Jump to content

Recommended Posts

Posted
My children will not be using personal tech until they are at least 16. They can cry as much as they want, not happening.

 

* raises eyebrow * That's what you think. Keeping them off technology at home is no way to educate or protect them

  • Thanks 2
Posted (edited)
* raises eyebrow * That's what you think. Keeping them off technology at home is no way to educate or protect them

 

There will be a computer in the corner of the living room, they can use that for half an hour a day.:cool:

 

Its not just about security, it breaks my heart when I see children of 1 staring into an iPad. I really do hate it. Kids should be outdoors.

Edited by Nixon77
Posted (edited)

My eldest is 11 and my youngest is 9. Both have access to tech and have email accounts (controlled by me). However, any software\hardware registration is done in via another account set aside especially for this which identifies no one and is not connected to any devices directly.

I agree with elsiegee40 here, technology is so pervasive these days there is no point whatsoever hiding children from it. Much better to use and educate as and when you have to than avoid the issue.

Edited by elsiegee40
Replaced real name with posting name ;)
Posted (edited)
There will be a computer in the corner of the living room, they can use that for half an hour a day.:cool:

 

It's not just about security, it breaks my heart when I see children of 1 staring into an iPad. I really do hate it. Kids should be outdoors.

 

I can see @esafety_officer quietly screaming whilst banging her head against a wall.

 

You are kidding yourself and badly mis-serving children if you think that 30 minutes a day in a public room is the solution these days.

 

I agree. It breaks my heart too to see babes in arms competently using... and even owning... iPads. However, what teaches them best is for them to see technology as a tool for life not the answer to life. They need to learn how to use it and how and when to use it appropriately.

 

Denying them access or over-restricting it will only lead to secretive use. Be open. Share what you, and they, do. Learn from them and demonstrate to them

 

My one absolute, and it still applies now to the whole family with adults included and my kids being 22 and 19, is that technology has no place at the dinner table or at bed time. Phones, etc go on charge downstairs at bed time so they're ready for the next day.

Edited by elsiegee40
Posted

Tech should be an accessory to life, not a part of it.

 

The world can go on being more wrapped in tech, but I will not be, and nor will my children, at least when at home.

 

Im not sure what there is to learn, school will teach the basics, I will teach them more, but if when they turn 16 they want to create social accounts and what not, then its fine. I will have explained to them the dangers long before that age.

Posted

 

Its not just about security, it breaks my heart when I see children of 1 staring into an iPad. I really do hate it. Kids should be outdoors.

 

Are they mutually exclusive? My kids go swimming, horse riding, dancing and love going for walks / playing outdoors / on the trampoline (even in Bloomin winter)

 

They also own an iPad each where they can request apps for us to install. The oldest can now iMessage me and the wife.

The kids are 4 and 5.

 

As with everything in life it's all about moderation. And if you tell a kid they can't do something - they'll find a way to do it anyway.

Posted
Are they mutually exclusive? My kids go swimming, horse riding, dancing and love going for walks / playing outdoors / on the trampoline (even in Bloomin winter)

 

They also own an iPad each where they can request apps for us to install. The oldest can now iMessage me and the wife.

The kids are 4 and 5.

 

As with everything in life it's all about moderation. And if you tell a kid they can't do something - they'll find a way to do it anyway.

 

Have to agree. My eldest daughter LOVES coming out with me to learn bushcraft, knife skills, archery, woodland walks, identifying plants and taking samples for her book, making fire, and running around outside like kids do with the next door neighbours little girl.

 

She knows how to use a phone, a tablet and to an extent my PC/her mums laptop. We teach. And when she uses the tech, she goes on a VLAN (WiFi or via a separate ethernet cable) Which has a filtered Internet connection.

 

The trick is to teach them properly, not hide them away from tech.

Posted

I think the key with children, with anything is limitation. Where its tech or not. I physically dont charge the iPad regularly so the battery dies when his time is up - limits the amount of drama i have to deal with when its time to move on to the next thing, prob the only benefit of having oddy placed electrical sockets and a short charger cable

 

The worst thing about this breach is the use of MD5.

 

Not for me, its that the hack was aimed at info of children. No credit cards, etc. Pure parents email (and passwords) and kids info.

 

Security wise its hard to pick, the disclosure of key information (ie sql statements in error messages), the lack of ssl, md5 passwords like you said - still not as bad as 000webhost with its plain text passwords - http://www.troyhunt.com/2015/10/breaches-traders-plain-text-passwords.html?m=1

Posted
Tech should be an accessory to life, not a part of it.

 

The world can go on being more wrapped in tech, but I will not be, and nor will my children, at least when at home.

