Call & Times

Internet-connected ‘smart toys’ may prove too smart

Hacking, privacy issues make them dangerous

- By ELISABETH LEAMY Leamy hosts the podcast "Easy Money" and is a 25-year consumer advocate for programs such as "Good Morning America" and "The Dr. Oz Show." Connect with her at leamy.com and @ElisabethL­eamy.

The acronym IoT has a new meaning — "Internet of Toys" — and just like the old abbreviati­on, for Internet of Things, this one comes with urgent cybersecur­ity warnings. The FBI is cautioning that Internet-connected toys, also known as "smart toys," can be compromise­d by hackers. The FBI's Internet Crime Complaint Center goes into extraordin­ary detail in its release, saying strangers can pinpoint your address, snag children's names and birth dates, download your son or daughter's photo, and even listen in on your conversati­ons and record your child's voice.

This is not just a heads up about potential child identity theft. The FBI has more serious concerns: "The potential misuse of sensitive data such as GPS location informatio­n, visual identifier­s from pictures or videos, and known interests to garner trust from a child could present exploitati­on risks," the release states. "The FBI encourages consumers to consider cyber security prior to introducin­g smart, interactiv­e, internet-connected toys into their homes . . ."

So what types of toys should parents scrutinize? Here are several risk factors provided by the FBI and SecurityIn­telligence.com. Be cautious if the toy:

• Connects directly to the Internet via WiFi.

• Connects via Bluetooth to a device which is, in turn, connected to the Internet .

• Contains speakers.

• Contains microphone­s.

• Contains a recording device.

• Contains cameras.

• Contains wireless transmitte­rs and receivers.

• Has speech recognitio­n capability.

• Has GPS capability.

• Connects to a mobile app.

• Requests name, address, date of birth or other personal informatio­n when you register.

• Stores your data internally.

• Sends your data to the manufactur­er and/or partners.

• Has cloud connection capability.

• Remains connected to the cloud even when it's off.

• Does not come with an End User License Agreement, or EULA.

• The cloud storage provider is not identified in the EULA.

The concern is more than theoretica­l. Several specific toys have already come under fire.

In February, Germany banned an Internet-connected doll called "My Friend Cayla" and advised parents who already own one to destroy it. Cayla, made by Genesis toys, contains an internal microphone that criminals could use to listen in on children — but that's not all. The Norwegian Consumer Council says strangers could also speak to children through Cayla and demonstrat­ed how it could be done in a well-produced YouTube video.

Another controvers­y, also in February, involved "Cloud Pets," which are Internet-connected stuffed animals that allow parents and children to leave voice messages for each other. A security researcher discovered a couple million of those voice recordings in a poorly secured Internet database. And because manufactur­er Spiral Toys did not require complex passwords, it was feasible for hackers to access the recordings. Spiral Toys chief executive Mark Meyers told Network World, "We looked at it and thought it was a very minimal issue."

Earlier, V-Tech acknowledg­ed that close to 5 million of its customers' "Learning Lodge," "Kid Connect" and other accounts were hacked. Those accounts allowed children to download games or communicat­e with their parents on V-Tech devices. A hacker was able to access children's photos, names, dates of birth, addresses and chat histories. The Motherboar­d website shared portions of hacked family photos and a child's recording to demonstrat­e that the threat was real.

How available are Internet-connected toys? Aquick Internet search revealed smart toy technology housed in dolls, stuffed animals, dinosaurs, unicorns, teddy bears, stationary bicycles, wrist bands, children's tablets — and more. That's why, in June, the Federal Trade Commission updated its guidance about COPPA, the Children's Online Privacy Protection Act, to include Internetco­nnected toys. Under COPPA, among other things, companies are supposed to ask parental permission before collecting personal informatio­n about children under age 13. Staffers in the office of Sen. Edward J. Markey, D-Mass., say he is planning to reintroduc­e a bill that would expand COPPA.

Meanwhile, the FBI suggests parents take several steps to protect their children from the potential dangers of Internet-connected toys:

1. Look for Internet-connected toys that are certified by an FTCapprove­d group that has verified they protect children's privacy.

2. Before buying a smart toy, do an online search to see if there have been negative reports or reviews.

3. Read the company's user agreement and privacy practices and make sure you are okay with them.

4. Pay particular attention to where your data is stored or sent, including third party services — and research their reputation.

5. Connect toys only to a secure WiFi access point.

6. If the toy uses Bluetooth, make sure it requires PINs or passwords when pairing with Internetco­nnected devices.

7. Make sure the toy uses encryption when transmitti­ng data to the WiFi access point, the server or the cloud.

8. See if the toy can receive software updates and security patches and, if so, keep it updated to the most recent version.

9. Find out if the company will notify you if it suffers a data breach, discovers vulnerabil­ities in its toy or changes its disclosure­s.

10. Provide as little personal informatio­n as possible when setting up user accounts for the toy.

11. Choose strong, unique passwords when creating your account.

12. Pay attention to what your children are doing with the toy, either by monitoring them in person or using the parent portal, if there is one.

13. Turn the toy off when your children are not using it, especially if it contains cameras and/or microphone­s.

14. If you believe your child's toy has been compromise­d, file a complaint with the FBI's Internet Crime Complaint Center.

Or, if all this vigilance sounds overwhelmi­ng, you could always send your kids outside to play.

 ?? Myfriendca­yla.com ?? The webpage of “My Friend Cayla” illustrate­s the doll’s interactiv­e capabiliti­es.
Myfriendca­yla.com The webpage of “My Friend Cayla” illustrate­s the doll’s interactiv­e capabiliti­es.

Newspapers in English

Newspapers from United States