The Experts below are selected from a list of 1866 Experts worldwide ranked by ideXlab platform

Georg Carle - One of the best experts on this subject based on the ideXlab platform.

  • push away your privacy precise user tracking based on tls Client Certificate authentication
    Proceedings of the Applied Networking Research Workshop, 2018
    Co-Authors: Matthias Wachs, Quirin Scheitle, Georg Carle
    Abstract:

    While the Transport Layer Security (TLS) protocol is typically used to authenticate servers, it also offers the possibility to use Client Certificates for to authenticate Clients (CCA). We investigate the use of CCA based on two specific concerns:First, CCA is prone to being used in a context that encodes personal data into Client Certificates, such as identifying persons, e.g. in voting systems or VPN applications.Second, in versions prior to TLS1.3, the Client Certificate (as well as the server Certificate) is being sent in clear text, permitting systematic and large-scale eavesdropping.Based on these two concerns, we investigate the use of CCA at an ISP uplink. Besides confirming our two concerns by finding, e.g., person names in VPN Certificates, we also identify the Apple Push Notification Service (APNs) to leverage TLS CCA to identify Client devices. We consider this use highly critical as APNs is an integral part of all Apple operating systems, and APNs establishes a connection immediately upon connecting the device to a network. We show that these properties can be used by various attacker types to track devices (and hence, likely users) with great precision across the global Internet.This work was published in 2017, with the TLS1.3 standardization still ongoing, and we aimed to emphasize the necessity of encrypting Client Certificates in the TLS handshake, which was adopted in the TLS1.3 standard. Based on work published at TMA'17 [1].[1] Matthias Wachs, Quirin Scheitle, Georg Carle. 2017. Push Away Your Privacy: Precise User Tracking Based on TLS Client Certificate Authentication. In Proceedings of the 2017 Network Traffic Measurement and Analysis Conference (TMA '17)

  • push away your privacy precise user tracking based on tls Client Certificate authentication
    Traffic Monitoring and Analysis, 2017
    Co-Authors: Matthias Wachs, Quirin Scheitle, Georg Carle
    Abstract:

    The design and implementation of cryptographic systems offer many subtle pitfalls. One such pitfall is that cryptography may create unique identifiers potentially usable to repeatedly and precisely re-identify and hence track users. This work investigates TLS Client Certificate Authentication (CCA), which currently transmits Certificates in plain text. We demonstrate CCA's impact on Client traceability using Apple's Apple Push Notification service (APNs) as an example. APNs is used by all Apple products, employs plain-text CCA, and aims to be constantly connected to its backend. Its novel combination of large device count, constant connections, device proximity to users and unique Client Certificates provides for precise Client traceability. We show that passive eavesdropping allows to precisely re-identify and track users and that only ten interception points are required to track more than 80 percent of APNs users due to global routing characteristics. We conduct our work under strong ethical guidelines, responsibly disclose our findings, and can confirm a working patch by Apple for the highlighted issue. We aim for this work to provide the necessary factual and quantified evidence about negative implications of plain-text CCA to boost deployment of encrypted CCA as in TLS 1.3.

Matthias Wachs - One of the best experts on this subject based on the ideXlab platform.

  • push away your privacy precise user tracking based on tls Client Certificate authentication
    Proceedings of the Applied Networking Research Workshop, 2018
    Co-Authors: Matthias Wachs, Quirin Scheitle, Georg Carle
    Abstract:

    While the Transport Layer Security (TLS) protocol is typically used to authenticate servers, it also offers the possibility to use Client Certificates for to authenticate Clients (CCA). We investigate the use of CCA based on two specific concerns:First, CCA is prone to being used in a context that encodes personal data into Client Certificates, such as identifying persons, e.g. in voting systems or VPN applications.Second, in versions prior to TLS1.3, the Client Certificate (as well as the server Certificate) is being sent in clear text, permitting systematic and large-scale eavesdropping.Based on these two concerns, we investigate the use of CCA at an ISP uplink. Besides confirming our two concerns by finding, e.g., person names in VPN Certificates, we also identify the Apple Push Notification Service (APNs) to leverage TLS CCA to identify Client devices. We consider this use highly critical as APNs is an integral part of all Apple operating systems, and APNs establishes a connection immediately upon connecting the device to a network. We show that these properties can be used by various attacker types to track devices (and hence, likely users) with great precision across the global Internet.This work was published in 2017, with the TLS1.3 standardization still ongoing, and we aimed to emphasize the necessity of encrypting Client Certificates in the TLS handshake, which was adopted in the TLS1.3 standard. Based on work published at TMA'17 [1].[1] Matthias Wachs, Quirin Scheitle, Georg Carle. 2017. Push Away Your Privacy: Precise User Tracking Based on TLS Client Certificate Authentication. In Proceedings of the 2017 Network Traffic Measurement and Analysis Conference (TMA '17)

