Say no to deceptive and dangerous practices of Bark Technologies.
Take our tour to learn more about problems of Bark parental
controls.
Why this campaign?
We know that Bark has helped many families. However, there's a dark side to Bark's
technology. We have analyzed publicly available source code for some parts of their technology and
conducted a thorough investigation.
Bark's technology has severe vulnerabilities that put children's data at risk. These
vulnerabilities have existed for years, and Bark claims to undergo SOC II
audits, yet they have failed to address these critical issues. They have known about these
vulnerabilities for months, but they have not fixed them yet. Instead
of addressing these issues honestly, they choose to lie to customers rather than admit
their faults and resolve the problems as soon as possible.
Bark claims to protect children, but their platform lacks safety
measures to prevent the abuse of their technology by parents. While we
recognize that most parents love their children, sadly, some do not.
We urge Bark to fix their technology, stop lying, and incorporate
features that prevent child abuse.
Vulnerabilities Summary
Bark's Chrome extension has several serious security flaws that could harm your child's safety and
privacy. Here's an easy-to-understand breakdown:
Fake Activity Reports:
Hackers can manipulate how Bark sends activity reports by pretending to be someone else. For
example, they could make it look like a child visited harmful websites, even if they didn’t. This
can cause confusion and unnecessary fear for parents.
Weak Security for Communication:
The system doesn't properly check if the messages it receives are from a trusted source. This means
an attacker could send fake information to Bark's servers, bypassing basic safety measures.
Risk of Leaking Personal Information:
The extension sends a child’s email address as part of its communication. While this is protected by
secure connections (HTTPS), exposing emails this way increases the risk of phishing or other online
scams if someone gains access to the data.
Confusion from Rapid Changes:
If a child’s browsing activity changes quickly (like switching between tabs), the system may get
confused and send incorrect or incomplete reports. Hackers could also exploit this weakness to
tamper with what Bark reports.
We analyzed Bark's Chrome extension, which consists of only 164 lines of code. Despite
its small size, we identified 4 major vulnerabilities. These findings highlight a lack
of proper testing and security review. Alarmingly, these vulnerabilities have existed for
years, even though Bark claims to undergo SOC II audits.
Our analysis focused on a small area of vulnerabilities, yet the Bark Chrome extension
already demonstrates poor coding practices. The presence of multiple security flaws in
such a small codebase suggests pure amateurism in secure software development.
Furthermore, as we only reviewed the publicly available code of the Chrome extension,
there is a significant concern that similar bad security practices could be widespread
across Bark's entire platform.
Note: Described vulnerabilities affect Bark's extensions for Microsoft Edge as well.
Technical Details of Vulnerabilities
1. Spoofing the 'X-Bark-Email' Header
The code uses a custom header, X-Bark-Email, included in HTTP
requests to the server.
This header contains the user's email, fetched using
chrome.identity.getProfileUserInfo().
However, this email can be easily spoofed by an attacker through malicious scripts or
manipulation of request data.
Why is this insecure?
Attackers can falsify the reported user's email by modifying the request, undermining
trust in the reporting mechanism.
Impersonation of users or children is possible, exposing the system to misuse.
Mitigation: Use OAuth tokens, signed requests, or session-based tokens to
securely verify the user's email.
CVSS Rating: 7.5 (High)
2. Insecure Communication (Lack of Authentication for API Requests)
Data is transmitted to the API endpoint (https://urls.bark.us) via
POST requests without proper authentication.
Custom headers like X-Bark-Email and X-Bark-Extension do not validate the source of the request.
Why is this insecure?
Attackers can inject fake data into the server, impersonating legitimate clients.
The system lacks secure verification mechanisms, such as token-based authentication.
Mitigation: Implement token-based authentication or API keys to verify
requests.
CVSS Rating: 7.5 (High)
3. Exposure of Email in Request Headers
The user's email is transmitted in the X-Bark-Email header.
Although HTTPS encrypts the data in transit,
including emails in headers poses a privacy risk.
Why is this insecure?
Email addresses are Personally Identifiable Information (PII) that can be exploited for
phishing attacks.
Exposing sensitive information in headers risks unauthorized access through logging,
intermediaries, or non-compliance with data protection laws.
Mitigation: Avoid passing sensitive data in headers; instead, use tokens or
session identifiers.
CVSS Rating: 5.0 (Medium)
4. Potential Race Conditions with 'changedTabs' and 'timeout'
The code monitors tab changes and delays URL reporting using timeouts. Rapid user actions or
manipulation could cause the system to send incorrect or invalid data.
