- cross-posted to:
- technology@lemmit.online
- cross-posted to:
- technology@lemmit.online
AI chat toy company Bondu left its web console almost entirely unprotected. Researchers who accessed it found nearly all the conversations children had with the company’s stuffed animals.



Literally anyone could log in to the company’s Admin portal by OAuth authentication with a Google account. Bondu fixed the problem quickly, but yikes.
That doesn’t bode well for the quality of their developers.
Here is info from the researcher’s article, which is linked from the Wired article:
This is why authentication and authorization are both important, not just authentication.