论文标题

探索密码 - SSID在探针请求中的隐私影响

Probing for Passwords -- Privacy Implications of SSIDs in Probe Requests

论文作者

McDougall, Johanna Ansohn, Burkert, Christian, Demmler, Daniel, Schwarz, Monina, Hubbe, Vincent, Federrath, Hannes

论文摘要

探针请求可帮助移动设备发现活动的Wi-Fi网络。它们通常包含多种数据,可用于识别和跟踪设备以及其用户。过去几年是一种猫和鼠标的游戏,可以改善指纹并引入针对指纹的对策。本文分析了现场实验中移动设备和操作系统发送的探针请求的内容。在其中,我们发现用户(可能是偶然)将大量数据输入到SSID字段中,并查找密码,电子邮件地址,姓名和假日位置。通过这些发现,我们强调了探针请求应被视为敏感数据并得到很好的保护。为了保留用户隐私,我们建议并评估基于隐私友好的探针请求的构造和改进的用户控件。

Probe requests help mobile devices discover active Wi-Fi networks. They often contain a multitude of data that can be used to identify and track devices and thereby their users. The past years have been a cat-and-mouse game of improving fingerprinting and introducing countermeasures against fingerprinting. This paper analyses the content of probe requests sent by mobile devices and operating systems in a field experiment. In it, we discover that users (probably by accident) input a wealth of data into the SSID field and find passwords, e-mail addresses, names and holiday locations. With these findings we underline that probe requests should be considered sensitive data and be well protected. To preserve user privacy, we suggest and evaluate a privacy-friendly hash-based construction of probe requests and improved user controls.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源