South Korea Shoots The (Smart) Sheriff; Pull Support For Mandated, Severely Flawed Cellphone Spyware App
from the will-just-need-to-find-better-spyware-to-mandate dept
The South Korean government’s strong suggestion parents should install spyware in their kids’ phones resulted in the the official blessing of Smart Sheriff — a program that hoovered up communications and data and sent it all back to the MOIBA mothership with a minimum of security. Citizen Lab security researchers found numerous flaws in the spy app, ranging from the unencrypted transmission (and storage) of data to the circumvention of HTTPS protections in order to check sites against blacklists.
In response to the diclosure of these vulnerabilities, the South Korean government has put the Sheriff down.
Moon Hyun-seok, a senior official at the Korea Communications Commission, told The Associated Press that “Smart Sheriff” has been removed from the Play store, Google’s software marketplace, and that existing users are being asked to switch to other programs.
The government plans to shut down the service to existing users “as soon as possible,” he said.
In the meantime, Smart Sheriff will continue to barely protect the vast amount of data it’s been entrusted with. A follow-up report by Citizen Lab notes that, despite being notified more than 90 days ago, the developer has yet to address many of the vulnerabilities reported to it by the researchers.
A second audit of the Smart Sheriff application reveals that there are numerous unresolved security vulnerabilities that put minor children and parental users of the application at serious risk.
MOIBA, the Korean industry consortium responsible for the Smart Sheriff application, has been slow to respond to the issues raised (of which it was notified more than 90 days ago); the fixes that have been applied do not adequately or effectively address the issues, especially for users; and MOIBA has not communicated transparently to the public about Smart Sheriff’s known risks.
Citizen Lab recommended the removal of the spy app from the market, with its recommendation arriving only a day ahead of the South Korean government’s official announcement. The researchers still consider the app to be highly-exploitable, thanks to MOIBA’s half-assed patch job. At this point — with the app still in wide use — the only thing not leaking information is MOIBA’s PR team.
Smart Sheriff’s maker, an association of South Korean mobile operators called MOIBA, declined comment.
MOIBA claims to have addressed the issues raised by Citizen Lab, but researchers point out most of the “solutions” were cosmetic. The underlying vulnerabilities remain.
Overall, while some changes have been made in response to the initial disclosure made by Citizen Lab to MOIBA, attackers still have most of the same opportunities to exploit vulnerabilities in the application as they did in previous versions. Many of the issues that were marked as high priority in the previous report, such as the lack of protections around sensitive private data, and transport security, remain effectively unaddressed.
That the government has made the move to kill the app and repeal its support is a positive step, but it’s one that took place at several terrible decisions. Mandating spyware for phone users is already a problem, no matter the intent behind it. If parents want to spy on their kids’ phone use, it should be up to the parents, not the government. That the government threw its weight behind an app whose developers couldn’t even be bothered to implement halfway decent security measures until after researchers discovered the holes makes this even worse.