Contact Us
How to Access --- Employee Portal
Apply Now
Free Quotes
Open a Support -- Ticket
SecurityRI.com Internet Toy Risks

FBI Warns Parents: Your Kid’s Internet Smart Toys Could Be a Security Risk

While we continue to grow as a technology driven society, so doesn’t our children’s toys. Many smart toys in 2017 connect to the internet, and even though they’re extremely popular, they may introduce security risks to your children / family. As a cyber security company we encourage our community to follow the FBI’s instructions which is the following:

Consider cyber security prior to introducing smart, interactive, internet-connected toys into their homes or trusted environments. Smart toys and entertainment devices for children are increasingly incorporating technologies that learn and tailor their behaviors based on user interactions. These toys typically contain sensors, microphones, cameras, data storage components, and other multimedia capabilities – including speech recognition and GPS options. These features could put the privacy and safety of children at risk due to the large amount of personal information that may be unwittingly disclosed. – FBI

Why Does This Matter To My Family?

The features and functions of different toys vary widely. In some cases, toys with microphones could record and collect conversations within earshot of the device. Information such as the child’s name, school, likes and dislikes, and activities may be disclosed through normal conversation with the toy or in the surrounding environment. The collection of a child’s personal information combined with a toy’s ability to connect to the Internet or other devices raises concerns for privacy and physical safety. Personal information (e.g., name, date of birth, pictures, address) is typically provided when creating user accounts. In addition, companies collect large amounts of additional data, such as voice messages, conversation recordings, past and real-time physical locations, Internet use history, and Internet addresses/IPs. The exposure of such information could create opportunities for child identity fraud. Additionally, the potential misuse of sensitive data such as GPS location information, visual identifiers from pictures or videos, and known interests to garner trust from a child could present exploitation risks.

Consumers should examine toy company user agreement disclosures and privacy practices, and should know where their family’s personal data is sent and stored, including if it’s sent to third-party services. Security safeguards for these toys can be overlooked in the rush to market them and to make them easy to use. Consumers should perform online research of these products for any known issues that have been identified by security researchers or in consumer reports.

What Makes Internet-Connected Toys Vulnerable?

Data collected from interactions or conversations between children and toys are typically sent and stored by the manufacturer or developer via server or cloud service. In some cases, it is also collected by third-party companies who manage the voice recognition software used in the toys. Voice recordings, toy Web application (parent app) passwords, home addresses, Wi-Fi information, or sensitive personal data could be exposed if the security of the data is not sufficiently protected with the proper use of digital certificates and encryption when it is being transmitted or stored.

Smart toys generally connect to the Internet either:

  • Directly, through Wi-Fi to an Internet-connected wireless access point; or
  • Indirectly, via Bluetooth to an Android or iOS device that is connected to the Internet.

This information can be breached / hacked which may fall in the hands of the unwanted.

WHAT SHOULD I DO?

The FBI encourages consumers to consider the following recommendations, at a minimum, prior to using Internet-connected toys.

  • Research for any known reported security issues online to include, but not limited to:
  • Only connect and use toys in environments with trusted and secured Wi-Fi Internet access
  • Research the toy’s Internet and device connection security measures
    • Use authentication when pairing the device with Bluetooth (via PIN code or password)
    • Use encryption when transmitting data from the toy to the Wi-Fi access point and to the server or cloud
  • Research if your toys can receive firmware and/or software updates and security patches
    • If they can, ensure your toys are running on the most updated versions and any available patches are implemented
  • Research where user data is stored – with the company, third party services, or both – and whether any publicly available reporting exists on their reputation and posture for cyber security
  • Carefully read disclosures and privacy policies (from company and any third parties) and consider the following:
    • If the company is victimized by a cyber-attack and your data may have been exposed, will the company notify you?
    • If vulnerabilities to the toy are discovered, will the company notify you?
    • Where is your data being stored?
    • Who has access to your data?
    • If changes are made to the disclosure and privacy policies, will the company notify you?
    • Is the company contact information openly available in case you have questions or concerns?
  • Closely monitor children’s activity with the toys (such as conversations and voice recordings) through the toy’s partner parent application, if such features are available
  • Ensure the toy is turned off, particularly those with microphones and cameras, when not in use
  • Use strong and unique login passwords when creating user accounts (e.g., lower and upper case letters, numbers, and special characters)
  • Provide only what is minimally required when inputting information for user accounts (e.g., some services offer additional features if birthdays or information on a child’s preferences are provided) – FBI’s Website
0
Read More

Top Social Media Security Risks for Businesses & How to Avoid Them!

Top Social Media Security Risks for Businesses & How to Avoid

 

We live in a world today that everyone and most businesses use social media. Although, social media is great we need to ensure safety when using it. For instance, only 28% of the social network users update their privacy settings. Not updating your privacy setting or careless actions may lead to security breaches.

Here you will find the TOP  social media security risks for businesses and how you may avoid them:

  1. Human Error – Human error is the most common social media security threat. Disgruntled employees airing their dirty laundry or sharing inappropriate photos can put your company at risk, along with harming your reputation.
  2. Social Scams & Phishing AttacksPhishing attempts are up this year by 150%. Scammers are focusing on accounts because they can target hundreds of thousands of people at once, but also blend in with the crowd.
  3. Malicious Apps – The internet is filled with malicious software and it’s only getting worse. Spyware, for example, is any software that collects personal information or sends spam ads without your consent.
  4. Malware Attacks & Hacks
  5. Not Paying Attention on Social Media – Not being aware of your followers, receiving spam emails, etc.

Tips on How to Avoid

  1. Create a Social Media Policy for your business: Consider including guidelines on how to:
    • Create a secure password
    • Avoid spam, phishing attacks, and human error
    • Share on-brand and approved content
    • Engage properly on behalf of the brand
    • Avoid social media platforms’ default privacy and security settings
    • Proceed in the event of an attack
  2. Limit Social Media Access – Only give publishing access to employees who have been fully trained in the social policy, procedures, and technologies that protect your brand.
  3. Establish Training – Reinforce your social media policy with in-depth training. This will bring any potential issues or gaps in security to light.
  4. Put Someone in Charge or Outsource – Social media is a full time job. At least one person should be fully trained and educated in social media best practices or you can outsource to a reputable company.
  5. Invest in Secure Technology – With policy and education behind you, technology is the final piece of armor against social media security threats. Arm yourself with security software that automatically checks for malware, worms, viruses, and other cyber risks. Secure login information using passwords stronger than ‘Password1234’

In closing, social media opens a world of opportunity for your business to grow and connect with customers. Arm yourself against threats and go forward knowing you’ve done everything in your power to protect your business.

Be Safe!

0
Read More

Protect Your Website from Hackers

5 Tips When Securing Your Website

Website breaches happen every day, and we’re noticing many avoidable methods when they occur. During this blog, SecurityRI will point out five major key points when securing your website.

  1. Make sure your passwords are secure

It’s temping to go with the easy passwords, such as ABC or 123. Although, hackers can crack the common passwords within the blink of an eye. Ensure you’re using passwords with special characters and non-related to your user name, business or personal information.

  1. Use HTTPS

As a consumer, you may already know what a “secure” website looks like. It’s the “green” lock within the URL. If you have an online store, or if any part of your website will require visitors to hand over sensitive information like credit card numbers, you must invest in an SSL certificate. The cost to you is minor, but the extra level of encryption it offers will keep your customers safe along with your reputation. (more…)

0
Read More

Do Not Fall Victim!

Best Practices for Cyber Security in 2017

 

Many individuals believe in cyber security practice, although some people do not see the threats.  Why worry about something major if it never happened to you?

Well, statistics prove how damaging cyber threats are and how they can cripple your organization.  Please take note – not all cyber protection cost money.  If you believe in proper protocol and follow through with simple updates, you may protect yourself and others from future threats.

Here you will find a few simple preventative strategies (more…)

0
Read More
Locations

Corporate Headquarters
58 Waterman Avenue - North Providence RI 02911

MA Office
812 Sanford Road - Westport MA 02790

Toll Free: (888) 219-5296
Local: (401) 231-8130

Operating Live 24∙7∙365