论文标题

权威政府可以滥用访问权吗?

Can Authoritative Governments Abuse the Right to Access?

论文作者

Lauradoux, Cédric

论文摘要

访问权是GDPR提供的一个很好的工具,可以使数据主体授予其数据。但是,它需要正确实施,否则可以将主题访问请求与主题隐私相关。确实,最近的作品表明,有可能滥用使用模仿攻击的权利。我们建议通过考虑对手可以使用政府资源来扩展这些模仿攻击。在这种情况下,对手可以伪造官方文件或利用其副本。我们的攻击会影响更多的人。为了击败这种对手的攻击,可以使用多种解决方案,例如多因素或证据证明。我们的攻击突出了需要强大程序来验证主题访问请求的必要性。

The right to access is a great tool provided by the GDPR to empower data subjects with their data. However, it needs to be implemented properly otherwise it could turn subject access requests against the subjects privacy. Indeed, recent works have shown that it is possible to abuse the right to access using impersonation attacks. We propose to extend those impersonation attacks by considering that the adversary has an access to governmental resources. In this case, the adversary can forge official documents or exploit copy of them. Our attack affects more people than one may expect. To defeat the attacks from this kind of adversary, several solutions are available like multi-factors or proof of aliveness. Our attacks highlight the need for strong procedures to authenticate subject access requests.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源