发表机构
Trinity College Dublin(都柏林三一学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究评估了通过短信发送的SUPL_INIT消息对Pixel 8手机隐私的影响,发现手机不会向攻击者控制的服务器泄露位置或身份信息,未发现隐私问题。
AI 中文摘要
SUPL_INIT消息是一种网络发起的触发消息,可通过短信发送到手机,以单方面启动定位会话:收到该消息后,手机被指示确定自身位置,并将位置信息连同IMSI等标识符报告给消息中指定的服务器,而无需手机用户进行任何操作。本次调查的动机是担心此类消息可能被用于将手机的位置和用户身份静默泄露给攻击者控制的服务器。我们在Google Pixel 8手机上进行了调查,该手机使用三星Exynos调制解调器和博通GPS/GNSS子系统。我们未发现隐私问题:手机不会因通过短信传递的未经请求的SUPL_INIT而向攻击者选择的服务器发送位置数据。
英文摘要
A SUPL\_INIT message is a network-initiated trigger that can be sent to a handset using an SMS to unilaterally start a location session: on receipt, the handset is instructed to determine its own position and report it, together with an identifier such as its IMSI, to a server specified in the message, without any action by the phone's user. The concern motivating this investigation is whether such a message could be used to silently exfiltrate a handset's location and subscriber identity to a server under an attacker's control. We investigated this on a Google Pixel 8 handset, which uses a Samsung Exynos modem and a Broadcom GPS/GNSS subsystem. We find no privacy issue: the handset never sends location data to an attacker-chosen server as a result of an unsolicited SUPL\_INIT delivered by SMS.