Geo-locating Drivers: A Study of Sensitive Data Leakage in Ride-Hailing Services
Qingchuan Zhao, Chaoshun Zuo, Giancarlo Pellegrino, Zhiqiang Lin
摘要
Increasingly, mobile application-based ride-hailing services have become a very popular means of transportation. Due to the handling of business logic, these services also contain a wealth of privacy-sensitive information such as GPS locations, car plates, driver licenses, and payment data. Unlike many of the mobile applications in which there is only one type of users, ride-hailing services face two types of users: riders and drivers. While most of the efforts had focused on the rider's privacy, unfortunately, we notice little has been done to protect drivers. To raise the awareness of the privacy issues with drivers, in this paper we perform the first systematic study of the drivers' sensitive data leakage in ride-hailing services. More specifically, we select 20 popular ride-hailing apps including Uber and Lyft and focus on one particular feature, namely the nearby cars feature. Surprisingly, our experimental results show that largescale data harvesting of drivers is possible for all of the ridehailing services we studied. In particular, attackers can determine with high-precision the driver's privacy-sensitive information including mostly visited address (e.g., home) and daily driving behaviors. Meanwhile, attackers can also infer sensitive information about the business operations and performances of ride-hailing services such as the number of rides, utilization of cars, and presence on the territory. In addition to presenting the attacks, we also shed light on the countermeasures the service providers could take to protect the driver's sensitive information.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android AppsYongliang Chen, Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang 等ICSE 2024 · 被引用 5 次
- Automated Cross-Platform Reverse Engineering of CAN Bus Commands From Mobile AppsHaohuang Wen, Qingchuan Zhao, Qi Alfred Chen, Zhiqiang LinNDSS 2020
- Notice the Imposter! A Study on User Tag Spoofing Attack in Mobile AppsShuai Li, Zhemin Yang, Guangliang Yang, Hange Zhang 等USENIX Security 2023
它引用的顶会 Paper5
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 被引用 123 次
- ORide: A Privacy-Preserving yet Accountable Ride-Hailing ServiceAnh Pham, Italo Dacosta, Guillaume Endignoux, Juan Ramón Troncoso-Pastoriza 等USENIX Security 2017 · 被引用 83 次
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 被引用 59 次
- Automatic Forgery of Cryptographically Consistent Messages to Identify Security Vulnerabilities in Mobile ServicesChaoshun Zuo, Wubing Wang, Zhiqiang Lin, Rui WangNDSS 2016 · 被引用 40 次
相关 Paper
- Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating AppsKarel Dhondt, Victor Le Pochat, Yana Dimova, Wouter Joosen 等USENIX Security 2024 · 被引用 4 次
- RMS: Removing Barriers to Analyze the Availability and Surge Pricing of Ridesharing ServicesHassan Ali Khan, Hassan Iqbal, Muhammad Shahzad, Guoliang JinCHI 2022 · 被引用 4 次
- A Queueing-Theoretic Framework for Vehicle Dispatching in Dynamic Car-HailingPeng Cheng, Jiabao Jin, Lei Chen, Xuemin Lin 等VLDB 2021 · 被引用 18 次
- Privacy in Urban Sensing with Instrumented Fleets, Using Air Pollution Monitoring As A UsecaseIsmi Abidi, Ishan Nangia, Paarijaat Aditya, Rijurekha SenNDSS 2022
- Understanding Worldwide Private Information Collection on AndroidYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniNDSS 2021
