{"id":4445,"date":"2017-03-01T23:25:51","date_gmt":"2017-03-01T15:25:51","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=4445"},"modified":"2017-03-01T23:26:04","modified_gmt":"2017-03-01T15:26:04","slug":"another-mongodb-hack-leaks-two-million-recordings-of-kids","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2017\/03\/another-mongodb-hack-leaks-two-million-recordings-of-kids\/","title":{"rendered":"Another MongoDB Hack Leaks Two Million Recordings Of Kids"},"content":{"rendered":"

No surprises here, but there’s been another big MongoDB hack and from the looks of it, it’s been owned for quite some time. This time 2 million records from over 820,000 accounts have been leaked due to yet another default MongoDB installation with no authentication listening on the public IP address.<\/p>\n

\"Another<\/p>\n

The terrible part is, this has been happening for a while, the company has known about it and done nothing to secure it. What I suspect is if they turned auth on, the bears would probably stop working, and they couldn’t do that could they? I imagine they don’t have a firmware push facility built in to the bear.<\/p>\n

Two million voice recordings of kids and their families were exposed online and repeatedly held to ransom \u2013 because an IoT stuffed-toy maker used an insecure MongoDB installation.<\/p>\n

Essentially, the $40 cuddly CloudPets feature builtin microphones and speakers, and connect to the internet via an iOS or Android app on a nearby smartphone or tablet. Families can use the fake animals to exchange voice messages between their children, friends, and relatives.<\/p>\n

For example, a parent away on a work trip can open the CloudPets app on their smartphone, record an audio message, and beam it to their kid’s toy via a tablet within Bluetooth range of the gizmo at home; the recording plays when the tyke press a button on the animal’s paw.<\/p>\n

Similarly, the youngsters can record messages using the stuffed creature, and send the audio over to their mom, dad, grandparent, and so on, via the internet-connected app.<\/p><\/blockquote>\n