Professional Documents
Culture Documents
Gone (Your Privacy) in 32 Bit by Azra Rizal
Gone (Your Privacy) in 32 Bit by Azra Rizal
Gone (Your Privacy) in 32 Bit by Azra Rizal
Agenda
How easy to be trace?
Q&A
To this
S = - log2 Pr(X=x)
Total S = 37.4
Days Population = 365 Population = 6,909,000,000 Population - log Pr(1/365) = 8.51 S = = 6,909,000,000 2 Zip Code log2 Pr(1/6,909,000,000) = 32.68 S = - population = 69,000 5,000 Ethnic Population = S = - log2 Pr(69,000/6,909,000,000) = 16.61 S = - log Pr(1/12.28) = 12.28
2
Personal
Location
Source Transmitted by HTTP, logged by server Transmitted by HTTP, logged by server Inferred in HTTP, logged by server JavaScript AJAX post JavaScript AJAX post
Remarks
HTTP ACCEPT headers Cookies enabled? Screen resolution Timezone Browser plugins, plugin versions and MIME types System fonts
How did we arrived to that number ? S = - log2 Pr(X=x) How did we arrived to that number ? S = -log2 (1/6909000000) = 32.68 bits My postcode is 57000 assuming there is around 100 post code in KL and population of Kuala Lumpur is 6,900,000 so each postcode is assume to be around 69,000 people? S = -log2 (69,000/6909000000) = 16.61 bits My birthday is in December 12 1974 S = -log2 (1/365) = 8.51 bits My Ethnicity is Malay and assuming the world have around 2000 ethnic community S = -log2 (1/5000) = 12.28 bits Combining all there S = 16.61 + 8.51 + 12.28 = 37.4 With just 3 information we can deduce a person Infact there is a study done by Dr Ohm mentioning that you can identify 87% Of people from United States just by 3 information Zipcode, Date of Birth and Gender
IE 9 Tracking Protection
Demo #1
IE 9 Tracking Protection
References
Dr Ohm MIMOS Security Labs IE 9 TechNet Edge