaced the database with a ransom demand pointing to a Bitcoin address.[5] Data retrieved from the CloudPets database was sent to the Australian security researcher Troy Hunt who included it in Have I Been Pwned?, a database of users whose data has been compromised. The database of user records also contained links pointing to over 2.2 million audio files hosted on Amazon Web Services containing the voice messages sent to and from the toys.[4][6] Hunt stated that the database hack was "ridiculously easy".[7] Following disclosure of security vulnerabilities, CloudPets started enforcing stronger password requirements on users of the service—they had previously not enforced any password complexity requirements and their documentation had suggested short, weak passwords.[3] Numerous journalists and security researchers including Hunt noted that the company was non-responsive to disclosures from security researchers and enquiries from journalists.[4] See also
References1. ^{{Cite news|url=https://www.forbes.com/sites/leemathews/2017/02/28/cloudpets-data-leak-is-a-privacy-nightmare-for-parents-and-kids/|title=The Latest Privacy Nightmare For Parents: Data Leaks From Smart Toys|last=Mathews|first=Lee|work=Forbes|access-date=2017-08-06}} 2. ^{{Cite news|url=http://www.networkworld.com/article/3175225/security/smart-teddy-bears-involved-in-a-contentious-data-breach.html|title=Smart teddy bears involved in a contentious data breach|last=Kan|first=Michael|work=Network World|access-date=2017-08-06|language=en}} 3. ^1 {{Cite news|url=https://www.theguardian.com/technology/2017/feb/28/cloudpets-data-breach-leaks-details-of-500000-children-and-adults|title=CloudPets stuffed toys leak details of half a million users|last=Hern|first=Alex|date=2017-02-28|work=The Guardian|access-date=2017-08-06|language=en-GB|issn=0261-3077}} 4. ^1 2 {{Cite web|url=http://money.cnn.com/2017/02/27/technology/cloudpets-data-leak-voices-photos/index.html|title=Stuffed toys leak millions of voice recordings from kids and parents|last=Larson|first=Selena|date=2017-02-27|website=CNNMoney|access-date=2017-08-06}} 5. ^{{Cite news|url=https://www.bbc.co.uk/news/technology-39115001|title=Children's messages in CloudPets data breach|date=2017-02-28|work=BBC News|access-date=2017-08-06|language=en-GB}} 6. ^{{Cite news|url=http://www.computerweekly.com/news/450413962/CloudPets-data-breach-underlines-need-for-secure-cloud-apps|title=CloudPets’ data breach underlines need for secure cloud apps|work=ComputerWeekly|access-date=2017-08-06|language=en-GB}} 7. ^{{Cite news|url=http://www.huffingtonpost.com.au/2017/02/28/millions-of-private-messages-between-parents-and-kids-hacked-in_a_21816860/|title=Millions Of Private Messages Between Parents And Kids Hacked In Cloud Pets Security Breach|last=Cooper|first=Luke|date=2017-02-28|work=Huffington Post|access-date=2017-08-06|language=en-AU}} 5 : 2010s toys|Teddy bears|Hacking in the 2010s|Cyberattacks|Internet of things |
随便看 |
|
开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。