Say no to deceptive and dangerous practices of Bark Technologies
Take our tour to learn more.
Why this campaign?
We know that Bark has helped many families. However, there's a dark side to Bark's technology. We have analyzed publicly available source code for some parts of their technology and conducted a thorough investigation.
Bark's technology has severe vulnerabilities that put children's data at risk. These vulnerabilities have existed for years, and Bark claims to undergo SOC II audits, yet they have failed to address these critical issues. They have known about these vulnerabilities for months, but they have not fixed them yet. Instead of addressing these issues honestly, they choose to lie to customers rather than admit their faults and resolve the problems as soon as possible.
Bark claims to protect children, but their platform lacks safety measures to prevent the abuse of their technology by parents. While we recognize that most parents love their children, sadly, some do not.
We urge Bark to fix their technology, stop lying, and incorporate features that prevent child abuse.
Vulnerabilities Summary
Bark's Chrome extension has several serious security flaws that could harm your child's safety and privacy. Here's an easy-to-understand breakdown:
Fake Activity Reports:
Hackers can manipulate how Bark sends activity reports by pretending to be someone else. For example, they could make it look like a child visited harmful websites, even if they didn’t. This can cause confusion and unnecessary fear for parents.
Weak Security for Communication:
The system doesn't properly check if the messages it receives are from a trusted source. This means an attacker could send fake information to Bark's servers, bypassing basic safety measures.
Risk of Leaking Personal Information:
The extension sends a child’s email address as part of its communication. While this is protected by secure connections (HTTPS), exposing emails this way increases the risk of phishing or other online scams if someone gains access to the data.
Confusion from Rapid Changes:
If a child’s browsing activity changes quickly (like switching between tabs), the system may get confused and send incorrect or incomplete reports. Hackers could also exploit this weakness to tamper with what Bark reports.
We analyzed Bark's Chrome extension, which consists of only 164 lines of code. Despite its small size, we identified 4 major vulnerabilities. These findings highlight a lack of proper testing and security review. Alarmingly, these vulnerabilities have existed for years, even though Bark claims to undergo SOC II audits.
Our analysis focused on a small area of vulnerabilities, yet the Bark Chrome extension already demonstrates poor coding practices. The presence of multiple security flaws in such a small codebase suggests pure amateurism in secure software development.
Furthermore, as we only reviewed the publicly available code of the Chrome extension, there is a significant concern that similar bad security practices could be widespread across Bark's entire platform.
Technical Details of Vulnerabilities
1. Spoofing the 'X-Bark-Email' Header
The code uses a custom header, 'X-Bark-Email', included in HTTP requests to the server.
This header contains the user's email, fetched using chrome.identity.getProfileUserInfo().
However, this email can be easily spoofed by an attacker through malicious scripts or manipulation of request data.
Why is this insecure?
Attackers can falsify the reported user's email by modifying the request, undermining trust in the reporting mechanism.
Impersonation of users or children is possible, exposing the system to misuse.
Mitigation: Use OAuth tokens, signed requests, or session-based tokens to securely verify the user's email.
CVSS Rating: 7.5 (High)
2. Insecure Communication (Lack of Authentication for API Requests)
Data is transmitted to the API endpoint (https://urls.bark.us) via POST requests without proper authentication.
Custom headers like 'X-Bark-Email' and 'X-Bark-Extension' do not validate the source of the request.
Why is this insecure?
Attackers can inject fake data into the server, impersonating legitimate clients.
The system lacks secure verification mechanisms, such as token-based authentication.
Mitigation: Implement token-based authentication or API keys to verify requests.
CVSS Rating: 7.5 (High)
3. Exposure of Email in Request Headers
The user's email is transmitted in the 'X-Bark-Email' header. Although HTTPS encrypts the data in transit,
including emails in headers poses a privacy risk.
Why is this insecure?
Email addresses are Personally Identifiable Information (PII) that can be exploited for phishing attacks.
Exposing sensitive information in headers risks unauthorized access through logging, intermediaries, or non-compliance with data protection laws.
Mitigation: Avoid passing sensitive data in headers; instead, use tokens or session identifiers.
CVSS Rating: 5.0 (Medium)
4. Potential Race Conditions with 'changedTabs' and 'timeout'
The code monitors tab changes and delays URL reporting using timeouts. Rapid user actions or manipulation could cause the system to send incorrect or invalid data.
Why is this insecure?
Asynchronous handling of tab changes can lead to exploitable errors if not managed properly.
Mitigation: Employ robust concurrency controls to prevent exploitation.
CVSS Rating: 5.0 (Medium)
Exploiting Vulnerabilities: The Risks to Children and Families
These vulnerabilities can be exploited by an attacker with just knowledge of a child's email address. Using this knowledge, they could falsify activity reports to convince parents that their child has visited inappropriate or concerning websites. This manipulation could severely damage trust between parents and their child.
For example, an attacker could fabricate reports showing visits to:
Websites with adult content, leading parents to believe their child is engaging in inappropriate behavior.
Suicide prevention or self-harm forums, causing alarm about the child’s mental health.
Hate speech or extremist content, creating concerns about the child being influenced by harmful ideologies.
Illegal sites, implicating the child in criminal activity.
Since parents are likely to trust these reports as accurate, they may wrongly accuse their child or believe their child is lying when they deny these activities. This not only erodes family trust but also places unjust blame on the child.
The ability to manipulate such sensitive and impactful data demonstrates the severe risks posed by these vulnerabilities. Addressing these flaws is critical to ensure the integrity of Bark's reports and the trust of the families relying on them.
It's important to note that an email address is something we typically share with other people. Given this, the risk of these vulnerabilities being exploited is significant. When evaluating the decision to publish information about these vulnerabilities, we determined that warning parents and protecting children is far more important than potentially informing bad actors. These issues are not obscure—anyone can analyze Bark’s publicly available Chrome extension code and identify the same problems that we did.
Even if you don’t have technical knowledge, you can use AI tools like ChatGPT to verify the findings. Follow these steps:
Click the CRX Viewer extension icon and select "View source."
Find the file named monitor.js in the source code. Copy its content to your clipboard.
Open ChatGPT or any AI assistant capable of analyzing code.
Paste the content of the monitor.js file into ChatGPT and use the following prompt:
"Analyze spoofing vulnerabilities in this code."
The AI will provide insights on whether the code has vulnerabilities, such as spoofing or data manipulation, confirming the findings.
Misleading Customers: Bark’s Denial of Security Vulnerabilities
During our investigation, we discovered that Bark has not been transparent about the security flaws in their platform.
We first became aware of potential issues after reading a post on Reddit titled
Parents Beware: Bark.us and Bark Phone are Insecure.
The post raised concerns about Bark's platform security, prompting us to dig deeper.
Disguising ourselves as potential customers, we contacted Bark’s support team multiple times to inquire about possible vulnerabilities. Each time, Bark assured us that their systems were completely secure and claimed that there were no vulnerabilities.
This was more than a month after they had received a private disclosure about the issues from another person.
Following these interactions, we decided to analyze Bark's publicly available Chrome extensions. In doing so, we discovered at least 4 major vulnerabilities, confirming the concerns raised in the Reddit post. Despite receiving prior disclosure of these flaws, Bark chose to deny the existence of vulnerabilities rather than addressing the problems promptly.
Bark may try to excuse themselves by claiming that they refuse to respond to potential bad actors who inquire about vulnerabilities, arguing that doing so would confirm and empower malicious behavior. However, this is either a constructed lie or a failure of basic reasoning.
Bad actors do not need Bark’s confirmation to exploit these flaws—they can simply analyze the publicly available Chrome extension code. The vulnerabilities are evident in the code itself, meaning Bark’s denials are ineffective in stopping bad actors. Their refusal to acknowledge these issues only serves to mislead honest users while doing nothing to deter those with malicious intent.
This lack of honesty and responsibility raises serious questions about Bark’s commitment to ensuring the safety and security of its users.
