IPvSeeYou: Exploiting Leaked Identifiers in IPv6 for Street-Level Geolocation
Erik C. Rye, Robert Beverly
Abstract
We present IPvSeeYou, a privacy attack that permits a remote and unprivileged adversary to physically geolocate many residential IPv6 hosts and networks with street-level precision. The crux of our method involves: 1) remotely discovering wide area (WAN) hardware MAC addresses from home routers; 2) correlating these MAC addresses with their WiFi BSSID counterparts of known location; and 3) extending coverage by associating devices connected to a common penultimate provider router. We first obtain a large corpus of MACs embedded in IPv6 addresses via high-speed network probing. These MAC addresses are effectively leaked up the protocol stack and largely represent WAN interfaces of residential routers, many of which are all-in-one devices that also provide WiFi. We develop a technique to statistically infer the mapping between a router's WAN and WiFi MAC addresses across manufacturers and devices, and mount a large-scale data fusion attack that correlates WAN MACs with WiFi BSSIDs available in wardriving (geolocation) databases. Using these correlations, we geolocate the IPv6 prefixes of 12M routers in the wild across 146 countries and territories. Selected validation confirms a median geolocation error of 39 meters. We then exploit technology and deployment constraints to extend the attack to a larger set of IPv6 residential routers by clustering and associating devices with a common penultimate provider router. While we responsibly disclosed our results to several manufacturers and providers, the ossified ecosystem of deployed residential cable and DSL routers suggests that our attack will remain a privacy threat into the foreseeable future.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9c83efce-1c77-444b-a571-c3e356d62961Cited by top-tier papers5
- IPv6 Hitlists at Scale: Be Careful What You Wish ForErik C. Rye, Dave LevinSIGCOMM 2023 · 38 citations
- Hidden in Plain Sight: Exploring Encrypted Channels in Android AppsSajjad Pourali, Nayanamana Samarasinghe, Mohammad MannanCCS 2022 · 5 citations
- Surveilling the Masses with Wi-Fi-Based Positioning SystemsErik C. Rye, Dave LevinS&P 2024 · 5 citations
- Where Have All the Firewalls Gone? Security Consequences of Residential IPv6 TransitionErik Rye, Dave Levin, Robert BeverlyCCS 2026 · 2 citations
- WILD Attack: Stealthy Undermining of Wi-Fi-Based Geolocation Through Remote Crowdsourced Data InjectionChangjia Zhu, Xiao Han, Parush Gera, Zhuo Lu et al.USENIX Security 2026
Builds on2
Related papers
- Non-cooperative wi-fi localization & its privacy implicationsAli Abedi, Deepak VasishtMobiCom 2022 · 30 citations
- Location Heartbleeding: The Rise of Wi-Fi Spoofing Attack Via Geolocation APIXiao Han, Junjie Xiong, Wenbo Shen, Zhuo Lu et al.CCS 2022 · 7 citations
- Et Tu Alexa? When Commodity WiFi Devices Turn into Adversarial Motion SensorsYanzi Zhu, Zhujun Xiao, Yuxin Chen, Zhijing Li et al.NDSS 2020
- Exploring the Exposure of IPv6 End-Host NetworksHugo Hue, Abhishek Bhaskar, Amanda Hsu, Paul Pearce et al.CCS 2026
- Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi NetworksYuxiang Yang, Xuewei Feng, Qi Li, Kun Sun et al.NDSS 2024
