We present a detailed privacy analysis of Samsung's Offline Finding (OF) protocol, which is part of Samsung's Find My Mobile (FMM) location tracking system for locating Samsung mobile devices, such as Samsung smartphones and Bluetooth trackers (Galaxy SmartTags). The OF protocol uses Bluetooth Low Energy (BLE) to broadcast a unique beacon for a lost device. This beacon is then picked up by nearby Samsung phones or tablets (the {\em finder} devices), which then forward the unique beacon, along with the location it was detected at, to a Samsung managed server. The owner of a lost device can then query the server to locate their device. We examine several security and privacy related properties of the OF protocol and its implementation, from the perspectives of the owner, the finder and the vendor. These include examining: the possibility of identifying the owner of a device through the Bluetooth data obtained from the device, the possibility for a malicious actor to perform unwanted tracking against a person by exploiting the OF network, the possibility for the vendor to de-anonymise location reports to determine the locations of the owners or the finders of lost devices, and the possibility for an attacker to compromise the integrity of the location reports. Our findings suggest that there are privacy risks on all accounts, arising from issues in the design and the implementation of the OF protocol.
翻译:本文对三星离线查找(OF)协议进行了详细的隐私分析,该协议是三星“查找我的手机”(FMM)位置追踪系统的一部分,用于定位三星移动设备,例如三星智能手机和蓝牙追踪器(Galaxy SmartTag)。OF协议使用蓝牙低功耗(BLE)广播丢失设备的唯一信标。该信标随后被附近的三星手机或平板电脑(即“查找者”设备)接收,这些设备将唯一信标及其检测到的位置信息转发至三星管理的服务器。丢失设备的拥有者随后可查询服务器以定位其设备。我们从设备拥有者、查找者和供应商的角度,研究了OF协议及其实现的多项安全和隐私相关特性。这些研究包括:通过从设备获取的蓝牙数据识别设备拥有者的可能性;恶意行为者利用OF网络对个人进行非自愿追踪的可能性;供应商对位置报告进行去匿名化以确定丢失设备的拥有者或查找者位置的可能性;以及攻击者破坏位置报告完整性的可能性。我们的研究结果表明,由于OF协议设计和实现中存在的问题,在上述所有方面均存在隐私风险。
Source: 三星电子