German Regulators Urge Parents To Destroy WiFi Connected Doll Over Surveillance Fears

from the barbie-needs-a-new-firewall dept

For a while now, we’ve discussed how your children’s toys are quickly becoming the latest and greatest privacy threat courtesy of cryptic or half-cooked privacy policies and the treatment of device security as an afterthought; rather part and parcel now for the privacy dumpster fire that is the internet of not-so-smart things era. Numerous privacy groups have complained that smart Barbies and other toys not only now hoover up and monetize childrens’ prattle, but leave the door open to the devices’ being used nefariously by third parties.

The problems culminated in a lawsuit last December here in the States against Genesis Toys, maker of “smart” toys like the My Friend Cayla doll and the i-Que Intelligent Robot. The lawsuit accuses the company of violating COPPA (the Childrens’ Online Privacy Protection Act of 1998) by failing to adequately inform parents that their kids’ conversations and personal data collected by the toys are being shipped off to servers and third-party companies. The privacy policy for the toys does warn users that companies like Nuance Communications, also a government defense contractor, will receive this data for analysis:

“We may use the information that we collect for our internal purposes to develop, tune, enhance, and improve our products and services, and for advertising and marketing consistent with this Privacy Policy.” It continues, ?If you are under 18 or otherwise would be required to have parent or guardian consent to share information with Nuance, you should not send any information about yourself to us.”

The lawsuit alleges the toys are violating COPPA because they’re marketed to “ages 4 and up” and being mostly used by kids under age 18. Under COPPA, companies gathering kids’ data have to provide notice to, and obtain consent from parents regarding data collection. They also have to provide parents tools to access, review and delete this data if wanted, as well as the parental ability to dictate that the data can be collected, but not shared with third parties. The complaint suggests neither Nuance or Genesis Toys are doing any of this.

But Genesis is also under fire for the fact that these toys just aren’t all that secure. A report by the Norwegian Consumer Council (pdf) found that a lot of the data being transmitted by these toys is done so via vanilla, unencrypted HTTP connections that could be subject to man-in-the-middle attacks.

While Genesis faces a lawsuit here in the States, the FTC has yet to act against the company. Overseas however, German regulators are taking a different tack and urging parents to destroy the data-collecting dolls entirely:

“An official watchdog in Germany has told parents to destroy a talking doll called Cayla because its smart technology can reveal personal data. The warning was issued by the Federal Network Agency (Bundesnetzagentur), which oversees telecommunications. Researchers say hackers can use an unsecure bluetooth device embedded in the toy to listen and talk to the child playing with it.

As it stands, German regulators say that a bluetooth-enabled device could connect to Cayla’s speaker and microphone system within a radius of 33 feet. As a result, the doll is being effectively treated as a “concealed transmitting device,” illegal under an article in German telecom law. A spokesman for the Federal Network Agency said it doesn’t really matter what shape the device took; “it could be an ashtray or fire alarm” and would still be illegal. While demanding destruction of the dolls may be overkill, it’s just another example of how privacy and security apathy continue to haunt the IoT space.

Filed Under: , , , , ,
Companies: genesis toys

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “German Regulators Urge Parents To Destroy WiFi Connected Doll Over Surveillance Fears”

Subscribe: RSS Leave a comment
Roger Strong (profile) says:

Up next:

  • DHS demands your My Friend Cayla doll’s MAC address at the border.

  • The FBI demands access to the doll’s cloud servers because terrorists.

  • Music collecting societies realize that the audio captured by the dolls might include music, and start demanding royalties.

  • Google uses IFTTT to connect the doll to the self-driving car they place it in, to make it appear that the doll is driving. Highway patrol officers declare the doll’s behavior "suspicious", and the car is taken via civil asset forfeiture.
Anonymous Coward says:

Should return to manufacturer, not destroy

If the purchaser destroys the doll, the manufacturer presumably gets to keep money for the product, even though they knew or reasonably should have known the product was illegal. It would be better to wipe the doll’s tiny mind, then return it for a full refund. That leaves the manufacturer with a product they should have known better than to sell, and no money from the early sales to uninformed buyers.

Roger Strong (profile) says:

Re: Should return to manufacturer, not destroy

The manufacturer would almost certainly be in a different country with different laws. It’s often an import company further down the supply chain that’s responsible for ensuring that the product meets your local country’s laws, power requirements, radio frequencies etc. Even the big brand names are often just customers; the product will be sold under other brand names.

Neither the manufacturer nor the importer sold it to you, so they’re under no obligation to take it back. If they did take it back, the per-item amount they sold it to the distributor for will be a fraction of what you paid for it.

McGyver (profile) says:

"Highly unlikely" until it's "highly common"...

“We are aware of the Which? report, but understand the circumstances in which these investigations have taken place rely on a perfect set of circumstances and manipulation of the toys and the software that make the outcome highly unlikely in reality.”

So… “We are not going to do anything about it until something really bad happens and it looks like we are going to be held criminally responsible”…

Obviously not enough people got pissed off that the “My friend Cayla” doll and her robot counterpart were collecting data from children’s conversations and using it without consent.

And some people think this is all okay or use “whataboutism” to deflect criticism and a cautious approach.

The point is, if you don’t make a BIG stink about it now, it becomes a huge problem later… Regardless of how “highly unlikely” it may or may not be AT THE MOMENT in the opinion of the manufacturers…

Give these companies an inch and they’ll take a mile, if not immediately, very shortly…

Hey, how long ago were EULAs just a understandable agreement not to redistribute the software and not these current agreements that you own nothing, can repair nothing and have zero rights… Remember all the wise and trusting know-it-alls who insisted “just click agree” and that we would never be where we are today?

Haven’t we seen enough blazing dumpster fires of incompetence, indifference, greed and arrogance lately to at least be mindful that however “unlikely” someone claims something may be, that it often does eventually occur?

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...