{"id":13349,"date":"2016-10-28T09:00:24","date_gmt":"2016-10-28T13:00:24","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=13349"},"modified":"2019-11-15T06:52:08","modified_gmt":"2019-11-15T11:52:08","slug":"waze-wars","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/waze-wars\/13349\/","title":{"rendered":"Navigation wars"},"content":{"rendered":"<p>Even people who avoid online services can find their lives affected by them. For example, one morning you might wake up to find your usually quiet local street has become a busy highway. You can blame satellite navigation services for that.<\/p>\n<p>Satnav services optimize routes for their users by considering traffic jams, accidents, and roadwork. Such apps get data from municipal services and also from user reporting.<\/p>\n<p>Perhaps the best known service of this kind is Waze. Acquired by Google in 2013, Waze may serve as a perfect example of how online services can impinge on real life. While making users\u2019 life easier, they can also create safety and privacy problems.<br>\nFor example, in making the route from A to B faster for its users, Waze has brought intense road traffic to previously quiet streets. The app reroutes cars, trucks, and even tourist buses to quiet streets and alleys to minimize users\u2019 traffic delays.<\/p>\n<h3>Humans fight back<\/h3>\n<p>In Maryland, one neighborhood is trying to <a href=\"https:\/\/www.washingtonpost.com\/local\/traffic-weary-homeowners-and-waze-are-at-war-again-guess-whos-winning\/2016\/06\/05\/c466df46-299d-11e6-b989-4e5479715b54_story.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">subvert<\/a> Waze by using its own methods. Attempting to make their quiet alleys and streets less appealing to Waze, locals submit fake road accident reports to the service. Waze discards single road accident reports if the data says the real speed on this segment of the road hasn\u2019t decreased, so to overcome that obstacle, resistance groups combine efforts with their neighbors and submit identical fake notifications, thus fooling the app.<\/p>\n<p>https:\/\/twitter.com\/alexgoldmark\/status\/533368810829791233<\/p>\n<p>Do such tactics work? There are no figures to say one way or the other. <i>Wired<\/i> <a href=\"https:\/\/www.wired.com\/2016\/07\/better-ways-kill-traffic-lying-waze\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">suggests<\/a> more robust measures to ease neighborhood traffic, such as installing speed bumps, replacing simple intersections with roundabouts, narrowing lanes, and more. These methods work, but you can\u2019t deploy them based solely on a goodwill agreement with neighbors.<\/p>\n<h3>Official disapproval<\/h3>\n<p>It is not just local residents who are enraged. The police are as well \u2014 by a feature alerting drivers to police ambushes. Back in 2014, Los Angeles Chief of Police Charlie Beck went as far as writing a <a href=\"http:\/\/documents.latimes.com\/lapd-chief-becks-letter-google\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">letter<\/a> to Google CEO Larry Page after two police officers were shot in New York by a person who had used Waze to track their location.<\/p>\n<p>Another outraged letter to Page came from the head of the New York Police Union, Edward Mullins, who demanded Google remove the police-tracking feature from the app, <a href=\"http:\/\/www.nydailynews.com\/new-york\/nyc-crime\/head-sergeants-union-calls-google-scrap-mobile-app-article-1.2109817\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">threatening<\/a> legal action. Google did not acquiesce: the feature is still there.<\/p>\n<p>The face-off between the police and Waze made other players look closely at the app. Civil rights organizations such as the <a href=\"https:\/\/www.eff.org\/es\/mention\/police-privacy-groups-spar-over-apps-police-locator-too\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Electronic Frontier Foundation<\/a> sided with the service, citing the police\u2019s extensive use of face- and license-plate-recognition technologies and other tools that encroach on people\u2019s right to privacy. The EFF pointed out that law enforcement was asking for privacy that it denies citizens.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The dark side of facial recognition? <a href=\"https:\/\/t.co\/7I6B8MAZuW\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/7I6B8MAZuW<\/a> <a href=\"https:\/\/t.co\/j2O7QkmlF0\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/j2O7QkmlF0<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/767793551426121728?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">August 22, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Another use of Waze is to bypass police checkpoints. To counteract that use, Miami police reportedly <a href=\"http:\/\/www.nbcmiami.com\/news\/local\/Miami-Police-Fight-Back-Against-Waze-App-290290001.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">submitted fake police locations<\/a> to Waze to obscure their actual whereabouts. A spokesperson for the department denied the claim, so, at least officially, the practice is <a href=\"http:\/\/www.cnet.com\/news\/miami-cops-use-tech-to-fool-drivers-into-believing-theyre-not-there\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">not supported<\/a>.<\/p>\n<h3>Managing mistakes<\/h3>\n<p>The nature of Waze has also led to public perception that the service is responsible for some types of incidents. In 2015, for example \u2014 although there have been others \u2014 the service directed an elderly couple in Brazil to a dangerous neighborhood. They were looking for Quintino Bocai\u00fava <em>Avenue<\/em>, in S\u00e3o Francisco; Waze took them to Quintino Bocai\u00fava <em>Street<\/em>, in Caramujo. They were caught in a hail of gunfire and one was shot dead.<\/p>\n<p>To help users stay safe during the 2016 Olympics in Rio, Waze started to show notifications whenever a person entered a criminal neighborhood. (That data came from anonymous criminal activity reports from local citizens.)<\/p>\n<p><a href=\"http:\/\/www.wsj.com\/articles\/google-takes-on-uber-with-new-ride-share-service-1472584235\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Waze\u2019s incipient ride-sharing feature<\/a> may provoke a surge in public criticism as well. Take Uber, which Waze intends to compete with. The media coverage of all Uber incidents (from ordinary road accidents to kidnapping) highlights that when something goes wrong, the driver is blamed.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Renting a car abroad: survival guide \u2013 <a href=\"http:\/\/t.co\/cpWBwubEbx\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/cpWBwubEbx<\/a> <a href=\"http:\/\/t.co\/Pm8QCie0Zp\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/Pm8QCie0Zp<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/604560433631117313?