https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Beware Hacker Bait Barbie

  • Written by Lorna Garey
  • December 4, 2015
Bluebox Labs finds that IoT security is not child’s play.

Step away from the Internet-connected toys, please.

Today Bluebox Labs, with independent researcher Andrew Hay, released a report showing major security issues in the iOS and Android versions of the Hello Barbie mobile app developed by Mattel partner ToyTalk, as well as in the wireless communications between the doll and the cloud-based servers that process audio uploads. These findings are on top of security issues in the doll itself that could let an attacker zero in on a child’s home address, according to NBC news. 

And of course, VTech Holdings recently lost records of 6.4 million children and 4.9 million adults.

Internet of Things security problems aren’t just theoretical, and it’s not difficult to imagine serious consequences of the Barbie app being modified to reveal confidential information, including passwords — a real possibility, says Bluebox.

The Wi-Fi-connected Barbie works by recording a child’s comments or questions, uploading the audio to the cloud, then returning artificial-intelligence-based responses to approximate a real-time conversation. It’s slick use of IoT tech, but unfortunately, the implementation is riddled with holes. Besides the possibility of revealing Wi-Fi passwords, the app will connect the doll to any unsecured Wi-Fi network that has “Barbie” in the name, allowing for an attacker to impersonate the Barbie AI network. Moreover, client certificate authentication credentials could be used outside of the app to probe Hello Barbie cloud servers to look for more vulnerabilities. And, the researchers say, the ToyTalk server domain was on a cloud infrastructure susceptible to the POODLE attack, meaning attackers could downgrade SSL connection security and listen in on the child’s uploaded audio conversation from the doll.

Fortunately, Bluebox Labs disclosed all critical security issues to ToyTalk, which has already resolved many problems. However, overall, the message is clear that mobile apps associated with IoT devices are a potential source of problems, and toymakers seem unwilling to expend the time and money required for secure application development or to integrate self-defending capabilities into mobile and IoT apps. Earlier this year, Bluebox released research showing security problems in nine of the most popular children’s tablets as well. If you send a newsletter to customers, warnings on IoT-related toy vulnerabilities are timely and worth including.

Got an innovative security or IoT project in the works? Entries are open now for our fourth annual Channel Partners’ 360° awards program. Follow editor in chief @LornaGarey on Twitter.

Tags: Agents Cloud IoT Mobility & Wireless Security

Most Recent


  • Cloud Curtain
    Microsoft Unveils Key Cloud Partner Program Enhancements
    Microsoft's chief partner officer outlined the new initiatives that include training and support.
  • Bankruptcy Court
    Avaya Reduces Debt by $2.6 Billion, Gets Closer to Emerging from Bankruptcy
    The company will be backed by its existing lenders.
  • Magic Quadrant Leaders: Fortinet, VMware, Cisco, More
    SASE Revenue Grows 34%, with Cisco, Zscaler, VMware Leading
    SSE grew 38% in revenue last year, while SD-WAN grew 30% in revenue. See who else made the list.
  • Welcome aboard
    Ivanti Expands Channel Leadership with Blue Prism, Edgio Vets
    The new hires are part of Ivanti’s new global channels and alliances leadership team.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Conflict Boxing Gloves
    Channel Conflict, Controversy: SolarWinds Hack, Racism, Layoffs, Zoom-RingCentral
  • Social media smartphone
    Social Media Roundup: Partners Talk Crypto, Security Hiring
  • PlanetOne Gainey Golf Event Feature
    PlanetOne Golf Event: In-Person Channel Networking Makes Big Comeback
  • DIY Network and Security Management 'Gotchas'

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Microsoft Unveils Key Cloud Partner Program Enhancements

March 22, 2023

The CF List: 2023’s 20 Top Threat Intelligence Providers You Should Know

March 22, 2023

Lumen Channel Leaders: Activation Incentives ‘Resonating’ with Partner Community

March 21, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

.@GoIvanti adds to channel leadership team with @blue_prism, @edgioinc vets. #automation dlvr.it/SlKYTp https://t.co/WBtK80tZcj

March 22, 2023
ChannelFutures

Although @DellOroGroup observes a "crowded" SASE market, only four vendors are actually providing truly a unified S… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

#Microsoft prepares partners for new #GPT4 in @Azure @OpenAI. @msPartner dlvr.it/SlKR6q https://t.co/TNRQHslQ72

March 22, 2023
ChannelFutures

The new @TDSYNNEX directory will include exclusive and premium benefits for CommunitySolv members.… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

Tim Mueller with @mw_advisors provides useful strategies for selling your MSP #channelpartners #msp #technews… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

"...everybody that's ever influenced me in my life has been somebody that's been willing to listen..." 📺 Hear from… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

Our latest #CFList includes top #threatintelligence providers, with @CrowdStrike, @kaspersky, @Microsoft,… twitter.com/i/web/status/1…

March 22, 2023
ChannelFutures

🤔 What if we told you that DE&I could help you stay competitive and propel your business forward? Join us on April… twitter.com/i/web/status/1…

March 21, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X