For parents of young children and adolescents, the digital age has introduced many new challenges, including excessive screen time, inappropriate online content, cyber predators, and cyberbullying. To address these challenges, many parents rely on numerous parental control solutions on different platforms, including parental control network devices (e.g., WiFi routers) and software applications on mobile devices and laptops. While these parental control solutions may help digital parenting, they may also introduce serious security and privacy risks to children and parents, due to their elevated privileges and having access to a significant amount of privacy-sensitive data. In this paper, we present an experimental framework for systematically evaluating security and privacy issues in parental control software and hardware solutions. Using the developed framework, we provide the first comprehensive study of parental control tools on multiple platforms including network devices, Windows applications, Chrome extensions and Android apps. Our analysis uncovers pervasive security and privacy issues that can lead to leakage of private information, and/or allow an adversary to fully control the parental control solution, and thereby may directly aid cyberbullying and cyber predators.
翻译:对于幼儿和青少年的父母来说,数字时代带来了许多新的挑战,包括过长的屏幕时间、不适当的在线内容、网络掠食者和网络欺凌。为了应对这些挑战,许多父母依靠不同平台上的许多父母控制办法,包括父母控制网络装置(例如WiFi路由器)和移动设备及膝上电脑的软件应用。虽然这些父母控制办法可能有助于数字育儿,但也可能给儿童和父母带来严重的安全和隐私风险,因为他们的特权较高,而且能够获得大量隐私敏感数据。在本文件中,我们提出了一个实验框架,系统评价父母控制软件和硬件解决方案中的安全和隐私问题。我们利用已开发的框架,对多个平台上的父母控制工具,包括网络装置、视窗应用、铬扩展和机器人辅助装置进行首次全面研究。我们的分析发现普遍存在的安全和隐私问题可能导致私人信息泄漏,并(或)允许对手充分控制父母控制解决方案,从而可能直接帮助网络欺凌和网络捕食者。