<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>Bark.us parental controls: lies, data at risk, abuse</title>
    
    <!-- Favicon -->
    <link rel="icon" href="img/nobark.png" type="image/png">
	<link rel="stylesheet" href="fa/css/all.min.css">
    
    <style>
        body {
            font-family: Arial, sans-serif;
            background-color: #f0f8ff;
            margin: 0;
            padding: 0;
            display: flex;
            justify-content: center;
            align-items: center;
            height: 100vh;
            text-align: center;
        }

        .container {
            background-color: #ffffff;
            padding: 50px;
            border-radius: 8px;
            box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);
            width: 80%;
            max-width: 600px;
			z-index: 10;
        }

		.icon img {
			width: 256px;
			cursor: pointer;
			transition: transform 0.2s;
		}

		.icon img:hover {
			transform: rotate(15deg);
		}


        h1 {
            font-size: 36px;
            margin-top: 20px;
            color: #333;
        }

        p {
            font-size: 18px;
            color: #666;
			text-align: justify;
        }

        .button {
            margin-top: 20px;
            padding: 10px 20px;
            background-color: #ff5722;
            color: white;
            text-decoration: none;
            border-radius: 4px;
            font-weight: bold;
            cursor: pointer;
            transition: transform 0.2s ease;
        }

        .button:hover {
            background-color: #e64a19;
            transform: scale(1.05);
        }

        /* Style for the tour steps */
        .tour-step {
            display: none;
            opacity: 0;
            transition: opacity 0.5s ease;
        }

        .tour-step.active {
            display: block;
            opacity: 1;
        }

        .tour-step.fade-out {
            opacity: 0;
        }

        .tour-step h2 {
            font-size: 24px;
            color: #333;
            margin-bottom: 15px;
        }

        .tour-step p {
            font-size: 18px;
            margin-bottom: 15px;
        }

        .next-button {
            margin-top: 20px;
            padding: 10px 20px;
            background-color: #4caf50;
            color: white;
            text-decoration: none;
            border-radius: 4px;
            font-weight: bold;
            cursor: pointer;
            transition: transform 0.2s ease;
        }

        .next-button:hover {
            background-color: #45a049;
            transform: scale(1.05);
        }
		
		.fade-out {
			opacity: 0;
			transition: opacity 0.5s ease;
		}	

		.expander-button {
			background-color: #007BFF; /* Vibrant blue background */
			color: #ffffff; /* White text */
			font-size: 16px; /* Readable font size */
			font-weight: bold; /* Emphasized text */
			border: none; /* Remove default button border */
			border-radius: 8px; /* Smooth corners */
			padding: 10px 20px; /* Balanced padding for a good click area */
			cursor: pointer; /* Pointer cursor to indicate interactivity */
			transition: background-color 0.3s, transform 0.2s; /* Smooth hover effect */
			box-shadow: 0 4px 6px rgba(0, 0, 0, 0.1); /* Subtle shadow for depth */
		}

		.expander-button:hover {
			background-color: #0056b3; /* Darker blue for hover */
			transform: scale(1.05); /* Slight zoom effect */
		}

		.expander-button:active {
			background-color: #003d80; /* Even darker blue for active state */
			transform: scale(0.98); /* Slight shrink for click feedback */
		}

		.expander-button:focus {
			outline: none; /* Remove default focus outline */
			box-shadow: 0 0 0 3px rgba(0, 123, 255, 0.5);
		}
		
		/* Style the unordered list */
		ul {
			margin: 1em 0; /* Add space above and below the list */
			padding-left: 1.5em; /* Indent the list slightly */
			list-style-type: disc; /* Use a disc bullet point style */
			color: #333; /* Dark gray text color for readability */
		}

		/* Style the list items */
		ul li {
			margin: 0.5em 0; /* Add vertical spacing between list items */
			line-height: 1.5; /* Improve readability with proper line spacing */
			font-size: 1rem; /* Ensure consistent font size */
			color: #444; /* Slightly lighter text for balance */
		}

		/* Add emphasis to bold text within list items */
		ul li strong {
			color: #000; /* Make bold text black for contrast */
			font-weight: bold; /* Ensure strong emphasis */
		}

		/* Optional: Add hover effect for list items */
		ul li:hover {
			color: #007BFF; /* Change text color on hover to a nice blue */
			cursor: default; /* Indicate no interaction but still provide a visual change */
		}

	.navigation-menu {
		display: flex;
		flex-direction: column; /* Stack label and select on smaller screens */
		align-items: center; /* Center align the content */
		margin-top: 20px;
		width: 100%; /* Ensure it doesn't exceed container width */
		box-sizing: border-box; /* Include padding and borders in width */
	}

	.navigation-menu label {
		font-size: 16px;
		margin-bottom: 5px; /* Add spacing for better readability */
		text-align: center;
	}

	.navigation-menu select {
		padding: 8px;
		border: 1px solid #ccc;
		border-radius: 4px;
		font-size: 14px;
		max-width: 90%; /* Prevent overflowing on small screens */
		width: 300px; /* Set a reasonable default width */
		box-sizing: border-box; /* Include padding and borders in width */
	}

		
		/* Base styles for expandable content */
		.expandable-content {
			overflow: hidden; /* Smooth animation for expanding/collapsing */
			max-height: 0; /* Collapsed state */
			transition: max-height 0.5s ease, padding 0.5s ease; /* Smooth transitions */
			padding: 0 15px; /* Initial padding for collapsed state */
		}

		/* Expanded state with additional adjustments */
		.expandable-content[style*="block"] {
			padding: 15px; /* Add padding for expanded content */
		}

		html, body {
			overflow: auto;
		}

	
		body {
			font-family: Arial, sans-serif;
			background-color: #f4f4f4;
			margin: 0;
			padding: 0;
			display: flex;
			justify-content: center;
			align-items: flex-start; /* Align content to start */
			height: auto; /* Remove fixed height */
			text-align: center;
			overflow-x: hidden; /* Avoid horizontal scrolls */
		}

