论文标题
探索密码 - SSID在探针请求中的隐私影响
Probing for Passwords -- Privacy Implications of SSIDs in Probe Requests
论文作者
论文摘要
探针请求可帮助移动设备发现活动的Wi-Fi网络。它们通常包含多种数据,可用于识别和跟踪设备以及其用户。过去几年是一种猫和鼠标的游戏,可以改善指纹并引入针对指纹的对策。本文分析了现场实验中移动设备和操作系统发送的探针请求的内容。在其中,我们发现用户(可能是偶然)将大量数据输入到SSID字段中,并查找密码,电子邮件地址,姓名和假日位置。通过这些发现,我们强调了探针请求应被视为敏感数据并得到很好的保护。为了保留用户隐私,我们建议并评估基于隐私友好的探针请求的构造和改进的用户控件。
Probe requests help mobile devices discover active Wi-Fi networks. They often contain a multitude of data that can be used to identify and track devices and thereby their users. The past years have been a cat-and-mouse game of improving fingerprinting and introducing countermeasures against fingerprinting. This paper analyses the content of probe requests sent by mobile devices and operating systems in a field experiment. In it, we discover that users (probably by accident) input a wealth of data into the SSID field and find passwords, e-mail addresses, names and holiday locations. With these findings we underline that probe requests should be considered sensitive data and be well protected. To preserve user privacy, we suggest and evaluate a privacy-friendly hash-based construction of probe requests and improved user controls.