Poster: Privacy Implications of BSSID based Location Services

Muhammad Naveed,Xiaofeng Wang,Carl A. Gunter
2013-01-01
Abstract:In this work we show the threats to location privacy of an Android user from popular wireless Basic Service Set Identifier (BSSID) based location services. Our approach uses a combination of techniques an attacker can use to infer the location of a user. Firstly, we describe how an Android app (even with zero permissions) can stealthily steal the BSSIDs from a phone. Secondly, we were able to reverse-engineer the mobile-app to server protocol interaction of a popular BSSID based location service, allowing the attacker to get the location of any chosen BSSID. We make this BSSID to location lookup software available at [1]. We have a demo [3], which shows a malicious app (with zero permissions) stealing the BSSID of the wireless network and transmitting the same to the attacker, allowing the attacker to accurately locate the location of the user. Using our technique attacker can easily steal complete database of the BSSID to geolocation mappings.
What problem does this paper attempt to address?