That's fine. Children need to learn that there is more to life than a screen, but you are deluded if you think you are protecting them by keeping them away from it for all but 30 minutes a day at home.

 

Im not sure what there is to learn, school will teach the basics, I will teach them more, but if when they turn 16 they want to create social accounts and what not, then its fine. I will have explained to them the dangers long before that age.

 

There is EVERYTHING for children to learn about life both in the real world and in the electronic one.

 

Parents cannot, and should not, rely on school to teach them the skills they need to protect themselves in the world. A parent's role is to educate and model best practice ... whether that is how to cross the road safely, how to use a knife without drawing blood and when it's appropriate to use a knife and when it's likely to get you arrested, or how to use the internet safely and when it's appropriate to use the internet and when it's likely to get you arrested.

 

It's an ongoing process throughout life, not something you learn in school and let them do at age 16.

 

Your children will have social networking accounts of some sort before age 16. You cannot and will not prevent it. The way you see it though, you will not know about those accounts and that is dangerous.

  • 2 weeks later...
Posted

Man held in UK in VTech hacking probe - BBC News

 

A 21-year-old man has been arrested in Berkshire by police investigating the hacking of electronic toy maker VTech.

 

The man has been held on suspicion of "unauthorised access" to a computer, said the South East Regional Organised Crime Unit (Serocu) in a statement.

 

VTech was hit in mid-November when servers holding its customer information were breached.

 

In total, details of more than six million people are believed to have gone astray.

Posted
This is why I don't bother using any sort of device, or software, that requires "deeply personal" data for no apparent reason. Yes the DVLA needs my data - Why does Vtech need all that data for a toy computer?
Posted

Another kids website with extremely poor security. :(

 

Database leak exposes 3.3 million Hello Kitty fans

 

A database for sanriotown.com, the official online community for Hello Kitty and other Sanrio characters, has been discovered online by researcher Chris Vickery. The database houses 3.3 million accounts and has ties to a number of other Hello Kitty portals.

 

Vickery contacted Salted Hash and Databreaches.net about the leaked data Saturday evening.

 

The records exposed include first and last names, birthday (encoded, but easily reversible Vickery said), gender, country of origin, email addresses, unsalted SHA-1 password hashes, password hint questions, their corresponding answers, and other data points that appear to be website related.

 

Vickery also noted that accounts registered through the fan portals of the following websites were also impacted by this leak: hellokitty.com; hellokitty.com.sg; hellokitty.com.my; hellokitty.in.th; and mymelody.com.

 

In addition to the primary sanriotown database, two additional backup servers containing mirrored data were also discovered. The earliest logged exposure of this data is November 22, 2015.

 

In order to prevent identification of the database, Salted Hash is withholding screenshots of the data, IP information, DNS data, and other identifying markers.

 

Sanrio, as well as the ISP being used to host the database itself, have all been notified. An automated email from the ISP confirmed that the incident notification was logged, but no further details are available.

 

The Hello Kitty brand is highly popular the world over, to kids and adults, so the immediate concern is that the database might contain the personal information of children.

  • 1 month later...
Posted

I think a boycott is in order!

 

www.troyhunt.com/2016/02/no-vtech-cannot-simply-absolve-itself.html

 

A few months ago, the Hong Kong based toy maker VTech allowed itself to be hacked and millions of accounts exposed including hundreds of thousands of kids complete with names, ages, genders, photos and their relationships to their parents replete with where they (and assumedly their children) could be located. I chose this term deliberately – “allowed itself to be hacked” – because that’s precisely what happened. In an era where major incidents such as Ashley Madison and TalkTalk were front page news in the mainstream press, VTech continued to run a service with such egregious security flaws as the SQL injection risk the hacker originally exploited, unsalted MD5 password hashes, no SSL encryption anywhere, SQL statements returned in API calls (it’s actually in the JSON response body of my post above) and massively outdated web frameworks. What I didn’t write about at the time but reported privately was that they also had multiple serious direct object reference risks; the API that returned information on both kids and parents could be easily exploited just by manipulating an ID. Here’s what I shared with VTech via the reporter who originally broke the story (this is about the available methods on one of their APIs):

 

One of these is getKids and all it needs is the ID of the parent. No authentication token, no authorisation that the user can actually access the kid’s details, nothing more than a sequentially incrementing number. There’s also getParent which does exactly the same thing so the bottom line is that you don’t even need a data breach because as it stands today, you can simply enumerate the API. As an attacker, I can request the details on every single parent and get name, email and post code then take that parent ID and get every single child they’ve registered.

