Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile Browsers

Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile Browsers
复制标题

DOI:
10.1109/sp40000.2020.00077
复制
发表时间:
2020-05
期刊:
2020 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Brian Kondracki;Assel Aliyeva;Manuel Egele;Jason Polakis;Nick Nikiforakis
Brian Kondracki;Assel Aliyeva;Manuel Egele;Jason Polakis;Nick Nikiforakis
中科院分区:
其他
文献类型:
--
作者:
Brian Kondracki;Assel Aliyeva;Manuel Egele;Jason Polakis;Nick Nikiforakis

文献摘要

被引文献

相似文献

移动浏览器已成为我们在线活动的主要媒介之一。然而,随着网页大小不断增加以及移动流媒体变得司空见惯,移动数据计划限制仍然是用户的一个重大担忧。因此,在选择移动浏览器时,数据节省功能可能是一个差异化因素。在本文中,我们全面探讨了数据保存功能给用户带来的安全和隐私威胁。我们对 Android 的数据保存浏览器 (DSB) 生态系统进行了多维度的首次分析,包括各种浏览器基础设施的特征、它们的应用程序和协议级行为以及它们对用户浏览体验的影响。我们的研究明确表明,在主要浏览器中启用数据保存功能会引入严重的漏洞,从而导致用户的安全状况显着下降,而这些漏洞在正常操作期间不会出现在浏览器中。总之,我们的实验表明,启用数据节省会使用户面临以下风险:(i) 运行过时软件的代理服务器;(ii) 由于 TLS 证书验证有问题而导致中间人攻击;(iii) TLS 密码套件选择减弱;(iv) 缺乏对 HSTS 等安全标头的支持;(v) 被标记为机器人的可能性更高。虽然发现的问题可以得到解决,但我们认为,数据保存功能在日益加密的网络中带来了固有的风险,用户应该警惕他们每次启用此类功能时都隐式接受的关键节省与安全权衡。
Mobile browsers have become one of the main mediators of our online activities. However, as web pages continue to increase in size and streaming media on-the-go has become commonplace, mobile data plan constraints remain a significant concern for users. As a result, data-saving features can be a differentiating factor when selecting a mobile browser. In this paper, we present a comprehensive exploration of the security and privacy threat that data-saving functionality presents to users. We conduct the first analysis of Android’s data-saving browser (DSB) ecosystem across multiple dimensions, including the characteristics of the various browsers’ infrastructure, their application and protocol-level behavior, and their effect on users’ browsing experience. Our research unequivocally demonstrates that enabling data-saving functionality in major browsers results in significant degradation of the user’s security posture by introducing severe vulnerabilities that are not otherwise present in the browser during normal operation. In summary, our experiments show that enabling data savings exposes users to (i) proxy servers running outdated software, (ii) man-in-the-middle attacks due to problematic validation of TLS certificates, (iii) weakened TLS cipher suite selection, (iv) lack of support of security headers like HSTS, and (v) a higher likelihood of being labelled as bots. While the discovered issues can be addressed, we argue that data-saving functionality presents inherent risks in an increasingly-encrypted Web, and users should be alerted of the critical savings-vs-security trade-off that they implicitly accept every time they enable such functionality.