		.container {
			background-color: #ffffff;
			padding: 20px;
			border-radius: 8px;
			box-shadow: 0 4px 8px rgba(0, 0, 0, 0.1);
			width: 80%;
			max-width: 600px;
			position: relative;
			display: flex;
			flex-direction: column;
			justify-content: flex-start;
			align-items: center;
			margin: 10px 0; /* Add spacing for smaller viewports */
		}
		
		.tooltip {
			position: relative;
			display: inline-block;
			cursor: pointer;
		}

		.tooltip .tooltiptext {
			visibility: hidden;
			width: 200px;
			background-color: #555;
			color: #fff;
			text-align: center;
			border-radius: 5px;
			padding: 5px 0;
			position: absolute;
			z-index: 1;
			bottom: 125%; /* Position above the button */
			left: 50%;
			margin-left: -100px; /* Center align tooltip */
			opacity: 0;
			transition: opacity 0.3s ease;
		}

		.tooltip:hover .tooltiptext {
			visibility: visible;
			opacity: 1;
		}

		@keyframes spin {
			from {
				transform: rotate(0deg);
			}
			to {
				transform: rotate(360deg);
			}
		}

		#logo.spin {
			animation: spin 5s linear infinite;
		}
		
	   .paw-print {
			position: absolute;
			width: 40px;
			height: 40px;
			background-image: url('img/paw-print.png'); /* Replace with your paw image */
			background-size: contain;
			background-repeat: no-repeat;
			opacity: 0; /* Start invisible */
			animation: fadeIn 0.6s ease-in forwards;
		}

		@keyframes fadeIn {
			0% {
				opacity: 0;
			}
			100% {
				opacity: 1;
			}
		}

		@keyframes fadeOut {
			0% {
				opacity: 1;
			}
			100% {
				opacity: 0;
			}
		}
		
		.teasing-bubble {
			position: absolute;
			background: #ffcc00; /* Bright yellow for visibility */
			color: #333;
			font-size: 14px;
			font-weight: bold;
			padding: 10px 15px;
			border-radius: 8px;
			box-shadow: 0 4px 6px rgba(0, 0, 0, 0.1);
			z-index: 100;
			animation: fadeInOut 5s ease-out;
			top: -60px; /* Position above the container */
			left: 50%; /* Center horizontally */
			transform: translateX(-50%);
			width: 200px;
			height: 50px;
			white-space: normal;
			word-wrap: break-word; /* Break long words if necessary */
			text-align: center; /* Center text horizontally */
			display: flex;
			justify-content: center; /* Horizontal alignment */
			align-items: center; /* Vertical alignment */
		}

		.teasing-bubble::after {
			content: '';
			position: absolute;
			bottom: -10px; /* Position the triangle below the bubble */
			left: 20px; /* Align the triangle to the left side */
			width: 0;
			height: 0;
			border-style: solid;
			border-width: 10px 10px 0 0; /* Triangle pointing upwards */
			border-color: #ffcc00 transparent transparent transparent; /* Match the bubble's background */
		}


		@keyframes fadeInOut {
			0% {
				opacity: 0;
				transform: translate(-50%, -110%);
			}
			10% {
				opacity: 1;
				transform: translate(-50%, -100%);
			}
			90% {
				opacity: 1;
			}
			100% {
				opacity: 0;
				transform: translate(-50%, -90%);
			}
		}
    </style>
</head>
<body>


<div class="container">
	<div class="icon" id="logo-container">
		<img id="logo" src="img/nobark.png" alt="Logo" onclick="showPawsMessage()">
	</div>
	
    <h1 id="title-main">Say no to deceptive and dangerous practices of Bark Technologies</h1>
    <p id="subtitle-main" style="text-align: center">Take our tour to learn more.</p>
    
    <button class="button tooltip" id="startTour" onclick="startTour()">
		Take a Tour
		<span class="tooltiptext">Embark on a no-bark tour—safety first!</span>
	</button>


    <div class="tour-step" id="step1">
        <h2>Why this campaign?</h2>
		<p>We know that Bark has helped many families. However, there's a <strong>dark side</strong> to Bark's technology. We have analyzed publicly available source code for some parts of their technology and conducted a <strong>thorough investigation</strong>.</p>
		<p>Bark's technology has <strong>severe vulnerabilities</strong> that put children's data at risk. These vulnerabilities have existed for <strong>years</strong>, and Bark claims to undergo <strong>SOC II audits</strong>, yet they have failed to address these critical issues. They have known about these vulnerabilities for <strong>months</strong>, but they have not <strong>fixed</strong> them yet. Instead of addressing these issues honestly, they choose to <strong>lie to customers</strong> rather than admit their faults and resolve the problems as soon as possible.</p>
		<p>Bark claims to <strong>protect children</strong>, but their platform lacks <strong>safety measures</strong> to prevent the <strong>abuse</strong> of their technology by parents. While we recognize that most parents love their children, sadly, <strong>some do not</strong>.</p>
		<p>We urge Bark to <strong>fix their technology</strong>, <strong>stop lying</strong>, and incorporate features that <strong>prevent child abuse</strong>.</p>