 

I actually created two accounts in order to demonstrate that whilst logged on as one, I could access the data from the other. The level of sophistication involved here is being able to count, yet in a subsequent press release, VTech claimed that the incident was an “orchestrated and sophisticated attack on our network”. No, it was neither of these things firstly because it was a single individual therefore they weren’t exactly orchestrating anything with anyone and secondly, because being able to add numbers does not make for a sophisticated attack nor does being able to mount a SQL injection attack using some automated tools (indeed this was how a 15-year-old kid was able to compromise TalkTalk). As much as the attacker’s actions were illegal and he deserves to be held accountable, VTech has some serious blame to wear.

 

The problem though, is that apparently they now feel customers should wear all the risk for shortcomings in their systems:

 

7. 	Limitation of Liability

YOU ACKNOWLEDGE AND AGREE THAT YOU ASSUME FULL RESPONSIBILITY FOR YOUR USE OF THE SITE AND ANY SOFTWARE OR FIRMWARE DOWNLOADED THEREFROM. [color="#FF0000"][b]YOU ACKNOWLEDGE AND AGREE THAT ANY INFORMATION YOU SEND OR RECEIVE DURING YOUR USE OF THE SITE MAY NOT BE SECURE AND MAY BE INTERCEPTED OR LATER ACQUIRED BY UNAUTHORIZED PARTIES[/b][/color]. YOU ACKNOWLEDGE AND AGREE THAT YOUR USE OF THE SITE AND ANY SOFTWARE OR FIRMWARE DOWNLOADED THEREFROM IS AT YOUR OWN RISK. RECOGNIZING SUCH, YOU UNDERSTAND AND AGREE THAT, TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, NEITHER VTECH NOR ITS SUPPLIERS, LICENSORS, PARENT, SUBSIDIARIES, AFFILIATES, DIRECTORS, OFFICERS, AGENTS, CO-BRANDERS, OTHER PARTNERS, OR EMPLOYEES WILL BE LIABLE TO YOU FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY OR OTHER DAMAGES OF ANY KIND, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR OTHER TANGIBLE OR INTANGIBLE LOSSES OR ANY OTHER DAMAGES OR LOSS BASED ON CONTRACT, TORT, STRICT LIABILITY OR ANY OTHER THEORY (EVEN IF VTECH HAD BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES), RESULTING FROM THE SITE OR SOFTWARE OR FIRMWARE DOWNLOADED THEREFROM; THE USE OR THE INABILITY TO USE THE SITE; UNAUTHORIZED ACCESS TO OR ALTERATION OR DESTRUCTION OR DELETION OF YOUR TRANSMISSIONS OR DATA OR DEVICE; STATEMENTS OR CONDUCT OF ANY THIRD PARTY ON THE SITE; ANY ACTIONS WE TAKE OR FAIL TO TAKE AS A RESULT OF COMMUNICATIONS YOU SEND TO US; HUMAN ERRORS; TECHNICAL MALFUNCTIONS; FAILURES, INCLUDING PUBLIC UTILITY OR TELEPHONE OR INTERNET OUTAGES; OMISSIONS, INTERRUPTIONS, LATENCY, DELETIONS OR DEFECTS OF ANY DEVICE OR NETWORK, PROVIDERS, OR SOFTWARE; ANY INJURY OR DAMAGE TO COMPUTER EQUIPMENT; INABILITY TO FULLY ACCESS THE SITE OR ANY OTHER SITE; THEFT, TAMPERING, DESTRUCTION, OR UNAUTHORIZED ACCESS TO, OR ALTERATION OF, ENTRIES, IMAGES OR OTHER CONTENT OF ANY KIND; TYPOGRAPHICAL, PRINTING OR OTHER ERRORS, OR ANY COMBINATION THEREOF; OR ANY OTHER MATTER RELATING TO THE SITE OR THE SOFTWARE OR FIRMWARE DOWNLOADED THEREFROM. NOTWITHSTANDING ANYTHING TO THE CONTRARY CONTAINED HEREIN, VTECH’S LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO PURCHASE A VTECH DEVICE OR SOFTWARE.

 

But it’s their responsibility to secure it! Look, I’m the first person to acknowledge that there are very few absolutes in security and there always remains some sliver of a risk that things will go wrong but even then, you, as the organisation involved, have to take responsibility. Certainly that’s the expectation of the customer – that the information they provide will remain secure – and VTech (or anyone else for that matter) cannot simply just absolve themselves of that responsibility in their terms and conditions. People don’t even read these things! If they honestly don’t feel they’re not up to the task of protecting personal information, then perhaps put that on the box and allow consumers to consciously take their chances rather than implicitly opting into the “zero accountability” clause.

 

What makes this position even more absurd is that VTech is now heading into home security...

