The Experts below are selected from a list of 1866 Experts worldwide ranked by ideXlab platform
Georg Carle - One of the best experts on this subject based on the ideXlab platform.
-
push away your privacy precise user tracking based on tls Client Certificate authentication
Proceedings of the Applied Networking Research Workshop, 2018Co-Authors: Matthias Wachs, Quirin Scheitle, Georg CarleAbstract:While the Transport Layer Security (TLS) protocol is typically used to authenticate servers, it also offers the possibility to use Client Certificates for to authenticate Clients (CCA). We investigate the use of CCA based on two specific concerns:First, CCA is prone to being used in a context that encodes personal data into Client Certificates, such as identifying persons, e.g. in voting systems or VPN applications.Second, in versions prior to TLS1.3, the Client Certificate (as well as the server Certificate) is being sent in clear text, permitting systematic and large-scale eavesdropping.Based on these two concerns, we investigate the use of CCA at an ISP uplink. Besides confirming our two concerns by finding, e.g., person names in VPN Certificates, we also identify the Apple Push Notification Service (APNs) to leverage TLS CCA to identify Client devices. We consider this use highly critical as APNs is an integral part of all Apple operating systems, and APNs establishes a connection immediately upon connecting the device to a network. We show that these properties can be used by various attacker types to track devices (and hence, likely users) with great precision across the global Internet.This work was published in 2017, with the TLS1.3 standardization still ongoing, and we aimed to emphasize the necessity of encrypting Client Certificates in the TLS handshake, which was adopted in the TLS1.3 standard. Based on work published at TMA'17 [1].[1] Matthias Wachs, Quirin Scheitle, Georg Carle. 2017. Push Away Your Privacy: Precise User Tracking Based on TLS Client Certificate Authentication. In Proceedings of the 2017 Network Traffic Measurement and Analysis Conference (TMA '17)
-
push away your privacy precise user tracking based on tls Client Certificate authentication
Traffic Monitoring and Analysis, 2017Co-Authors: Matthias Wachs, Quirin Scheitle, Georg CarleAbstract:The design and implementation of cryptographic systems offer many subtle pitfalls. One such pitfall is that cryptography may create unique identifiers potentially usable to repeatedly and precisely re-identify and hence track users. This work investigates TLS Client Certificate Authentication (CCA), which currently transmits Certificates in plain text. We demonstrate CCA's impact on Client traceability using Apple's Apple Push Notification service (APNs) as an example. APNs is used by all Apple products, employs plain-text CCA, and aims to be constantly connected to its backend. Its novel combination of large device count, constant connections, device proximity to users and unique Client Certificates provides for precise Client traceability. We show that passive eavesdropping allows to precisely re-identify and track users and that only ten interception points are required to track more than 80 percent of APNs users due to global routing characteristics. We conduct our work under strong ethical guidelines, responsibly disclose our findings, and can confirm a working patch by Apple for the highlighted issue. We aim for this work to provide the necessary factual and quantified evidence about negative implications of plain-text CCA to boost deployment of encrypted CCA as in TLS 1.3.
Matthias Wachs - One of the best experts on this subject based on the ideXlab platform.
-
push away your privacy precise user tracking based on tls Client Certificate authentication
Proceedings of the Applied Networking Research Workshop, 2018Co-Authors: Matthias Wachs, Quirin Scheitle, Georg CarleAbstract:While the Transport Layer Security (TLS) protocol is typically used to authenticate servers, it also offers the possibility to use Client Certificates for to authenticate Clients (CCA). We investigate the use of CCA based on two specific concerns:First, CCA is prone to being used in a context that encodes personal data into Client Certificates, such as identifying persons, e.g. in voting systems or VPN applications.Second, in versions prior to TLS1.3, the Client Certificate (as well as the server Certificate) is being sent in clear text, permitting systematic and large-scale eavesdropping.Based on these two concerns, we investigate the use of CCA at an ISP uplink. Besides confirming our two concerns by finding, e.g., person names in VPN Certificates, we also identify the Apple Push Notification Service (APNs) to leverage TLS CCA to identify Client devices. We consider this use highly critical as APNs is an integral part of all Apple operating systems, and APNs establishes a connection immediately upon connecting the device to a network. We show that these properties can be used by various attacker types to track devices (and hence, likely users) with great precision across the global Internet.This work was published in 2017, with the TLS1.3 standardization still ongoing, and we aimed to emphasize the necessity of encrypting Client Certificates in the TLS handshake, which was adopted in the TLS1.3 standard. Based on work published at TMA'17 [1].[1] Matthias Wachs, Quirin Scheitle, Georg Carle. 2017. Push Away Your Privacy: Precise User Tracking Based on TLS Client Certificate Authentication. In Proceedings of the 2017 Network Traffic Measurement and Analysis Conference (TMA '17)
-
push away your privacy precise user tracking based on tls Client Certificate authentication
Traffic Monitoring and Analysis, 2017Co-Authors: Matthias Wachs, Quirin Scheitle, Georg CarleAbstract:The design and implementation of cryptographic systems offer many subtle pitfalls. One such pitfall is that cryptography may create unique identifiers potentially usable to repeatedly and precisely re-identify and hence track users. This work investigates TLS Client Certificate Authentication (CCA), which currently transmits Certificates in plain text. We demonstrate CCA's impact on Client traceability using Apple's Apple Push Notification service (APNs) as an example. APNs is used by all Apple products, employs plain-text CCA, and aims to be constantly connected to its backend. Its novel combination of large device count, constant connections, device proximity to users and unique Client Certificates provides for precise Client traceability. We show that passive eavesdropping allows to precisely re-identify and track users and that only ten interception points are required to track more than 80 percent of APNs users due to global routing characteristics. We conduct our work under strong ethical guidelines, responsibly disclose our findings, and can confirm a working patch by Apple for the highlighted issue. We aim for this work to provide the necessary factual and quantified evidence about negative implications of plain-text CCA to boost deployment of encrypted CCA as in TLS 1.3.
