Positioning system used by iPhone and iPod breached

In January, Skyhook Wireless Inc. announced that Apple would use Skyhook's WiFi Positioning System (WPS) for its popular Map applications. The WPS database contains information on access points throughout the world.

Skyhook itself provides most of the data in the database, with users contributing via direct entries to the database, and requests for localization. ETH Zurich Professor Srdjan Capkun of the Department of Computer Science and his team of researchers analysed the security of Skyhook's positioning system. The team's results demonstrate the vulnerability of Skyhook's and similar public WLAN positioning systems to location spoofing attacks.

Impersonation and elimination

When an Apple iPod or iPhone wants to find its position, it detects its neighbouring access points, and sends this information to Skyhook servers. The servers then return the access point locations to the device. Based on this data, the device computes its location. To attack this localization process, Professor Capkun's team decided to use a dual approach. First, access points from a known remote location were impersonated. Second, signals sent by access points in the vicinity were eliminated by jamming. These actions created the illusion in localized devices that their locations were different from their actual physical locations.

Simple falsification

Skyhook's WPS works by requiring a device to report the Media Access Control (MAC) addresses that it detects. However, since MAC addresses can be forged by rogue access points, they can be easily impersonated. Furthermore, access point signals can be jammed and signals from access points in the vicinity of the device can thus be eliminated. These two actions make location spoofing attacks possible. In a test case, one of the devices was misleadingly induced to show its position as being in New York City, whereas the correct position was Zurich (Switzerland).

Compromised usage

Professor Capkun explained that by demonstrating these attacks, the team hoped to point out the limitations, despite guarantees, of public WLAN-based localization services as well as of applications for such services. He said “Given the relative simplicity of the performed attacks, it is clear that the use of WLAN-based public localization systems, such as Skyhook's WPS, should be restricted in security and safety-critical applications”.

Further Information

ETH Zurich
Professor Srdjan Capkun
Department of Computer Science
Telephone: +41 (0)44 632 71 90
Email: srdjan.capkun@inf.ethz.ch

All latest news from the category: Power and Electrical Engineering

This topic covers issues related to energy generation, conversion, transportation and consumption and how the industry is addressing the challenge of energy efficiency in general.

innovations-report provides in-depth and informative reports and articles on subjects ranging from wind energy, fuel cell technology, solar energy, geothermal energy, petroleum, gas, nuclear engineering, alternative energy and energy efficiency to fusion, hydrogen and superconductor technologies.

Back to home

Comments (0)

Write a comment

Newest articles

Trotting robots reveal emergence of animal gait transitions

A four-legged robot trained with machine learning by EPFL researchers has learned to avoid falls by spontaneously switching between walking, trotting, and pronking – a milestone for roboticists as well…

Innovation promises to prevent power pole-top fires

Engineers in Australia have found a new way to make power-pole insulators resistant to fire and electrical sparking, promising to prevent dangerous pole-top fires and reduce blackouts. Pole-top fires pose…

Possible alternative to antibiotics produced by bacteria

Antibacterial substance from staphylococci discovered with new mechanism of action against natural competitors. Many bacteria produce substances to gain an advantage over competitors in their highly competitive natural environment. Researchers…

Partners & Sponsors