<- Back to the timetable

Talking Behind Your Back

Vasilios Mavroudis, Federico Maggi

This talk will present the outcomes of the first comprehensive security study on the ultrasound tracking ecosystem. This ecosystem remained almost unknown to the general public until recently, when a newly-founded company faced the nemesis of the security community and the regulators (e.g., the Federal Trade Commission) for its controversial tracking techniques. However, there are many more “traditional players” using ultrasound tracking techniques for various purposes, raising a number of levels of security and privacy issues with different security and privacy models. In general, the main advantage of the ultrasound technology compared to already existing solutions is that it does not require any specialized equipment (unlike wifi and bluetooth), while it remains inaudible to humans. For this reason, the technology is already utilized in a number of different real-world applications, such as device pairing, proximity detection, and cross-device tracking. From a technical perspective, ultrasound tracking is based an ecosystem featuring multiple participating entities (e.g., the users, the advertisers, the content providers, the tracking provider). In this talk, we will present the first comprehensive and in-depth security analysis of ultrasound tracking technology and the surrounding ecosystem. More specifically, we will provide visibility within the ecosystem’s walled garden, examine the different facets of the ultrasound technology, explain how it is currently used in the real world, and subsequently evaluate the privacy and security of the technology itself and the existing deployments. Based on our findings, we will then introduce a new class of attacks against ultrasound tracking mechanisms, along with analysis of real-world Android apps featuring ultrasound frameworks. In particular, we will show how an ultrasound cross-device tracking framework can be abused to perform stealthy de-anonymization attacks (e.g., to unmask users who browse the Internet through anonymity networks such as Tor), to inject fake or spoofed audio beacons, and to leak users’ private information. In the mitigation part of our talk, we will outline immediately deployable defenses that empower practitioners, researchers, and everyday users to protect their privacy. In particular, we will release a browser extension and an Android permission module that enable users to selectively suppress frequencies falling within the ultrasonic spectrum. In the last part of our talk, we would like to engage in discussion with the audience regarding the standardization of ultrasound beacons, and share our design of a flexible OS-level API that addresses both the effortless deployment of ultrasound-enabled applications and the existing privacy and security problems.

Download Slides
PDF ZIP JSON
0:00:07 - 0:00:10
0:00:38 - 0:00:43
0:00:43 - 0:00:48
0:00:50 - 0:00:53
0:01:13 - 0:01:25
0:02:06 - 0:02:12
0:02:22 - 0:02:51
0:02:52 - 0:03:01
0:03:07 - 0:03:12
0:03:22 - 0:03:37
0:03:38 - 0:03:41
0:03:41 - 0:03:47
0:03:53 - 0:03:59
0:04:00 - 0:04:09
0:04:23 - 0:04:40
0:05:05 - 0:05:19
0:06:30 - 0:06:43
0:07:02 - 0:07:11
0:07:17 - 0:07:20
0:07:28 - 0:07:38
0:07:48 - 0:08:04
0:08:34 - 0:09:02
0:09:25 - 0:09:34
0:09:43 - 0:10:04
0:10:14 - 0:10:17
0:13:21 - 0:13:46
0:13:47 - 0:14:28
0:14:54 - 0:15:30
0:17:54 - 0:18:04
0:18:11 - 0:18:16
0:18:19 - 0:18:38
0:19:10 - 0:19:23
0:19:26 - 0:19:31
0:19:42 - 0:19:49
0:19:55 - 0:20:04
0:20:10 - 0:20:17
0:20:59 - 0:21:16
0:21:19 - 0:21:38
0:22:54 - 0:23:23
0:23:54 - 0:24:03
0:24:05 - 0:24:45
0:25:16 - 0:25:25
0:25:35 - 0:25:57
0:26:07 - 0:26:38
0:29:05 - 0:29:31
0:29:55 - 0:30:21
0:30:35 - 0:30:55
0:31:44 - 0:32:07
0:33:36 - 0:34:12
0:34:13 - 0:34:45
0:35:14 - 0:35:38
0:35:49 - 0:35:58
0:37:44 - 0:38:03
0:38:03 - 0:38:12
0:48:48 - 0:49:05
0:57:17 - 0:57:19
0:57:32 - 0:57:41
0:58:47 - 0:58:50
0:58:51 - 0:58:56
0:58:56 - 0:59:01