{"id":13828,"date":"2018-11-14T10:45:13","date_gmt":"2018-11-14T18:45:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/11\/14\/news-7595\/"},"modified":"2018-11-14T10:45:13","modified_gmt":"2018-11-14T18:45:13","slug":"news-7595","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/11\/14\/news-7595\/","title":{"rendered":"Mozilla&#8217;s &#8216;Privacy Not Included&#8217; Gift Report Highlights Security Concerns"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5beb6aa80eb20a52df543cd1\/master\/pass\/BebopParrot2-583760424.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Wed, 14 Nov 2018 16:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">A good rule <\/span>of thumb when it comes to internet-connected toys is <a href=\"https:\/\/www.wired.com\/story\/dont-gift-internet-connected-toys\/\">not to buy them<\/a>. Security too often sits too low on the priority list of the companies that make them. But in a new report, Mozilla, the nonprofit behind <a href=\"https:\/\/www.wired.com\/story\/firefox-quantum-the-browser-built-for-2017\/\">the popular Firefox browser<\/a>, has a more finely tuned privacy appraisal of not just toys but dozens of popular <a href=\"https:\/\/www.wired.com\/gallery\/wish-list-2018-48-awesome-holiday-gift-ideas\/\">holiday gifts<\/a>\u2014some of which may not rate much better than coal.<\/p>\n<p>Now in its second year, Mozilla\u2019s <a href=\"https:\/\/foundation.mozilla.org\/en\/privacynotincluded\/\" target=\"_blank\">\u201cPrivacy Not Included\u201d<\/a> guide rates 70 products, ranging from toys to smart speakers to a sous vide, across multiple categories. It\u2019s also rolling out\u2014along with advocacy groups Internet Society and Consumers International\u2014new \u201cminimum security requirements,\u201d and awarding badges to giftables that score high marks.<\/p>\n<p class=\"paywall\">\u201cWe want to provide people information about how to make informed decisions when shopping for gifts that are connected to the internet,\u201d says Ashley Boyd, vice president of advocacy at Mozilla. \u201cThese products are becoming really popular. And in some cases, it\u2019s easy to forget that they\u2019re even connected to the internet.\u201d<\/p>\n<p class=\"paywall\">Among the important signifiers of a trustworthy stocking stuffer, according to Mozilla\u2019s rubric: the use of encryption, pushing automatic software security updates, strong password hygiene, a way to deal with vulnerabilities should they arise, and a privacy policy that doesn\u2019t take a PhD to parse.<\/p>\n<p>&quot;We\u2019re trying to give people essentially a way to look at any product and what to look for, what questions to ask.&quot;<\/p>\n<p name=\"inset-left\" class=\"inset-left-component__el\">Ashley Boyd, Mozilla<\/p>\n<p class=\"paywall\">The most surprising result of Mozilla\u2019s testing may be how many products actually earned its seal of approval. Thirty-three of the 70 items in the \u201cPrivacy Not Included\u201d guide passed muster; fans of the Nintendo Switch, Google Home, and Harry Potter Kano Coding Kit can sleep a little easier. On the other end of the scale, Mozilla highlighted seven products that may not hit the mark\u2014yes, including <a href=\"https:\/\/www.wired.com\/review\/anova-precision-cooker-nano\/\">the sous vide wand, the Anova Precision Cooker<\/a>. Also scoring low marks in Mozilla&#x27;s accounting: the DJI Spark Selfie Drone (no encryption, does not require users to change the default password), the Parrot Bebop 2 drone (no encryption, complex privacy policy), and, <a href=\"https:\/\/www.wired.com\/2015\/09\/security-news-week-turns-baby-monitors-wildly-easy-hack\/\">unsurprisingly<\/a>, at least one baby monitor.<\/p>\n<p class=\"paywall\">DJI says that there&#x27;s no indication that the Spark has ever been hacked, other than intentionally by enthusiasts looking for a performance boost. And to its credit, the company is also proactive in fixing issues that do arise; just last week, it patched an authentication bug that <a href=\"https:\/\/www.wired.com\/story\/dji-drones-bugs-exposed-users-data\/\">would have allowed hackers to access user accounts<\/a>.<\/p>\n<p class=\"paywall\">Anova CEO Steve Svajian says that the company plans to add encryption to the next generation of its product, and is exploring ways to add it retroactively to those already on the market. &quot;We take privacy and security very seriously,&quot; says Svajian. &quot;It&#x27;s crucially important for the community to trust what we do.