If you're into chastity play, you might own an internet-enabled chastity device designed to share your kink with your partner. And you also might want to change your password.
TechCrunch reports that several flaws in an unnamed smart sex toy manufacturer's servers have exposed over 10,000 of its users' personal data, including information which can be used to identify them. This includes email addresses, plaintext passwords, home addresses, IP addresses, PayPal logs, and even GPS coordinates.
Unfortunately, there's no quick and easy way of knowing whether you've been impacted. The company has not been publicly identified in order to protect its customers, as the vulnerability has not yet been fixed.
SEE ALSO: What to look for when buying a sex toyHowever, TechCrunch has confirmed that the company makes chastity devices for penises, which can be controlled by a partner using an Android app and an internet connection. Said partner can also track the person wearing the device via GPS.
Chastity devices, such as harnesses, cages, and straps, form part of chastity play, a kink which involves one partner using a device to prevent themselves from becoming fully aroused. The idea is that once the person is freed from the device, they'll be able to unleash their full desire.
If you own an internet-enabled chastity device, it might be time for an internet security checkup — and perhaps some consideration to the idea of deleting any unused accounts. Even if you do change your sex toy's password, your new one could be just as exposed if the server flaw isn't addressed.
And if you indulge in the cardinal security sin of reusing passwords, you should definitely change any that share the same one as your chastity device.
SEE ALSO: What are password managers and how to pick the right oneAccording to the publisher, the vulnerability was first detected by an anonymous security researcher, who told TechCrunch they reached out to notify the sex toy company on July 17. Then, when they did not receive any response, the researcher reportedly vandalised the company's website to leave a warning to users on Aug. 23.
"[COMPANY] has left the site wide open, allowing any script kiddie to grab any and all customer information," the researcher wrote on the homepage. "This includes plaintext passwords and contrary to what [COMPANY] has claimed, also shipping addresses… If you have paid for a physical unit and now cannot use it, I’m sorry. But there are thousands of people with accounts on here and I could not in good faith leave everything up for grabs."
The message was removed within a day, but the servers' security flaws still remain.
While smart sex toys offer novel possibilities for sexual escapades, they also carry the risk of making security breaches even more distressing than they already are. In 2020, a vulnerability found in the Cellmate penis chastity device made it possible for hackers to lock all devices simultaneously. If it had been exploited, the lack of a manual override meant trapped penises may have had to be cut free using power tools.
The Cellmate chastity devices were reportedly later hacked in 2021, with attackers demanding 0.02 Bitcoin to free users' genitals — the equivalent of $750 at the time. There are no reports of users losing access to their penis, as the victims who spoke to Vice were not wearing the Cellmate at the time. But then again, some impacted people may not have been too keen to step forward. Cellmate manufacturer QIUI has categorically denied all reports of any hacks.
It's unlikely that QIUI is the mystery company at the centre of this latest smart sex toy scare, as TechCrunch noted that the impacted device only has an Android app. CAG.INK, the rebranded Cellmate, has both Android and iOS apps.
Even so, it's a good opportunity to check your security settings, change your passwords, and delete unused accounts regardless of the specific device you're using. And maybe consider exploring some lower-tech toys.
文章
64294
浏览
153
获赞
547
Please wash your hands, not just because all the Purell is sold out
Please wash your damn hands. It's 2020 and yes, full grown adults still need to hear it. Health offiTake a call and keep Google Maps open with Assistant's 'driving mode'
Your phone can become the ultimate dashboard screen with Google Assistant's upcoming "driving mode."Of course Chrissy Teigen celebrated her birthday Pan
Chrissy Teigen was flying high on her birthday yesterday. She celebrated her 32nd birthday with a PaHow to watch Google I/O 2019 keynote and what to expect
Tech conference season is in full swing. Facebook had its F8 keynote earlier this week, and now GoogDisappearing WhatsApp messages roll out to iOS beta users
Eight months after launching self-destructing posts on Android, WhatsApp is rolling out the same feaThe hell of Trump's Twitter mentions and his choice of retweets
Donald Trump loves to tweet, this much is known. But he also has a thing for occasionally retweetingMicrosoft gains control of domains used by Iranian hackers linked to U.S. fugitive
A U.S. court has granted Microsoft the authority to seize domain names in order to take down a phishSamsung's Galaxy Fold might ship on June 13
Samsung's Galaxy Fold -- the $1,980 folding phone whose launch has been delayed after several reviewHow to find stalkerware on your smartphone
Privacy Pleaseis an ongoing series exploring the ways privacy is violated in the modern world, and wMeghan Markle started on 'Deal or No Deal' way before her big royal engagement
Meghan Markle knows all about making important decisions. Before she became a paralegal on SuitsandThe 'Godfathers of AI' win Turing Award
The winners of the 2018 Turing Award have been announced.Geoffrey Hinton, Yann LeCun, and Yoshua BenTwitter to start monitoring users outside of Twitter, will ban people affiliated with hate groups
Twitter is cracking down on hate speech and not just by looking at its own site. In what amounts toYou probably shouldn't give skincare as a gift
Like a lot of other people who pride themselves on organization to a point, I have a designated &ldqSamsung invests $2.9 million in crypto wallet Ledger
Samsung has invested 2.6 million euro (roughly $2.9 million) into French cryptocurrency company LedgSamsung's Galaxy Fold might ship on June 13
Samsung's Galaxy Fold -- the $1,980 folding phone whose launch has been delayed after several review