HTTPS is not enough: boffins fingerprint user environments without cracking crypto

  • 17 March 2016
  • 1 reply
  • 116 views

Userlevel 7
Badge +54

Comms patterns ID OS, browser and application

 
                                      


  17 Mar 2016 at 07:56, Richard Chirgwin Encryption might hide important content from prying eyes, but a group of Israeli researchers has found that HTTPS traffic alone can fingerprint a user's operating system, browser, and application.
 
With a big enough learning set, they write, they were able to identify users' environments with 96.06 per cent accuracy.
 
In their paper at Arxiv, the group – from Ariel University and the Ben-Gurion University of the Negev – show that the characteristics of communication traffic (timing, flows in both directions, variations in packet size and the like) are distinctive enough to create the fingerprint.
 
Full Article

1 reply

Userlevel 7
This being said what is the answer than??? Privacy is a important issue and this needs to be addressed.

Reply