A Run a Day Won't Keep the Hacker Away: Inference Attacks on Endpoint Privacy Zones in Fitness Tracking Social Networks
Karel Dhondt, Victor Le Pochat, Alexios Voulimeneas, Wouter Joosen, Stijn Volckaert
Abstract
Fitness tracking social networks such as Strava allow users to record sports activities and share them publicly. Sharing encourages peer interaction but also constitutes a risk, because an activity's start or finish may inadvertently reveal privacy-sensitive locations such as a home or workplace. To mitigate this risk, networks introduced endpoint privacy zones (EPZs), which hide track portions around protected locations. In this paper, we show that EPZ implementations of major services remain vulnerable to inference attacks that significantly reduce the effective anonymity provided by the EPZ, and even reveal the protected location. Our attack leverages distance information leaked in activity metadata, street grid data, and the locations of the entry points into the EPZ. This yields a constrained search space where we use regression analysis to predict protected locations. Our evaluation on 1.4 million Strava activities shows that our attack discovers the protected location for up to 85% of EPZs. Larger EPZs reduce the performance of our attack, while geographically dispersed activities in sparser street grids yield better performance. We propose six countermeasures, that, however, come with a usability trade-off, and responsibly disclosed our findings and countermeasures to the major networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Communicating the Privacy-Utility Trade-off: Supporting Informed Data Donation with Privacy Decision Interfaces for Differential PrivacyDaniel Franzen, Claudia Müller-Birn, Odette WegwarthCSCW 2024 · 11 citations
- Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating AppsKarel Dhondt, Victor Le Pochat, Yana Dimova, Wouter Joosen et al.USENIX Security 2024 · 4 citations
Builds on4
- Understanding Fitness Tracker Users' Security and Privacy Knowledge, Attitudes and BehavioursSandra Gabriele, Sonia ChiassonCHI 2020 · 61 citations
- Analysis of Privacy Protections in Fitness Tracking Social Networks -or- You can run, but can you hide?Wajih Ul Hassan, Saad Hussain, Adam BatesUSENIX Security 2018 · 40 citations
- Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking AppsJaron Mink, Amanda Rose Yuile, Uma Pal, Adam J. Aviv et al.CHI 2022 · 11 citations
- The Tools and Tactics Used in Intimate Partner Surveillance: An Analysis of Online Infidelity ForumsEmily Tseng, Rosanna Bellini, Nora McDonald, Matan Danos et al.USENIX Security 2020
Related papers
- From Options to Action: Evaluating Adoption of Privacy Features in Fitness - Tracking PlatformsPantelina Ioannou, Angeliki Aktypi, Elias AthanasopoulosCHI 2026 · 1 citation
- You Are Who You Know and How You Behave: Attribute Inference Attacks via Users' Social Friends and BehaviorsNeil Zhenqiang Gong, Bin LiuUSENIX Security 2016 · 156 citations
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 119 citations
- Synthesizing Plausible Privacy-Preserving Location TracesVincent Bindschaedler, Reza ShokriS&P 2016 · 193 citations
- Please Forget Where I Was Last Summer: The Privacy Risks of Public Location (Meta)DataKostas Drakonakis, Panagiotis Ilia, Sotiris Ioannidis, Jason PolakisNDSS 2019 · 37 citations