        <button class="next-button" onclick="showNextStep(1)">Next</button>
    </div>

	<div class="tour-step" id="step2">
		<h2>Vulnerabilities Summary</h2>
		<p>Bark's Chrome extension has several serious security flaws that could harm your child's safety and privacy. Here's an easy-to-understand breakdown:</p>
		<ul>
			<li>
				<strong>Fake Activity Reports:</strong> 
				Hackers can manipulate how Bark sends activity reports by pretending to be someone else. For example, they could make it look like a child visited harmful websites, even if they didn’t. This can cause confusion and unnecessary fear for parents.
			</li>
			<li>
				<strong>Weak Security for Communication:</strong> 
				The system doesn't properly check if the messages it receives are from a trusted source. This means an attacker could send fake information to Bark's servers, bypassing basic safety measures.
			</li>
			<li>
				<strong>Risk of Leaking Personal Information:</strong> 
				The extension sends a child’s email address as part of its communication. While this is protected by secure connections (HTTPS), exposing emails this way increases the risk of phishing or other online scams if someone gains access to the data.
			</li>
			<li>
				<strong>Confusion from Rapid Changes:</strong> 
				If a child’s browsing activity changes quickly (like switching between tabs), the system may get confused and send incorrect or incomplete reports. Hackers could also exploit this weakness to tamper with what Bark reports.
			</li>
		</ul>
		<p>
			We analyzed Bark's Chrome extension, which consists of only <strong>164 lines of code</strong>. Despite its small size, we identified <strong>4 major vulnerabilities</strong>. These findings highlight a lack of proper testing and security review. Alarmingly, these vulnerabilities have existed for <strong>years</strong>, even though Bark claims to undergo <strong>SOC II audits</strong>.
		</p>
		<p>
			Our analysis focused on a <strong>small area of vulnerabilities</strong>, yet the Bark Chrome extension already demonstrates <strong>poor coding practices</strong>. The presence of multiple security flaws in such a small codebase suggests <strong>pure amateurism</strong> in secure software development.
		</p>
		<p>
			Furthermore, as we only reviewed the <strong>publicly available code</strong> of the Chrome extension, there is a significant concern that similar <strong>bad security practices</strong> could be widespread across Bark's entire platform.
		</p>
		
		<!-- Expander Section -->
		<p style="text-align: center"><button class="expander-button" onclick="toggleDetails('.technical-details')">View technical details</button></p>
		<div class="technical-details expandable-content" style="display: none; margin-top: 1em; text-align: justify; background-color: #f9f9f9; padding: 15px; border-radius: 8px; box-shadow: 0 4px 6px rgba(0, 0, 0, 0.1);">
			<h3>Technical Details of Vulnerabilities</h3>
			<h4>1. Spoofing the 'X-Bark-Email' Header</h4>
			<p>
				The code includes a custom header, <code>'X-Bark-Email'</code>, which is passed in the HTTP request to the server. 
				This header holds the user's email, which is fetched using <code>chrome.identity.getProfileUserInfo()</code>. 
				However, this email can be easily spoofed by an attacker if they inject malicious scripts or manipulate the request content.
			</p>
			<p><strong>Why is this insecure?</strong></p>
			<ul>
				<li>An attacker could falsify which user is being reported by modifying the email sent with the URL.</li>
				<li>This undermines the reporting mechanism, as attackers could impersonate another user or child.</li>
			</ul>
			<p><strong>Mitigation:</strong> Use OAuth tokens, signed requests, or session-based tokens to verify the user's email securely.</p>
			<p><strong>CVSS Rating:</strong> 7.5 (High)</p>
			
			<h4>2. Insecure Communication (Lack of Authentication for API Requests)</h4>
			<p>
				Data is sent to the API endpoint (<code>https://urls.bark.us</code>) via a POST request without authentication. 
				Custom headers like <code>'X-Bark-Email'</code> and <code>'X-Bark-Extension'</code> do not verify the source of the request.
			</p>
			<p><strong>Why is this insecure?</strong></p>
			<ul>
				<li>Attackers could send fake data to the server, pretending to be a legitimate client.</li>
				<li>The system lacks secure verification, such as token-based authentication.</li>
			</ul>
			<p><strong>Mitigation:</strong> Implement token-based authentication or API keys to validate requests.</p>
			<p><strong>CVSS Rating:</strong> 7.5 (High)</p>
			
			<h4>3. Exposure of Email in Request Headers</h4>
			<p>
				The user's email is sent in the <code>'X-Bark-Email'</code> header. While HTTPS protects the request in transit, exposing email addresses in headers is still a data privacy risk.
			</p>
			<p><strong>Why is this insecure?</strong></p>
			<ul>
				<li>Emails are Personally Identifiable Information (PII) and could be used in phishing attacks.</li>	
				<li>				Sending an email address in an HTTP(S) request header is a bad practice due to privacy and security risks, such as exposure of personal information through logging, unauthorized sharing with intermediaries, and potential non-compliance with data protection regulations.</li>
			</ul>
			<p><strong>Mitigation:</strong> Avoid passing sensitive data in headers; use tokens or session identifiers instead.</p>
			<p><strong>CVSS Rating:</strong> 5.0 (Medium)</p>
			
			<h4>4. Potential Race Conditions with 'changedTabs' and 'timeout'</h4>
			<p>
				The code tracks tab changes and delays URL reporting using timeouts. Rapid activity or manipulation could cause the system to send incorrect or manipulated data.
			</p>
			<p><strong>Why is this insecure?</strong></p>
			<ul>
				<li>Improper handling of asynchronous changes can lead to errors or exploitation.</li>
			</ul>
			<p><strong>Mitigation:</strong> Use robust concurrency controls to prevent tampering.</p>
			<p><strong>CVSS Rating:</strong> 5.0 (Medium)</p>
		</div>
		
		<button class="next-button" onclick="showPreviousStep(2)">Back</button>
		<button class="next-button" onclick="showNextStep(2)">Next</button>
	</div>

	<div class="tour-step" id="step3">
		<h2>Exploiting Vulnerabilities: The Risks to Children and Families</h2>
		<p>
			These vulnerabilities can be exploited by an attacker with just knowledge of a child's <strong>email address</strong>. Using this knowledge, they could <strong>falsify activity reports</strong> to convince parents that their child has visited <strong>inappropriate or concerning websites</strong>. This manipulation could severely damage <strong>trust</strong> between parents and their child.
		</p>
		<p>
			For example, an attacker could fabricate reports showing visits to:
			<ul>
				<li><strong>Websites with adult content</strong>, leading parents to believe their child is engaging in inappropriate behavior.</li>
				<li><strong>Suicide prevention or self-harm forums</strong>, causing alarm about the child’s mental health.</li>
				<li><strong>Hate speech or extremist content</strong>, creating concerns about the child being influenced by harmful ideologies.</li>
				<li><strong>Illegal sites</strong>, implicating the child in criminal activity.</li>
			</ul>
		</p>
		<p>
			Since parents are likely to <strong>trust these reports as accurate</strong>, they may <strong>wrongly accuse their child</strong> or believe their child is lying when they deny these activities. This not only erodes <strong>family trust</strong> but also places <strong>unjust blame</strong> on the child.
		</p>
		<p>
			The ability to <strong>manipulate such sensitive and impactful data</strong> demonstrates the severe risks posed by these vulnerabilities. Addressing these flaws is critical to ensure the <strong>integrity</strong> of Bark's reports and the <strong>trust</strong> of the families relying on them.
		</p>
		<p>
			It's important to note that an <strong>email address is something we typically share with other people</strong>. Given this, the risk of these vulnerabilities being exploited is significant. When evaluating the decision to publish information about these vulnerabilities, we determined that <strong>warning parents</strong> and protecting children is far more important than potentially informing bad actors. These issues are not obscure—<strong>anyone can analyze Bark’s publicly available Chrome extension code</strong> and identify the same problems that we did.
		</p>
		
		<p style="text-align: center">
			<button class="expander-button" onclick="toggleDetails('.how-to-check-source')">
				How to check Bark's Chrome extension source code?
			</button>
		</p>
		<div class="how-to-check-source expandable-content" style="display: none; margin-top: 1em; text-align: justify; background-color: #f9f9f9; padding: 15px; border-radius: 8px; box-shadow: 0 4px 6px rgba(0, 0, 0, 0.1);">
			<p>
				Even if you don’t have technical knowledge, you can use AI tools like ChatGPT to verify the findings. Follow these steps:
			</p>
			<ol>
				<li>Install the <a href="https://chromewebstore.google.com/detail/chrome-extension-source-v/jifpbeccnghkjeaalbbjmodiffmgedin" target="_blank">Chrome extension source viewer</a>.</li>
				<li>Open <a href="https://chromewebstore.google.com/detail/bark-for-chrome/jcocgejjjlnfddlhpbecfapicaajdibb" target="_blank">Bark's extension site</a> in the Chrome Web Store.</li>
				<li>Click the CRX Viewer extension icon and select "View source."</li>
				<li>
					Find the file named <strong>monitor.js</strong> in the source code. Copy its content to your clipboard.
				</li>
				<li>Open ChatGPT or any AI assistant capable of analyzing code.</li>
				<li>
					Paste the content of the <strong>monitor.js</strong> file into ChatGPT and use the following prompt: 
					<blockquote>
						"Analyze spoofing vulnerabilities in this code."
					</blockquote>
				</li>
				<li>
					The AI will provide insights on whether the code has vulnerabilities, such as spoofing or data manipulation, confirming the findings.
				</li>
			</ol>
</div>

		
		<button class="next-button" onclick="showPreviousStep(3)">Back</button>
		<button class="next-button" onclick="showNextStep(3)">Next</button>
	</div>

	<div class="tour-step" id="step4">
		<h2>Misleading Customers: Bark’s Denial of Security Vulnerabilities</h2>
		<p>
			During our investigation, we discovered that Bark has not been transparent about the security flaws in their platform.
		</p>
		<p>
			We first became aware of potential issues after reading a post on Reddit titled 
			<a href="https://www.reddit.com/r/parentalcontrols/comments/1hz2m96/parents_beware_barkus_and_bark_phone_are_insecure/" target="_blank"><strong>Parents Beware: Bark.us and Bark Phone are Insecure</strong></a>. 
			The post raised concerns about Bark's platform security, prompting us to dig deeper.
		</p>
		<p>
			Disguising ourselves as potential customers, we contacted Bark’s support team multiple times to inquire about possible vulnerabilities. Each time, Bark assured us that their systems were <strong>completely secure</strong> and claimed that there were <strong>no vulnerabilities</strong>. 
			This was more than a month after they had received a private disclosure about the issues from another person.
		</p>
		<p>
			Following these interactions, we decided to analyze Bark's publicly available Chrome extensions. In doing so, we discovered <strong>at least 4 major vulnerabilities</strong>, confirming the concerns raised in the Reddit post. Despite receiving prior disclosure of these flaws, Bark chose to <strong>deny the existence of vulnerabilities</strong> rather than addressing the problems promptly.
		</p>
		<p>
			Bark may try to excuse themselves by claiming that they refuse to respond to potential bad actors who inquire about vulnerabilities, arguing that doing so would confirm and empower malicious behavior. However, this is either a <strong>constructed lie or a failure of basic reasoning</strong>. 
			Bad actors do not need Bark’s confirmation to exploit these flaws—they can simply analyze the publicly available Chrome extension code. The vulnerabilities are evident in the code itself, meaning Bark’s denials are ineffective in stopping bad actors. Their refusal to acknowledge these issues only serves to mislead honest users while doing nothing to deter those with malicious intent.
		</p>
		<p>
			This lack of honesty and responsibility raises serious questions about Bark’s commitment to ensuring the safety and security of its users.
		</p>
		<p>
			As a parent, you probably wouldn’t let a nanny babysit your kids if you knew she was dishonest about her qualifications or past mistakes. The same logic applies to parental controls like Bark. If a company lies about the security of its platform, how can you trust it to protect your children?
		</p>

