login

Cybercasing the joint: on the privacy implications of geo-tagging

Published 10 August 2010
Gerald Friedland, Robin Sommer
Citations105

TL;DR

It is argued that the security and privacy community needs to shape the further development of geo-location technology for better protecting users from the consequences of using geo-tagged information to mount real-world attacks.

Abstract

This article aims to raise awareness of a rapidly emerging privacy threat that we term cybercasing: using geo-tagged information available online to mount real-world attacks. While users typically realize that sharing locations has some implications for their privacy, we provide evidence that many (i) are unaware of the full scope of the threat they face when doing so, and (ii) often do not even realize when they publish such information. The threat is elevated by recent developments that make systematic search for specific geo-located data and inference from multiple sources easier than ever before. In this paper, we summarize the state of geo-tagging; estimate the amount of geo-information available on several major sites, including YouTube, Twitter, and Craigslist; and examine its programmatic accessibility through public APIs. We then present a set of scenarios demonstrating how easy it is to correlate geotagged data with corresponding publicly-available information for compromising a victim’s privacy. We were, e.g., able to find private addresses of celebrities as well as the origins of otherwise anonymized Craigslist postings. We argue that the security and privacy community needs to shape the further development of geo-location technology for better protecting users from such consequences. 1

Keywords

Social SciencesComputer Science