On Security Protocols for Desktop Sharing.
Ulrich Kühn · 2010
Abstract: In this paper we examine security protocols employed in anumber of tools for desktop sharing. These tools allowone user to see and interact with the desktop of another user,i.e. transmitting the contents of one computer’slogical display to another place, including user interaction. In contrast to remote sessions, with desktop sharing, the access to the machine is shared, e.g. for interactive user support or for supporting administrators by experts for certain tasks or application programs. Anumber of these tools use an external communication server as arelay to sidestep problems when both the user and the support agent are behind firewalls. In this paper we identify design flaws in the security protocols employed by anumber of such tools, most notably aproblem which allows the provider of the communication server to compromise the security of the communication. Further, weexamine the certificates of security that some of these tools bear in the light of our findings. Additionally,weanalyse the security requirements for arelayed communication protocol, which seems to be missing so far, and makehigh-levelsuggestions for an instantiation. 1