Why is this insecure?
Asynchronous handling of tab changes can lead to exploitable errors if not managed
properly.
Mitigation: Employ robust concurrency controls to prevent exploitation.
CVSS Rating: 5.0 (Medium)
Exploiting Vulnerabilities: The Risks to Children and Families
These vulnerabilities can be exploited by an attacker with just knowledge of a child's email
address. Using this knowledge, they could falsify activity reports to
convince parents that their child has visited inappropriate or concerning websites.
This manipulation could severely damage trust between parents and their child.
For example, an attacker could fabricate reports showing visits to:
Websites with adult content, leading parents to believe their child is engaging in
inappropriate behavior.
Suicide prevention or self-harm forums, causing alarm about the child’s mental
health.
Hate speech or extremist content, creating concerns about the child being
influenced by harmful ideologies.
Illegal sites, implicating the child in criminal activity.
Since parents are likely to trust these reports as accurate, they may wrongly
accuse their child or believe their child is lying when they deny these activities. This
not only erodes family trust but also places unjust blame on the
child.
The ability to manipulate such sensitive and impactful data demonstrates the severe
risks posed by these vulnerabilities. Addressing these flaws is critical to ensure the
integrity of Bark's reports and the trust of the families relying on
them.
It's important to note that an email address is something we typically share with other
people. Given this, the risk of these vulnerabilities being exploited is significant. When
evaluating the decision to publish information about these vulnerabilities, we determined that
warning parents and protecting children is far more important than potentially
informing bad actors. These issues are not obscure—anyone can analyze Bark’s publicly available
Chrome extension code and identify the same problems that we did.
Even if you don’t have technical knowledge, you can use AI tools like ChatGPT to verify the
findings. Follow these steps:
Click the CRX Viewer extension icon and select "View source."
Find the file named monitor.js in the source code. Copy its content to your
clipboard.
Open ChatGPT or any AI assistant capable of analyzing code.
Paste the content of the monitor.js file into ChatGPT and use the following
prompt:
"Analyze spoofing vulnerabilities in this code."
The AI will provide insights on whether the code has vulnerabilities, such as spoofing or data
manipulation, confirming the findings.
Misleading Customers: Bark’s Denial of Security Vulnerabilities
During our investigation, we discovered that Bark has not been transparent about the security flaws in
their platform.
We first became aware of potential issues after reading a post on Reddit titled
Parents Beware: Bark.us and Bark Phone are Insecure.
The post raised concerns about Bark's platform security, prompting us to dig deeper.
Disguising ourselves as potential customers, we contacted Bark’s support team multiple times to inquire
about possible vulnerabilities. Each time, Bark assured us that their systems were completely
secure and claimed that there were no vulnerabilities.
This was more than a month after they had received a private disclosure about the issues from another
person.
Following these interactions, we decided to analyze Bark's publicly available Chrome extensions. In
doing so, we discovered at least 4 major vulnerabilities, confirming the concerns
raised in the Reddit post. Despite receiving prior disclosure of these flaws, Bark chose to deny
the existence of vulnerabilities rather than addressing the problems promptly.
Bark may try to excuse themselves by claiming that they refuse to respond to potential bad actors who
inquire about vulnerabilities, arguing that doing so would confirm and empower malicious behavior.
However, such type of argument is either a constructed lie or a failure of basic
reasoning.
Bad actors do not need Bark’s confirmation to exploit these flaws—they can simply analyze the publicly
available Chrome extension code. The vulnerabilities are evident in the code itself, meaning Bark’s
denials are ineffective in stopping bad actors. Their refusal to acknowledge these issues only serves to
mislead honest users while doing nothing to deter those with malicious intent.
This lack of honesty and responsibility raises serious questions about Bark’s commitment to ensuring the
safety and security of its users.
As a parent, you probably wouldn’t let a nanny babysit your kids if you knew she was dishonest about her
qualifications or past mistakes. The same logic applies to parental controls like Bark. If a company
lies about the security of its platform, how can you trust it to protect your children?
Bark's Response:
Tahnee here and thank you for your patience. I understand your concern, and I want to assure you
that Bark takes security very seriously. There's no security risks with our service. We use
state-of-the-art technologies to protect your family's data, and we have not identified any security
risks like those mentioned online. Your child's information is encrypted and handled with the utmost
care to ensure privacy and safety.
We use SSL encryption on the web to present data to you and your children. All data analyzed is
stored within an encrypted database. We are SOC-II compliant, a standard of security excellence.
