App used by parents to spy on their kids suffers data breach
If you're a parent, you might be familiar with an app called TeenSafe. This is an app that allows Mom and Dad to actually spy on their children and control their online and mobile behavior. The app has a YouTube channel with several videos that show users how to block their kids from using Snapchat and give directions on how to turn the little ones' phones off during a family dinner. The company says it has over a million parents using the service on both the iOS and Android platform.
But today's news is really not about the app's features. It appears that TeenSafe's servers were hosted by Amazon's cloud service and were accessible to anyone without requiring a password. According to Robbie Wiggins, a security researcher in the U.K., two servers belonging to the company were leaking. While one of the servers only dealt with test data, the other one contained the parent's email address associated with an account, the Apple ID email address belonging to the child, the child's device name and its UDID number. It also stored the password to the child's Apple ID in plaintext.
TeenSafe requires that two factor authentication be disabled, which means that using the leaked information, a hacker could access a child's account and collect personal data and content. The company's website says that encryption is used in case of a data breach, although that doesn't seem to have worked in this case.
TeenSafe has started to alert all of the subscribers involved. 10,200 records from the last three months were in that server, although some of the records were duplicates.
source: ZDNet
Things that are NOT allowed: