A smartphone can be located in the subway with 92% accuracy – Security researchers can track smartphones in the subway with 92% accuracy through data stolen from the accelerometers of Android smartphones.
A PDF document published by security researchers from the security team originating from Nanjing University in China states that data from motion accelerometers helps them track the target with up to 92% accuracy.
The study is called "We Can Track You If You Take the Metro: Tracking Metro Riders Using Accelerometers on Smartphones" and you can read it here.
Motion sensors are built into modern smartphones. Now, for Android devices, the team says they were able to access accelerator data because these elements don't require special permissions.
By combining the location data from the station and the accelerometer, the researchers were able to determine how the user was moving. They used malware that they had installed on the smartphones of eight volunteers. The malware automatically read and sent the accelerometer data.
They conducted their tests on the subway of a major city in China, and the researchers were able to identify Android users at six stations with up to 92 percent accuracy.
The team explains:
"We believe that if a person with a smartphone containing a malicious app takes the subway, hackers can use the accelerometer to track them. The reason is that subway trains run on rails, which makes their movement much more noticeable than cars or buses moving on regular roads."
It is possible that the movement of a train between two neighboring stations produces (something like) a characteristic fingerprint for a mobile device's accelerometer, a vulnerability that helps attackers track a passenger's movements."
The study says the attack is much more effective and powerful than a GPS or cellular network attack, as trains in the subway disrupt cellular signals and GPS-based applications. It is a well-known phenomenon that we have no signal in the subway.
The team says the vulnerability allows the victim's daily schedule to be recorded. An attacker could read the victim's daily movements through their movements and thus know very personal details, such as when they are at work, when they are at home, or any other activities.
After carefully studying the victim's program, malicious users would be able to predict his movements.
The researchers suggest that such attacks could be disrupted or prevented by introducing noise into the measurements of Android sensors that collect geolocation information.
Additionally, the team says that continuous requests for data collection would require too much power, which would be reflected in battery usage.
Source: iguru

