Basics of Privacy Flashcards

1
Q

Privacy compared to other security goals?

A

§ Privacy often relates to what others actually do with the data
§ Privacy in many cases is something that can hardly be controlled by the individual whose data is to be kept private

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Anonymity on the Internet pro and con?

A
§ Positive aspects
- Avoiding detection, retribution and embarrassment
- Freedom of expression
- Whistle-blowing
§ Negative aspects (Illegal activity)
- Anonymous bribery
- Copyright infringement
- Harassment and financial scams
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Anonymity vs. Privacy

A

§ Privacy
- claim of an entity to determine for themselves when, how, and to what extend information about them is communicated to others
§ Anonymity
- not being identifiable in a set of subjects
§ Privacy != Anonymity
- anonymity is a way to maintain privacy, but not always necessary to achieve privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Anonymous communication: VPN/Proxy

A

§ Idea: use intermediate server to serve as proxy for a user’s actions
§ Problem:
-requires trust in proxy server
- ISP could figure out with timing-collision

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Towards Onion Routing

A

§ Similar to proxy, but use multiple servers
§ Problem: single compromised proxy breaks anonymity
- first proxy knows the recipient, payload, and original sender

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Onion Routing - Circuit Construction

A

§ Establish symmetric keys between the sender and proxy nodes such that
- only the sender and a proxy node knows the key, and
- a proxy node does not know entities other than its neighbours on the path (or circuit)
§ Sender creates layered encryption of message (onion) and sends it to the first node in selected circuit
- sender uses public key of node for each layer
§ Each proxy decrypts one layer of the onion and forwards to the next proxy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

K-Anonymity (Intuitive Idea)

A
  • Privacy means that one can hide within a set of (at least) K - 1 other people with the same quasi-identifiers.

Achieving K-Anonymity
- Reduce the information such that the data collapses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Attacks on K-Anonymity

A

Homogeneity
- One may learn a lot of information about an individual, if there are k people with this information

Background Knowledge
- Background knowledge that might look unsuspicious or not too privacy critical may lead to privacy breaches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

L-Diversity

A

§ There have to be L different, “representative” results for each set of quasi identifiers.
-> homogeneity attacks no longer possible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Attack on L-Diversity

A

Lots of knowledge in a scenario

How well did you know this?
1
Not at all
2
3
4
5
Perfectly