论文标题
我们的指纹不会从我们触摸的应用中淡入:指纹识别Android WebView
Our fingerprints don't fade from the Apps we touch: Fingerprinting the Android WebView
论文作者
论文摘要
大量研究表明,浏览器指纹构成对用户的安全性和隐私有害。但是,对于浏览器指纹对Android Hybrid应用的影响知之甚少 - 在该应用中,将剥离的铬浏览器集成到应用程序中。这些应用程序通过在本机应用程序和Web之间采用双向通信来扩展攻击表面。本文研究了浏览器指纹对这些嵌入式浏览器的影响。为此,我们启动了Android框架,以记录和提取用于指纹的信息。我们研究了20,000多个应用程序,包括Google Play商店中最受欢迎的应用程序。我们体现了诸如Instagram之类的流行应用程序中的安全缺陷和严重信息泄漏。我们的研究表明,混合应用程序中的指纹可能包含特定于帐户和特定于设备的信息,这些信息可以独特地识别多个设备的用户。此外,我们的结果表明,混合应用程序浏览器并不总是遵守标准浏览器特定的隐私政策。
Numerous studies demonstrated that browser fingerprinting is detrimental to users' security and privacy. However, little is known about the effects of browser fingerprinting on Android hybrid apps -- where a stripped-down Chromium browser is integrated into an app. These apps expand the attack surface by employing two-way communication between native apps and the web. This paper studies the impact of browser fingerprinting on these embedded browsers. To this end, we instrument the Android framework to record and extract information leveraged for fingerprinting. We study over 20,000 apps, including the most popular apps from the Google play store. We exemplify security flaws and severe information leaks in popular apps like Instagram. Our study reveals that fingerprints in hybrid apps potentially contain account-specific and device-specific information that identifies users across multiple devices uniquely. Besides, our results show that the hybrid app browser does not always adhere to standard browser-specific privacy policies.