As a parent, you probably wouldn’t let a nanny babysit your kids if you knew she was dishonest about her qualifications or past mistakes. The same logic applies to parental controls like Bark. If a company lies about the security of its platform, how can you trust it to protect your children?
Bark's Response:
Tahnee here and thank you for your patience. I understand your concern, and I want to assure you that Bark takes security very seriously. There's no security risks with our service. We use state-of-the-art technologies to protect your family's data, and we have not identified any security risks like those mentioned online. Your child's information is encrypted and handled with the utmost care to ensure privacy and safety.
We use SSL encryption on the web to present data to you and your children. All data analyzed is stored within an encrypted database. We are SOC-II compliant, a standard of security excellence. Additionally, every employee goes through extensive background checks for clearance.
It's important to clarify that the assertions made in the Reddit post do not accurately reflect the workings of our system. This Reddit user does not work for or is related to Bark, nor has knowledge on how our system works. Rest assured, Bark's security infrastructures are solid, and we are well-protected against the types of vulnerabilities mentioned.
Our Analysis:
While Bark claims there are "no security risks with our service," this is demonstrably false. During our analysis, we identified at least 4 major vulnerabilities in Bark's publicly available Chrome extensions. These issues include the ability for attackers to falsify activity reports, spoof email addresses, and inject malicious data due to a lack of proper input validation. These vulnerabilities undermine Bark's assurances about data security and privacy.
Bark also states that they use "state-of-the-art technologies" and that their systems are "SOC-II compliant." While SOC-II compliance sets a standard for security practices, it does not mean a system is free from vulnerabilities. Our findings clearly show that Bark's Chrome extension exhibits poor coding practices, such as the absence of robust authentication and input validation. This strongly contradicts the claim that they are "well-protected" against vulnerabilities.
Additionally, Bark dismisses the Reddit post, stating that the user "does not work for or is related to Bark" and lacks knowledge of their system. However, the concerns raised in the post align closely with our independent analysis. Anyone can review Bark's publicly available code and observe the same issues we identified. By denying these concerns outright, Bark demonstrates a lack of transparency and accountability.
Finally, while Bark emphasizes the use of SSL encryption and encrypted databases, these measures are standard practices and do not address the specific vulnerabilities in their Chrome extensions. These issues go beyond data transmission or storage and affect the overall integrity of their platform.
Think You're Safe Without Bark's Chrome Extensions? Think Again
If you think the vulnerabilities we identified only affect Bark's Chrome extensions, think again. The fact that the Chrome extensions, with publicly available code, are so poorly coded raises serious concerns about the quality of Bark's private codebase. If such basic security principles are neglected in public code, it’s reasonable to assume that their private code may also suffer from similar or even more severe issues.
Moreover, the endpoint used by the Chrome extension to send URLs visited by the user is likely part of Bark's broader infrastructure. While we cannot confirm this, it is possible that this same endpoint is used by other tools and products developed by Bark, such as the Bark Phone, Bark Premium, or other services. If this is the case, the vulnerabilities we discovered could be exploited in those products as well.
This interconnected nature of systems means that vulnerabilities in one product often indicate risks for others, especially when the same underlying infrastructure or practices are shared. Without full transparency from Bark or an independent security audit, it’s impossible to know how far-reaching these issues may be.
As a parent or user, it's crucial to recognize that ignoring these vulnerabilities in one product could leave your family’s data and privacy at risk across Bark’s entire platform.
The Media and Bark: Surface-Level Coverage
Bark has invested heavily in marketing and public relations, employing a large team dedicated to promoting their brand. As a result, Bark has been featured in many reputable media outlets, including Bloomberg, CNN, and BBC. While this coverage might seem like a stamp of approval, it’s important to recognize that most of these articles focus on Bark’s marketing narratives rather than critically examining their technology.
