Wi-Fi tracking : Fingerprinting attacks and counter-measures

Célestin Matte 1, 2
2 PRIVATICS - Privacy Models, Architectures and Tools for the Information Society
Inria Grenoble - Rhône-Alpes, CITI - CITI Centre of Innovation in Telecommunications and Integration of services
Abstract : The recent spread of everyday-carried Wi-Fi-enabled devices (smartphones, tablets and wearable devices) comes with a privacy threat to their owner, and to society as a whole. These devices continuously emit signals which can be captured by a passive attacker using cheap hardware and basic knowledge. These signals contain a unique identifier, called the MAC address. To mitigate the threat, device vendors are currently deploying a countermeasure on new devices: MAC address randomization. Unfortunately, we show that this mitigation, in its current state, is insufficient to prevent tracking. To do so, we introduce several attacks, based on the content and the timing of emitted signals. In complement, we study implementations of MAC address randomization in some recent devices, and find a number of shortcomings limiting the efficiency of these implementations at preventing device tracking. At the same time, we perform two real-world studies. The first one considers the development of actors exploiting this issue to install Wi-Fi tracking systems. We list some real-world installations and discuss their various aspects, including regulation, privacy implications, consent and public acceptance. The second one deals with the spread of MAC address randomization in the devices population. Finally, we present two tools: an experimental Wi-Fi tracking system for testing and public awareness raising purpose, and a tool estimating the uniqueness of a device based on the content of its emitted signals even if the identifier is randomized.
Complete list of metadatas

Cited literature [242 references]  Display  Hide  Download

https://tel.archives-ouvertes.fr/tel-01921596
Contributor : Abes Star <>
Submitted on : Tuesday, November 13, 2018 - 8:56:05 PM
Last modification on : Tuesday, November 19, 2019 - 12:04:37 PM
Long-term archiving on : Thursday, February 14, 2019 - 4:44:01 PM

File

these.pdf
Version validated by the jury (STAR)

Identifiers

  • HAL Id : tel-01921596, version 1

Citation

Célestin Matte. Wi-Fi tracking : Fingerprinting attacks and counter-measures. Networking and Internet Architecture [cs.NI]. Université de Lyon, 2017. English. ⟨NNT : 2017LYSEI114⟩. ⟨tel-01921596⟩

Share

Metrics

Record views

204

Files downloads

4716