In January, Skyhook Wireless Inc. announced that Apple would use Skyhook's WiFi Positioning System (WPS) for its popular Map applications. The WPS database contains information on access points throughout the world.
Skyhook itself provides most of the data in the database, with users contributing via direct entries to the database, and requests for localization. ETH Zurich Professor Srdjan Capkun of the Department of Computer Science and his team of researchers analysed the security of Skyhook's positioning system. The team's results demonstrate the vulnerability of Skyhook's and similar public WLAN positioning systems to location spoofing attacks.
Impersonation and elimination
When an Apple iPod or iPhone wants to find its position, it detects its neighbouring access points, and sends this information to Skyhook servers. The servers then return the access point locations to the device. Based on this data, the device computes its location. To attack this localization process, Professor Capkun's team decided to use a dual approach. First, access points from a known remote location were impersonated. Second, signals sent by access points in the vicinity were eliminated by jamming. These actions created the illusion in localized devices that their locations were different from their actual physical locations.
Skyhook's WPS works by requiring a device to report the Media Access Control (MAC) addresses that it detects. However, since MAC addresses can be forged by rogue access points, they can be easily impersonated. Furthermore, access point signals can be jammed and signals from access points in the vicinity of the device can thus be eliminated. These two actions make location spoofing attacks possible. In a test case, one of the devices was misleadingly induced to show its position as being in New York City, whereas the correct position was Zurich (Switzerland).
Professor Capkun explained that by demonstrating these attacks, the team hoped to point out the limitations, despite guarantees, of public WLAN-based localization services as well as of applications for such services. He said "Given the relative simplicity of the performed attacks, it is clear that the use of WLAN-based public localization systems, such as Skyhook's WPS, should be restricted in security and safety-critical applications".
Further InformationETH Zurich
Roman Klingler | idw
Neuron and synapse-mimetic spintronics devices developed
17.04.2019 | Tohoku University
New discovery makes fast-charging, better performing lithium-ion batteries possible
16.04.2019 | Rensselaer Polytechnic Institute
A stellar flare 10 times more powerful than anything seen on our sun has burst from an ultracool star almost the same size as Jupiter
A localization phenomenon boosts the accuracy of solving quantum many-body problems with quantum computers which are otherwise challenging for conventional computers. This brings such digital quantum simulation within reach on quantum devices available today.
Quantum computers promise to solve certain computational problems exponentially faster than any classical machine. “A particularly promising application is the...
The technology could revolutionize how information travels through data centers and artificial intelligence networks
Engineers at the University of California, Berkeley have built a new photonic switch that can control the direction of light passing through optical fibers...
Physicists observe how electron-hole pairs drift apart at ultrafast speed, but still remain strongly bound.
Modern electronics relies on ultrafast charge motion on ever shorter length scales. Physicists from Regensburg and Gothenburg have now succeeded in resolving a...
Engineers create novel optical devices, including a moth eye-inspired omnidirectional microwave antenna
A team of engineers at Tufts University has developed a series of 3D printed metamaterials with unique microwave or optical properties that go beyond what is...
17.04.2019 | Event News
15.04.2019 | Event News
09.04.2019 | Event News
18.04.2019 | Life Sciences
18.04.2019 | Physics and Astronomy
18.04.2019 | Life Sciences