Orlando Sentinel

Researcher­s: New S. Korean child-monitoring app flawed

- By Youkyung Lee and Raphael Satter

SEOUL, South Korea — A South Korean childmonit­oring smartphone app that was removed from the market in 2015 after it was found to be riddled with security flaws has been reissued under a new name but it still puts children at risk, researcher­s said.

The app “Cyber Security Zone” is part of government efforts to curb what authoritie­s consider excessive cellphone use by young people. Parents are required by law to install monitoring software on smartphone­s for all children 18 and younger.

The app is almost identical to a previous system, “Smart Sheriff,” that left children’s private informatio­n vulnerable to hackers, according to internet watchdog Citizen Lab at the University of Toronto. Both were developed under the auspices of MOIBA, the industry associatio­n for South Korean cellphone service providers.

“The flaws in the apps open the door to possible breaches of sensitive informatio­n including passwords, phone numbers, and other user data,” Citizen Lab said in a statement Monday.

“Smart Sheriff” was one of a family of apps intended to monitor children’s online behavior. Some, like Smart Sheriff, act as filtering or blocking tools, while others send alerts to parents if children swear or talk about sex or bullying.

The apps have raised privacy activists’ hackles, but experts have also been scathing about their lack of security. Cure53, a German auditing firm, said in 2015 that Smart Sheriff was “fundamenta­lly broken.”

Citizen Lab and Cure53 now say the app appears to have been rebranded as “Cyber Security Zone” — the equivalent of putting a fresh coat of paint on a dangerous old clunker.

“Users are being misled,” said the Citizen Lab report.

MOIBA denied the two systems were the same and an official of the group said a review by the government’s Korean Internet & Security Agency found security for “Cyber Security Zone” satisfacto­ry.

“We cannot agree to the opinion that the applicatio­n was not developed with security in mind,” said the official, Noh Yong-lae.

Noh said MOIBA cut ties with the developer of “Smart Sheriff” and hired another company to update and develop apps.

KISA officials who looked at the Citizen Lab report said their agency’s audit failed to catch at least one security lapse: the app’s developer had not encrypted a key to the password.

“They should not have built the app this way,” said Kim Chan-il, a KISA manager. He said the government and MOIBA should make sure to hire developers who pay attention to security and have enough time to build an app.

An audit by KISA “does not guarantee security against all weaknesses,” Kim said.

Rates of smartphone and internet use in South Korea are among the world’s highest. The government operates filters to block access to pro-North Korean websites and material deemed pornograph­ic.

Newspapers in English

Newspapers from United States