• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

everthing

  • Home
  • About
  • Animals
  • Lastes-posts
  • Medicine
  • NBA All-Star Game
  • Pharmacy
  • Software
  • Contact

Childcare monitoring apps are ‘dangerously unsafe’, report finds

June 23, 2022 by admin

Popular daycare and childcare communications apps are “dangerously insecure” according to newly published research, exposing children and parents to the risk of data breaches with lax security settings and indulgent or downright misleading privacy policies.

The details come from a new report from the Electronic Frontier Foundation (EFF), which released the results of a months-long research project on Tuesday.

The investigation, conducted by Alexis Hancock, EFF’s technical director for the Certbot project, found that popular apps such as Brightwheel, HiMama, and Tadpoles lacked two-factor authentication (2FA), meaning any malicious actor who could obtain a user’s password, log in remotely. Closer analysis of the application code revealed a number of other privacy-damaging features, including data sharing with Facebook and other third parties, that were not mentioned in the privacy policy.

After contacting the EFF, Brightwheel implemented 2FA, claiming to be “the first in the early education industry to add this extra layer of security”. HiMama reportedly said it would pass the feature request on to its design team, but has not yet implemented the additional security feature. It is unknown if Tadpoles plans to implement 2FA.

Network traffic analysis shows that the Tadpoles app sends data about user events to Facebook.
Image: EFF

Hancock began researching the privacy and security settings of several childcare apps after she was asked to download Brightwheel when she first enrolled her two-year-old daughter in childcare. Hancock told The edge that she initially liked using the app to get updates about her daughter, but was concerned about a lack of security given the potentially sensitive nature of the information.

“In the beginning there was a lot of comfort in seeing [my daughter] during the day, with the images they sent me,” Hancock said. “Then I looked at the app from, huh, I don’t really see security controls that I would normally see in most services like this.”

With a background in software development, Hancock was able to use a range of tools such as Apktool and mitmproxy to analyze the application code and examine network calls made by each of the childcare apps, and was surprised to find some easily fixable errors.

“I found trackers in a few apps. I found a weak security policy, a weak password policy,” Hancock said. “I discovered vulnerabilities that were very easy to fix as I went through some of the applications. Basically just low hanging fruit.”

“I discovered vulnerabilities that were very easy to fix as I went through some of the applications. Basically just low hanging fruit.”

The new report from the EFF isn’t the first to draw attention to serious flaws in applications trusted to protect children. For years, researchers have raised concerns about security vulnerabilities in baby monitor apps and associated hardware, with some of these weaknesses being exploited by hackers to send messages to children. More broadly, a survey of 1,000 apps likely to be used by children found that more than two-thirds sent personal information to the advertising industry.

Hancock hopes that reporting on these privacy and security flaws could lead to better regulation of child-directed apps, but the findings nevertheless worry her.

“As a parent, I felt even more afraid of my child,” she said. ‘I don’t want her to have a data breach before she’s five. I’m doing everything I can to make sure that doesn’t happen.”

Related

Filed Under: Software

Primary Sidebar

Recent Posts

  • Lakers Rumors: LA Urged to Trade for Hornets’ Gordon Hayward
  • How do the Machine Learning Engineer and Software Engineer salaries compare?
  • Penn Medicine receives $9 million to advance research into imaging technology that alleviates tumors
  • Fishtown Seafood brings oyster happy hours and sustainable seafood to Fishtown
  • Lakers ‘Make Sense’ for Nets Free-Agent Blake Griffin

Recent Comments

  1. A WordPress Commenter on Hello world!

Archives

  • June 2022

Categories

  • Animals
  • Lastes-posts
  • Medicine
  • NBA All-Star Game
  • Pharmacy
  • Software

Footer

Design

With an emphasis on typography, white space, and mobile-optimized design, your website will look absolutely breathtaking.

Learn more about design.

Pages

  • About
  • Affiliate Disclosure
  • Contact
  • Homepage
  • Landing Page
  • Privacy Policy
  • Sample Page
  • Terms And Conditions

Content

Our team will teach you the art of writing audience-focused content that will help you achieve the success you truly deserve.

Learn more about content.

Strategy

We help creative entrepreneurs build their digital business by focusing on three key elements of a successful online platform.

Learn more about strategy.

Copyright © 2022 · Genesis Sample on Genesis Framework · WordPress · Log in

Go to mobile version