Connect with us

Technology

South Korea-backed app puts children at risk

Published

on

(Shutterstock image)

(Shutterstock image)

SEOUL, South Korea – Security researchers say they found critical weaknesses in a South Korean government-mandated child surveillance app – vulnerabilities that left the private lives of the country’s youngest citizens open to hackers.

In separate reports released Sunday, Internet watchdog group Citizen Lab and German software auditing company Cure53 said they found a catalog of worrying problems with “Smart Sheriff,” the most popular of more than a dozen child monitoring programs that South Korea requires for new smartphones sold to minors.

“There was literally no security at all,” Cure53 director Mario Heiderich said. “We’ve never seen anything that fundamentally broken.”

Smart Sheriff and its fellow surveillance apps are meant to serve as electronic baby sitters, letting parents know how much time their children are spending with their phones, keeping kids off objectionable websites and even alerting parents if their children send or receive messages with words like “bully” or “pregnancy.”

In April, Seoul required new smartphones sold to those 18 and under to be equipped with such software, a first-of-its-kind move, according to Korea University law professor Park Kyung-sin. The Korean Communications Commission has promoted Smart Sheriff and schools have sent out letters to parents encouraging them to download the app.

Sometime afterward, Citizen Lab, based at the University of Toronto’s Munk School of Global Affairs, and Cure53, acting on a request from the Washington-based Open Technology Fund, began sifting through Smart Sheriff’s code.

What they found was “really, really bad,” Heiderich said.

Children’s phone numbers, birth dates, web browsing history and other personal data were being sent across the Internet unencrypted, making them easy to intercept. Authentication weaknesses meant Smart Sheriff could easily be hijacked, turned off or tricked into sending bogus alerts to parents. Even worse, they found that many weaknesses could be exploited at scale, meaning that thousands or even all of the app’s 380,000 users could be compromised at once.

“Smart Sheriff is the kind of baby sitter that leaves the doors unlocked and throws a party where everyone is invited,” said Collin Anderson, an independent researcher who collaborated with Citizen Lab on its report.

Citizen Lab said it alerted MOIBA, the association of South Korean mobile operators that developed and operated the app, to the problems on Aug. 3. When contacted Friday, MOIBA said the vulnerabilities had been fixed.

“As soon as we received the email in August, we immediately took action,” said Noh Yong-lae, a manager in charge of the Smart Sheriff app.

The researchers were skeptical.

“We suspect that very little of these measures taken actually remedy issues that we’ve flagged in the report,” Anderson said, adding that he believed at least one of MOIBA’s fixes had opened a new weakness in the program.

Independent experts also weren’t impressed with Smart Sheriff.

Ryu Jong-myeong, chief executive of security firm SoTIS, said the app did now appear to be encrypting its transmissions. But he was scathing about some of the other failures uncovered by Citizen Lab, giving the Smart Sheriff’s server infrastructure a security rating of zero out of 10.

“People who made Smart Sheriff cared nothing about protecting private data,” he said.

Kwon Seok-chul, chief executive of computer security firm Cuvepia Inc., said the lingering weaknesses meant children’s data was still at risk.

“From a hacker’s point of view, (the door) stays open,” he said.

Many smartphone applications are unsafe, leaking private data or sending or storing it in risky ways.

But Citizen Lab Director Ronald Deibert said Smart Sheriff, a government-mandated program intended to monitor the intimate moments of so many children’s lives, merited special scrutiny.

“This is not just a fitness tracker,” Deibert said. “It’s an application meant to satiate parents’ concerns about their children’s use of mobile or social media, which is in fact putting them at more risk.”

Park, the law professor, said the security flaws should push the government “to revisit the whole idea of requiring a personal communication device to be equipped with software that allows another person to monitor and control that device.”

Some South Korean parents may soldier on with Smart Sheriff regardless. Lee Kyung-hwa, a mother of two whose Cyber Parents Union On Net endorses child surveillance, says all the app needs is an upgrade.

“If mothers feel happy thanks to the app, it is still helpful,” she said.

But Kim Kha Yeun, a general counsel at libertarian-minded Open Net Korea, predicted that the revelations would turn parents against the technology.

“If they knew that the apps infect and endanger their children, I don’t think any South Korean parents would want their children to have this monitoring app,” he said.

The research has already prompted one mother to say she’s uninstalling Smart Sheriff.

Yoon Jiwon told The Associated Press that she had previously been put off by the way in which the battery-hungry app kept sending her misleading alerts about her sons being bullied, prompting her to cross-examine them about each chat and text message, breeding frustration and mistrust.

She plans to uninstall the app after learning about the security weaknesses uncovered by Citizen Lab and now says Smart Sheriff was not a good way of interacting with her children.

“It’s just not right for a mom to snoop on everything,” she said.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest

News8 hours ago

DOJ forms TWG to hasten creation of separate ‘heinous crimes’ prisons

MANILA – The Department of Justice (DOJ) has ordered the creation of a technical working group (TWG) to hasten the...

Philippine Navy spokesperson for the West Philippine Sea Commodore Roy Vincent Trinidad Philippine Navy spokesperson for the West Philippine Sea Commodore Roy Vincent Trinidad
News9 hours ago

Navy: Measures in place vs. possible Chinese interference in Balikatan

MANILA – A ranking Philippine Navy (PN) official said while China is not expected to interfere in the ongoing “Balikatan”...

Entertainment9 hours ago

Meet Five of Seoul’s Most Glamorous Elite in ‘Super Rich in Korea’ Official Trailer

Super Rich in Korea offers a golden ticket into the extravagant world of Seoul’s top 1% — individuals who’ve made...

Entertainment9 hours ago

Who’s In for “Something Really Fun”? The Curtain Rises on ‘The 8 Show’ with Thrilling Teaser Trailer and Character Posters

“Do you really want something fun?” This question opens the zany teaser trailer for The 8 Show, a thrilling new...

Entertainment10 hours ago

Discover Your K-Pop Persona With Spotify’s New Interactive Experience

In the last decade, as K-Pop cemented its status as a global phenomenon, Spotify has helped fans around the world...

Canada News10 hours ago

International student resentment brews but allowing fewer students into Canada isn’t the answer

Canada has prided itself on being a welcoming haven for students from around the world. But beneath the surface of...

Business and Economy10 hours ago

Supreme Court appears open to Starbucks’ claims in labor-organizing case

What factors must a court consider when the National Labor Relations Board requests an order requiring an employer to rehire...

British PM Rishi Sunak British PM Rishi Sunak
News10 hours ago

The obstacles that could still stop flights to Rwanda from taking off

  Rishi Sunak has finally secured the legislation he needs to support his Rwanda plan. A late night session of...

News10 hours ago

Parliament passes bill declaring Rwanda safe – but can it really be called a law at all?

After months of deadlock, the House of Lords withdrew its opposition to the safety of Rwanda (asylum and immigration) bill,...

News10 hours ago

Why Germany ditched nuclear before coal – and why it won’t go back

One year ago, Germany took its last three nuclear power stations offline. When it comes to energy, few events have...

WordPress Ads