Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Millions of Phones Leaking Information Via Tor
InfoSecurity ^ | 11 October 2019 | Sean Michael Kerner

Posted on 10/14/2019 6:25:36 AM PDT by ShadowAce

There is a privacy threat lurking on perhaps hundreds of millions of devices, that could enable potential attackers to track and profile users, by using information leaked via the Tor network, even if the users never intentionally installed Tor in the first place.

In a session at the SecTor security conference in Toronto, Canada on October 10, researchers Adam Podgorski and Milind Bhargava from Deloitte Canada outlined and demonstrated previously undisclosed research into how they were able to determine that personally identifiable information (PII) is being leaked by millions of mobile users every day over Tor.

The irony of the issue is that Tor is a technology and a network that is intended to help provide and enable anonymity for users. With Tor, traffic travels through a number of different network hops to an eventual exit point in the hope of masking where the traffic originated from. Podgorski said that there are some users that choose to install a Tor browser on their mobile devices, but that’s not the problem. The problem is that Tor is being installed by mobile applications without user knowledge and potentially putting users at risk.

The researchers explained that they set up several Tor exit nodes, just to see what they could find, and the results were surprising. The researchers found that approximately 30% of all Android devices are transmitting data over Tor.

“You’re probably scratching your head now, like we were a couple of months ago, because that doesn’t make any sense,” Podgorski said. “There's no way a third of Android users know what Tor is and are actually using it.”

What the researchers determined is that Tor is being bundled, embedded and installed in other applications and users are not aware of its existence. It was not entirely clear to the researchers why Tor was being bundled with so many applications. Podgorski said that it could be due to a misunderstanding of the technology and how it can be used. Tor was also found on Apple IOS devices, but the numbers were smaller with only approximately 5% of devices sending data.

Tracking Users

In a series of demonstrations, including live dashboards shown by Bhargava, the researchers showed what data they had collected from mobile users that were inadvertently using Tor. The data included GPS coordinates, web addresses, phone numbers, keystrokes and other PII.

“This data can be used to build a robust profile of an individual,” Podgorski said.

Bhargava explained that the exit nodes the researchers set up intentionally attempted to force browsers to not use encrypted versions of websites, forcing the devices to regular HTTP when possible. With data coming to the exit node without encryption, it was possible for the researchers to see the user data. Bhargava noted that for sites that force HTTPS encryption and do not offer any fallback option to regular un-encrypted HTTP, they wouldn’t be able to see the users data.

Also of note, Bhargava admitted that he found his own phone number in the data, which was a surprise to him, as he had not installed Tor on his device. The only applications on his phone were applications installed by the carrier.

There are several things that need to happen to fix the issue. Podgorski said that the first is awareness that there is a problem, which is what the research is intended to highlight for legislators, government and organizations. For users, Podgorski emphasized that good operational security practices need to be employed, by using encryption everywhere.

In Podgorski's view, there is already a legal compliance risk that the mobile application PII data leaks expose.

“We’re pretty sure what we found breaches GDPR on multiple levels,” he said, “but the issue is that governments can’t enforce the law if they’re not aware.”


TOPICS: Computers/Internet
KEYWORDS: phones; pii; tor
Navigation: use the links below to view more comments.
first 1-2021-4041-43 next last
From a comment at the site:
If 30% of all Android phones were regularly connecting with Tor, the number of daily users of Tor in the US would be in the tens of millions. Tor actually reports 380k mean daily users in the US.
Something does not add up here.

1 posted on 10/14/2019 6:25:36 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; Ernest_at_the_Beach; martin_fierro; ...

Tech Ping


2 posted on 10/14/2019 6:26:10 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

The NSA/CIA appreciates your cooperation in this sensitive matter.


3 posted on 10/14/2019 6:30:32 AM PDT by Delta 21 (Be strong & prosper, be weak & die! Stay true.... ~~ Donald J. Trump)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Podgorski said that the first is awareness that there is a problem

I doubt very seriously it is a Problem as he describes, it sounds more like a Feature, intentionally built in to harvest data.


4 posted on 10/14/2019 6:31:18 AM PDT by eyeamok
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Imho Shadow is tip of spear or less


5 posted on 10/14/2019 6:40:18 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

May I have your and the forum’s expertise on a report by local media in my area ??? Local media reported that flat screen TVs have receivers and transmitters ...... any opinions


6 posted on 10/14/2019 6:44:27 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 1 | View Replies]

To: no-to-illegals

Hard to give feedback without seeing the actual story. Do you have a link?


7 posted on 10/14/2019 6:45:44 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce

>>> that could enable potential attackers to track and profile users <<<

... the standard business model for social media and tech firms.


8 posted on 10/14/2019 6:49:44 AM PDT by Oldeconomybuyer (The problem with socialism is that you eventually run out of other people's money.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: eyeamok

Agreed, in fact I suspect Whatsapp as one if the culprits.


9 posted on 10/14/2019 6:49:45 AM PDT by GreatRoad
[ Post Reply | Private Reply | To 4 | View Replies]

To: Delta 21

Our govt developed TOR in the first place. Is it any surprise that it is surreptitiously used against us.


10 posted on 10/14/2019 6:50:09 AM PDT by Lurkina.n.Learnin (If you want a definition of "bullying" just watch the Democrats in the Senate)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

Was a report from WSOC in Charlotte given out on morning newscast but have no link


11 posted on 10/14/2019 6:50:58 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Lurkina.n.Learnin

Patriot Act ??? Perhaps ???


12 posted on 10/14/2019 6:52:28 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 10 | View Replies]

To: no-to-illegals

Vizio privacy settlement:

https://koaa.com/news/2019/02/14/vizio-announces-17-million-settlement-in-class-action-lawsuit/


13 posted on 10/14/2019 6:52:56 AM PDT by Oldeconomybuyer (The problem with socialism is that you eventually run out of other people's money.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce

Newscast mentioned is two or three days old


14 posted on 10/14/2019 6:53:48 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Oldeconomybuyer

The report involved audio and possible video


15 posted on 10/14/2019 6:56:09 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 13 | View Replies]

Mama always said TV was more complex than anyone realized


16 posted on 10/14/2019 6:57:53 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 15 | View Replies]

To: ShadowAce

My apology for hijacking your thread ......


17 posted on 10/14/2019 6:58:55 AM PDT by no-to-illegals ( Liberals, leftists, Rinos, moslems, illegals, lamestream media. All want America to fail and die)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

It seems like a straightforward solution would be to check for connections to known tor nodes.

https://www.dan.me.uk/tornodes


18 posted on 10/14/2019 7:01:21 AM PDT by beef (Caution: Potential Sarcasm - Process Accordingly)
[ Post Reply | Private Reply | To 1 | View Replies]

To: no-to-illegals
Some TVs do have receivers for WiFi as well as signal tuners (A tuner is how it receives a TV signal). Mine has only WiFi--no signal tuner. I watch TV through my Roku device and we occasionally cast a show from a phone.

Don't get one that advertises the ability to Facetime/Portal/Alexa/etc with other people. That definitely has a transmitter that can possibly be controlled externally.

19 posted on 10/14/2019 7:02:02 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 11 | View Replies]

To: no-to-illegals

Only smart TVs.


20 posted on 10/14/2019 7:10:48 AM PDT by E. Pluribus Unum (We cannot spare this man. He fights.)
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-43 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson