{"id":62723,"date":"2017-08-21T00:00:00","date_gmt":"2017-08-21T00:00:00","guid":{"rendered":"http:\/\/blog.mozilla.org\/foxtail\/2017\/08\/21\/iot-surveillance\/"},"modified":"2021-02-03T01:11:16","modified_gmt":"2021-02-03T01:11:16","slug":"iot-surveillance","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/","title":{"rendered":"The dolls have ears"},"content":{"rendered":"<p>As our modern lives become more conveniently connected by \u201csmart\u201d phones, appliances, toys and the like, it\u2019s worth pausing to consider the privacy and security implications of inviting these devices into our homes.<\/p>\n<h2><b>Out of the mouths of baby dolls<\/b><\/h2>\n<p>Take, for example, the <a href=\"https:\/\/www.myfriendcayla.com\">My Friend Cayla doll<\/a>, an interactive toy that engages children in conversation. She connects via Bluetooth to an app installed on a phone or tablet. When children talk to her, Cayla records what they say and converts the audio recording into text. The text is then transmitted over the Internet to a third party database where it is used to look up answers, which are then relayed back to Cayla to speak.<\/p>\n<p>Within Cayla\u2019s app, children are also prompted to give personal information, including their name and their parents\u2019 names, their favorite toy, TV show and food, their school and where they live. Cayla uses this information to chat with children about their day, play games, answer questions and even offer instructions on how to bake a cake.<\/p>\n<p>How secure is Cayla and the data she collects? Not secure enough, according to Germany\u2019s Federal Network Agency, which <a href=\"https:\/\/www.bundesnetzagentur.de\/SharedDocs\/Pressemitteilungen\/EN\/2017\/17022017_cayla.html\">banned the toy<\/a> earlier this year:<\/p>\n<blockquote><p>\u201cThere is a particular danger in toys being used as surveillance devices: Anything the child says or other people&#8217;s conversations can be recorded and transmitted without the parents&#8217; knowledge. A company could also use the toy to advertise directly to the child or the parents. Moreover, if the manufacturer has not adequately protected the wireless connection (such as Bluetooth), the toy can be used by anyone in the vicinity to listen in on conversations undetected.\u201d<\/p><\/blockquote>\n<p>In the United States, a group of consumer advocates has <a href=\"https:\/\/epic.org\/privacy\/kids\/EPIC-IPR-FTC-Genesis-Complaint.pdf\">filed a complaint<\/a> with the U.S. Federal Trade Commission, requesting an investigation into the toy.<\/p>\n<blockquote><p>\u201cThis complaint concerns toys that spy. By purpose and design, these toys record and collect the private conversations of young children without any limitations on collection, use, or disclosure of this personal information. The toys subject young children to ongoing surveillance and are deployed in homes across the United States without any meaningful data protection standards. They pose an imminent and immediate threat to the safety and security of children in the United States.\u201d<\/p><\/blockquote>\n<p>The BBC also covered the story, talking with security researchers at <a href=\"https:\/\/www.pentestpartners.com\/security-blog\/making-childrens-toys-swear\/\">Pen Test Partners<\/a> to get an inside look at how vulnerable Cayla is to hacking.<\/p>\n<p><iframe loading=\"lazy\" title=\"BBC News   What did she say ! Talking doll  ;Cayla ; is hacked\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/K8jAMTjz1dw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe><\/p>\n<h2><b>Don\u2019t play dumb about smart devices<\/b><\/h2>\n<p>In July this year, the U.S. Federal Bureau of Investigation issued an <a href=\"https:\/\/www.ic3.gov\/media\/2017\/170717.aspx\">alert to consumers<\/a> that Internet connected toys could pose a security and privacy risk in the home. While the weaknesses in the Cayla doll are alarming, Internet of Things (IoT) products are here to stay, and usage is growing. The number of\u00a0 devices is projected to reach over 46 billion by 2021, <a href=\"https:\/\/www.juniperresearch.com\/press\/press-releases\/%E2%80%98internet-of-things%E2%80%99-connected-devices-to-triple-b\">according to Juniper Research<\/a>.<\/p>\n<p>But just because a doll can be hacked doesn\u2019t mean IoT is destined for a bleak future. If there\u2019s an immediate take away, it\u2019s that <a href=\"https:\/\/www.mozilla.org\/about\/policy\/lean-data\/\">manufacturers must be more responsible about data collection and storage<\/a>, and consumers must be vigilant and demand higher security standards.<\/p>\n<h2><b>What do you think?<\/b><\/h2>\n<p>As part of Mozilla\u2019s work keeping the Internet safe, secure and healthy, we\u2019re asking you to share your thoughts.<\/p>\n<p><a href=\"https:\/\/www.surveygizmo.com\/s3\/3643927\/091fb5d9e0e1\"><strong>Take our quick survey<\/strong><\/a><strong> to let us know how you feel about being connected.<\/strong><\/p>\n<p>Your input helps Mozilla to run advocacy campaigns, to create web literacy curriculum and more. We\u2019ll share the results in a few weeks. Your responses will help us understand how we can work together to create a safer connected future for us all.<\/p>\n<table bgcolor=\"#d7d9f2\">\n<tbody>\n<tr>\n<td>\n<h2><img decoding=\"async\" loading=\"lazy\" class=\"alignleft wp-image-408\" src=\"http:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/06\/moz_podcast_IRLwVB_cover_300x300-150x150.png\" alt=\"IRL with Veronica Belmont\" width=\"300\" height=\"300\" \/>Get more\u00a0real talk<\/h2>\n<p>We react against the idea of surveillance, but it turns out that we\u2019ve invited it into our homes through devices like digital assistants, connected toys and baby monitors. Are you comfortable with the idea that someone might be watching you or listening to you right now?<\/p>\n<p>Listen as we explore these issues in <a href=\"https:\/\/irlpodcast.org\/episode5\/?utm_source=internetcitizen&amp;utm_medium=blog&amp;utm_campaign=irl&amp;utm_content=dollshaveears\">I Spy With My Digital Eye<\/a>, the latest episode of IRL, an original podcast from Mozilla, hosted by Veronica Belmont.<\/p>\n<p>Find IRL on our <a href=\"https:\/\/irlpodcast.org\/?utm_source=internetcitizen&amp;utm_medium=blog&amp;utm_campaign=irl&amp;utm_content=dollshaveears\">Website<\/a>, and subscribe wherever you get your podcasts.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>As our modern lives become more conveniently connected by \u201csmart\u201d phones, appliances, toys and the like, it\u2019s worth pausing to consider the privacy and security implications of inviting these devices into our homes. Out of the mouths of baby dolls Take, for example, the My Friend Cayla doll, an interactive toy that engages children in [&hellip;]<\/p>\n","protected":false},"author":727,"featured_media":20463,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[464058],"tags":[],"coauthors":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>My Friend Cayla | The Dolls Have Ears | Mozilla Internet Citizen<\/title>\n<meta name=\"description\" content=\"How secure is the Cayla doll and the data she collects? Not secure enough, says Germany\u2019s Federal Network Agency, which banned the toy earlier this year.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/\",\"url\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/\",\"name\":\"My Friend Cayla | The Dolls Have Ears | Mozilla Internet Citizen\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/08\/moz_social_surveillance_creepy-noir_spies.png\",\"datePublished\":\"2017-08-21T00:00:00+00:00\",\"dateModified\":\"2021-02-03T01:11:16+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c\"},\"description\":\"How secure is the Cayla doll and the data she collects? Not secure enough, says Germany\u2019s Federal Network Agency, which banned the toy earlier this year.\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#primaryimage\",\"url\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/08\/moz_social_surveillance_creepy-noir_spies.png\",\"contentUrl\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/08\/moz_social_surveillance_creepy-noir_spies.png\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The dolls have ears\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/en\/\",\"name\":\"The Mozilla Blog\",\"description\":\"News and Updates about Mozilla\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c\",\"name\":\"M.J. Kelly\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/image\/70718b02fa9f11d88288b937f1da2ac1\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g\",\"caption\":\"M.J. Kelly\"},\"description\":\"Mozilla Communications\",\"url\":\"https:\/\/blog.mozilla.org\/en\/author\/mjkellymozilla-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"My Friend Cayla | The Dolls Have Ears | Mozilla Internet Citizen","description":"How secure is the Cayla doll and the data she collects? Not secure enough, says Germany\u2019s Federal Network Agency, which banned the toy earlier this year.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/","url":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/","name":"My Friend Cayla | The Dolls Have Ears | Mozilla Internet Citizen","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#primaryimage"},"image":{"@id":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/08\/moz_social_surveillance_creepy-noir_spies.png","datePublished":"2017-08-21T00:00:00+00:00","dateModified":"2021-02-03T01:11:16+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c"},"description":"How secure is the Cayla doll and the data she collects? Not secure enough, says Germany\u2019s Federal Network Agency, which banned the toy earlier this year.","breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#primaryimage","url":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/08\/moz_social_surveillance_creepy-noir_spies.png","contentUrl":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2017\/08\/moz_social_surveillance_creepy-noir_spies.png","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/en\/internet-culture\/deep-dives\/iot-surveillance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/en\/"},{"@type":"ListItem","position":2,"name":"The dolls have ears"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/en\/#website","url":"https:\/\/blog.mozilla.org\/en\/","name":"The Mozilla Blog","description":"News and Updates about Mozilla","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c","name":"M.J. Kelly","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/image\/70718b02fa9f11d88288b937f1da2ac1","url":"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g","caption":"M.J. Kelly"},"description":"Mozilla Communications","url":"https:\/\/blog.mozilla.org\/en\/author\/mjkellymozilla-com\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts\/62723"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/users\/727"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/comments?post=62723"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts\/62723\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/media\/20463"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/media?parent=62723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/categories?post=62723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/tags?post=62723"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/coauthors?post=62723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}