VPN app, FRITZ!Box, or travel router? Which setup is right for you? Read Can my child bypass parental controls? Parents should be aware of these vulnerabilities

Can my child bypass parental controls? Parents should be aware of these vulnerabilities

Can my child bypass parental controls? Parents should be aware of these vulnerabilities

Many parents set up Google Family Link, Qustodio, or Apple Screen Time and then assume that their child's smartphone is fully protected.

The problem: Parental controls consist of several layers of technical protection. If even one of them remains unprotected, a tech-savvy child might be able to find another way to access the desired content.

The crucial question, therefore, is not:

"Which parental controls are unbreakable?"

Rather:

"As a parent, what other vulnerabilities do I need to address?"

In this article, we highlight the key vulnerabilities of Family Link, Qustodio, and Apple Screen Time—and explain why Talos Family also operates at the network level.

Vulnerability 1: The child can change system settings

One of the most significant vulnerabilities is not in the parental control app itself, but in the smartphone's settings.

If a child has access to relevant system settings, they might, for example, try to change permissions, network options, or user accounts.

Qustodio therefore points out that parents using Android should not only protect the Qustodio settings but also restrict access to the Android system settings.

What Parents Should Check

On a device intended for children, it's not just the parental control app itself that should be protected.

Parents should also check the following:

  • Can my child change system settings?

  • Can it remove important permissions from a security app?

  • Can it create additional user accounts?

  • Can a security app delete it?

  • Can it change network or cellular settings?

This is crucial because parental controls can only work as long as the operating system grants them the necessary permissions.


Vulnerability 2: Multiple Users or Guest Mode on Android

One thing many parents aren't aware of at all:

Some Android devices support multiple user profiles or a guest mode.

This can be problematic if parental controls only work within the user profile that was originally set up.

Qustodio explicitly warns that additional Android users or guest mode can be used to bypass the protection. The provider therefore recommends disabling this feature and restricting access to the Android settings.

For parents, this means

It's not necessarily enough to just install Qustodio and then stop monitoring altogether.

Also check to see if the smartphone:

Child Profile → Protected

but at the same time:

Guest profile → may be configured differently

can use.

Especially on Android, you should therefore check whether additional user profiles or guest mode are even necessary.


Vulnerability 3: The parental control app can be removed or modified

A protection app only works as long as it is active on the device.

That is why one of the most important questions is:

Can my child uninstall the safety app or change its settings?

Qustodio also addresses this very issue in its own documentation and offers additional safeguards against changes to or removal of the app.

When it comes to computers, Qustodio even explicitly recommends:

Parents → Administrator Account

Child → Standard account without administrator privileges

This is intended to prevent the child from modifying or removing the parental control software on their own.

This principle applies regardless of the manufacturer:

Parental controls should never rely on the child voluntarily leaving the protection software unchanged.


What are the vulnerabilities of Google Family Link?

Google Family Link is particularly well integrated into the operating system on Android. However, Family Link does not provide complete control over all internet traffic.

Family Link primarily monitors apps, accounts, and screen time

With Family Link, for example, parents can:

  • Block apps,

  • Set time limits,

  • Manage permissions,

  • Monitor downloads,

  • Set device usage times.

However, Google itself points out that certain system apps cannot be subject to standard app limits.

That's an important difference:

App control does not automatically equate to network control.

Just because a particular app has been blocked doesn't automatically mean that the same service isn't accessible through another technical means.


Vulnerability: Not every app can be controlled in the same way

A child doesn't necessarily have to try to reactivate a locked app.

Another question is more interesting:

Is the same content available through another approved app?

For example, an internet service can generally be accessed through various apps or through a browser.

That is why parents need to do more than just think about:

"Did I block the TikTok app?"

but rather:

"Is TikTok still accessible via the network?"

This is exactly where the difference lies between an app lock and a network lock.


Vulnerability: App Permissions

Family Link can manage app permissions.

Google points out, however, that these permissions can generally be managed by both parents and children—though parents can set it so that only they are allowed to grant permissions.

