Skip to main content

Teddy talk: Fisher-Price’s smart stuffed animals found to have security flaws

fisher price smart toys found to have security vulnerabilities
Image used with permission by copyright holder
Just in time for Christmas last year, a security firm found that Hello Barbie, Mattel’s Wi-Fi-enabled doll with a sweet silver jacket and speech recognition, was vulnerable to hacking. Now Fisher-Price, which is owned by Mattel, has its own toy troubles. Its “Smart Toys” (Internet-connected stuffed animals), have a similar vulnerability, according to security researchers at Rapid7.

The “interactive learning friend,” aimed at kids aged 3-8, listens to and talks back to the child, tells stories and jokes, and knows the weather and news headlines. Whereas a beloved stuffed rabbit could only make a child vulnerable by becoming contaminated with scarlet fever germs, adding Wi-Fi could expose their identities. “It was determined that many of the platform’s web service (API) calls were not appropriately verifying the ‘sender’ of messages, allowing for a would-be attacker to send requests that shouldn’t be authorized under ideal operating conditions,” reports Rapid7. This means an attacker could have gotten the toy’s details (including its toy ID, name, type), accessed the child’s profile (which has data such as name, birthday, gender, and language), changed account details, and seen other information, such as game scores and customer purchases.

Recommended Videos

“While in the particular, names and birthdays are nominally non-secret pieces of data, these could be combined later with a more complete profile of the child in order to facilitate any number of social engineering or other malicious campaigns against either the child or the child’s caregivers,” Raipd7’s Mark Stanislav wrote in a post about the smart toys’ vulnerabilities.

Please enable Javascript to view this content

After Rapid7 contacted Fisher-Price about the issues, the company addressed the problem. Smart watch hereO, meant to help families keep track of each other, also had a vulnerability, researchers found. The GPS platform had an authorization flaw since it was patched; one that could have allowed attackers to send an accept an authorization request. That authorization grants access to family members’ locations and location histories.

It’s a tough time to be a connected kid. Last week, the New York City Department of Consumer Affairs launched an investigation of connected baby monitors, thanks to a Rapid7 report raising security issues. 

Jenny McGrath
Former Digital Trends Contributor
Jenny McGrath is a senior writer at Digital Trends covering the intersection of tech and the arts and the environment. Before…
Smarten up your holiday scene with the Govee Icicle Lights
The Govee Icicle Lights.

Keen to make your home this holiday season look fantastic? If you’re aiming for a National Lampoon’s Christmas Vacation style appearance but want it smarter, you need more than just the Philips Hue deals going on. Right now, you can buy the Govee Icicle Lights set for just $90 at Best Buy so you’re saving $50 off the regular price of $140. They make the outside of your home look gorgeous while being super practical. Here’s all you need to know before you buy.

Why you should buy the Govee Icicle Lights
I love Govee products. Since buying the Govee Lyra Smart Floor Lamp, I’ve been consistently impressed by how well its products work while being very keenly priced. It’s a different kind of technology than the best cheap smart light bulbs but it’s perfect for stringing together some lights around your home or room. The only downside is the company's app isn't as stylish as the Hue one but you get all the same benefits for a much better price.

Read more
Quick! The Dyson V7 Cordless Vacuum Cleaner is 50% off at Walmart right now
dyson cordless upright vacuum deals best buy kohls the home depot pre memorial day sale  v7 motorhead cord free stick fuschia

Dyson deals are always worth checking out as they mean you can enjoy all the advantages of owning a Dyson without spending a fortune. Right now, one of the best cordless vacuum deals is on the Dyson V7 which normally costs $400. Right now, you can buy it from Walmart for 50% off so it costs $200. This is the investment you need for your home as it’ll help you clean up your home far more efficiently than alternatives. Here’s what it has to offer for the great price.

Why you should buy the Dyson V7 Cordless Vacuum Cleaner
The best Dyson vacuums truly enrich your life by making it much easier to suck up whatever is littering your home. That could be regular dirt and debris or it could be pet hair. It’s all stuff you don’t want messing up your home. With the Dyson V7 Cordless Vacuum Cleaner, you get powerful Dyson suction. It has advanced, whole-machine filtration which captures pet allergens and fine dust, while expelling cleaner air.

Read more
Multicolor markdown: This Philips Hue 3-Pack of A19 bulbs is $80 off today
Philips hue white and color ambiance light bulbs in box.

When it comes to smart home tech, one of the top brands that comes to mind for smart lighting is Philips Hue. Designed for plug-and-play connectivity, Philips Hue devices are easy to set up and a breeze to control. And if you’re operating a Hue Bridge, you’ll be able to control up to 50 different Hue products! Philips Hue deals can be a little hard to come by, which is why we’ve chosen to highlight this great Best Buy offer. Right now, when you purchase the Philips Hue A19 White and Color Ambiance (3-Pack), you’ll only pay $80. At full price, this model sells for $135.

Why you should buy the Philips Hue A19 White and Color Ambiance (3-Pack)
While investing in a Hue Bridge will unlock the full capabilities of your Philips Hue system, this A19 White and Color Ambiance (3-Pack) can be controlled over Bluetooth, too. Do keep in mind this introduces range and device limitations, though, so going Wi-Fi might be a top consideration regardless. Not to mention, you’ll be able to control your Hue system remotely (Bluetooth relies on a host device to be nearby).

Read more