 

The bigger picture here is that companies are building grossly negligent software – not just one mistake in otherwise well-written software (the Patreon incident is a good example of this) – and then simply not being held accountable when it all goes wrong. I genuinely hope the proposed EU data protection laws requiring up to 4% of gross revenue to be paid in the incident of a data breach serves as incentive for orgs to get their act together because as it stands, too many companies just aren’t taking this seriously. What I find unfathomable is how C-suite execs don’t take a moment whilst watching all these hacks appear in prime time news – and they simply cannot have missed some of 2015’s very well-publicised incidents – and think to themselves “Hey, I wonder if my multi-billion-dollar business might be at risk, perhaps we should make sure we’re prepared”. Or perhaps it’s just easier to write a dismissive set of T&Cs and move on.
  • Thanks 4
  • 1 year later...
  • 8 months later...
Posted

Electronic toymaker VTech settles for $650,000 with FTC over children’s privacy suit

 

The Federal Trade Commission said today that the electronic toymaker VTech Electronics has agreed to settle for a fine of $625,000 to be paid within the next seven days after charges that it violated children’s privacy. The Hong Kong-based VTech is also the parent company of LeapFrog, a popular brand for educational entertainment for children.

 

The FTC alleges that VTech collected "personal information of hundreds of thousands of children" through its KidiConnect mobile app “without providing direct notice and obtaining their parent’s consent.” The personal information included children’s first and last names, email addresses, dates of birth, and genders. VTech also allegedly stated in its privacy policy that such data would be encrypted, but did not actually encrypt any of it.

 

Under the Children’s Online Privacy Protection Act (COPPA), companies are required to disclose information collection practices and obtain consent from parents when collecting information from children under age 13.

 

"As connected toys become increasingly popular, it’s more important than ever that companies let parents know how their kids’ data is collected and used and that they take reasonable steps to secure that data", Maureen Ohlhausen, the acting FTC chairman, said in a statement on the FTC website. “Unfortunately, VTech fell short in both of these areas.”

 

The settlement dates back to the 2015 data breach that VTech suffered. By November 2015, about 2.25 million parents had registered and created accounts on VTech’s platform for almost 3 million children. At the same time, VTech was informed by media that a hacker had accessed its computer network and children’s personal information.

 

Although VTech has agreed to pay the fine, in a press release it says, "VTech does not admit any violations of law or liability". And VTech still claims on its site that its smart device and app have been designed to be the “perfect tech toy for kids” with children’s safety and security in mind.

 

In addition to the monetary settlement, VTech is also required to start running a comprehensive data security program that will be subject to independent audits for 20 years.

 

^ VTech have got off lightly. :(

Posted
So, who'd bought the kids anything VTech, lets hope you never upgraded/registered it otherwise your data is out in the public!

 

Troy Hunt: When children are breached – inside the massive VTech hack

 

Everyone bought my Nephew a bunch of noisy V-Tech toys for xmas but as far as I know none of them are registered or have any kind of sign on. They just sing stupid songs and make a bunch of noise.

 

Although he has one thing which I don't think is V-Tech but my Sister calls it 'Beep-bo' which is a singing and dancing Robot thing with a 'record your own phrase' function - 'record something and I'll sing it back to you' he proclaims innocently.....

 

MUCH hilarity ensued when we recorded swear words and a certain Detective McClane's favourite catchphrase for Beep-Bo to 'sing back to us'.... LOL Kids toys CAN be fun....

  • Thanks 1
  • 10 months later...
Posted

VTech flags tablet flaw after BBC Watchdog probe

 

Child gadget-maker VTech's website is promoting a security fix for its flagship tablet, following an investigation by BBC Watchdog Live.

 

The Storio Max - which is called the InnoTab Max in the UK - suffers a software flaw that could allow hackers to remotely take control of the device and snoop on its users.

 

VTech was alerted to the vulnerability months ago by a UK cyber-security firm.

 

The Chinese company issued a fix but some parents have yet to install it.

 

The notice at the top of its homepage and the broadcast of the BBC programme should ensure the issue gets more prominence.

 

It had previously relied on pop-up alerts that appeared on the devices themselves to prompt owners into action.

 

VTech said it was also contacting retailers that are selling affected units.

 

The issue has come to light nearly three years after the firm was criticised for its handling of a separate cyber-security incident that exposed millions of its child customers' account details.

 

Vtech markets the Max tablets to children aged between three and nine years old.

 

"This was a controlled and targeted 'ethical hack' by... a sophisticated cyber-firm that was in possession of a detailed knowledge of hacking techniques and InnoTab/Storio Max's firmware," said VTech in a statement about the latest incident.

 

"We are not aware of any actual attempt to exploit the vulnerability and we consider the prospects of this happening to be remote.

 

"However, the safety of children is our top priority and we are constantly looking to improve the security of our devices."

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...