The Same-Origin Attack against Location Privacy
George Theodorakopoulos · 2015
A plethora of applications benefit from location context, but a person's whereabouts can be linked to her personal sensitive information. Hence, protection mechanisms have been proposed that add systematic noise to a user's location before sending it out of the user's device. We describe the same-origin attack, to which a group of such mechanisms are vulnerable, we evaluate it against two mechanisms (spatial cloaking and geo-indistinguishability), and we propose our own mechanism, inspired by the maximum entropy principle. We find that spatial cloaking is much worse than the other two, and the maximum-entropy mechanism performs slightly better than geo-indistinguishability. Designing an optimal mechanism remains an open problem.