Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

AI toy leaked 50,000 chat records with children: anyone could access them via a Gmail account

AI toy maker Bondu left its web console almost completely unsecured, and researchers who accessed it found recordings of virtually every conversation children had with their stuffed animals.

Leave a comment
AI toy leaked 50,000 chat records with children: anyone could access them via a Gmail account

AI toy maker Bondu left its web console almost completely unsecured, and researchers who accessed it found recordings of virtually every conversation children had with their stuffed animals.

In January, cybersecurity researcher Joseph Tucker was approached by his neighbor asking him to check the safety of an AI toy she had ordered for her children, writes Ars Technica.

These are plush dinosaurs from Bondu, which have an AI chat function that allows children to communicate with the toy as a kind of "imaginary friend."

After spending just a few minutes on the job, Joseph Tucker and his friend, web security researcher Joel Margolis, made a startling discovery: the Bondu web portal, designed to allow parents to monitor their children's conversations and company staff to monitor the operation of toys, also allowed anyone with a Gmail account to view transcripts of virtually every conversation that young users had ever had with the toy.

Without any hacking, just by logging in with a random Google account, two researchers instantly saw the children's private conversations. They were exposed to the affectionate nicknames the little ones gave their Bondu, the likes and dislikes of the little toy owners, their favorite treats and dance moves.

Overall, the researchers found that this data included the children's names, their dates of birth, the names of family members, the child's developmental "goals" chosen by the parents, and, most disturbingly, detailed reports and full transcripts of all previous conversations between the child and their Bondu. This toy was actually designed to encourage intimate face-to-face communication.

In conversations with researchers, Bondu confirmed that over 50,000 chat transcripts were available through an open web portal—essentially every conversation the toys had ever had, except for those that had been manually deleted by parents or staff.

According to Tucker and Margolis, when they alerted Bondu to the blatant data vulnerability, the company responded immediately and within minutes, took down the console. The portal was relaunched the next day with proper authentication measures in place.

Bondu CEO Fatin Anam Rafid said the security fixes “were completed within hours, followed by a broader security audit and additional preventative measures for all users.” He also added that the company “found no evidence of third-party access to data beyond the aforementioned researchers.”

An AI animal that learns from its owner: Casio introduced the interactive toy Moflin
An AI animal that learns from its owner: Casio introduces the interactive toy Moflin
On the topic
An AI animal that learns from its owner: Casio introduces the interactive toy Moflin
A new version of the digital toy Tamagotchi was introduced in Tokyo. And the most interesting thing is that its body is made of eggshells.
A new version of the digital toy Tamagotchi was introduced in Tokyo. And the most interesting thing is that its body is made of eggshells.
On the topic
A new version of the digital toy Tamagotchi was introduced in Tokyo. And the most interesting thing is that its body is made of eggshells.
An engineer from Germany has modified a toy car that is now capable of reaching a top speed of 14,845 km/h
An engineer from Germany has modified a toy car, which is now capable of reaching a top speed of 148.45 km/h
On the topic
An engineer from Germany has modified a toy car, which is now capable of reaching a top speed of 148.45 km/h
UI designer Boolat Play creates the world of Japanese Sylvanian Families toys. How a hobby helps her concentrate and distract her from everything bad
UI designer Boolat Play creates the world of Japanese Sylvanian Families toys. How a hobby helps her concentrate and distract her from everything bad
On the topic
UI designer Boolat Play creates the world of Japanese Sylvanian Families toys. How a hobby helps her concentrate and distract her from everything bad
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram
Also Read
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Roosh запускає нову освітню платформу AI HOUSE CLUB для ML/AI-спеціалістів та дата сайнтистів. Розповідаємо, як подати заявку та чому навчатимуть
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Як нейромережі бачать вільну та незалежну Україну? Тест dev.ua
Нейронні мережі для генерації зображень бачать світ по-своєму, їхню логіку зрозуміти часом зовсім неможливо. Але таки хочеться. На честь Дня Незалежності України редакція dev.ua вирішила провести невеликий експеримент. Ми задали чотирьом різним нейронним мережам п’ять однакових запитів: «прапор України», «День Незалежності України», «український Крим», «перемога України» та «українці». Отриманими результатами ми ділимося з вами нижче.
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok тепер можна генерувати фон за допомогою нейромережі. Ми протестували її та ділимося результатами
У TikTok з’явилася нова функція «Розумний фон». З її допомогою як фон для тіктоків можна підставляти згенеровані нейромережею зображення. Редакція dev.ua протестувала цю технологію і ділиться своїми враженнями.
1 comment
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака
Які IT-спеціальності будуть потрібні в найближчі п'ять років? Ми з'ясували у голови американського стартапу ADAM Дениса Гурака

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.