Smart Sheriff, Dumb Idea: The Wild West of Government Assisted Parenting

Presented at DeepSec 2016 „Ten“, Unknown date/time (Unknown duration)

Would you want to let your kids discover the darker corners of the internet without protection? Wouldn't it be handy to know what they do online, to be alerted when they search for dangerous keywords and to be able to control what websites they can visit and even when they play games? Worry no longer, the South Korean government got you covered. Simply install the "Smart Sheriff" app on your and your kids' phones. Smart Sheriff is the first parental-control mobile app that has been made a legally required, obligatory install in an entire country! Yay, monitoring! Well, something shady yet mandatory like this cannot come about without an external pentest. And even better, one that wasn't solicited by the maintainer but initiated by the OTF and CitizenLab and executed by the Cure53 team! In this talk, two of the Cure53 testers involved in the first and, who would have guessed, second penetration test against the "Smart Sheriff" app, will share their findings. Maybe everything went allright, maybe the million kids forced to have this app run on their devices are safe. Maybe. But if so would there be a talk about it? We all know, mandated surveillance apps to protect children are a great idea, and outsourcing to the lowest bidder, always delivers the best results. Right? Going over the first and second pentest results we will share our impressions about the "security" of this ecosystem and show examples about the "comprehensive" vendor response, addressing "all" the findings impeccably. This talk is a great example of how security research concerning a serious political decision and mandatory measures might achieve nothing at all - or of how a simple pentest together with excellent activist work may spark a political discussion and more.

Presenters:

  • Fabian Fäßler - Cure53
  • Abraham Aranguren - Cure53
    Abraham was an honors student in Information Security at university. His work experience from 2000 until 2007 was mostly defensive: Fixing vulnerabilities, source code reviews and later on trying to prevent vulnerabilities at the design level as an application and framework architect. From 2007 onwards Abraham focused more on the offensive side of security with special focus on web app security. He is a senior member of the Cure53 team, and a senior consultant for Version 1 - the top IT consultancy in Ireland. Abraham is also the creator of "Practical Web Defense" - a hands-on eLearnSecurity attack and defense course, as well as an OWASP OWTF project leader. He sometimes writes on http://7-a.org or twitter as @7a_ and @owtfp. Abraham holds a Major degree and a Diploma in Computer Science apart from a number of information security certifications: CISSP, OSCP, GWEB, OSWP, CPTS, CEH, MCSE:Security, MCSA:Security, Security+. As a shell scripting fan trained by unix dinosaurs Abraham wears a proud manly beard. Previous presentations and some recordings can be found here: http://www.slideshare.net/abrahamaranguren/presentations http://blog.7-a.org/search/label/Public%20Speaking

Links:

Similar Presentations: