Nowadays privacy in the connected world is a big user's concern. The ubiquity of mobile devices permits billions of users browse the web at anytime, anywhere. Near Field Communication (NFC) appeared as a seamlessly and simply communication protocol between devices. Commercial services such as Android Pay, and Apple Pay offer contactless payment methods that are spreading in more and more scenarios. However, we take risks while using NFC on Android devices, we can be hacked, and our privacy can be affected. In this paper we study the current vulnerabilities in the NFC-Android ecosystem. We conduct a series of experiments and we expose that with NFC and Android devices are vulnerable to URL/URI spoofing, Bank/social network information hacking, and user's device tracking via fingerprint and geo-location. It is important for the community to understand the problem and come up solution that can tackle these issues and inform the users about privacy awareness and risks on using these contactless services.
翻译:目前,连通世界的隐私是一个很大的用户问题。 移动装置的普遍存在允许数十亿用户随时随地浏览网络。 近地通信( NFC) 是一个无缝且简单的设备间通信协议。 诸如Android Pay 和 Apple Pay 等商业服务提供无接触支付方法,这些方法在越来越多的情景中蔓延。 然而,我们在使用NFC安装安非他明装置时承担风险,我们可能会被黑入,我们的隐私也会受到影响。 在本文中,我们研究了NFC-Android生态系统中目前的脆弱性。 我们进行了一系列的实验,并揭露了NFC和Android装置很容易受到UR/URI poofing、 银行/社会网络信息黑客和用户通过指纹和地理定位跟踪装置的伤害。 重要的是,社区要了解问题,提出解决问题的办法,并告知用户使用这些无接触服务时的隐私意识和风险。