{"id":19426,"date":"2022-06-23T10:45:05","date_gmt":"2022-06-23T18:45:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/06\/23\/news-13159\/"},"modified":"2022-06-23T10:45:05","modified_gmt":"2022-06-23T18:45:05","slug":"news-13159","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/06\/23\/news-13159\/","title":{"rendered":"Parents Need to Know What\u2019s Going On Inside Their Day Care Apps"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62b3a4dc403df153e676029d\/master\/pass\/ideas-daycare-app.jpg\"\/><\/p>\n<p><strong>Credit to Author: Alexis Hancock| Date: Thu, 23 Jun 2022 11:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/alexis-hancock\">Alexis Hancock<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">Last year, like<\/span> many new parents, I was walking the extreme tightrope of keeping my young child healthy <em>and<\/em> happy. When my daughter left the stages of infancy into becoming a much more aware toddler, I decided that it was high time to put her in preschool. It was better than her staring at the same four walls of the living room while I contemplated the health risks over and over. After a few internet searches and some phone calls, I chose one that was close <em>and<\/em> had spots open (which was pretty hard to obtain). When I started the enrollment process, I saw a flyer in the huge packet that immediately threw me into a new set of worries I didn\u2019t want to deal with: \u201cWe also use <a data-offer-url=\"https:\/\/mybrightwheel.com\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/mybrightwheel.com\/&quot;}\" href=\"https:\/\/mybrightwheel.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Brightweel<\/a>, a mobile application to log attendance, share milestones, and keep parents up to date on daily interactions.&#x27;\u201d<\/p>\n<p class=\"paywall\"><strong>Alexis Hancock<\/strong> is director of engineering at the Electronic Frontier Foundation.<\/p>\n<p class=\"paywall\">I don\u2019t know what goes through other parents\u2019 minds at this point, but I do privacy- and security-oriented work as my day job at the Electronic Frontier Foundation, so I couldn\u2019t help myself from looking at the security controls Brightwheel gave to me as a parent. This was my child\u2019s data left up to some company. Don\u2019t get me wrong, the app provided some comfort, allowing me to see my baby smiling, making friends, and enjoy riding bikes during outside playtime. <em>Especially<\/em> in that first week when you aren\u2019t there to oversee every aspect of their life for the first time. But looking at my account, I saw very few settings that said anything about security. There was a PIN code to check them in and out, but that was about it.<\/p>\n<p class=\"paywall\">Over several months, I looked at the gigantic amount of data that was being shared and stored by this app every day. Diaper changes, story time pictures, nap times, etc. The more data about my daughter I saw, the more my worry grew.<\/p>\n<p class=\"paywall\">By October 2021, I couldn\u2019t sit on this any longer. I wouldn\u2019t call myself a hacker by the definition in most people\u2019s heads. But in this case, for my daughter\u2019s sake, being a mother means doing everything in my power to keep her safe. So I began a months-long dive into the early education landscape of apps\u2014and didn\u2019t like what I found.<\/p>\n<p class=\"paywall\">I am lucky in where I work. Some cold emails and a little networking later, a coworker (also a new parent being asked to use Brightwheel) and I finally got a meeting with an actual person at the company. The meeting was productive in the sense that Brightwheel seemed to understand the concerns but confirmed how woefully behind the entire industry was in privacy and security protections.<\/p>\n<p class=\"paywall\">For example, a very basic and well-known protection measure is two-factor authentication. You know how some services now require you to enter a one-time code in addition to your password? That\u2019s two-factor authentication, which gives an enormous bang for your buck in terms of security. It\u2019s been spreading rapidly, and at least <em>offering<\/em> it is pretty much an industry standard these days.<\/p>\n<p class=\"paywall\">Brightwheel now has <a data-offer-url=\"https:\/\/help.mybrightwheel.com\/en\/articles\/5918580-2fa-at-sign-in-overview\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/help.mybrightwheel.com\/en\/articles\/5918580-2fa-at-sign-in-overview&quot;}\" href=\"https:\/\/help.mybrightwheel.com\/en\/articles\/5918580-2fa-at-sign-in-overview\" rel=\"nofollow noopener\" target=\"_blank\">two-factor authentication<\/a> available for all school or day care administrators and parents, but it is the only one to have done so. Which is bullshit.