Another Lawsuit Highlights How Many 'Smart' Toys Violate Privacy, Aren't Secure
from the Barbie-is-a-rat dept
So we've talked a bit about the privacy implications of smart toys, and the fact that people aren't exactly thrilled that Barbie now tracks your childrens' behavior and then uploads that data to the cloud. Like most internet-of-not-so-smart things, these toys often come with flimsy security and only a passing interest in privacy. As such we've increasingly seen events like the Vtech hack, where hackers obtained the names, email addresses, passwords, and home addresses of 4,833,678 parents, and the first names, genders and birthdays of more than 200,000 kids.Unsurprisingly, the collection of kids' babbling while in the company of smart toys continues to ruffle feathers. This week, a coalition of consumer advocates including the Consumer's Union filed suit against Genesis Toys, the maker of two such toys, the My Friend Cayla doll and the i-Que Intelligent Robot. According to the full lawsuit (pdf), the toy maker is violating COPPA (the Childrens’ Online Privacy Protection Act of 1998) by failing to adequately inform parents' that their kids conversations and personal data collected by the toys are being shipped off to servers and third-party companies.
Among the problems cited in the complaint is that the privacy policies governing the collection of kids' data aren't clear, aren't prominently displayed, and often change without notice. Parents aren't properly informed that data is being culled from the toys and sent off to companies like Nuance Communications, most commonly known for its Dragon voice recognition software, but a company that also has prominent roles in healthcare dictation and as a defense contractor. Both toys by proxy are governed by Nuance's privacy policy, which among other things says:
"We may use the information that we collect for our internal purposes to develop, tune, enhance, and improve our products and services, and for advertising and marketing consistent with this Privacy Policy." It continues, “If you are under 18 or otherwise would be required to have parent or guardian consent to share information with Nuance, you should not send any information about yourself to us."With the toys being marketed to "ages 4 and up" and being mostly used by kids under age 18, the lawsuit states the companies selling and collecting this toy data are violating COPPA. Under COPPA, companies gathering kids data have to provide notice to, and obtain consent from parents regarding data collection. They also have to provide parents tools to access, review and delete this data if wanted, as well as the parental ability to dictate that the data can be collected, but not shared with third parties. The complaint suggests neither Nuance or Genesis Toys are doing any of this.
And again, privacy is just part of the equation. There's also the fact that these toys just aren't all that secure. A report by the Norwegian Consumer Council (pdf) found that a lot of the data being transmitted by these toys is done so via vanilla, unencrypted HTTP connections that could be subject to man in the middle attacks. Reconfiguring the devices to create in-home surveillance tools was also "very easy and requires little technical know-how," according to the report.So again, much like all internet of things devices, companies were so excited to integrate internet connectivity, they effectively forgot about user privacy and security. Are we perhaps noticing a ongoing theme yet?
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: coppa, i-que intelligent robot, iot, my friend cayla, privacy, security, smart toys
Companies: genesis toys, nuance
Reader Comments
Subscribe: RSS
View by: Time | Thread
I must not get out much...
[ link to this | view in chronology ]
Re: I must not get out much...
[ link to this | view in chronology ]
Wrong attack
Actually, such connections are subject to passive eavesdropping attacks. As in your neighbor simply monitoring the WiFi transmissions.
But still, as highlighted in the post, by far the greatest danger is not using HTTP, it's that the party receiving the information is probably not capable of protecting it properly.
[ link to this | view in chronology ]
Re: Wrong attack
[ link to this | view in chronology ]
Blame Rule 41
-- FBI Snitch Barbie
[ link to this | view in chronology ]
Does it count as making terrorist threats if you're playacting with a doll?
...Why is it that while I was reading this post, my first thought was to use it as a means to spread malicious slander?
[ link to this | view in chronology ]
Re: Does it count as making terrorist threats if you're playacting with a doll?
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Re:
Nothing to fear but fear itself.
[ link to this | view in chronology ]
[ link to this | view in chronology ]
[ link to this | view in chronology ]
[ link to this | view in chronology ]
[ link to this | view in chronology ]
“If you are under 18 or otherwise would be required to have parent or guardian consent to share information with Nuance, you should not send any information about yourself to us."
But, but... Didn't opening the shrinkwrap on the package mean consent was given?
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Mommy, can I play with your toy?
https://www.cnet.com/news/internet-connected-vibrator-we-vibe-lawsuit-privacy-data/
[ link to this | view in chronology ]
Not even that much attention is paid to security and privacy. These companies don't care because they can get away with it and pocket extra money from selling the information they glean. THey have absolutely no reason to do otherwise and every reason to squeeze as much profit they can "for the shareholders" out of these products. Until these companies can be held financially accountable for these practices, to the tune of sacrificing the entire gross profit (to keep them from arguing net profits are negligible like the film industry thanks to corporate shell games and creative accounting) this isn't going to change.
[ link to this | view in chronology ]