Additionally, every employee goes through extensive background checks for clearance.
It's important to clarify that the assertions made in the Reddit post do not accurately reflect the
workings of our system. This Reddit user does not work for or is related to Bark, nor has knowledge
on how our system works. Rest assured, Bark's security infrastructures are solid, and we are
well-protected against the types of vulnerabilities mentioned.
Our Analysis:
While Bark claims there are "no security risks with our service," this is demonstrably false. During
our analysis, we identified at least 4 major vulnerabilities in Bark's publicly
available Chrome extensions. These issues include the ability for attackers to falsify activity
reports, spoof email addresses, and inject malicious data due to a lack of proper input validation.
These vulnerabilities undermine Bark's assurances about data security and privacy.
Bark also states that they use "state-of-the-art technologies" and that their systems are "SOC-II
compliant." While SOC-II compliance sets a standard for security practices, it does not mean a
system is free from vulnerabilities. Our findings clearly show that Bark's Chrome extension exhibits
poor coding practices, such as the absence of robust authentication and input
validation. This strongly contradicts the claim that they are "well-protected" against
vulnerabilities.
Additionally, Bark dismisses the Reddit post, stating that the user "does not work for or is related
to Bark" and lacks knowledge of their system. However, the concerns raised in the post align closely
with our independent analysis. Anyone can review Bark's publicly available code and observe the same
issues we identified. By denying these concerns outright, Bark demonstrates a lack of
transparency and accountability.
Finally, while Bark emphasizes the use of SSL encryption and encrypted databases, these measures are
standard practices and do not address the specific vulnerabilities in their Chrome extensions. These
issues go beyond data transmission or storage and affect the overall integrity of their platform.
Think You're Safe Without Bark's Chrome Extensions? Think Again
If you think the vulnerabilities we identified only affect Bark's Chrome and Microsoft Edge extensions, think again. The
fact that the Chrome extensions, with publicly available code, are so poorly coded
raises serious concerns about the quality of Bark's private codebase. If such
basic security principles are neglected in public code, it’s reasonable to assume that
their private code may also suffer from similar or even more severe issues.
Moreover, the endpoint used by the Chrome extension to send URLs visited by the user is
likely part of Bark's broader infrastructure. While we cannot confirm this, it is
possible that this same endpoint is used by other tools and products developed by Bark, such as the
Bark Phone, Bark Premium, or other services. If this is the case, the
vulnerabilities we discovered could be exploited in those products as well.
This interconnected nature of systems means that vulnerabilities in one product often
indicate risks for others, especially when the same underlying infrastructure or practices are shared.
Without full transparency from Bark or an independent security audit,
it’s impossible to know how far-reaching these issues may be.
As a parent or user, it's crucial to recognize that ignoring these vulnerabilities in one product could
leave your family’s data and privacy at risk across Bark’s entire platform.
The Media and Bark: Surface-Level Coverage
Bark has invested heavily in marketing and public relations, employing a large team
dedicated to promoting their brand. As a result, Bark has been featured in many reputable media
outlets, including Bloomberg, CNN, and BBC. While this coverage might seem like a stamp of
approval, it’s important to recognize that most of these articles focus on Bark’s marketing
narratives rather than critically examining their technology.
Unfortunately, no major media outlet has conducted a real investigation into Bark’s
platform. Instead, they often rely on Bark’s own claims without taking the time to look "under the hood"
at the actual technology, code, or security practices. This leaves parents and families with a
one-sided perspective, shaped by marketing rather than evidence-based evaluations.
Our investigation stands apart because we took a critical and independent approach. By
analyzing publicly available code and uncovering significant vulnerabilities, we have provided insights
that no other outlet has explored. These findings show that Bark's marketing image does
not align with the real security risks posed by their platform.
It’s crucial for parents to understand that media coverage does not equate to technical scrutiny. Bark's
focus on public relations has allowed them to present an image of trustworthiness and innovation, while
failing to address serious flaws in their platform. True accountability requires
independent evaluation, not reliance on promotional narratives.
As a parent, always ask: has this company earned my trust through transparency and proven security, or
is it relying on its reputation built through polished marketing and media appearances?
The Risks of Misusing Bark Phone's Features
The Bark Phone includes a feature that allows parents to control who their child can talk or text with,
as well as who can contact their child. While this feature is intended to protect children by
preventing predators, gangs, or drug dealers from
reaching them, it also carries the potential for serious misuse.
Children using the Bark Phone can only call approved contacts and 911. This limitation
is designed for safety, but in cases where parents are abusive, they can use this feature to
prevent their child from seeking help. Allowing calls only to 911 is insufficient, as
911 is primarily for emergencies. Children may need access to helplines, child
protection services, or other important support numbers that offer assistance for ongoing
abuse or difficult situations.
We strongly urge Bark to take the following steps to address this critical issue:
Always allow calls to helplines that assist children in reporting abuse, contacting
child protection services, and seeking help.
Enable children to delete call records of helpline calls from the phone's call log
to protect their privacy and safety.
Prevent reporting sensitive messages in which children discuss abuse to abusive
parents, ensuring their communications are not weaponized against them.
Display a list of always-allowed helpline numbers in the Bark Phone interface,
along with tips on what children should do if their parents are abusive.
We have already seen reports in public forums from users claiming that the Bark Phone was
misused to control children. This is likely just the tip of the
iceberg. Bark has a responsibility to ensure that their technology, while designed to
protect, does not become a tool of abuse.
By implementing these changes, Bark can take a strong stand against misuse and better protect the
children they aim to serve.
A Call for Bark to Improve
Throughout this tour, we’ve highlighted significant security flaws and raised concerns
about Bark’s lack of transparency and accountability. While much of what we’ve shared has been critical,
it’s important to acknowledge that Bark’s technology also helps families. Their
platform has made a positive impact by providing tools that enable parents to monitor their children’s
online safety.
However, this positive contribution does not excuse the serious vulnerabilities and
misleading practices we’ve uncovered. Our goal is not to discredit Bark entirely, but
to encourage them to take the steps necessary to earn the trust of the families who
rely on them.
We urge Bark to:
Reconsider their approach to marketing: Be honest and transparent with users,
rather than dismissing valid concerns.
Publicly admit the issues we and others have identified, and ideally,
apologize to their users for the risks these vulnerabilities pose.
Fix the vulnerabilities we’ve discovered and ensure their systems are secure.
Conduct a thorough, independent security audit of their entire platform and address
any additional issues identified.
Publish the results of the security audit, demonstrating a commitment to
transparency and user safety.
Implement anti-abuse features to Bark Phone, demonstrating a commitment to protect
children from abuse.
We believe Bark has the potential to be a valuable tool for families, but only if they take these steps
to ensure their technology is truly secure and trustworthy. By acknowledging and fixing these problems,
Bark can become the kind of company that parents can confidently rely on to protect their children.
Why You Can Trust Us
Our primary goal is to protect children from harm and abuse. This presentation was
created to raise awareness about serious vulnerabilities in Bark's platform, and our intentions are
rooted in genuine concern for families.
We understand that trust is essential, so we've provided clear steps that allow anyone,
even those without technical expertise, to verify our findings independently. By using
publicly available tools and AI assistance, you can confirm the issues we have highlighted.
Learn how to check Bark's
Chrome extension source code.
To protect ourselves from potential retaliation from Bark or its affiliates, we have chosen to remain
anonymous. However, this does not diminish the validity of our findings, which are based on a
comprehensive investigation. This includes analyzing Bark's Chrome extension code,
examining how Bark Phone works, recommending steps to prevent the abuse of Bark's technology, and
evaluating how Bark communicates with its users.
It’s important to note that we believe Bark's technology has the potential to do good by helping
families stay connected and safe. However, this potential is undermined by the serious issues we have
uncovered. We hope this presentation encourages Bark to take accountability, improve their security
practices, and ensure their technology cannot be misused to harm children.
We have approached this issue with honesty and integrity. Every claim made in this
presentation is supported by the evidence we gathered during our investigation. We encourage you to
review the provided information critically, verify it for yourself, and join us in advocating for better
protections for children.
Together, we can hold companies accountable and ensure that the technologies we rely on to protect our
families are truly safe, trustworthy, and free from vulnerabilities that could cause harm.
Thank You for Taking the Tour
Thank you for taking the time to learn about the important issues surrounding Bark's platform. Your
attention and willingness to understand these concerns are critical in creating a safer environment for
children online.
If you found this information valuable, we encourage you to share it with others. By spreading
awareness, you can help ensure that families everywhere are informed and empowered to demand better
security and accountability from Bark and similar services.
Share this on social media:
Together, we can make a difference by ensuring that companies prioritize safety, transparency, and
accountability in the digital tools they provide for families.
Paws and think before
trusting just any platform 🐾.