		<!-- Expander Section for Example Response -->
		<p style="text-align: center;">
			<button class="expander-button" onclick="toggleDetails('.example-response')">View Example Response from Bark</button>
		</p>
		<div class="example-response expandable-content" style="display: none; margin-top: 1em; text-align: justify; background-color: #f9f9f9; padding: 15px; border-radius: 8px; box-shadow: 0 4px 6px rgba(0, 0, 0, 0.1);">
			<p><strong>Bark's Response:</strong></p>
			<p>
				Tahnee here and thank you for your patience. I understand your concern, and I want to assure you that Bark takes security very seriously. There's no security risks with our service. We use state-of-the-art technologies to protect your family's data, and we have not identified any security risks like those mentioned online. Your child's information is encrypted and handled with the utmost care to ensure privacy and safety.
			</p>
			<p>
				We use SSL encryption on the web to present data to you and your children. All data analyzed is stored within an encrypted database. We are SOC-II compliant, a standard of security excellence. Additionally, every employee goes through extensive background checks for clearance.
			</p>
			<p>
				It's important to clarify that the assertions made in the Reddit post do not accurately reflect the workings of our system. This Reddit user does not work for or is related to Bark, nor has knowledge on how our system works. Rest assured, Bark's security infrastructures are solid, and we are well-protected against the types of vulnerabilities mentioned.
			</p>
			<p><strong>Our Analysis:</strong></p>
			<p>
				While Bark claims there are "no security risks with our service," this is demonstrably false. During our analysis, we identified <strong>at least 4 major vulnerabilities</strong> in Bark's publicly available Chrome extensions. These issues include the ability for attackers to falsify activity reports, spoof email addresses, and inject malicious data due to a lack of proper input validation. These vulnerabilities undermine Bark's assurances about data security and privacy.
			</p>
			<p>
				Bark also states that they use "state-of-the-art technologies" and that their systems are "SOC-II compliant." While SOC-II compliance sets a standard for security practices, it does not mean a system is free from vulnerabilities. Our findings clearly show that Bark's Chrome extension exhibits <strong>poor coding practices</strong>, such as the absence of robust authentication and input validation. This strongly contradicts the claim that they are "well-protected" against vulnerabilities.
			</p>
			<p>
				Additionally, Bark dismisses the Reddit post, stating that the user "does not work for or is related to Bark" and lacks knowledge of their system. However, the concerns raised in the post align closely with our independent analysis. Anyone can review Bark's publicly available code and observe the same issues we identified. By denying these concerns outright, Bark demonstrates a <strong>lack of transparency</strong> and accountability.
			</p>
			<p>
				Finally, while Bark emphasizes the use of SSL encryption and encrypted databases, these measures are standard practices and do not address the specific vulnerabilities in their Chrome extensions. These issues go beyond data transmission or storage and affect the overall integrity of their platform.
			</p>
		</div>


		<button class="next-button" onclick="showPreviousStep(4)">Back</button>
		<button class="next-button" onclick="showNextStep(4)">Next</button>
	</div>
	
	<div class="tour-step" id="step5">
		<h2>Think You're Safe Without Bark's Chrome Extensions? Think Again</h2>
		<p>
			If you think the vulnerabilities we identified only affect Bark's Chrome extensions, think again. The fact that the Chrome extensions, with publicly available code, are so <strong>poorly coded</strong> raises serious concerns about the quality of Bark's <strong>private codebase</strong>. If such <strong>basic security principles</strong> are neglected in public code, it’s reasonable to assume that their private code may also suffer from <strong>similar or even more severe issues</strong>.
		</p>
		<p>
			Moreover, the <strong>endpoint</strong> used by the Chrome extension to send URLs visited by the user is likely part of Bark's <strong>broader infrastructure</strong>. While we cannot confirm this, it is possible that this same endpoint is used by other tools and products developed by Bark, such as the <strong>Bark Phone</strong>, <strong>Bark Premium</strong>, or other services. If this is the case, the vulnerabilities we discovered could be <strong>exploited</strong> in those products as well.
		</p>
		<p>
			This <strong>interconnected nature of systems</strong> means that vulnerabilities in one product often indicate risks for others, especially when the same underlying infrastructure or practices are shared. Without <strong>full transparency</strong> from Bark or an <strong>independent security audit</strong>, it’s impossible to know how far-reaching these issues may be.
		</p>
		<p>
			As a parent or user, it's crucial to recognize that ignoring these vulnerabilities in one product could leave your family’s <strong>data and privacy at risk</strong> across Bark’s entire platform.
		</p>
		<button class="next-button" onclick="showPreviousStep(5)">Back</button>
		<button class="next-button" onclick="showNextStep(5)">Next</button>
	</div>
	
	<div class="tour-step" id="step6">
		<h2>The Media and Bark: Surface-Level Coverage</h2>
		<p>
			Bark has invested heavily in <strong>marketing and public relations</strong>, employing a large team dedicated to promoting their brand. As a result, Bark has been featured in many <strong>reputable media outlets</strong>, including Bloomberg, CNN, and BBC. While this coverage might seem like a stamp of approval, it’s important to recognize that most of these articles focus on <strong>Bark’s marketing narratives</strong> rather than critically examining their technology.
		</p>
		<p>
			Unfortunately, no major media outlet has conducted a <strong>real investigation</strong> into Bark’s platform. Instead, they often rely on Bark’s own claims without taking the time to look "under the hood" at the actual technology, code, or security practices. This leaves parents and families with a <strong>one-sided perspective</strong>, shaped by marketing rather than evidence-based evaluations.
		</p>
		<p>
			Our investigation stands apart because we took a <strong>critical and independent approach</strong>. By analyzing publicly available code and uncovering significant vulnerabilities, we have provided insights that no other outlet has explored. These findings show that <strong>Bark's marketing image</strong> does not align with the <strong>real security risks</strong> posed by their platform.
		</p>
		<p>
			It’s crucial for parents to understand that media coverage does not equate to technical scrutiny. Bark's focus on public relations has allowed them to present an image of trustworthiness and innovation, while failing to address serious flaws in their platform. <strong>True accountability</strong> requires independent evaluation, not reliance on promotional narratives.
		</p>
		<p>
			As a parent, always ask: has this company earned my trust through transparency and proven security, or is it relying on its reputation built through polished marketing and media appearances?
		</p>
		<button class="next-button" onclick="showPreviousStep(6)">Back</button>
		<button class="next-button" onclick="showNextStep(6)">Next</button>
	</div>

	<div class="tour-step" id="step7">
		<h2>The Risks of Misusing Bark Phone's Features</h2>
		<p>
			The Bark Phone includes a feature that allows parents to control who their child can talk or text with, as well as who can contact their child. While this feature is intended to protect children by <strong>preventing predators</strong>, <strong>gangs</strong>, or <strong>drug dealers</strong> from reaching them, it also carries the potential for serious misuse.
		</p>
		<p>
			Children using the Bark Phone can only call <strong>approved contacts</strong> and 911. This limitation is designed for safety, but in cases where parents are abusive, they can use this feature to <strong>prevent their child from seeking help</strong>. Allowing calls only to 911 is insufficient, as 911 is primarily for emergencies. Children may need access to <strong>helplines</strong>, <strong>child protection services</strong>, or other important support numbers that offer assistance for ongoing abuse or difficult situations.
		</p>
		<p>
			We strongly urge Bark to take the following steps to address this critical issue:
			<ul>
				<li><strong>Always allow calls to helplines</strong> that assist children in reporting abuse, contacting child protection services, and seeking help.</li>
				<li><strong>Enable children to delete call records</strong> of helpline calls from the phone's call log to protect their privacy and safety.</li>
				<li><strong>Prevent reporting sensitive messages</strong> in which children discuss abuse to abusive parents, ensuring their communications are not weaponized against them.</li>
				<li><strong>Display a list of always-allowed helpline numbers</strong> in the Bark Phone interface, along with tips on what children should do if their parents are abusive.</li>
			</ul>
		</p>
		<p>
			We have already seen reports in public forums from users claiming that the Bark Phone was <strong>misused to control children</strong>. This is likely just the <strong>tip of the iceberg</strong>. Bark has a responsibility to ensure that their technology, while designed to protect, does not become a tool of abuse.
		</p>
		<p>
			By implementing these changes, Bark can take a strong stand against misuse and better protect the children they aim to serve.
		</p>
		<button class="next-button" onclick="showPreviousStep(7)">Back</button>
		<button class="next-button" onclick="showNextStep(7)">Next</button>
	</div>
	
	<div class="tour-step" id="step8">
		<h2>A Call for Bark to Improve</h2>
		<p>
			Throughout this tour, we’ve highlighted significant <strong>security flaws</strong> and raised concerns about Bark’s lack of transparency and accountability. While much of what we’ve shared has been critical, it’s important to acknowledge that <strong>Bark’s technology also helps families</strong>. Their platform has made a positive impact by providing tools that enable parents to monitor their children’s online safety.
		</p>
		<p>
			However, this positive contribution does not excuse the <strong>serious vulnerabilities</strong> and <strong>misleading practices</strong> we’ve uncovered. Our goal is not to discredit Bark entirely, but to encourage them to take the steps necessary to <strong>earn the trust</strong> of the families who rely on them.
		</p>
		<p>
			We urge Bark to:
			<ul>
				<li><strong>Reconsider their approach to marketing</strong>: Be honest and transparent with users, rather than dismissing valid concerns.</li>
				<li><strong>Publicly admit the issues</strong> we and others have identified, and ideally, <strong>apologize</strong> to their users for the risks these vulnerabilities pose.</li>
				<li><strong>Fix the vulnerabilities</strong> we’ve discovered and ensure their systems are secure.</li>
				<li><strong>Conduct a thorough, independent security audit</strong> of their entire platform and address any additional issues identified.</li>
				<li><strong>Publish the results of the security audit</strong>, demonstrating a commitment to transparency and user safety.</li>
				<li><strong>Implement anti-abuse features to Bark Phone</strong>, demonstrating a commitment to protect children from abuse.</li>
			</ul>
		</p>
		<p>
			We believe Bark has the potential to be a valuable tool for families, but only if they take these steps to ensure their technology is truly secure and trustworthy. By acknowledging and fixing these problems, Bark can become the kind of company that parents can confidently rely on to protect their children.
		</p>
		<button class="next-button" onclick="showPreviousStep(8)">Back</button>
		<button class="next-button" onclick="showNextStep(8)">Next</button>
	</div>

	<div class="tour-step" id="step9">
		<h2>Thank You for Taking the Tour</h2>
		<p>
			Thank you for taking the time to learn about the important issues surrounding Bark's platform. Your attention and willingness to understand these concerns are critical in creating a safer environment for children online.
		</p>
		<p>
			If you found this information valuable, we encourage you to share it with others. By spreading awareness, you can help ensure that families everywhere are informed and empowered to demand better security and accountability from Bark and similar services.
		</p>
		<p style="font-weight: bold;">Share this on social media:</p>
		<div style="display: flex; justify-content: center; gap: 15px; margin-top: 15px; font-size: 24px;">
			<a href="https://www.facebook.com/sharer/sharer.php?u=https://barkscam.com" target="_blank" style="color: #3b5998; text-decoration: none;">
				<i class="fab fa-facebook"></i>
			</a>
			<a href="https://www.instagram.com/" target="_blank" style="color: #E4405F; text-decoration: none;">
				<i class="fab fa-instagram"></i>
			</a>
			<a href="https://twitter.com/intent/tweet?url=https://barkscam.com&text=Check+out+this+important+tour+about+Bark%27s+security+issues" target="_blank" style="color: #1DA1F2; text-decoration: none;">
				<i class="fab fa-x-twitter"></i>
			</a>
			<a href="https://www.linkedin.com/sharing/share-offsite/?url=https://barkscam.com" target="_blank" style="color: #0077b5; text-decoration: none;">
				<i class="fab fa-linkedin"></i>
			</a>
		</div>
		<p style="margin-top: 20px;">
			Together, we can make a difference by ensuring that companies prioritize safety, transparency, and accountability in the digital tools they provide for families.
		</p>
		<button class="next-button" onclick="showPreviousStep(9)">Back</button>
	</div>

	<div id="navigation-menu" class="navigation-menu" style="margin-top: 20px; display: none;">
		<label for="jumpToStep" style="font-weight: bold;">Jump to Step:</label>
		<select id="jumpToStep" style="margin-left: 10px; padding: 5px; border-radius: 4px;" onchange="jumpToStep()">
			<option value="1">Why this campaign?</option>
			<option value="2">Vulnerabilities Summary</option>
			<option value="3">Exploiting Vulnerabilities: The Risks to Children and Families</option>
			<option value="4">Misleading Customers: Bark’s Denial of Security Vulnerabilities</option>
			<option value="5">Think You're Safe Without Bark's Chrome Extensions? Think Again</option>
			<option value="6">The Media and Bark: Surface-Level Coverage</option>
			<option value="7">The Risks of Misusing Bark Phone's Features</option>
			<option value="8">A Call for Bark to Improve</option>
			<option value="9">Thank You for Taking the Tour</option>
		</select>
	</div>

