Security

US Senator snaps on glove, probes insecure IoT toymaker CloudPets

'Will we do this the easy way, or will we do it the hard way?'


Spiral Toys, makers of the insecure Bluetooth-connected stuffed animals dubbed CloudPets, is being grilled for information by a US Senator.

On Tuesday, Bill Nelson (D-FL), ranking member of the Senate's Committee on Commerce, Science and Transportation, sent Spiral ten questions demanding answers about the security of its voice-messaging cuddly toys.

CloudPets was earlier caught running an unsecured MongoDB installation, completely open to the world. That exposed hundreds of thousands of user account records – including email addresses and easily crackable hashed passwords – along with links to as many as two million voice recordings children and parents had sent each other via the toys and their iOS and Android app.

Within a day, it also emerged that the toys' microphones could be accessed by nearby snoops, via Spiral's poorly secured implementation of the Web Bluetooth API.

Nelson wants Spiral to explain its database leak in step-by-step detail, whether there's any identity theft protection in place, and what control people have over data collected by their CloudPets.

He also wants to know whether the Children's Online Privacy Protection Act applies to Spiral Toys' operation, details about its data collection and who data is shared with, whether any other breaches have happened in the past two years, whether consumers have the chance to delete their data, and more.

The letter came to light via Microsoft MVP Troy Hunt, who investigated the MongoDB leak:

The letter may reveal some actual useful information from California-based Spiral Toys. The biz sent a disingenuous statement to journalists in February. Back then it wrongly claimed the user data was “password encrypted,” and it was only a staging server that was compromised (it just happened to hold 500,000-plus production records). ®

Send us news
12 Comments

IBM to acquire Hashi for $6.4 billion, hopes it will boost software biz and Red Hat

Investors want to know what Big Blue is smoking after growth disappoints

Australia’s spies and cops want ‘accountable encryption’ - aka access to backdoors

And warn that AI is already being used by extremists to plot attacks

Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

Don't get too comfortable: 'Line Dancer' malware may be targeting other vendors, too

With Run:ai acquisition, Nvidia aims to manage your AI kubes

Now Jensen has a control plane to play with his army of NIMs

Apple releases OpenELM, a slightly more accurate LLM

It's not the fastest machine learning model, but you can't have everything

Musk moves Tesla's goalposts, investors happily move shares higher

It's the millions-of-robotaxis promise again – and all y'all buying it this time, too?

Shouldn't Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking

Doctorow: 'The most amazing part is that this isn't already the way it's done'

Now all Windows 11 users are getting adverts to 'make the Start menu great again'

And you thought the Bing begging was annoying

Lenovo and Micron first to implement LPCAMM2 in laptop

The SODIMM replacement finally arrives

Microsoft cannot keep its own security in order, so what hope for its add-ons customers?

Secure-by-default... if your pockets are deep enough

US Chamber of Commerce to sue FTC for banning noncompetes in most jobs

Senior execs making $150K+ will still have to abide by them, but they fall away for everyone else

Another Boeing whistleblower comes forward – with receipts

What's that? Q1 was better than expected? Pump those shares