<\/p>\n<p class=\"paywall\">Several of these companies don\u2019t disclose what data they collect and where it goes. And what we\u2019ve found is that what they do is, in some cases, track and share information in the way Facebook is also known to. That\u2019s bad enough when it\u2019s data about adults on a public social media site, but it\u2019s horrifying when it\u2019s information about a preschooler.<\/p>\n<p class=\"paywall\">Figuring out the privacy and security issues around the app your child\u2019s day care uses isn\u2019t like researching how to sleep-train a baby or what high chair to use, where parents can easily find trusted sources of information. This information isn\u2019t out there. Parents and administrators are being sold on convenience, but they aren\u2019t given even the most basic tools to choose a secure app.<\/p>\n<p class=\"paywall\">And for those of us who have the know-how to find these vulnerabilities and fix them, we\u2019ve run into the problem of the companies not wanting to hear about it. As an ethical hacker, the thing I <em>planned<\/em> to do was disclose what I found and wait 90 days for a response (a common security industry practice). Even there, I hit roadblocks.<\/p>\n<p class=\"paywall\">Beyond not finding a way to contact them on their websites, I discovered that <a href=\"https:\/\/www.researchgate.net\/publication\/358904572_We_may_share_the_number_of_diaper_changes_A_Privacy_and_Security_Analysis_of_Mobile_Child_Care_Applications\">researchers based in Germany<\/a> released a paper in March 2022 identifying security and privacy problems with 42 early education and day care management applications. In addition to outlining the vulnerabilities, the paper also explained that the researchers did their due diligence by ethically reporting the issues and had almost no response from the companies.<\/p>\n<p class=\"paywall\">That\u2019s unacceptable. If your company handles sensitive information, and researchers do the work of figuring out how to make your product more secure for you, not responding to them is a terrible practice.<\/p>\n<p class=\"paywall\">I <a data-offer-url=\"https:\/\/www.eff.org\/deeplinks\/2022\/06\/daycare-apps-are-dangerously-insecure\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.eff.org\/deeplinks\/2022\/06\/daycare-apps-are-dangerously-insecure&quot;}\" href=\"https:\/\/www.eff.org\/deeplinks\/2022\/06\/daycare-apps-are-dangerously-insecure\" rel=\"nofollow noopener\" target=\"_blank\">published my own research into these apps on EFF\u2019s website<\/a>, where you can dig into the technical details, but the major takeaway is that these services are not as secure as they can or should be.<\/p>\n<p class=\"paywall\">Some very basic demands we have for all of these companies:<\/p>\n<p class=\"paywall\">In addition, we would like to see it become standard for these apps to secure any messages sent between the schools and parents. End-to-end encryption would do that, and there\u2019s no need for a server to be seeing the updates on a child\u2019s life.<\/p>\n<p class=\"paywall\">And finally, these companies need to monitor and proactively respond to reports of problems with their applications. It should not take a technologist who happens to work at a digital privacy organization and a coworker who happens to be a lawyer on these same issues cold-emailing and working contacts to get a meeting.<\/p>\n<p class=\"paywall\">Being able to get daily updates on how your child is faring in day care is extremely comforting to a parent. It was for me. Unfortunately, that comfort was soon outweighed by the danger I found.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/daycare-app-privacy-security\/\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62b3a4dc403df153e676029d\/master\/pass\/ideas-daycare-app.jpg\"\/><\/p>\n<p><strong>Credit to Author: Alexis Hancock| Date: Thu, 23 Jun 2022 11:00:00 +0000<\/strong><\/p>\n<p>After months of digging into privacy and security issues around these apps, I have some serious concerns.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[21330,21382],"class_list":["post-19426","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-ideas","tag-security-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19426"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19426\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19426"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}