Discontinued Privacy: Personal Data Leaks in Apple Bluetooth-Low-Energy Continuity Protocols

Discontinued Privacy: Personal Data Leaks in Apple Bluetooth-Low-Energy Continuity Protocols
复制标题

隐私终止:Apple 低功耗蓝牙连续性协议中的个人数据泄露

DOI:
10.2478/popets-2020-0003
复制
发表时间:
2020
影响因子:
--
通讯作者:
M. Cunche
M. Cunche
中科院分区:
--
文献类型:
--
作者:
Guillaume Celosia;M. Cunche

文献摘要

被引文献

相似文献

苹果连续性协议是苹果连续性服务的底层网络组件,它允许无缝附近的应用程序,如活动和文件传输,设备配对和共享网络连接。这些协议依靠蓝牙低功耗(BLE)在设备之间交换信息:Apple Continuity消息嵌入在BLE广告包的付费负载中,由设备定期广播。最近,Martin等人发现了一些与Apple Continuity协议相关的隐私问题;我们表明,这只是冰山一角,苹果连续性协议泄露了广泛的个人信息。在这项工作中,我们提出了一个彻底的苹果连续性协议的逆向工程,我们使用它来发现一系列隐私泄露。我们引入了新的工件,包括标识符、计数器和电池电量,可用于被动跟踪,并描述了一种基于切换消息的新型主动跟踪攻击。除了跟踪问题,我们还揭示了严重的隐私缺陷。首先,除了微不足道的设备特性和状态暴露之外,我们发现HomeKit配件泄露了智能家居中的人类活动。然后,我们证明了AirDrop和Nearby Action协议可以被被动观察者利用来恢复用户的电子邮件地址和电话号码。最后,我们利用对广告流量的被动观察来推断用户的Siri语音命令。
Abstract Apple Continuity protocols are the underlying network component of Apple Continuity services which allow seamless nearby applications such as activity and file transfer, device pairing and sharing a network connection. Those protocols rely on Bluetooth Low Energy (BLE) to exchange information between devices: Apple Continuity messages are embedded in the pay-load of BLE advertisement packets that are periodically broadcasted by devices. Recently, Martin et al. identified [1] a number of privacy issues associated with Apple Continuity protocols; we show that this was just the tip of the iceberg and that Apple Continuity protocols leak a wide range of personal information. In this work, we present a thorough reverse engineering of Apple Continuity protocols that we use to uncover a collection of privacy leaks. We introduce new artifacts, including identifiers, counters and battery levels, that can be used for passive tracking, and describe a novel active tracking attack based on Handoff messages. Beyond tracking issues, we shed light on severe privacy flaws. First, in addition to the trivial exposure of device characteristics and status, we found that HomeKit accessories betray human activities in a smarthome. Then, we demonstrate that AirDrop and Nearby Action protocols can be leveraged by passive observers to recover e-mail addresses and phone numbers of users. Finally, we exploit passive observations on the advertising traffic to infer Siri voice commands of a user.