Security Flaws with Vibrastissimo Sex Toy Exposed
Researchers disclosed critical security flaws with the Vibrastissimo Panty Buster sex toy for women ahead of Valentine’s Day. More than 100,000 may own the device based on estimates compiled from app downloads.
Remote control of the device was possible without consent because links sent between users were easy to guess and the device owner was not required to confirm access before allowing control to the third-party. Passwords for the site were in an open file on the website and user passwords were stored in plain text so it was possible to grab passwords for owner accounts. The url for images uploaded by users was also easy to guess.
Austrian company SEC Consult discovered the flaws and some changes were made by the sex toy company immediately but others required the device to be sent back to the company for an update in the firmware.