&quot;<\/p>\n<p class=\"paywall\">The remaining 30 items on the list all exist somewhere in the murky middle, usually because Mozilla was unable to confirm at least one attribute. Which may be the real takeaway from the report: Too often, you have no reasonable way to find out if a given internet-connected device is secure.<\/p>\n<p class=\"paywall\">\u201cIf you can\u2019t tell, that says that there\u2019s a problem of communication between manufacturers and consumers,\u201d says Boyd. \u201cWe would love for makers of these products to be more clear and more transparent about what they\u2019re doing and not doing. That\u2019s a big place we think change is needed.\u201d<\/p>\n<p class=\"paywall\">Mozilla rightly acknowledges that a survey of 70 products shouldn\u2019t be seen as any sort of definitive buying guide. There are thousands of internet-connected presents waiting to be gifted this year, all of them offering a wide range of privacy controls. But that\u2019s not the point.<\/p>\n<p class=\"paywall\">\u201cThe number of products is a drop in the bucket,\u201d says Boyd. \u201cWe\u2019re trying to drive a conversation where manufacturers can see that consumers care about this information. We\u2019re trying to give people essentially a way to look at any product and what to look for, what questions to ask.\u201d<\/p>\n<p class=\"paywall\">Still, giving a simple thumbs-up or thumbs-down\u2014or, in the majority of cases, no thumb at all\u2014feels overly broad. To badly paraphrase Tolstoy: Secure products are all alike; every not-secure product is not secure in its own way. The risks of a hackable baby monitor far outweigh those of a cooking implement, and a garbled privacy policy seems less problematic than a disregard for encryption. Those distinctions aren\u2019t immediately clear when you scan \u201cPrivacy Not Included,\u201d and in fact become further complicated by a \u201cCreep-O-Meter,\u201d which lets readers rate how creepy they think a given product is, regardless of its actual merits.<\/p>\n<p class=\"paywall\">At the very least, Mozilla&#x27;s guide does elucidate what can actually go wrong if someone compromises your gear. Like, say, that sous vide: \u201cSomeone could hack your Wi-Fi, crank up the cooking temperature on your sous vide, and over cook your steak,\u201d reads the entry, presenting a worst-case scenario that\u2019s not quite Grade A. Svajian also disputes Mozilla&#x27;s characterization of how Anova handles customer data; the company uses it for analytics and marketing purposes, but does not and will not ever sell it to third parties.<\/p>\n<p class=\"paywall\">So yes, Mozilla may be painting with an overly broad brush here. But at least those issues are weighed against the report\u2019s admirable goals. Simply knowing it exists might help consumers think twice about letting an internet-connected camera or microphone into their home, no matter how adorable the teddy bear it\u2019s attached to.<\/p>\n<p class=\"paywall\">\u201cSo much of the news that people are reading about the technology industry is scary. People aren\u2019t clear what to do and how to improve their safety online,\u201d Boyd says. \u201cConsumer products are a great place for people to learn more, because they\u2019re things that people bring into their home. This is a place where people are pretty empowered.\u201d<\/p>\n<p class=\"paywall\"><em>UPDATE 11\/12\/18 12:00PM: This story has been updated with comment from Anova CEO Steve Svajian.<\/em><\/p>\n<p class=\"related-cne-video-component__dek\">It\u2019s 2017! It\u2019s time to start using an encrypted messaging app. Why? Using end-to-end encryption means that no one can see what you\u2019re sharing back and forth.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/mozilla-privacy-not-included-internet-connected-toys\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5beb6aa80eb20a52df543cd1\/master\/pass\/BebopParrot2-583760424.jpg\"\/><\/p>\n<p><strong>Credit to Author: Brian Barrett| Date: Wed, 14 Nov 2018 16:00:00 +0000<\/strong><\/p>\n<p>In its second annual \u201cPrivacy Not Included\u201d guide, the nonprofit highlights internet-connected gifts that value your privacy\u2014and the ones that may not.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-13828","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13828"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13828\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13828"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}