Ghost trace on the wire? Using key evidence for informed decisions
View / Open Files
Authors
Vasile, DA
Kleppmann, M
Thomas, DR
Beresford, AR
Publication Date
2020Journal Title
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Conference Name
Twenty-seventh International Workshop on Security Protocols
ISSN
0302-9743
ISBN
9783030570422
Publisher
Springer International Publishing
Volume
12287 LNCS
Pages
245-257
Type
Conference Object
This Version
AM
Metadata
Show full item recordCitation
Vasile, D., Kleppmann, M., Thomas, D., & Beresford, A. (2020). Ghost trace on the wire? Using key evidence for informed decisions. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 12287 LNCS 245-257. https://doi.org/10.1007/978-3-030-57043-9_23
Abstract
Modern smartphone messaging apps now use end-to-end encryption to provide authenticity, integrity and confidentiality.
Consequently, the preferred strategy for wiretapping such apps is to insert a ghost user by compromising the platform's public key infrastructure.
The use of warning messages alone is not a good defence against a ghost user attack since users change smartphones, and therefore keys, regularly, leading to a multitude of warning messages which are overwhelmingly false positives.
Consequently, these false positives discourage users from viewing warning messages as evidence of a ghost user attack.
To address this problem, we propose collecting evidence from a variety of sources, including direct communication between smartphones over local networks and CONIKS, to reduce the number of false positives and increase confidence in key validity.
When there is enough confidence to suggest a ghost user attack has taken place, we can then supply the user with evidence to help them make a more informed decision.
Keywords
Clinical Research
Sponsorship
EPSRC (1453426)
Engineering and Physical Sciences Research Council (EP/M020320/1)
Engineering and Physical Sciences Research Council (EP/M508007/1)
Identifiers
External DOI: https://doi.org/10.1007/978-3-030-57043-9_23
This record's URL: https://www.repository.cam.ac.uk/handle/1810/293953
Rights
All rights reserved
Licence:
http://www.rioxx.net/licenses/all-rights-reserved
Statistics
Total file downloads (since January 2020). For more information on metrics see the
IRUS guide.
Recommended or similar items
The current recommendation prototype on the Apollo Repository will be turned off on 03 February 2023. Although the pilot has been fruitful for both parties, the service provider IKVA is focusing on horizon scanning products and so the recommender service can no longer be supported. We recognise the importance of recommender services in supporting research discovery and are evaluating offerings from other service providers. If you would like to offer feedback on this decision please contact us on: support@repository.cam.ac.uk