Live data from Hacker News

Ultrasound Tracking Could Be Used to Deanonymize Tor Users

bleepingcomputer.com

41–50 of 67 posts

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#41

TorBrowser has Javascript disabled by default, doesn't that mean you have to first 'trick' targets into visiting the webpage, and then trick them into turning on js?

TorBrowser has JS on by default I thought.

No. That would be reckless and would compromise Tor Browser Bundle from the outset. By default, the NoScript plugin disallows JS from running globally

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#42
If you're interested in trying a little data passing in ultrasonic in your browser, try my creation https://quiet.github.io/quiet-js/

This generally doesn't work in mobile, though, or at least reception doean't. Also, neither desktop nor mobile Safari can do mic access, and firefox's mic won't pick up ultrasonic. So try desktop Chrome :)

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#43
post #3

Wait what? How can a webpage play a sound if my speakers are muted? How do they bypass the little sound notification on my tabs? >If the Tor user has his phone somewhere nearby and if certain types of apps are on his phone, then his mobile device will ping back one or more advertisers with details about his device, so the advertiser can build an advertising profile on the user, linking his computer with his phone. Th…

Are you sure? I would guess that a huge amount of perfectly mainstream and popular apps have a ton of advertising SDKs bundled with them, and you never know what the fuck those SDKs are going to be doing half the time.

Not even just mainstream and popular apps, but also pre-installed and unremovable apps.

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#44
For those looking for an app which uses this technique (so called data-over-audio technology) look no further than Chirp

https://www.chirp.io/

    Enhance your products by integrating with Chirp™
    - the world’s most trusted data-over-audio technology
    used by the leading brands in more than 90 countries

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#46
post #3

Wait what? How can a webpage play a sound if my speakers are muted? How do they bypass the little sound notification on my tabs? >If the Tor user has his phone somewhere nearby and if certain types of apps are on his phone, then his mobile device will ping back one or more advertisers with details about his device, so the advertiser can build an advertising profile on the user, linking his computer with his phone. Th…

It's also pretty exceptional to think that there are apps constantly listening for ultrasonic cues, even when not being actively used. This would be a huge battery drain, so I can't imagine any manufacturer bundling such a thing with a device.

Even if it was the case, I can't imagine such apps would give granular enough information to be enormously useful. You'd get one, maybe two people to actually get their computers to play the audio and have it picked up by a device that's actually listening for it. What then? How many advertising companies with legitimate marketing businesses actually sell the user identities? You'd get what, a UUID, maybe some aggregate demographic information, and a rough location. It seems unlikely that such a platform would actually give out specific PII for individuals.

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#47
post #41

Earlier quoted context omitted.

TorBrowser has JS on by default I thought.

No. That would be reckless and would compromise Tor Browser Bundle from the outset. By default, the NoScript plugin disallows JS from running globally

NoScript is not enabled by default in Tor Browser (in tails).

from: https://tails.boum.org/doc/anonymous_internet/Tor_Browser/#i...

To allow more control over JavaScript, for example to disable JavaScript completely on some websites, Tor Browser includes the NoScript extension.

By default, NoScript is disabled and some JavaScript is allowed by the Torbutton extension as explained above.

So, "Yes", this is reckless and would compromise Tor Browser from the outset.

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#48
post #3

Wait what? How can a webpage play a sound if my speakers are muted? How do they bypass the little sound notification on my tabs? >If the Tor user has his phone somewhere nearby and if certain types of apps are on his phone, then his mobile device will ping back one or more advertisers with details about his device, so the advertiser can build an advertising profile on the user, linking his computer with his phone. Th…

It's also pretty exceptional to think that there are apps constantly listening for ultrasonic cues, even when not being actively used. This would be a huge battery drain, so I can't imagine any manufacturer bundling such a thing with a device. Even if it was the case, I can't imagine such apps would give granular enough information to be enormously useful. You'd get one, maybe two people to actually get their compute…

> It's also pretty exceptional to think that there are apps constantly listening for ultrasonic cues, even when not being actively used.

It would not need to be constantly listening for it to be useful. If the point is identification, why would you leave it on after you have reasonably identified the person?

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#49
post #40

Earlier quoted context omitted.

> How can a webpage play a sound if my speakers are muted? Well it can't obviously, but lots of people (although maybe not the types of people who use tor) browse the internet with their speakers on and active. Most people don't unmute their speakers just before they're about to listen to something. > How do they bypass the little sound notification on my tabs? Admittedly they probably can't, but are you sure you're…

FWIW, there was a BBC article about always-on audio detector apps. Describing an Android proof-of-concept app: "The battery drain during our experiments was minimal and, using wi-fi, there was no data plan spike." http://www.bbc.com/news/technology-35639549

They don't give much information on what "minimal" battery drain means. I'm skeptical. Keeping an app running in the background and keeping a stream of audio data piped into it to be processed on the CPU is not cheap. Google has a dedicated DSP on phones to do hotword detection (among other things), and IIRC that's not exposed to unprivileged apps. Hell, even iOS needs to be charging to get "hey siri" support (not sure about now; it was like this in previous versions, though).

Either way, it doesn't sound like that's what the article describes: they're talking about collecting and sending all audio wholesale. Sending that much audio data over 3g or LTE would be expensive (transcoding it to decrease payload would be expensive, too), and would surely be noticeable looking at data usage charts.

> using wi-fi, there was no data plan spike

Uh, yeah. Because it's using wifi. Phones are on wifi far less often than you'd imagine.

It's certainly possible, but it's just not plausible.

Re: Ultrasound Tracking Could Be Used to Deanonymize Tor Users

#50

Earlier quoted context omitted.

It's also pretty exceptional to think that there are apps constantly listening for ultrasonic cues, even when not being actively used. This would be a huge battery drain, so I can't imagine any manufacturer bundling such a thing with a device. Even if it was the case, I can't imagine such apps would give granular enough information to be enormously useful. You'd get one, maybe two people to actually get their compute…

> It's also pretty exceptional to think that there are apps constantly listening for ultrasonic cues, even when not being actively used. It would not need to be constantly listening for it to be useful. If the point is identification, why would you leave it on after you have reasonably identified the person?

I mean, we're under the assumption here that the app that's listening isn't owned by the attacker. If it was, you already know the person's identity (and location, and probably a lot more) because you control the app on their device. It would be a lot of work to target and infect someone's phone with malware just so you could confirm that they did in fact visit a page on Tor. Probably the same amount of work to just infect their computer with malware and take a screenshot.

If we assume it's a third-party ad network, which is the only plausible explanation for why there's an app listening for ultrasonic cues on a user's device, it would need to be listening all the time. That is what the article describes.

Post reply on HN