- May 7, 2002
- 10,371
- 762
- 126
Well, not only are those devices broadcasting (Bluetooth or Wifi), it could also be possible for strangers to take over said device, and to take that a step further, blackmail the person that has the device...with them.
https://www.bleepingcomputer.com/ne...he-sad-state-of-bluetooth-le-implementations/PTP, a well-known UK-based company specialized in security audits of smart devices, has discovered almost the same BLE-related security flaws in several smart toys, such as the Lovense Hush butt plug, the Kiiroo Fleshlight sleeve, the Lovense Nora rabbit vibrator, the Lovense Max sleeve, and LELO smart wand.
...
For example, the Lovense Hush butt plug uses the same LVS-Z001 identifier. Lomas says that an attacker could drive around a city with a powerful antenna and map out all sex toys ready to pair up.
Because some devices use the same identifier, everyone could use such services to map out sex toy usage across a city or larger geographical area.
"We went hunting… and found some devices in an exploitable state… in people," said Lomas. It usually takes one step to go from mapping insecure devices to attacking insecure devices.