Skip to content

Access to magnetometer and potential security & privacy issues #394

Open
@MTuner

Description

@MTuner

I would like to share potential privacy issues regarding magnetometer sensors, as an addition to the listed in the current Working Draft.

  • Magnetometer measurements can be used to identify running apps or webpages, as the sensor is disturbed by the device's CPU activity [Matyunin et al.]. I am a co-author of this paper.
  • Magnetometer measurements can be used to fingerprint the device [J.Zhang et al., B.Perez et al.].

As we discuss in the paper, the Secure context and Limited sampling frequency do limit the attack vectors, but do not prevent the side channel completely. Therefore, we think it is better to ask a user for a permission (to not grant it by default) and/or further decrease the sampling frequency.

Do you know if there are any plans to release the Magnetometer interface in Chrome or other browsers (without the #enable-generic-sensor-extra-classes flag)?

Metadata

Metadata

Assignees

No one assigned

    Labels

    privacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.security-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions