论文标题
丢失并发现:停止蓝牙发现器泄漏私人信息
Lost and Found: Stopping Bluetooth Finders from Leaking Private Information
论文作者
论文摘要
蓝牙查找器是一种小型电池供电的设备,可以连接到重要物品,例如袋子,钥匙扣或自行车。 Finder与用户手机保持蓝牙连接,并立即在连接损失时通知用户。我们提供了当前商业蓝牙查找器的首次全面安全和隐私分析。我们的分析揭示了这些产品中有关移动应用程序和云中相应的后端服务的几个重要安全漏洞。我们还表明,所有分析的基于云的产品泄漏了比各自云服务所需的更多私人数据。 总体而言,蓝牙发现器有一个大市场,但现有产品都不是隐私友好的。我们通过设计和实施私人发现来缩小这一差距,从而确保用户的位置永远不会泄漏到第三方。它旨在使用与现有发现器相似的硬件运行,允许供应商使用私人信息更新其系统。
A Bluetooth finder is a small battery-powered device that can be attached to important items such as bags, keychains, or bikes. The finder maintains a Bluetooth connection with the user's phone, and the user is notified immediately on connection loss. We provide the first comprehensive security and privacy analysis of current commercial Bluetooth finders. Our analysis reveals several significant security vulnerabilities in those products concerning mobile applications and the corresponding backend services in the cloud. We also show that all analyzed cloud-based products leak more private data than required for their respective cloud services. Overall, there is a big market for Bluetooth finders, but none of the existing products is privacy-friendly. We close this gap by designing and implementing PrivateFind, which ensures locations of the user are never leaked to third parties. It is designed to run on similar hardware as existing finders, allowing vendors to update their systems using PrivateFind.