Web portal leaves kids’ chats with AI toy open to anyone with Gmail account



Earlier this month, Joseph Thacker’s neighbor mentioned to him that she’d preordered a couple of stuffed dinosaur toys for her children. She’d chosen the toys, called Bondus, because they offered an AI chat feature that lets children talk to the toy like a kind of machine-learning-enabled imaginary friend. But she knew Thacker, a security researcher, had done work on AI risks for kids, and she was curious about his thoughts.

So Thacker looked into it. With just a few minutes of work, he and a web security researcher friend named Joel Margolis made a startling discovery: Bondu’s web-based portal, intended to allow parents to check on their children’s conversations and for Bondu’s staff to monitor the products’ use and performance, also let anyone with a Gmail account access transcripts of virtually every conversation Bondu’s child users have ever had with the toy.

Without carrying out any actual hacking, simply by logging in with an arbitrary Google account, the two researchers immediately found themselves looking at children’s private conversations, the pet names kids had given their Bondu, the likes and dislikes of the toys’ toddler owners, their favorite snacks and dance moves.

In total, Margolis and Thacker discovered that the data Bondu left unprotected—accessible to anyone who logged in to the company’s public-facing web console with their Google username—included children’s names, birth dates, family member names, “objectives” for the child chosen by a parent, and most disturbingly, detailed summaries and transcripts of every previous chat between the child and their Bondu, a toy practically designed to elicit intimate one-on-one conversation. Bondu confirmed in conversations with the researchers that more than 50,000 chat transcripts were accessible through the exposed web portal, essentially all conversations the toys had engaged in other than those that had been manually deleted by parents or staff.



Source link

  • Related Posts

    Malicious packages for dYdX cryptocurrency exchange empties user wallets

    Open source packages published on the npm and PyPI repositories were laced with code that stole wallet credentials from dYdX developers and backend systems and, in some cases, backdoored devices,…

    More Than 800 Google Workers Urge Company to Cancel Any Contracts With ICE and CBP

    More Than 880 employees and contractors working for Google signed a petition this week calling on the company to disclose and cancel any contracts it may have with US immigration…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Did they hit a nerve? OpenAI CEO Sam Altman’s response to ‘authoritarian’ Anthropic’s annihilation of ads-supported AI doesn’t make me trust it more

    Did they hit a nerve? OpenAI CEO Sam Altman’s response to ‘authoritarian’ Anthropic’s annihilation of ads-supported AI doesn’t make me trust it more

    Winter Olympics 2026 opening ceremony recap: Let the Games begin! Team Canada gets 'huge cheers' from Milan during showcase of Italian culture

    Winter Olympics 2026 opening ceremony recap: Let the Games begin! Team Canada gets 'huge cheers' from Milan during showcase of Italian culture

    2026 Winter Olympics opening ceremony: Best moments from Milan

    2026 Winter Olympics opening ceremony: Best moments from Milan

    Can government coerce women into having more babies?

    Can government coerce women into having more babies?

    Marine Layer on Brick-and-Mortar, Sustainability & B Corp Values

    Marine Layer on Brick-and-Mortar, Sustainability & B Corp Values

    Malicious packages for dYdX cryptocurrency exchange empties user wallets

    Malicious packages for dYdX cryptocurrency exchange empties user wallets