Quirin Scheitle - One of the best experts on this subject based on the ideXlab platform.
-
push away your privacy precise user tracking based on tls Client Certificate authentication
Proceedings of the Applied Networking Research Workshop, 2018Co-Authors: Matthias Wachs, Quirin Scheitle, Georg CarleAbstract:While the Transport Layer Security (TLS) protocol is typically used to authenticate servers, it also offers the possibility to use Client Certificates for to authenticate Clients (CCA). We investigate the use of CCA based on two specific concerns:First, CCA is prone to being used in a context that encodes personal data into Client Certificates, such as identifying persons, e.g. in voting systems or VPN applications.Second, in versions prior to TLS1.3, the Client Certificate (as well as the server Certificate) is being sent in clear text, permitting systematic and large-scale eavesdropping.Based on these two concerns, we investigate the use of CCA at an ISP uplink. Besides confirming our two concerns by finding, e.g., person names in VPN Certificates, we also identify the Apple Push Notification Service (APNs) to leverage TLS CCA to identify Client devices. We consider this use highly critical as APNs is an integral part of all Apple operating systems, and APNs establishes a connection immediately upon connecting the device to a network. We show that these properties can be used by various attacker types to track devices (and hence, likely users) with great precision across the global Internet.This work was published in 2017, with the TLS1.3 standardization still ongoing, and we aimed to emphasize the necessity of encrypting Client Certificates in the TLS handshake, which was adopted in the TLS1.3 standard. Based on work published at TMA'17 [1].[1] Matthias Wachs, Quirin Scheitle, Georg Carle. 2017. Push Away Your Privacy: Precise User Tracking Based on TLS Client Certificate Authentication. In Proceedings of the 2017 Network Traffic Measurement and Analysis Conference (TMA '17)
-
push away your privacy precise user tracking based on tls Client Certificate authentication
Traffic Monitoring and Analysis, 2017Co-Authors: Matthias Wachs, Quirin Scheitle, Georg CarleAbstract:The design and implementation of cryptographic systems offer many subtle pitfalls. One such pitfall is that cryptography may create unique identifiers potentially usable to repeatedly and precisely re-identify and hence track users. This work investigates TLS Client Certificate Authentication (CCA), which currently transmits Certificates in plain text. We demonstrate CCA's impact on Client traceability using Apple's Apple Push Notification service (APNs) as an example. APNs is used by all Apple products, employs plain-text CCA, and aims to be constantly connected to its backend. Its novel combination of large device count, constant connections, device proximity to users and unique Client Certificates provides for precise Client traceability. We show that passive eavesdropping allows to precisely re-identify and track users and that only ten interception points are required to track more than 80 percent of APNs users due to global routing characteristics. We conduct our work under strong ethical guidelines, responsibly disclose our findings, and can confirm a working patch by Apple for the highlighted issue. We aim for this work to provide the necessary factual and quantified evidence about negative implications of plain-text CCA to boost deployment of encrypted CCA as in TLS 1.3.
Leijon Jon - One of the best experts on this subject based on the ideXlab platform.
-
A mobile gateway for medical auscultation : Enhanced Client Certificate Authentication and MTLS Security
Umeå universitet Institutionen för datavetenskap, 2016Co-Authors: Leijon JonAbstract:Attempting to re-engineer a telemedicine application, this report sets out to make a cheap yet robust solution that is portable and easy to use. It will be a Inera compliant system using Android that authenticates in a secure way with a .NET server behind F5 full proxy.The report begins with a background to telemedicine, and a technical specification that might fulfill the demands of privacy laws regarding health care records. The focus of the report moves on to inspects the choices for authentication. The results consists of formulating a possible solution for authentication by self signed Client Certificate between Android and a Windows server
Jon Leijon - One of the best experts on this subject based on the ideXlab platform.
-
a mobile gateway for medical auscultation enhanced Client Certificate authentication and mtls security
2016Co-Authors: Jon LeijonAbstract:Attempting to re-engineer a telemedicine application, this report sets out to make a cheap yet robust solution that is portable and easy to use. It will be a Inera compliant system using Android ...