{"id":5118,"date":"2018-12-05T11:11:01","date_gmt":"2018-12-05T11:11:01","guid":{"rendered":"http:\/\/www.styledeals.co.uk\/blog\/vtech-flags-tablet-flaw-after-bbc-watchdog-probe\/"},"modified":"2018-12-05T11:11:01","modified_gmt":"2018-12-05T11:11:01","slug":"vtech-flags-tablet-flaw-after-bbc-watchdog-probe","status":"publish","type":"post","link":"https:\/\/www.styledeals.co.uk\/blog\/vtech-flags-tablet-flaw-after-bbc-watchdog-probe\/","title":{"rendered":"VTech flags tablet flaw after BBC Watchdog probe"},"content":{"rendered":"\n<div property=\"articleBody\">\n<figure class=\"media-landscape has-caption full-width lead\"><span class=\"image-and-copyright-container\"><\/p>\n<p>                <img loading=\"lazy\" decoding=\"async\" class=\"js-image-replace\" alt=\"Innotab Max\" src=\"https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/14443\/production\/_104611038_32ef1def-f06a-41d3-9273-971f55dd679a.jpg\" width=\"976\" height=\"549\"\/><span class=\"off-screen\">Image copyright<\/span><br \/>\n                 <span class=\"story-image-copyright\">VTech<\/span><\/p>\n<p>            <\/span><figcaption class=\"media-caption\"><span class=\"off-screen\">Image caption<\/span><br \/>\n                <span class=\"media-caption__text\"><br \/>\n                    VTech allows parents to determine which sites their children can visit with the tablet<br \/>\n                <\/span><br \/>\n            <\/figcaption><\/figure>\n<p class=\"story-body__introduction\">Child gadget-maker VTech&#8217;s website is promoting a security fix for its flagship tablet, following an investigation by BBC Watchdog Live.<\/p>\n<p>The Storio Max &#8211; which is called the InnoTab Max in the UK &#8211; suffers a software flaw that could allow hackers to remotely take control of the device and snoop on its users.<\/p>\n<p>VTech was alerted to the vulnerability months ago by a UK cyber-security firm.<\/p>\n<p>The Chinese company issued a fix but some parents have yet to install it.<\/p>\n<p>The notice at the top of its homepage and the broadcast of the BBC programme should ensure the issue gets more prominence. <\/p>\n<p>It had previously relied on pop-up alerts that appeared on the devices themselves to prompt owners into action.<\/p>\n<p>VTech said it was also contacting retailers that are selling affected units.<\/p>\n<p>The issue has come to light nearly three years after the firm was <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-35532644\" class=\"story-body__link\">criticised for its handling of a separate cyber-security incident<\/a> that exposed millions of its child customers&#8217; account details.<\/p>\n<p>Vtech markets the Max tablets to children aged between three and nine years old.<\/p>\n<p>&#8220;This was a controlled and targeted &#8216;ethical hack&#8217; by&#8230; a sophisticated cyber-firm that was in possession of a detailed knowledge of hacking techniques and InnoTab\/Storio Max&#8217;s firmware,&#8221; said VTech in a statement about the latest incident.<\/p>\n<p>&#8220;We are not aware of any actual attempt to exploit the vulnerability and we consider the prospects of this happening to be remote.<\/p>\n<p>&#8220;However, the safety of children is our top priority and we are constantly looking to improve the security of our devices.&#8221;<\/p>\n<h2 class=\"story-body__crosshead\">Hacked webcam<\/h2>\n<p>Vtech&#8217;s Max tablets are designed to allow parents to restrict their children to websites that they have personally approved.<\/p>\n<figure class=\"media-landscape has-caption full-width\"><span class=\"image-and-copyright-container\"><\/p>\n<p>                 <span class=\"off-screen\">Image copyright<\/span><br \/>\n                 <span class=\"story-image-copyright\">VTech<\/span><\/p>\n<p>            <\/span><figcaption class=\"media-caption\"><span class=\"off-screen\">Image caption<\/span><br \/>\n                <span class=\"media-caption__text\"><br \/>\n                    VTech markets the tablets as being suitable for children as young as three<br \/>\n                <\/span><br \/>\n            <\/figcaption><\/figure>\n<p>But earlier this year, researchers at London-based SureCloud discovered a flaw in the firm&#8217;s software that they said made it vulnerable to attack if one or more of the pre-vetted sites were compromised.