Further Updates March 26th, 2020
Dear iBaby users,
We’re happy to announce that we have released a new firmware update together with a new version of the iBaby Care app in order to further enhance data security. This process should have been automatic if you have your device setup with automatic updates. If not, we strongly encourage all users to update the firmware and iBaby Care App to the latest version (shown below) by following the instructions here.
Firmware Version: V5.4.2
Android iBaby Care App Version: V2.9.5A
IOS iBaby Care App Version: V 2.4.4
*The new iBaby Care App update is compatible with iOS devices running iOS 9.3 or higher as industry practice. Please make sure that your iPad or iOS device is compatible before updating in the App store.
Again, customer data safety is our #1 priority and we appreciate your cooperation to ensure your data safety.
If you still have difficulty updating your device, reach out to our customer support at firstname.lastname@example.org or by calling at (650) 396-2436 (M-F 9-5 PM PDT).
Further Updates March 12th, 2020
Dear iBaby users,
Following our updates on February 29th, 2020, in which we announced our fixes.
The original reporter, PCMag, took the initiative and asked the original researchers at Bitdefender to verify our fixes. They announced their findings in the new article ‘iBaby Fixes Security Flaws in Popular Baby Monitor‘ published on Mar 4,2020. Bitdefender’s IoT wizard Jay Balan commented and confirmed the fix, “I can say that at this point the attack vectors we identified in our research don’t work anymore,” and they were delighted by the speed with which we delivered the fix.
Bitdefender also updated their original whitepaper post announcing our quick fix on March 12th, 2020.
Since there was a communication breakdown, and we weren’t aware of the attempts from the community to reach us in this instance, we launched a new email for reporting any security issues to avoid any potential delays in the future: email@example.com
Customer data safety has been our #1 priority. We strive to provide our users with the highest security so they can freely and securely care for their loved ones.
We want to thank everyone in the IoT community for their help and efforts to promote secure baby monitoring systems.
A firmware update is expected soon to further enhance data security.
If you are a customer and need further clarification, reach out to our support team at firstname.lastname@example.org
If you are a member of the media and you would like to talk to us, please email us at email@example.com
Further Updates February 29th, 2020
Dear iBaby users,
After a day of research and investigating the potential issue as posted on several media sources, we have the following updates:
Online resources reported potential vulnerabilities of iBaby M6S on February 26-27th.
What iBaby has done:
We have immediately deactivated the potentially compromised AWS authentication information. In addition, we’ve taken a few measures to tighten the security such as limited the cloud storage access and enhanced the MQTT server configuration to strictly limit the topics to which each device can subscribe to. We are continuing to enhance all our safety efforts.
Information that could have been potentially impacted:
Some information uploaded to the cloud storage S3 by the device. So far, no hackings have been spotted and no critical information regarding your account was affected (username, password).
What you can do:
Since there was no breach of data, your iBaby account has been secure and protected. However, as a security measure, you should periodically change your password and delete inactive invited users. We also recommend that you do not use a similar password to other websites.
What iBaby will do:
Soon we will also release a firmware update to be pushed out to your device. Once it’s available, you will receive a notification. This will further enhance data security.
Since iBaby Labs was established in 2011, customer security has been our #1 priority. We sincerely thank you to our loyal users for over ten generations of products.
We are so thankful to have had our iBaby monitors featured in many articles and reputable online channels and nominated as top devices in the baby monitor industry. We are also thankful for the researcher’s and reporter’s in-depth reports and help to build a better IoT ecosystem for everyone. We will continue to strive to design and produce the best baby monitors on the market!
If you have any further question, please feel free to contact our team: firstname.lastname@example.org or visit our website www.ibabylabs.com
If you are a member of the media and would like to reach out to us, please email us at email@example.com
February 27, 2020
Dear iBaby users,
It has come to our attention that certain online articles (published Feb. 26-27th, 2020) regarding the vulnerabilities of our iBaby M6S have caused concerns. We want to reassure you that the security of our customers’ database is and has always been our utmost #1 priority. We follow strict government privacy guidelines and use the industry’s highest standards to guard the safety of our customers’ data.
However, we are quickly researching these reports and verifying the validity of the claims.
Right now we have not received any data compromising reports. We are also working with members of the media to research and investigate their reports.
We appreciate your patience while we search these issues and bring you new updates as soon as they’re available.
*If you’re a member of the media and would like to reach out to us, please email us at firstname.lastname@example.org.