Boffins propose Pretty Good Phone Privacy to end pretty invasive location data harvesting by telcos
- Reference: 1628640418
- News link: https://www.theregister.co.uk/2021/08/11/phone_location_masking/
- Source link:
"We solve something that had previously been thought impossible – achieving location privacy in mobile networks," said Paul Schmitt, an associate research scholar at the Center for Information Technology Policy (CITP) at Princeton University, told The Register .
In "Pretty Good Phone Privacy,"
[1]PDF
a paper scheduled to be presented on Thursday [2]at the Usenix Security Symposium , Schmitt and Barath Raghavan, assistant professor of computer science at the University of Southern California, describe a way to re-engineer the mobile network software stack so that it doesn't betray the location of mobile network customers.[3]
"It's always been thought that since cell towers need to talk to phones then all users have to accept the status quo in which mobile operators track our every movement and sell the data to data brokers (as [4]has [5]been [6]extensively [7]reported )," said Schmitt. "We show how it's possible to protect users' mobile privacy while at the same time providing normal connectivity, and to do so without changing any of the hardware in mobile networks."
[8]
[9]
In recent years, mobile carriers have been routinely selling and leaking location data, to the detriment of customer privacy. Efforts to alter the status quo have been hampered by an uneven regulatory landscape, the resistance of data brokers that profit from the status quo, and the assumption that cellular network architecture requires knowing where customers are located.
But thanks to evolving networking technology, which has shifted many core cellular functions from hardware to software, it's now possible to redesign mobile networks to limit the availability of location data.
[10]
The SUPI (Subscription Permanent Identifier), the paper explains, is the 5G equivalent of the IMSI (International Mobile Subscriber Identity) used in 4G LTE networks. The SUPI gets encrypted before transmission in 5G networks to create a Subscription Concealed Identifier (SUCI); but when connecting to legacy networks, the SUPI like the IMSI may be exposed.
Schmitt and Raghavan describe a new logical network entity called the Pretty Good Phone Privacy Gateway (PGPPGW), which sits between public internet and the UPF (User Plane Function), the gateway that provides global IP connectivity from the network core.
[11]Latest phones are great at thwarting Wi-Fi tracking. Other devices, not so much – study
[12]ICO survey on data flouters: 50% say they receive more unwanted calls than before pandemic
[13]Amnesty International and French media protection org claim massive misuse of NSO spyware
[14]Apple is about to start scanning iPhone users' devices for banned content, warns professor
The purpose of Pretty Good Phone Privacy (PGPP) is to avoid using a unique identifier for authenticating customers and granting access to the network. It's a technology that allows a Mobile Virtual Network Operator (MVNO) to issue SIM cards with identical SUPIs for every subscriber because the SUPI is only used to assess the validity of the SIM card. The PGPP network can then assign an IP address and a GUTI (Globally Unique Temporary Identifier) that can change in subsequent sessions, without telling the MVNO where the customer is located.
"We decouple network connectivity from authentication and billing, which allows the carrier to run Next Generation Core (NGC) services that are unaware of the identity or location of their users but while still authenticating them for network use," the paper explains. "Our architectural change allows us to nullify the value of the user’s SUPI, an often targeted identifier in the cellular ecosystem, as a unique identifier."
Not illegal, inventors claim
PGPP is not intended as a defense against law enforcement or intelligence agencies, though the researchers believe it would limit bulk surveillance of mobile customers. It's primary focus is defending against the surreptitious sale of location data by network providers.
"Our aim is to improve privacy in line with prior societal norms and user expectations, and to present an approach in which privacy enhanced service can be seamlessly deployed," the paper says.
The technology may improve the privacy of cellular network architecture but it leaves adjacent privacy issues unresolved. It does nothing to prevent apps from gathering location data, it doesn't provide voice or text privacy, and it doesn't address the tracking of hardware identifiers like IMEI.
[15]
The paper argues that PGPP is legal because while [16]CALEA (Communications Assistance for Law Enforcement Act) requires that communication providers offer lawful interception of voice and SMS traffic, a PGPP-based carrier would be data-only, with third-party voice and messaging services, and CALEA compliance would be handled by providing access to communication data in the form of raw (and probably encrypted) network traffic via the UPF gateway.
But just because it's legal doesn't mean that MVNOs will rush to disavow data sales revenue and to implement technology that puts their customers' interests above their own.
More realistically, Schmitt argues PGPP will help mobile operators comply with current and emerging data privacy regulations in US states like California, Colorado, and Virginia, and post-GDPR rules in Europe. ®
Get our [17]Tech Resources
[1] https://www.cs.princeton.edu/~pschmitt/docs/pgpp.pdf
[2] https://www.usenix.org/conference/usenixsecurity21/presentation/schmitt
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRNLdjmrCAp64oWaTBaqogAAAAQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2020/12/03/aclu_phone_location/
[5] https://www.theregister.com/2021/02/03/location_tracking_report_xmode_sdk/
[6] https://www.theregister.com/2018/08/21/sueball_flies_at_google_over_is_it_off_location_data_slurping/
[7] https://www.theregister.com/2020/08/05/nsa_location_data_guide/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRNLdjmrCAp64oWaTBaqogAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRNLdjmrCAp64oWaTBaqogAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRNLdjmrCAp64oWaTBaqogAAAAQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2021/05/18/wifi_tracking_failures/
[12] https://www.theregister.com/2021/07/08/ico_data_protection_survey/
[13] https://www.theregister.com/2021/07/19/mass_misuse_of_nso_pegasus_spyware_alleged/
[14] https://www.theregister.com/2021/08/05/apple_csam_scanning/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRNLdjmrCAp64oWaTBaqogAAAAQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.fcc.gov/public-safety-and-homeland-security/policy-and-licensing-division/general/communications-assistance
[17] https://whitepapers.theregister.com/
Unless I'm wrong...
This won't work. A cellphone needs to connect to something in order to communicate. Whatever it connectes to will then have a ping time. The source location is known, the signal strength is known, so a ping time gives a rough radius of how far the phone is from said source. The moment the phone tries to handshake with a second source, that tells you the direction in which the phone is headed, plus it pinpoints almost exactly where the intersection of those two signals would be to have a device of X ping encounter said second source. GPS or not, you have just coughed up your physical location to anyone/everyone with the resources to read the logs. The more signals you connect to, the more accurate the location fix as there can only be a very limited number of places where all those signals come together. Get ping times from more than one source & it only narrows down the possible locations even further.
It doesn't matter if you encrypt your phone traffic, the act of connecting to a signal source (cell, wifi, bluetooth, whatever) means the signal source can ping you, which gives them a rough estimate of where you could be, and the moment your device handshakes to another source to continue the transmission, you've just had the possible locations reduced to the point where boots on the ground would spot you.
I like the idea of encrypting the cell communications, but that by itself won't be enough to stop you from being able to be pinpointed on a map. Perhaps not in realtime, but near enough to it to make a ThreeLetterAgency agent able to scoop you up out of a crowd...
Great work going nowhere
" But just because it's legal doesn't mean that MVNOs will rush to disavow data sales revenue and to implement technology that puts their customers' interests above their own."
Without legislation, this is just an academic paper. Great work and a novel solution that, unfortunately, no companies, be they MVNOs or their data customers, is asking for.
It's time for governments to act in the interest of their constituents instead of their contributors. I'm not holding my breath.