  • push away your privacy precise user tracking based on tls Client Certificate authentication
    Traffic Monitoring and Analysis, 2017
    Co-Authors: Matthias Wachs, Quirin Scheitle, Georg Carle
    Abstract:

    The design and implementation of cryptographic systems offer many subtle pitfalls. One such pitfall is that cryptography may create unique identifiers potentially usable to repeatedly and precisely re-identify and hence track users. This work investigates TLS Client Certificate Authentication (CCA), which currently transmits Certificates in plain text. We demonstrate CCA's impact on Client traceability using Apple's Apple Push Notification service (APNs) as an example. APNs is used by all Apple products, employs plain-text CCA, and aims to be constantly connected to its backend. Its novel combination of large device count, constant connections, device proximity to users and unique Client Certificates provides for precise Client traceability. We show that passive eavesdropping allows to precisely re-identify and track users and that only ten interception points are required to track more than 80 percent of APNs users due to global routing characteristics. We conduct our work under strong ethical guidelines, responsibly disclose our findings, and can confirm a working patch by Apple for the highlighted issue. We aim for this work to provide the necessary factual and quantified evidence about negative implications of plain-text CCA to boost deployment of encrypted CCA as in TLS 1.3.

Quirin Scheitle - One of the best experts on this subject based on the ideXlab platform.

  • push away your privacy precise user tracking based on tls Client Certificate authentication
    Proceedings of the Applied Networking Research Workshop, 2018
    Co-Authors: Matthias Wachs, Quirin Scheitle, Georg Carle
    Abstract:

    While the Transport Layer Security (TLS) protocol is typically used to authenticate servers, it also offers the possibility to use Client Certificates for to authenticate Clients (CCA). We investigate the use of CCA based on two specific concerns:First, CCA is prone to being used in a context that encodes personal data into Client Certificates, such as identifying persons, e.g. in voting systems or VPN applications.Second, in versions prior to TLS1.3, the Client Certificate (as well as the server Certificate) is being sent in clear text, permitting systematic and large-scale eavesdropping.Based on these two concerns, we investigate the use of CCA at an ISP uplink. Besides confirming our two concerns by finding, e.g., person names in VPN Certificates, we also identify the Apple Push Notification Service (APNs) to leverage TLS CCA to identify Client devices. We consider this use highly critical as APNs is an integral part of all Apple operating systems, and APNs establishes a connection immediately upon connecting the device to a network. We show that these properties can be used by various attacker types to track devices (and hence, likely users) with great precision across the global Internet.This work was published in 2017, with the TLS1.3 standardization still ongoing, and we aimed to emphasize the necessity of encrypting Client Certificates in the TLS handshake, which was adopted in the TLS1.3 standard. Based on work published at TMA'17 [1].[1] Matthias Wachs, Quirin Scheitle, Georg Carle. 2017. Push Away Your Privacy: Precise User Tracking Based on TLS Client Certificate Authentication. In Proceedings of the 2017 Network Traffic Measurement and Analysis Conference (TMA '17)

  • push away your privacy precise user tracking based on tls Client Certificate authentication
    Traffic Monitoring and Analysis, 2017
    Co-Authors: Matthias Wachs, Quirin Scheitle, Georg Carle
    Abstract:

    The design and implementation of cryptographic systems offer many subtle pitfalls. One such pitfall is that cryptography may create unique identifiers potentially usable to repeatedly and precisely re-identify and hence track users. This work investigates TLS Client Certificate Authentication (CCA), which currently transmits Certificates in plain text. We demonstrate CCA's impact on Client traceability using Apple's Apple Push Notification service (APNs) as an example. APNs is used by all Apple products, employs plain-text CCA, and aims to be constantly connected to its backend. Its novel combination of large device count, constant connections, device proximity to users and unique Client Certificates provides for precise Client traceability. We show that passive eavesdropping allows to precisely re-identify and track users and that only ten interception points are required to track more than 80 percent of APNs users due to global routing characteristics. We conduct our work under strong ethical guidelines, responsibly disclose our findings, and can confirm a working patch by Apple for the highlighted issue. We aim for this work to provide the necessary factual and quantified evidence about negative implications of plain-text CCA to boost deployment of encrypted CCA as in TLS 1.3.

Leijon Jon - One of the best experts on this subject based on the ideXlab platform.

  • A mobile gateway for medical auscultation : Enhanced Client Certificate Authentication and MTLS Security
    Umeå universitet Institutionen för datavetenskap, 2016
    Co-Authors: Leijon Jon
    Abstract:

      Attempting to re-engineer a telemedicine application, this report sets out to make a cheap yet robust solution that is portable and easy to use. It will be a Inera compliant system using Android that authenticates in a secure way with a .NET server behind F5 full proxy.The report begins with a background to telemedicine, and a technical specification that might fulfill the demands of privacy laws regarding health care records. The focus of the report moves on to inspects the choices for authentication. The results consists of formulating a possible solution for authentication by self signed Client Certificate between Android and a Windows server

Jon Leijon - One of the best experts on this subject based on the ideXlab platform.