<\/p>\n<p>&#8220;To find the vulnerability in the first place wasn&#8217;t easy,&#8221; Luke Potter, the firm&#8217;s cyber-security practice director told BBC News.<\/p>\n<p>&#8220;But to actually exploit it once you know it&#8217;s there is reasonably simple.&#8221;<\/p>\n<p>The flaw means that malicious code can be remotely triggered to run on the devices from afar. <\/p>\n<p>Mr Potter said this could involve making use of &#8220;off-the-shelf&#8221; malware available from criminal markets or running customised code.<\/p>\n<p>&#8220;Remote access can be gained without the child even knowing,&#8221; he explained.<\/p>\n<p>&#8220;So effectively being able to monitor the child, listen to them, talk to them, have full access and control of the device.<\/p>\n<p>&#8220;For example, we demonstrated viewing things through the webcam.&#8221;<\/p>\n<h2 class=\"story-body__crosshead\">&#8216;Rigorous tests&#8217;<\/h2>\n<p>Mr Potter said that after his firm informed VTech of the problem it was quick to issue a software fix in May.<\/p>\n<p>VTech boasts about its safety credentials on its website, saying that &#8216;&#8221;through rigorous testing, we maintain strict control and supervision over the quality of our products&#8221;.<\/p>\n<figure class=\"media-landscape has-caption full-width\"><span class=\"image-and-copyright-container\"><\/p>\n<p>                 <span class=\"off-screen\">Image copyright<\/span><br \/>\n                 <span class=\"story-image-copyright\">VTech<\/span><\/p>\n<p>            <\/span><figcaption class=\"media-caption\"><span class=\"off-screen\">Image caption<\/span><br \/>\n                <span class=\"media-caption__text\"><br \/>\n                    SecureCloud said the problem was in VTech&#8217;s software and not the underlying Android system<br \/>\n                <\/span><br \/>\n            <\/figcaption><\/figure>\n<p>It told Watchdog Live: &#8220;We thank SureCloud for bringing this vulnerability&#8230; to our attention. We took immediate action in early summer to resolve the issue and pushed out a firmware upgrade to all affected InnoTab\/Storio Max devices in Europe.&#8221;<\/p>\n<p>The company added that it had recently sent an email to European owners who had not performed the upgrade to urge them to do so.<\/p>\n<p>But until BBC Watchdog Live got involved, VTech had not specifically warned customers about the security vulnerability or the risks it posed. <\/p>\n<p><a href=\"https:\/\/www.vtech.co.uk\/support\/innotabmax_firmware_upgrade\" class=\"story-body__link-external\">An &#8220;upgrade reminder&#8221; on its website<\/a> is now more explicit and provides an illustrated step-by-step guide to applying the fix.<\/p>\n<p>However, Mr Potter said the issue might have been picked up at an earlier stage had the tablets been subject to more thorough checks before going on sale.<\/p>\n<p>&#8220;Any cyber-security firm that is following a best-practice approach to testing these devices&#8230; would be likely to have spotted this issue,&#8221; he said.<\/p>\n<p><i>The full report on the vulnerability can be seen on Watchdog Live tonight at 2000GMT on BBC One.<\/i><\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.co.uk\/news\/technology-46440532\">Source<\/a> by <a href=\"\">[author_name]<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Image copyright VTech Image caption VTech allows parents to determine which sites their children can visit with the tablet Child gadget-maker VTech&#8217;s website is promoting a security fix for its flagship tablet, following an investigation by BBC Watchdog Live. The Storio Max &#8211; which is called the InnoTab Max in the UK &#8211; suffers a &hellip; <\/p>\n","protected":false},"author":0,"featured_media":5119,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5118","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/posts\/5118","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=5118"}],"version-history":[{"count":0,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/posts\/5118\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/media\/5119"}],"wp:attachment":[{"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=5118"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=5118"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.styledeals.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=5118"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}