Guess Who's Texting You? Evaluating the Security of Smartphone Messaging Applications

نویسندگان

  • Sebastian Schrittwieser
  • Peter Frühwirt
  • Peter Kieseberg
  • Manuel Leithner
  • Martin Mulazzani
  • Markus Huber
  • Edgar R. Weippl
چکیده

In recent months a new generation of mobile messaging and VoIP applications for smartphones was introduced. These services offer free calls and text messages to other subscribers, providing an Internet-based alternative to the traditional communication methods managed by cellular network carriers such as SMS, MMS and voice calls. While user numbers are estimated in the millions, very little attention has so far been paid to the security measures (or lack thereof) implemented by these providers. In this paper we analyze nine popular mobile messaging and VoIP applications and evaluate their security models with a focus on authentication mechanisms. We find that a majority of the examined applications use the user’s phone number as a unique token to identify accounts, which further encumbers the implementation of security barriers. Finally, experimental results show that major security flaws exist in most of the tested applications, allowing attackers to hijack accounts, spoof sender-IDs or enumerate subscribers.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Re-evaluating Smartphone Messaging Application Security

During the last two years mobile messaging and VoIP applications for smartphones have seen a massive surge in popularity, which has also sparked the interest in research related to the security of these applications. Various security researchers and institutions have performed in-depth analyses of specific applications or vulnerabilities. In this paper I will give an overview of the status quo ...

متن کامل

Security and Privacy of Smartphone Messaging Applications1

In recent years mobile messaging and VoIP applications for smartphones have seen a massive surge in popularity, which has also sparked the interest in research related to the security and privacy of these applications. Various security researchers and institutions have performed in-depth analyses of specific applications or vulnerabilities. This paper gives an overview of the status quo in term...

متن کامل

Objective: We assess the driving distraction potential of texting with Google Glass (Glass), a mobile wearable platform capable of receiving and sending short-message-service and other messaging

potential of texting with Google Glass (Glass), a mobile wearable platform capable of receiving and sending short-message-service and other messaging formats. Background: A known roadway danger, texting while driving has been targeted by legislation and widely banned. Supporters of Glass claim the head-mounted wearable computer is designed to deliver information without concurrent distraction. ...

متن کامل

Communicating While Receiving Mechanical Ventilation: Texting With a Smartphone.

Two young adults with severe facial injuries were receiving care in the trauma/surgical intensive care unit at a tertiary care, level I trauma center in the southeastern United States. Both patients were able to communicate by texting on their cellphones to family members, friends, and caregivers in the intensive care unit. Patients who are awake and already have experience texting with a smart...

متن کامل

Studying Security Weaknesses of Android System

As smartphones are generalized, various technologies and services have been introduced and are in wide use. From simply using calling or texting services, Internet banking and transaction system that require sensitive personal information emerged. Google’s Android, one of the representative OS of smartphones, was developed based on an open source, having various weaknesses and exposed to securi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012