Can Authoritative Governments Abuse the Right to Access?

03/03/2022
by   Cédric Lauradoux, et al.
0

The right to access is a great tool provided by the GDPR to empower data subjects with their data. However, it needs to be implemented properly otherwise it could turn subject access requests against the subjects privacy. Indeed, recent works have shown that it is possible to abuse the right to access using impersonation attacks. We propose to extend those impersonation attacks by considering that the adversary has an access to governmental resources. In this case, the adversary can forge official documents or exploit copy of them. Our attack affects more people than one may expect. To defeat the attacks from this kind of adversary, several solutions are available like multi-factors or proof of aliveness. Our attacks highlight the need for strong procedures to authenticate subject access requests.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/12/2021

Amplifying Privacy: Scaling Up Transparency Research Through Delegated Access Requests

In recent years, numerous studies have used 'data subject access request...
research
01/14/2021

How to Attack and Defend 5G Radio Access Network Slicing with Reinforcement Learning

Reinforcement learning (RL) for network slicing is considered in the 5G ...
research
01/21/2021

Adversarial Machine Learning for Flooding Attacks on 5G Radio Access Network Slicing

Network slicing manages network resources as virtual resource blocks (RB...
research
11/10/2019

Minimalistic Attacks: How Little it Takes to Fool a Deep Reinforcement Learning Policy

Recent studies have revealed that neural network-based policies can be e...
research
05/05/2023

Streamlining personal data access requests: From obstructive procedures to automated web workflows

Transparency and data portability are two core principles of modern priv...
research
10/09/2021

A Multiple Snapshot Attack on Deniable Storage Systems

While disk encryption is suitable for use in most situations where confi...
research
02/07/2023

A Review of existing GDPR Solutions for Citizens and SMEs

The GDPR grants data subjects certain rights, like the right to access t...

Please sign up or login with your details

Forgot password? Click here to reset