	<p id="pawsMessage" style="display: none; margin-top: 20px; font-size: 16px; color: #333;">Paws and think before trusting just any platform 🐾.</p>
</div>

<script>
	function startTour() {
		const startButton = document.getElementById('startTour');
		const title = document.getElementById('title-main');
		const subtitle = document.getElementById('subtitle-main');
		const navMenu = document.getElementById('navigation-menu');
		const firstStep = document.getElementById('step1');

		// Add fade-out effect to the main content
		startButton.classList.add('fade-out');
		title.classList.add('fade-out');
		subtitle.classList.add('fade-out');
	    navMenu.classList.add('fade-in');

		// Wait for the fade-out animation to complete
		setTimeout(() => {
			// Hide the main content
			startButton.style.display = 'none';
			title.style.display = 'none';
			subtitle.style.display = 'none';
			navMenu.style.display = 'block';
			
			// Show the first step with fade-in
			firstStep.classList.add('active');
		}, 500); // Match the transition duration
		
	}


	function showNextStep(currentStep) {
		const currentStepDiv = document.getElementById(`step${currentStep}`);
		const nextStepDiv = document.getElementById(`step${currentStep + 1}`);
		const jumpToMenu = document.getElementById("jumpToStep");

		if (currentStepDiv && nextStepDiv) {
			// Add fade-out effect to the current step
			currentStepDiv.classList.add("fade-out");

			// Wait for fade-out animation to complete
			setTimeout(() => {
				currentStepDiv.classList.remove("active", "fade-out");
				currentStepDiv.style.display = "none";

				// Show the next step
				nextStepDiv.style.display = "block";
				nextStepDiv.classList.add("active");

				// Synchronize navigation menu
				jumpToMenu.value = currentStep + 1;

				// Scroll to the top after layout updates
				scrollToTop();
			}, 500);
			
			if (currentStep == 8)
				showTeasingBubble('Woof, maybe you should tap me with your paw.');
		}
	}

	function showPreviousStep(currentStep) {
		const currentStepDiv = document.getElementById(`step${currentStep}`);
		const prevStepDiv = document.getElementById(`step${currentStep - 1}`);
		const jumpToMenu = document.getElementById("jumpToStep");

		if (currentStepDiv && prevStepDiv) {
			// Add fade-out effect to the current step
			currentStepDiv.classList.add("fade-out");

			// Wait for fade-out animation to complete
			setTimeout(() => {
				currentStepDiv.classList.remove("active", "fade-out");
				currentStepDiv.style.display = "none";

				// Show the previous step
				prevStepDiv.style.display = "block";
				prevStepDiv.classList.add("active");

				// Synchronize navigation menu
				jumpToMenu.value = currentStep - 1;

				// Scroll to the top after layout updates
				scrollToTop();
			}, 500);
		}
	}
	
	function jumpToStep() {
		const selectedStep = document.getElementById("jumpToStep").value;
		const currentStep = document.querySelector(".tour-step.active");
		const targetStep = document.getElementById(`step${selectedStep}`);

		if (currentStep && targetStep) {
			// Add fade-out effect to the current step
			currentStep.classList.add("fade-out");

			// Wait for fade-out animation to complete
			setTimeout(() => {
				currentStep.classList.remove("active", "fade-out");
				currentStep.style.display = "none";

				// Show the selected step
				targetStep.style.display = "block";
				targetStep.classList.add("active");

				// Scroll to the top after layout updates
				scrollToTop();
			}, 500);
			
			if (selectedStep == 9)
				showTeasingBubble('Woof, maybe you should tap me with your paw.');
		}
	}
	
	function toggleDetails(element) {
		const details = document.querySelector(element);

		if (!details) return;

		if (details.style.maxHeight) {
			// Collapse: Add animation
			details.style.maxHeight = null;
			
			setTimeout(() => {
				details.style.display = 'none'; 
			}, 500); // Match the CSS transition duration
		} else {
			// Expand: Add animation
			details.style.display = 'block'; // Ensure it's visible initially
			const scrollHeight = details.scrollHeight; // Measure current scroll height
			details.style.maxHeight = scrollHeight + 'px';

			// Update scroll height after animation to account for dynamic content
			setTimeout(() => {
				details.style.maxHeight = details.scrollHeight + 'px';
			}, 500); // Match the CSS transition duration

			// Scroll into view after the expansion starts
			setTimeout(() => {
				details.scrollIntoView({ behavior: 'smooth', block: 'nearest' });
			}, 200);
		}
	}
	
	function scrollToTop() {
		setTimeout(() => {
			window.scrollTo({ top: 0, behavior: 'smooth' });
		}, 10); // Add a slight delay to ensure layout changes are applied
	}

	function showPawsMessage() {
		const pawsMessage = document.getElementById('pawsMessage');
		pawsMessage.style.display = 'block';
	}

	let inputBuffer = ''; // To track what the user types

	function showPawsMessage() {
		const pawsMessage = document.getElementById('pawsMessage');
		pawsMessage.style.display = 'block';
		startAnimation();
	}

	// Listen for key presses to detect the word "brandon"
	document.addEventListener('keydown', (e) => {
		const logo = document.getElementById('logo');
		const pawsMessage = document.getElementById('pawsMessage');

		// Add the pressed key to the buffer and limit its length
		inputBuffer += e.key.toLowerCase();
		if (inputBuffer.length > 7) {
			inputBuffer = inputBuffer.slice(-7); // Keep only the last 7 characters
		}

		// Check if the buffer matches "brandon" and the paw message is visible
		if (inputBuffer === 'brandon' && pawsMessage.style.display === 'block') {
			logo.src = 'img/nobark2.png'; // Change logo image
			logo.classList.add('spin'); // Add spinning effect
		}
	});
</script>

<script>
    const pawInterval = 800; // Interval between each paw
    const pawSpacing = 60; // Vertical spacing between paw prints
    const pawOffsetX = 20; // Horizontal offset for alternating paws
    const animationSides = ["left", "right"]; // Alternating sides
    const fadeOutDuration = 500; // Duration of fade-out in milliseconds

    let currentSideIndex = 0; // Start with the left side
    let currentY = document.body.scrollHeight - 50; // Start at the bottom of the screen
    let isLeftPaw = true; // Toggle for left and right paw placement
    let pawElements = []; // Keep track of paw elements for removal
	let animationRunning = false;

    function createPaw() {
        if (currentY < 0) {
            // Remove all paw prints with a fade-out effect
            removeAllPaws();
            return;
        }

        const container = document.querySelector('.container');
        if (!container) return; // Ensure the container div exists

        const containerRect = container.getBoundingClientRect(); // Get container's position
        const paw = document.createElement('div');
        paw.className = 'paw-print';

        // Determine X position based on the side
        let pawX;
        if (animationSides[currentSideIndex] === "left") {
            pawX = containerRect.left - pawOffsetX - 80; // Position to the left of the container
        } else {
            pawX = containerRect.right + pawOffsetX + 40; // Position to the right of the container
        }

        // Alternate left and right paw placement
        paw.style.left = `${pawX + (isLeftPaw ? -pawOffsetX : pawOffsetX)}px`;
        paw.style.top = `${currentY}px`;
        paw.style.opacity = '1'; // Make it visible

        document.body.appendChild(paw);
        pawElements.push(paw); // Add to the list for later removal

        // Update for the next paw
        currentY -= pawSpacing;
        isLeftPaw = !isLeftPaw; // Alternate between left and right paws
    }

	function removeAllPaws() {
		// Fade out all paw prints
		pawElements.forEach((paw) => {
			paw.style.animation = 'fadeOut 0.5s ease-out forwards'; // Apply fade-out animation
			setTimeout(() => paw.remove(), fadeOutDuration); // Remove after fade-out
		});

		// Reset paw elements and switch sides
		pawElements = [];
		currentY = document.body.scrollHeight - 50; // Restart at the bottom of the current content height
		currentSideIndex = (currentSideIndex + 1) % animationSides.length; // Alternate sides
		
		 // Show the teasing bubble near the logo
		showTeasingBubble();
	}

	function startAnimation() {
		if (animationRunning)
			return;
			
		const container = document.querySelector('.container');
		if (!container) return; // Ensure the container exists

		// Get the container's width and screen width
		const containerWidth = container.offsetWidth;
		const screenWidth = window.innerWidth;

		// Calculate the space needed for the container and paws
		const spaceNeeded = containerWidth + 240; // 80px on each side for paws

		// Check if the screen is wide enough
		if (screenWidth < spaceNeeded) {
			console.warn('Screen is too narrow for paw animation.');
			showTeasingBubble();
			return; // Do not start animation
		}

		// Start the paw animation
		setInterval(createPaw, pawInterval);
		animationRunning = true;
	}

    // Listen for changes in content height
    window.addEventListener('resize', () => {
        currentY = document.body.scrollHeight; // Adjust to new height
    });
	
	const teasingMessages = [
		"Oops, sorry, I won't lie again to customers.",
		"Woof, I am digging my paw into code to fix these errors.",
		"Bad data barked up the wrong tree!",
		"I'll be pawsitively honest from now on!",
		"Woof woof, let's debug these errors together!",
		"Uh-oh, this bark needs a fact check!",
		"I promise not to bark up the wrong audit trail again!",
		"Ruff day for security, huh?",
		"My bad—I'll paw-sitively fix that code!",
		"SOC-II? More like SOC-Woof! Time to improve.",
		"Caught red-pawed! Time to fix those vulnerabilities.",
		"Even the best barks can bite back sometimes.",
		"Let’s bury these errors once and for all.",
		"I pawmise I pay bug bounty to Scaratek.",
		"Good wuck with fixing and let us know if you ever want to Bark in more responsible way. ✌️",
		"Paws and think before you trust another bark.",
		"Oops, I fetched the wrong report again!",
		"Sometimes, I bark more than I bite—fixing that now.",
		"Woof! Transparency fetches trust.",
		"Don't worry, I'm on the case to paw-dle these flaws.",
		"Woof woof! Let me dig into the root cause.",
		"I'll fetch a better solution next time!",
		"I’d bite my CTO for these errors, but I’m muzzled like support.",
		"These bugs are barking louder than our compliance claims!",
		"Who let the bugs out? Woof, woof!",
		"I need a chew toy while I fix this mess!",
		"Woof, this code smells worse than week-old kibble.",
		"I’ll paw-lease fetch some better coding practices!",
		"This bark needs a new bite—better patch those holes!",
		"Security audits shouldn’t be like chasing my tail!",
		"Woof! Debugging is my new leash on life.",
		"I sniffed out these issues faster than our dev team!",
		"Even my doghouse has better firewalls than this!"
	];

	bool firstBubble = true;

	function showTeasingBubble(text) {
		const logoContainer = document.getElementById('logo-container');
		if (!logoContainer) {
			console.warn("Logo container not found!");
			return;
		}

		const bubble = document.createElement('div');
		bubble.className = 'teasing-bubble';

		// Position the bubble relative to the logo container
		bubble.style.position = 'absolute'; // Absolute positioning relative to the container
		bubble.style.top = '75px'; // Position above the container
		bubble.style.left = '75%'; // Center horizontally within the container
		bubble.style.transform = 'translateX(-50%)'; // Correct alignment
		bubble.style.zIndex = '100'; // Ensure it appears above everything

		// Add a random teasing message
		const randomMessage = teasingMessages[Math.floor(Math.random() * teasingMessages.length)];
		bubble.textContent = randomMessage;
		
		if (firstBubble){
			bubble.textContent = 'Good wuck with fixing and let us know if you ever want to Bark in more responsible way. ✌️'
		}
		
		if (text)
			bubble.textContent = text;

		// Append the bubble to the logo container
		logoContainer.appendChild(bubble);

		// Remove the bubble after 3 seconds
		setTimeout(() => {
			bubble.remove();
		}, 4800);
	}



    
</script>

</body>
</html>
