South Korea Shoots The (Smart) Sheriff; Pull Support For Mandated, Severely Flawed Cellphone Spyware App

from the will-just-need-to-find-better-spyware-to-mandate dept

The South Korean government’s strong suggestion parents should install spyware in their kids’ phones resulted in the the official blessing of Smart Sheriff — a program that hoovered up communications and data and sent it all back to the MOIBA mothership with a minimum of security. Citizen Lab security researchers found numerous flaws in the spy app, ranging from the unencrypted transmission (and storage) of data to the circumvention of HTTPS protections in order to check sites against blacklists.

In response to the diclosure of these vulnerabilities, the South Korean government has put the Sheriff down.

Moon Hyun-seok, a senior official at the Korea Communications Commission, told The Associated Press that “Smart Sheriff” has been removed from the Play store, Google’s software marketplace, and that existing users are being asked to switch to other programs.

The government plans to shut down the service to existing users “as soon as possible,” he said.

In the meantime, Smart Sheriff will continue to barely protect the vast amount of data it’s been entrusted with. A follow-up report by Citizen Lab notes that, despite being notified more than 90 days ago, the developer has yet to address many of the vulnerabilities reported to it by the researchers.

A second audit of the Smart Sheriff application reveals that there are numerous unresolved security vulnerabilities that put minor children and parental users of the application at serious risk.

MOIBA, the Korean industry consortium responsible for the Smart Sheriff application, has been slow to respond to the issues raised (of which it was notified more than 90 days ago); the fixes that have been applied do not adequately or effectively address the issues, especially for users; and MOIBA has not communicated transparently to the public about Smart Sheriff’s known risks.

Citizen Lab recommended the removal of the spy app from the market, with its recommendation arriving only a day ahead of the South Korean government’s official announcement. The researchers still consider the app to be highly-exploitable, thanks to MOIBA’s half-assed patch job. At this point — with the app still in wide use — the only thing not leaking information is MOIBA’s PR team.

Smart Sheriff’s maker, an association of South Korean mobile operators called MOIBA, declined comment.

MOIBA claims to have addressed the issues raised by Citizen Lab, but researchers point out most of the “solutions” were cosmetic. The underlying vulnerabilities remain.

Overall, while some changes have been made in response to the initial disclosure made by Citizen Lab to MOIBA, attackers still have most of the same opportunities to exploit vulnerabilities in the application as they did in previous versions. Many of the issues that were marked as high priority in the previous report, such as the lack of protections around sensitive private data, and transport security, remain effectively unaddressed.

That the government has made the move to kill the app and repeal its support is a positive step, but it’s one that took place at several terrible decisions. Mandating spyware for phone users is already a problem, no matter the intent behind it. If parents want to spy on their kids’ phone use, it should be up to the parents, not the government. That the government threw its weight behind an app whose developers couldn’t even be bothered to implement halfway decent security measures until after researchers discovered the holes makes this even worse.

Filed Under: , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “South Korea Shoots The (Smart) Sheriff; Pull Support For Mandated, Severely Flawed Cellphone Spyware App”

Subscribe: RSS Leave a comment
9 Comments
Anonymous Coward says:

keeping it in perspective

While North Korea gets played as the perpetual bogeyman, something that virtually never gets mentioned in the US mainstream media is South Korea’s sordid history as an undemocratic, totalitarian, and sometimes genocidal state. It’s reality is a far cry from the sort of liberal, freedom-loving democracy that’s generally presented with this US-occupied country.

http://thediplomat.com/2014/08/south-koreas-own-history-problem/

tqk (profile) says:

Re: keeping it in perspective

… South Korea’s sordid history as an undemocratic, totalitarian, and sometimes genocidal state.

South Korea is a Cold War proxy puppet state of the west and is still in a state of war, and that’s after surviving WWII Japanese occupation. That country has suffered through a century of crap landing on it from outside. It’s not very surprising that it’s since suffered under the rule of a few totalitarian dictatorships, but you’ve got to admit it’s today a vast improvement over what it was when I was growing up. Brian Haig’s “Mortal Allies” is an interesting (though fictional) take on the current situation from a modern (2002) point of view.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...