Parents should take their time to ponder how good an idea it is to give smart toys to their kids. Security researchers have reported another connected product that comes with security flaws that affect privacy and safety of kids, demonstrating how it could mistreat them with offensive language.
Teksta Toucan smart toy, equipped with speakers and a microphone, can act as a two-way communication tool via a companion app installed on a Bluetooth-enabled device. The toy can play audio messages recorded by the app and send back the sound picked up by the built-in microphone.
The toy comes from the same manufacturer as the My Friend Cayla doll and ti-Que robot, which have either been banned or are on probation by data protection agencies in Europe. The sanction and the official notification to comply with data privacy laws result from the possibility to use the toys to listen in on conversations around them.
Bluetooth-enabled gadgets can connect to the toys without authenticating first, based on their proximity and connection history; Teksta Toucan works in the same way, so anyone near the toy can pair with it. Researchers from Pen Test Partners warn that the lack of authentication could allow a third party to spy on your kids and your house. For this reason, they contacted the German telecommunications regulator (Bundesnetzagentur), hoping they would also ban the talking toucan.
The modern toys no longer function within the limits of scripted responses, instead embracing the latest technology to provide more interactive features. They can access the internet, either directly or through a companion mobile app, interact with children through speech recognition software, process voice patterns, and offer a communication channel with parents. The information collected and handled this way is sensitive enough to warrant security measures; all the more when kids are involved.
Parents should be