South Korea pulls plug on child monitoring app
LONDON (AP) -- The most widely used child surveillance app in South Korea is being quietly pulled from the market after security specialists raised serious concerns about the program's safety.
Moon Hyun-seok, a senior official at the Korea Communications Commission, told The Associated Press that "Smart Sheriff" has been removed from the Play store, Google's software marketplace, and that existing users are being asked to switch to other programs. Smart Sheriff's maker, an association of South Korean mobile operators called MOIBA, declined comment.
A law passed in April requires all new smartphones sold to those 18 and under to be equipped with software which parents can use to snoop on their kids' social media activity. Smart Sheriff, the most popular of more than a dozen state-approved apps, was meant to keep children safe from pornography, bullying and other threats, but experts say its abysmal security left the door wide open to hackers and put the personal information of some 380,000 users at risk.
Pulling the plug on Smart Sheriff was "long overdue," said independent researcher Collin Anderson, who worked with Internet watchdog group Citizen Lab and German software auditing firm Cure53 to comb through the app's code. In a pair of reports published in September, Cure53 described the app's security as "catastrophic." Citizen Lab, which is based at the University of Toronto's Munk School of Global Affairs, said the problems could lead to a "mass compromise" of all users.
MOIBA said in response then that the vulnerabilities had been dealt with in the six weeks preceding publication of the reports, but the researchers said in new reports published Sunday that the fixes were mainly cosmetic, "akin to putting a lock on a few of the doors but then leaving the keys to the locks outside," Anderson said.
Heiderich said it wasn't his place to say whether it was right to mandate the installation of monitoring apps on children's phones. But he said Smart Sheriff's implementation of the surveillance was disastrous.
"If you are going to do it at all, you have to do it right," he said. "And this was not done right at all."
It was unclear precisely why or exactly when the government decided to pull Smart Sheriff from the Play store. The app wasn't receiving any new users as of Sunday, but it wasn't clear whether the government plans to cut off users who wish to keep the app installed despite the security concerns.
That may be a temptation for some parents as Smart Sheriff was free and most of its competitors charge a fee. Anderson noted that there was no guarantee those competitors didn't also have security issues.
"How do we know that any of these other apps are not similarly exposed?" he said.