Privacy at the Link Layer
Privacy at the Link Layer
复制标题
链路层的隐私
DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Ian Brown
中科院分区:
文献类型:
--
作者:
Ian Brown
Many people now carry at least one device that routinely uses globally-unique link layer identifiers to locate and attach to local networks. Such link layer, or MAC, addresses are frequently emitted wirelessly in a variety of scenarios. This indiscriminate broadcast of a unique and effectively personal identifier allows for unregulated and broad-scale tracking of individuals via their personal devices, whether or not those devices have made use of a particular service or not. These addresses typically remain unchanged for the lifetime of a device, creating a persistent, lifelong tracking capability. These interface identifiers are now increasingly being monitored, collated, and analysed by a number of organisations, without meaningful regulation, for a variety of purposes without explicit permission from, or notification to, the individual. At higher levels in the stack, on mobile devices, endpoint identifiers are generally ephemeral and change when attaching to different networks. Several efforts have been made to provide privacy or unlinkability at the IP level: private addressing, privacy extensions for IPv6 addresses, and Network Addresses Translators. Once a device seeks to connect to a network, however, there are a number of behaviours that can further weaken or compromise the privacy of devices and their owners, a notable example being the aggressive use of Detection of Network Attachment (DNA) services. Whilst, at a higher level, there is some level of user choice in access to communications services such as social media or cloud services, link layer identification is far less visible and accessible to normal users. Given the ease with which link layer identifiers can be abused it would be advisable for for end systems to connect to networks without utilising an immutable, unique identifier where possible. We contend that, in many cases, the existence of unique global identifiers at the link layer is largely unjustified, and is increasingly a source of serious potential harm. End systems should therefore have the capability to employ an ephemeral address at the link layer to prevent long-term tracking and correlation of devices and individuals. We consider that the deployment of such systems should be both possible and practical within the constraints of many existing networks.