Pairing is a big paint point though AIUI, releasing this toy with the need to pair it first would probably have cost them significant numbers of returns. Not saying it's justified, but ...
Perhaps they could give away an optional tin-foil suit for furbies of owners who have security concerns!
Oh yeah, totally. BLE support on both android and iOS is lacking. Older versions of android, and I believe all versions of iOS (please correct me if I'm wrong) do not offer a programmatic way of supplying the pin for pairing. This means that when you programmatically connect to a BLE device from an app, the user will get a pin prompt. This prompt covers most of the screen so it really is a pain.
Though for the furby it shouldn't be too bad. Just display the pin on one of its eyes.