A family tracking app was leaking real-time location data
techcrunch.com
techcrunch.com
And people trust this with the real time location data of their children so they can keep them "safe". Absolutely ridiculous
A few years ago, I discovered the open MongoDB database of an educational website called Kaizena, which we were using in my high school English class. When I reported the problem to them, they quickly fixed it (probably with some iptables hack). They even wrote a blog post [1] about fixing it, where they claimed they added "additional firewalls to the database". More like _one_ firewall.
As a side note, Kaizena also had another security bug where their API would return JSON payloads that had private information in it (e.g. the voice feedback for other students' work). I reported it years ago, but who knows if it's fixed.
[1] https://blog.kaizena.com/post/68627783859/a-note-on-security
https://stackoverflow.com/questions/21421410/how-to-disable-...
But this:
> ...plaintext passwords...
Why, oh why, store plaintext passwords?!?
You start a project. You set up a DB with minimal security because you're just starting the project, and you figure that down the road before you release to the public, you will secure that DB.
A few weeks/months pass and you are ready to release your app into the wild. But by that time you are focused on other things and that unsecured DB is forgotten because it has "just worked" since that initial setup. You release and sometime later something like this happens because that DB never got the attention to security it needed because it "just worked" and was forgotten.
Don't get me wrong this is still very bad. But I can see how an unsecured server/plaintext passwords happen. It's not by design b but rather a shortcut you took way back when that you have since completely forgotten about.
* identify a hashing library * install/import it * call it (when storing the password and when comparing)
It’s a matter of minutes really.
So they accessed the database as well as personal information of users? Is this not a crime whether or not the database was unprotected?
Journalists do enjoy certain freedoms, but to my knowledge (as a former lawyer), special treatment under the CFAA isn't one of them.
1: https://www.wired.com/2014/04/att-hacker-conviction-vacated/
I used the "find my frieds" enabling my wife to track me for when I went in a long distance working trip from Italy in a very sketchy area of the US called SILICON VALLEY.
Jokes apart, a temporary "find my friends" can be useful, but a continuous tracking it's nonsense to me.
So in wanting to keep your child safe by checking these apps often, you can make them _less_ safe and more dishonest.
I constantly struggle with balance between keeping my children safe and allowing them agency and the development of personal responsibility. Among other things, this ranges over such topics as location tracking, internet filtering, browser history, screen-time, etc.
I will absolutely admit that much of this sounds like the stuff that repressive governments engage in, but then again, my children are not full citizens. They are developing human beings that require a certain degree of protection.
Are you only opposed to location tracking? What level of "nanny-state" do think is acceptable in a household setting?
(I'm a father of a 3 year old; I'll likely use _something_ like this when she's old enough to go to the store around the corner and back by herself, but will likely stop once she's old enough to take the subway by herself.)
Parents monitor their kids for a combination of:
1. Worry about the outside world. Justified - but monitoring location doesn't make it any less likely that they'll get hurt.
2. Worry about their child doing something they consider dumb. Again - justified. They will absolutely do something you consider dumb. But monitoring your child won't make then agree with you and won't stop them from doing something you don't like. The tighter the grip, the more they'll fight and the more they'll resent you for making them fight.
Parents like to think that this resentment will go away when the child is older. It doesn't. Many of you probably resent something your parents did when you were younger. But it does become less intense with distance - like everything else.
Anywho - Monitoring teenagers doesn't actually help anything. Monitoring younger children might make you feel more safe, though.
The absolute worst genre of HN comments is "single childless guy criticizes others about their parenting". You've got some examples in the replies to this comment.
I will say you're probably doing fine.
The https://www.zood.xyz/products/location#about-zood-location page doesn't really say anything other than you promise you are doing what you say (and you probably are).
While in beta, I'm not charging, but in order to align my interests with those of users I will be charging for it once I'm done beta testing. So far I've only been testing with family and close friends.
The app isn't currently open source, but I want to find a license model that will let folks see the source code while still preventing someone from forking it and running their own instance of my company. As you noted, this needs to be a sustainable endeavor, and I think that would be unlikely if I just release it all under MIT or BSD-3
It's too early for an audit (and I don't have the money for one yet), but I'm using libsodium for the crypto so there's no need to worry about me writing my own bad crypto primitves.
The website is sparse, because the current audience for it is my family and friends who I've contacted about helping me with the beta testing. I intend to flesh out the site a lot more before I come out of beta.
Copyleft open source licenses only help you so much, people can still clone your company as long as their version is also open source. There's no way to prohibit corporate use of your code and still have an OSI-approved license.
The spot that kinda falls between those two classes is if you want people to be able to fork or self-host for personal/non-commercial use, and there's a few also not open source license examples out there for that too. There's a couple of that sort listed under https://en.wikipedia.org/wiki/Source-available_software (Commons Clause or Mega Limited Code Review sound fairly similar to what you might want.)
[0]https://itunes.apple.com/us/app/find-my-friends/id466122094