ITE: Twitter survey is presented in NDSS next month

(ITE): Old Twitter posts could reveal a lot about you. More than you think, according to a survey released. Tweets could reveal places you visited, and things you did, even if you didn't mention them.

ITE

Researchers from the Institute of Technology and Research (ITE) in Greece and the University of Illinois found this after they wrote a tool called LPAuditor. The software automatically discovers all tweets data that are available to the public using a service API.

Using the tool, researchers analyzed metadata, hidden information from each tweet to identify user homes, workplaces, and sensitive places they visited. In dozens of cases, they were able to identify the exact identity of the users, even behind the anonymous Twitter accounts.

In the research that is titled Please Forget Where I Was Last Summer: The Privacy Risks of Public Location (Meta) Data, (PDF) researchers report:

Or even if users are cautious and do not reveal anything in the tweets, the site information can be retrieved which can lead to significant loss of personal data.

Before 2015 users simply looking at the of Twitter or the app's website, unknowingly giving away their location and other information. Users were unaware of the data's existence because it only appeared in the raw data collected through the API. Although Twitter has stopped collecting this data since 2015, the information is still publicly available through the API.

So the researchers were able to obtain GPS coordinates and use commonly available geolocation services to map them to an address. Then, they grouped the tweets that corresponded to the same address, creating clusters of tweets and matching the trends, frequency and timing of the user's tweets from specific locations.

Researchers also mapped the user's tweets coordinates in relation to other addresses referenced in Foursquare. This has revealed them from which other sites users could have made the tweets. This created potentially sensitive clusters (PSCs from potentially sensitive clusters) that suggested sensitive sites likely to be visited by users.

They were able to discover all of the above without even looking at the actual content of the tweets. Only by correlating the metadata could they get a clear picture of what the user did. By searching for phrases such as "at home" or "at work", they could confirm that a location was a home or work address.

Similarly, searching for large keyword lists related to medical, religious, and sexual activities or nightlife activities has been able to confirm that a user is in a sensitive location and deals with a specific activity, even though the tweet did not even mention the place nor his behavior.

Researchers were able to infer more about users than their tweets, and they were able to accurately track many anonymous twitter accounts, according to the PDF.

Twitter allows users to delete their tweets or remove their location data. The but is that the data is publicly available, data "hunters" are likely to already have copies of it.

So deleting location data from Twitter data will not stop someone who wants to find you and knows how.
The researchers will present the them on Network and Distributed System Security Symposium (NDSS) next month.

____________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).