Betrayed by the Guardian: Security and Privacy Risks of Parental Control Solutions

被引:10
作者
Ali, Suzan [1 ]
Elgharabawy, Mounir [1 ]
Duchaussoy, Quentin [1 ]
Mannan, Mohammad [1 ]
Youssef, Amr [1 ]
机构
[1] Concordia Univ, Montreal, PQ, Canada
来源
36TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2020) | 2020年
关键词
Parental control network devices; Android apps; Windows applications; Web extensions; Privacy; Security;
D O I
10.1145/3427228.3427287
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
For parents of young children and adolescents, the digital age has introduced many new challenges, including excessive screen time, inappropriate online content, cyber predators, and cyberbullying. To address these challenges, many parents rely on numerous parental control solutions on different platforms, including parental control network devices (e.g., WiFi routers) and software applications on mobile devices and laptops. While these parental control solutions may help digital parenting, they may also introduce serious security and privacy risks to children and parents, due to their elevated privileges and having access to a significant amount of privacy-sensitive data. In this paper, we present an experimental framework for systematically evaluating security and privacy issues in parental control software and hardware solutions. Using the developed framework, we provide the first comprehensive study of parental control tools on multiple platforms including network devices, Windows applications, Chrome extensions and Android apps. Our analysis uncovers pervasive security and privacy issues that can lead to leakage of private information, and/or allow an adversary to fully control the parental control solution, and thereby may directly aid cyberbullying and cyber predators.
引用
收藏
页码:69 / 83
页数:15
相关论文
共 76 条
  • [11] Bellissimo A., 2006, HOTSEC
  • [12] Bluesnap.com, BLU SN ONL PAYM SOL
  • [13] Mystique: Uncovering Information Leakage from Browser Extensions
    Chen, Quan
    Kapravelos, Alexandros
    [J]. PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 1687 - 1700
  • [14] Chrome, 2017, REM DHE BAS CIPH
  • [15] CIRT.net, NIKT WEB SERV SCANN
  • [16] Common Sense Media and SurveyMonkey, 2017, SURVEY REPORT
  • [17] I know your MAC address: targeted tracking of individual using Wi-Fi
    Cunche, Mathieu
    [J]. JOURNAL IN COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2014, 10 (04): : 219 - 227
  • [18] de Carne de Carnavalet X, 2016, NDSS
  • [19] DQinstitute.org, 2020, NEARL 2 3 CHILDR SUR
  • [20] Eikenberg Ronald, 2019, KASPERSKY SCRIPT INJ