DEV Community

Cover image for One Phone Gets Hacked. Everyone in the Family Circle Is Exposed.
Short Lived
Short Lived

Posted on Originally published at shortlivedage.substack.com AI-assisted

One Phone Gets Hacked. Everyone in the Family Circle Is Exposed.

What the research found

A forensic analysis of Life360, one of the most used family location tracking apps, found that compromising a single device gives access to the personal data of each member in that person’s Circle, not just the one phone. Researchers recovered detailed location histories, driving data, and other sensitive artifacts through standard forensic tools applied to only one device, exposing information about people who never had their own phone touched. The same analysis found the app doesn’t require entering a child’s age during account setup, a gap that sidesteps the added protections apps are supposed to apply to younger users.

A separate, far larger study, the largest of its kind on this topic, surveyed 3,000 people and found half of them use continuous location-sharing apps. Among 896 who completed detailed surveys about their experience, a share described real discomfort with how the apps were used. Follow-up interviews with those who reported the most negative experiences found a pattern that builds over time. It starts with a boundary being crossed, continues as ongoing unease, and can end with someone changing their behavior and choices because they know they’re being watched.


Why a “trusted circle” doesn’t function like private data

The appeal of these apps rests on the idea that visibility stays contained within a small, trusted group: family, close friends, people you’d already tell your location to anyway. The forensic findings complicate that framing in two ways. On the technical side, trust in the people you’ve added doesn’t protect you from a security failure on any single device in that group, since compromising one phone was enough to expose the whole Circle’s data in the research. On the social side, “trusted” doesn’t mean “comfortable,” and the discomfort study found that even within family relationships, continuous visibility can shift a dynamic in ways neither party expected going in.


The practical takeaway

If your family uses a location-sharing app, check each phone’s security on its own, since the weakest device in the group becomes the weak link for everyone in it. Use a strong passcode and enable any available two-factor authentication on the account itself, not just the device. And treat the emotional side with the same weight as the technical side: the discomfort research suggests it’s worth having a direct conversation about what the sharing is for and revisiting it now and then, rather than setting it up once during a moment of worry and leaving it running for years without either side reconsidering it.

This research focused on Life360, the most used app in this category. Other family tracking apps may handle security and data in a different way, so the specific technical findings shouldn’t be assumed to apply the same way across each app in this space, even though the underlying single-point-of-failure risk is a structural concern worth checking regardless of which app you use.


References

  1. Aagaard, P., Dinyarian, B., Abduljabbar, O., Choo, K.-K. R. “Family locating sharing app forensics: Life360 as a case study.” Forensic Science International: Digital Investigation, 2023. https://cspecc.utsa.edu/publications/files/Refereed_Papers/2022-Choo-Family%20locating%20sharing%20app%20forensics-Life360%20as%20a%20case%20study.pdf

  2. Childs, K., Gibson, C., Crowder, A., Warren, K., Stillman, C., Redmiles, E. M., Jain, E., Traynor, P., Butler, K. R. B. “I Had Sort of a Sense that I Was Always Being Watched...Since I Was: Examining Interpersonal Discomfort From Continuous Location-Sharing Applications.” Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security. https://par.nsf.gov/servlets/purl/10561479

Support Me on Ko-fi

Top comments (0)