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">May 30, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>A resource called WhoIsDrivingYou.org lists all incidents related to Uber and its rival Lyft. It is owned by Taxicab, Limousine &amp;\u00a0Paratransit Association, an organization representing traditional transportation services in the US.<\/p>\n<p>In contrast with Uber\u2019s approach, Waze\u2019s administrators do not plan to check their drivers for \u201ctrustworthiness.\u201d The selection will be based purely on user ratings.<\/p>\n<h3>Ghost cars<\/h3>\n<p>And finally, we come to our constant concerns: leaks, threats, and vulnerabilities. What is special about Waze, and how could cybercriminals take advantage of it? We\u2019re not talking about server-level hacks \u2014 those are pretty much the same for everyone. But how about \u201cghost\u201d cars in the crowd-sourced navigation tool? Researchers from the Technion \u2013 Israel Institute of Technology <a href=\"http:\/\/arxiv.org\/pdf\/1410.0151v1.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">ran such an experiment<\/a> back in 2014.<\/p>\n<p>The scientists first created bots, which gained Waze\u2019s trust by seeming to drive around the area, and then started to simulate traffic jams, which the system marked as legitimate. The apparent traffic jams caused the service to plan detours to avoid those areas.<\/p>\n<p>Now, the potential evolution: Hackers use nonexistent traffic jams to cause cars to avoid certain routes, thus provoking a total traffic standstill.<\/p>\n<p>Last spring, researchers at the University of California, Santa Barbara and the University of Tsinghua, in Beijing, <a href=\"http:\/\/www.cs.ucsb.edu\/~ravenben\/publications\/pdf\/waze-mobisys16.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">offered<\/a> another method of compromising Waze. The service plots users\u2019 avatars with names and other user profile attributes against the map. By automating requests to show nearby users to Waze\u2019s server, the researchers could track their movements.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/ICYMI?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#ICYMI<\/a> How to stop <a href=\"https:\/\/twitter.com\/hashtag\/iOS?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#iOS<\/a> location tracking <a href=\"https:\/\/t.co\/xaJZkP8udi\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/xaJZkP8udi<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/mobile?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#mobile<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/privacy?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#privacy<\/a> <a href=\"https:\/\/t.co\/vaMnK52KAd\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/vaMnK52KAd<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/767023470467244032?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">August 20, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Waze\u2019s administration was quick to <a href=\"https:\/\/blog.waze.com\/2016\/04\/privacy-and-waze.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">deny<\/a> such privacy threats. Users can enable invisible mode and hide their whereabouts from other drivers, they pointed out. However, the developers nevertheless enhanced their privacy efforts by taking users\u2019 names out of the freely available data pool (although their friends\u2019 names remained visible on the map).<\/p>\n<p>After this update, however, the researchers were still able to reproduce the experiment \u2014 using not names but instead the date on which a profile was created as their baseline for tracking. This date is precise to the second and makes a corresponding user identifiable. Later, the developers <a href=\"http:\/\/fusion.net\/story\/311419\/waze-hack-finally-fixed\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">fixed the issue<\/a>.<\/p>\n<p>As a result of the new ride-sharing feature Waze is testing, rumors once again are surfacing that Google is secretly developing a fully automated taxi service that will use Waze data to pick optimal routes. At present, you can override the driver\u2019s or app\u2019s route suggestions, but with driverless taxis, that might no longer be the case. We hope that before rolling out driverless cabs (if that is indeed the plan), Google will be able to fix the flaws in Waze to ensure a smooth and safe user experience.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Waze navigation service creates problems for locals, police, users, and itself<\/p>\n","protected":false},"author":2049,"featured_media":13350,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1788,1789],"tags":[22,385,1646,43,1862],"class_list":{"0":"post-13349","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"category-technology","9":"tag-google","10":"tag-gps","11":"tag-navigation","12":"tag-privacy","13":"tag-waze"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/waze-wars\/13349\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/waze-wars\/7952\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/waze-wars\/7890\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/waze-wars\/7910\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/waze-wars\/9442\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/waze-wars\/9255\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/waze-wars\/13500\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/waze-wars\/6247\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/waze-wars\/5591\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/waze-wars\/9115\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/waze-wars\/13079\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/waze-wars\/13500\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/waze-wars\/13349\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/waze-wars\/13349\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/privacy\/","name":"privacy"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/13349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2049"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=13349"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/13349\/revisions"}],"predecessor-version":[{"id":30110,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/13349\/revisions\/30110"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/13350"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=13349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=13349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=13349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}