Tracking Users on Waze

A security researcher discovered a wulnerability in Waze that breaks the anonymity of users:

I found out that I can visit Waze from any web browser at waze.com/livemap so I decided to check how are those driver icons implemented. What I found is that I can ask Waze API for data on a location by sending my latitude and longitude coordinates. Except the essential traffic information, Waze also sends me coordinates of other drivers who are nearby. What caught my eyes was that identification numbers (ID) associated with the icons were not changing over time. I decided to track one driver and after some time she really appeared in a different place on the same road…

Continue reading Tracking Users on Waze

Tor Project tests new tool for foiling de-anonymization attacks

Upcoming hardened releases of the Tor Browser will use a new technique aimed at preventing de-anonymization efforts by anyone who might want to mount them. Created by a group of researchers from the University of California, Irvine, and dubbed “selfrando,” the technique allows for enhanced and practical load-time randomization. Selfrando is significantly more effective than standard address space layout randomization (ASLR) techniques currently used by Firefox and other mainstream browsers, the researchers say. The technique … More Continue reading Tor Project tests new tool for foiling de-anonymization attacks