This attitude is important for parents.

After all, an effective protection system should prevent a child from simply changing the rights on which the monitoring is based.


What are Qustodio's weaknesses?

Qustodio offers many features for controlling apps, websites, and devices.

But Qustodio itself clearly outlines in its documentation which areas parents should additionally protect.

Android settings must be protected

Qustodio strongly recommends:

  • Protect Qustodio Settings

  • Protect Your Android Settings

  • Check for additional user profiles

Why?

Because many attempts to bypass the software are not directly aimed at Qustodio.

Instead, an attempt is made to change the environment in which Qustodio operates.

That's a crucial difference.


Vulnerability: Other User Profiles

On Android, additional user profiles can be particularly useful.

Qustodio explicitly identifies this option as a potential way to bypass the protection.

Parents should therefore follow this rule:

Don't just set up Qustodio—set up the entire device.


Vulnerability: Administrator privileges on PC and Mac

On a Windows or Mac computer, Qustodio recommends that the child not use an administrator account.

Qustodio recommends:

Parent Account = Administrator

Child Account = Standard User

This makes sense because a user with administrator privileges has significantly more options for modifying installed software and system settings.


What are the weaknesses of Apple's Screen Time?

Apple offers comprehensive built-in protection features through Screen Time.

Among other things, parents can:

  • Restrict apps,

  • Prevent app installations,

  • prevent apps from being deleted,

  • Restrict web content,

  • Prevent account changes,

  • Limit changes to mobile data.

Apple explicitly documents these options.

The problem, therefore, often lies less with screen time itself than with an incomplete configuration.


Vulnerability: Apps can be deleted

Suppose there is a security, filtering, or VPN app on the iPhone in addition to Screen Time.

In that case, of course, the child shouldn't be able to just delete this app.

Apple therefore explicitly allows users to prevent the deletion of apps through Screen Time.

This setting is especially important for parents when additional security software is being used.


Vulnerability: Changes to Account and Mobile Service

Apple also allows parents to prevent certain changes from being made to the device.

These include, among other things:

Account Changes

and

Changes to Mobile Data

You shouldn't ignore settings like these.

After all, a robust protection plan means:

The child is allowed to use the smartphone—but not to alter the smartphone's security architecture.


The major vulnerability of many parental controls: the network

Here's a point that many parents overlook.

Family Link, Screen Time, and Qustodio focus heavily on the device itself.

But a smartphone is constantly connected to the Internet.

That is why there is a second level:

The Network

For example, a device needs to determine which IP address corresponds to a domain.

DNS is used for this purpose.

For example, a classic DNS filter can decide:

Allowed website → DNS resolution allowed

Blocked website → DNS resolution blocked

But now the next problem arises.

What happens if the device simply uses a different DNS server?


Vulnerability: Use a different DNS server

A typical DNS system operates on port 53.

In theory, a device could attempt to use a different public DNS service instead of the designated DNS server.

That's exactly why Talos Family goes one step further:

Talos Family does not allow unrestricted external DNS traffic over port 53

On the Talos Family Gateway, outbound standard DNS traffic over TCP and UDP port 53 is blocked.

A protected device therefore cannot simply use just any external traditional DNS server.

The intended DNS path remains under the control of the Talos Family network.

In simple terms:

Device

WireGuard

Talos Family Gateway

Controlled DNS

Internet

A traditional external DNS server on port 53 should not be available as a simple fallback option.


But then there's DNS over HTTPS

And this is exactly where things get interesting from a technical standpoint.

Modern browsers and apps can also encrypt DNS requests over HTTPS.

That's what they call:

DNS over HTTPS – DoH

DoH typically uses HTTPS over port 443.

And you can't just block port 443 entirely.

Why?

Because practically the entire modern web runs on it.

Google, Wikipedia, online banking, online stores, and nearly every other modern website use HTTPS.

That is why DoH is particularly relevant for DNS-based filters.


That is why Talos Family also supports DoH

Talos Family also blocks known DNS-over-HTTPS services.

This is intended to prevent browsers or apps from simply using an external DoH resolver to bypass the intended DNS filter.

The principle of protection therefore consists of several levels:

1. Traditional external DNS via Port 53

→ is blocked from the outside.

2. Intended DNS resolver

→ is used via Talos Family.

3. Well-known DNS-over-HTTPS services

→ are subject to additional restrictions.

4. Internet Traffic

→ is routed through the WireGuard tunnel.

This makes it much more difficult to bypass DNS filtering than with a system that simply configures a DNS server in the router.


The next vulnerability: What happens if the VPN is turned off?

That is precisely the crucial question.

After all, even the best network filter is of little use if the device can simply connect directly to the Internet again.

That is why the VPN connection must also be secured.


Android: Keep WireGuard Always On

Android has a very important feature for this:

Always-on VPN

Android can configure a VPN connection to be used as a permanent VPN.

In addition, there is a feature that allows you to block network traffic without a VPN connection.

This results in a significantly stronger model:

WireGuard is active → The Internet is working

WireGuard is not active → no normal Internet access

Android explicitly provides these mechanisms for VPN connections.

This prevents apps from simply bypassing the designated VPN tunnel.

This is particularly interesting for the Talos Family.

This allows parents to choose a combination of:

Talos Family + WireGuard + Always-on VPN + Blocking Without a VPN

use.

This makes it much more difficult to simply switch to an unfiltered connection.


And on the iPhone?

The technical architecture works differently on the iPhone and iPad.

For example, parents can use Apple Screen Time to:

  • prevent apps from being deleted,

  • Prevent account changes,

  • restrict certain changes to the device,

  • Limit changes to mobile data.

This can, for example, prevent the WireGuard app—which is necessary for protection—from simply being deleted.

However, it is important to note that:

A standard personal iPhone does not offer exactly the same VPN lockdown mechanism as Android, with "Always-on VPN" and "Block connections without VPN."

For Apple devices subject to particularly strict management, there are additional management mechanisms that are more commonly found in the enterprise and MDM sectors.

That's why you shouldn't treat Android and iOS as equivalent in this context.


Why Talos Family Doesn't Replace Family Link, Qustodio, or Screen Time

Talos Family is not intended to replace these systems.

Device protection and network protection address different issues.

A robust safety plan might look something like this:

Android

Google Family Link or Qustodio

controlled:

Apps, Screen Time, and device settings.

PLUS

Talos Family on WireGuard

controlled:

Network access, DNS, and known alternative DNS routes.

PLUS

Android Always-On VPN

makes it more difficult to use the Internet outside the VPN tunnel.


iPhone

Apple Screen Time

controlled:

Apps, installations, deletions, account changes, and other device settings.

PLUS

Talos Family on WireGuard

complements network-level monitoring.

PLUS

Protection Against Deletion of the WireGuard App

reduces the likelihood that the additional layer of protection can be easily removed.


The most important rule for parents: Don't just secure one app

The most important finding is therefore:

A single parental control app should not be the only line of defense.

Parents should consider several questions:

Can my child delete the safety app?

Can it change system settings?

Can it use additional user profiles?

Can it access apps through other means?

Can it use a different DNS server?

Can it use DNS over HTTPS?

Can I turn off the VPN and then continue browsing as usual?

The more these routes are monitored, the harder it becomes to circumvent them.

Conclusion: Device Protection + Network Protection

Google Family Link, Qustodio, and Apple Screen Time are important tools.

However, they mainly work on the device.

Talos Family complements this protection at the network level.

On Android in particular, this can result in a multi-layered architecture:

Family Link / Qustodio

Protected device settings

WireGuard Always-on VPN

No Internet access outside the VPN

Talos Family Gateway

External DNS blocked on port 53

Well-known DoH services restricted

filtered Internet access

As a result, parental controls no longer depend on just a single app or a single setting.

And that is precisely the advantage of multi-layered protection: if one layer of protection has a vulnerability, there is another one behind it.

Leave a comment

Your email address will not be published. Required fields are marked with an *