On the Privacy and Integrity Risks of Contact-Tracing Applications

12/06/2020
by   Jianwei Huang, et al.
0

Smartphone-based contact-tracing applications are at the epicenter of the global fight against the Covid-19 pandemic. While governments and healthcare agencies are eager to mandate the deployment of such applications en-masse, they face increasing scrutiny from the popular press, security companies, and human rights watch agencies that fear the exploitation of these technologies as surveillance tools. Finding the optimal balance between community safety and privacy has been a challenge, and strategies to address these concerns have varied among countries. This paper describes two important attacks that affect a broad swath of contact-tracing applications. The first, referred to as contact-isolation attack, is a user-privacy attack that can be used to identify potentially infected patients in your neighborhood. The second is a contact-pollution attack that affects the integrity of contact tracing applications by causing them to produce a high volume of false-positive alerts. We developed prototype implementations and evaluated both attacks in the context of the DP-3T application framework, but these vulnerabilities affect a much broader class of applications. We found that both attacks are feasible and realizable with a minimal attacker work factor. We further conducted an impact assessment of these attacks by using a simulation study and measurements from the SafeGraph database. Our results indicate that attacks launched from a modest number (on the order of 10,000) of monitoring points can effectively decloak between 5-40% of infected users in a major metropolis, such as Houston.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/06/2020

Contact Tracing: An Overview of Technologies and Cyber Risks

The 2020 COVID-19 pandemic has led to a global lockdown with severe heal...
research
08/02/2021

On the Privacy of National Contact Tracing COVID-19 Applications: The Coronavírus-SUS Case

The 2019 Coronavirus disease (COVID-19) pandemic, caused by a quick diss...
research
11/14/2020

SpreadMeNot: A Provably Secure and Privacy-Preserving Contact Tracing Protocol

Contact tracing via mobile applications is gaining significant traction ...
research
08/21/2020

BlindSignedID: Mitigating Denial-of-Service Attacks on Digital Contact Tracing

Due to the recent outbreak of COVID-19, many governments suspended outdo...
research
06/18/2020

SwissCovid: a critical analysis of risk assessment by Swiss authorities

Ahead of the rollout of the SwissCovid contact tracing app, an official ...
research
05/17/2020

A socio-technical framework for digital contact tracing

In their efforts to tackle the COVID-19 crisis, decision makers are cons...
research
09/13/2020

Proximity Tracing in an Ecosystem of Surveillance Capitalism

Proximity tracing apps have been proposed as an aide in dealing with the...

Please sign up or login with your details

Forgot password? Click here to reset