On Privacy Risks of Public WiFi Captive Portals

07/03/2019
by   Suzan Ali, et al.
0

Open access WiFi hotspots are widely deployed in many public places, including restaurants, parks, coffee shops, shopping malls, trains, airports, hotels, and libraries. While these hotspots provide an attractive option to stay connected, they may also track user activities and share user/device information with third-parties, through the use of trackers in their captive portal and landing websites. In this paper, we present a comprehensive privacy analysis of 67 unique public WiFi hotspots located in Montreal, Canada, and shed some light on the web tracking and data collection behaviors of these hotspots. Our study reveals the collection of a significant amount of privacy-sensitive personal data through the use of social login (e.g., Facebook and Google) and registration forms, and many instances of tracking activities, sometimes even before the user accepts the hotspot's privacy and terms of service policies. Most hotspots use persistent third-party tracking cookies within their captive portal site; these cookies can be used to follow the user's browsing behavior long after the user leaves the hotspots, e.g., up to 20 years. Additionally, several hotspots explicitly share (sometimes via HTTP) the collected personal and unique device information with many third-party tracking domains.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/17/2021

User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track Users

During the past few years, mostly as a result of the GDPR and the CCPA, ...
research
03/07/2021

Differential Tracking Across Topical Webpages of Indian News Media

Online user privacy and tracking have been extensively studied in recent...
research
02/03/2022

Towards Understanding First-Party Cookie Tracking in the Field

Third-party web tracking is a common, and broadly used technique on the ...
research
08/01/2022

The Hitchhiker's Guide to Facebook Web Tracking with Invisible Pixels and Click IDs

Over the past years, advertisement companies have used a variety of trac...
research
01/04/2022

OConsent – Open Consent Protocol for Privacy and Consent Management with Blockchain

In the current connected world - Websites, Mobile Apps, IoT Devices coll...
research
11/02/2020

There's No Trick, Its Just a Simple Trick: A Web-Compat and Privacy Improving Approach to Third-party Web Storage

While much current web privacy research focuses on browser fingerprintin...
research
07/15/2019

Tracking sex: The implications of widespread sexual data leakage and tracking on porn websites

This paper explores tracking and privacy risks on pornography websites. ...

Please sign up or login with your details

Forgot password? Click here to reset