Unfortunately, no major media outlet has conducted a real investigation into Bark’s platform. Instead, they often rely on Bark’s own claims without taking the time to look "under the hood" at the actual technology, code, or security practices. This leaves parents and families with a one-sided perspective, shaped by marketing rather than evidence-based evaluations.
Our investigation stands apart because we took a critical and independent approach. By analyzing publicly available code and uncovering significant vulnerabilities, we have provided insights that no other outlet has explored. These findings show that Bark's marketing image does not align with the real security risks posed by their platform.
It’s crucial for parents to understand that media coverage does not equate to technical scrutiny. Bark's focus on public relations has allowed them to present an image of trustworthiness and innovation, while failing to address serious flaws in their platform. True accountability requires independent evaluation, not reliance on promotional narratives.
As a parent, always ask: has this company earned my trust through transparency and proven security, or is it relying on its reputation built through polished marketing and media appearances?
The Risks of Misusing Bark Phone's Features
The Bark Phone includes a feature that allows parents to control who their child can talk or text with, as well as who can contact their child. While this feature is intended to protect children by preventing predators, gangs, or drug dealers from reaching them, it also carries the potential for serious misuse.
Children using the Bark Phone can only call approved contacts and 911. This limitation is designed for safety, but in cases where parents are abusive, they can use this feature to prevent their child from seeking help. Allowing calls only to 911 is insufficient, as 911 is primarily for emergencies. Children may need access to helplines, child protection services, or other important support numbers that offer assistance for ongoing abuse or difficult situations.
We strongly urge Bark to take the following steps to address this critical issue:
Always allow calls to helplines that assist children in reporting abuse, contacting child protection services, and seeking help.
Enable children to delete call records of helpline calls from the phone's call log to protect their privacy and safety.
Prevent reporting sensitive messages in which children discuss abuse to abusive parents, ensuring their communications are not weaponized against them.
Display a list of always-allowed helpline numbers in the Bark Phone interface, along with tips on what children should do if their parents are abusive.
We have already seen reports in public forums from users claiming that the Bark Phone was misused to control children. This is likely just the tip of the iceberg. Bark has a responsibility to ensure that their technology, while designed to protect, does not become a tool of abuse.
By implementing these changes, Bark can take a strong stand against misuse and better protect the children they aim to serve.
A Call for Bark to Improve
Throughout this tour, we’ve highlighted significant security flaws and raised concerns about Bark’s lack of transparency and accountability. While much of what we’ve shared has been critical, it’s important to acknowledge that Bark’s technology also helps families. Their platform has made a positive impact by providing tools that enable parents to monitor their children’s online safety.
However, this positive contribution does not excuse the serious vulnerabilities and misleading practices we’ve uncovered. Our goal is not to discredit Bark entirely, but to encourage them to take the steps necessary to earn the trust of the families who rely on them.
We urge Bark to:
Reconsider their approach to marketing: Be honest and transparent with users, rather than dismissing valid concerns.
Publicly admit the issues we and others have identified, and ideally, apologize to their users for the risks these vulnerabilities pose.
Fix the vulnerabilities we’ve discovered and ensure their systems are secure.
Conduct a thorough, independent security audit of their entire platform and address any additional issues identified.
Publish the results of the security audit, demonstrating a commitment to transparency and user safety.
Implement anti-abuse features to Bark Phone, demonstrating a commitment to protect children from abuse.
We believe Bark has the potential to be a valuable tool for families, but only if they take these steps to ensure their technology is truly secure and trustworthy. By acknowledging and fixing these problems, Bark can become the kind of company that parents can confidently rely on to protect their children.
Thank You for Taking the Tour
Thank you for taking the time to learn about the important issues surrounding Bark's platform. Your attention and willingness to understand these concerns are critical in creating a safer environment for children online.
If you found this information valuable, we encourage you to share it with others. By spreading awareness, you can help ensure that families everywhere are informed and empowered to demand better security and accountability from Bark and similar services.
Share this on social media:
Together, we can make a difference by ensuring that companies prioritize safety, transparency, and accountability in the digital tools they provide for families.
Paws and think before trusting just any platform 🐾.