Brave new world: privacy risks for mobile users

Brave new world: privacy risks for mobile users
复制标题

DOI:
10.1145/2646584.2646585
复制
发表时间:
2014-09
期刊:
Proceedings of the ACM MobiCom workshop on Security and privacy in mobile environments
影响因子:
--
通讯作者:
Paarijaat Aditya;Bobby Bhattacharjee;P. Druschel;V. Erdélyi;Matthew Lentz
Paarijaat Aditya;Bobby Bhattacharjee;P. Druschel;V. Erdélyi;Matthew Lentz
中科院分区:
其他
文献类型:
--
作者:
Paarijaat Aditya;Bobby Bhattacharjee;P. Druschel;V. Erdélyi;Matthew Lentz

文献摘要

被引文献

相似文献

复杂的移动计算、传感和记录设备已司空见惯。智能手机已经实现了显着的普及,像谷歌眼镜这样的新颖设备即将出现。这些设备可以提供传统笔记本电脑的大部分功能,但还具有一系列附加功能,包括图像/音频/视频记录、GPS 定位、指南针、加速计、近距离无线电(NFC 和蓝牙)以及即将推出的健康和健身监视器。此外,用户几乎全天候携带这些设备,模糊了线上和线下世界之间的区别,并实现了变革性的新应用程序和服务。例如,移动应用程序可以提供位置和活动敏感的服务和信息,如果谷歌眼镜直接覆盖在用户的视野上。他们可以记录用户所做的、看到的和听到的,以供将来参考;他们可以跟踪用户与附近用户设备的接触情况,以实现与共享体验或事件相关的通信。然而,这些应用程序和服务也给用户隐私带来了一系列新的威胁。当用户携带它时,移动设备可以捕获用户位置、线上和线下活动以及社交遭遇的完整记录,可能包括视听记录。虽然这样的记录对于用户自己的参考和启用新的应用程序非常有用,但它也是高度敏感的并且本质上是私密的。与用户在 Facebook 或 Twitter 上发布的信息不同,大多数用户可能不想与任何人分享如此全面的记录。在本文中,我们对这些设备和应用程序引入的隐私威胁进行了分类。我们对威胁的调查强调了来自移动设备的隐私威胁与以前的系统有何根本不同,并且本质上更危险。对于每个特定的风险向量,我们描述了技术挑战,如果解决这些挑战,可以减轻其影响。我们注意到,技术创新仅仅提供了一个起点:端到端的隐私保护基础设施将需要改变基本服务的部署方式、法律的方式
Sophisticated mobile computing, sensing and recording devices are commonplace. Smart phones have achieved significant penetration and novel devices like Google Glass are imminent. These devices can serve most functions of a conventional notebook computer, but also have a range of additional capabilities, including image/audio/video recording, GPS location, compass, accelerometer, nearrange radio (NFC and Bluetooth), and soon health and fitness monitors. Moreover, these devices are carried by their users virtually around the clock, blurring the distinction between the online and offline world and enabling transformative new applications and services. For instance, mobile apps can provide location and activity-sensitive services and information, in the case of Google Glass overlaid right onto a user’s field of view. They can record what the user does, sees and hears for future reference; and they can keep track of a user’s encounters with nearby users’ devices to enable communication related to a shared experience or event. However, these applications and services also introduce a range of new threats to users’ privacy. While a user carries it, a mobile device can capture a complete record of the user’s location, online and offline activities, and social encounters, potentially including an audio-visual record. While such a record is very useful to a user for their own reference and to enable new applications, it is also highly sensitive and inherently private. Unlike information users post on Facebook or Twitter, most users would likely not want to share such a comprehensive record with anyone. In this paper, we catalog privacy threats introduced by these devices and applications. Our survey of threats underlines how privacy threats from mobile devices are fundamentally different and inherently more dangerous than in prior systems. For each specific risk vector, we describe technical challenges that, if solved, can mitigate its effects. We note that technical innovations merely provide a starting point: an end-to-end privacy-preserving infrastructure will require changes in how basic services are deployed, how laws