<div class="csl-bib-body">
<div class="csl-entry">Tagliaro, C., Hahn, F., Sepe, R., Aceti, A., & Lindorfer, M. (2023). I Still Know What You Watched Last Sunday: Privacy of the HbbTV Protocol in the European Smart TV Landscape. In <i>Proceedings Network and Distributed System Security (NDSS) Symposium 2023</i>. 30th Annual Network and Distributed System Security Symposium (NDSS) 2023, San Diego, United States of America (the). https://doi.org/10.14722/ndss.2023.24102</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/194425
-
dc.description.abstract
The ever-increasing popularity of Smart TVs and support for the Hybrid Broadcast Broadband TV (HbbTV) standard allow broadcasters to enrich content offered to users via the standard broadcast signal with Internet-delivered apps, e.g., ranging from quizzes during a TV show to targeted advertisement. HbbTV works using standard web technologies as transparent overlays over a TV channel. Despite the number of HbbTV-enabled devices rapidly growing, studies on the protocol’s security and privacy aspects are scarce, and no standard protective measure is in place.
We fill this gap by investigating the current state of HbbTV in the European landscape and assessing its implications for users’ privacy. We shift the focus from the Smart TV’s firmware and app security, already studied in-depth in related work, to the content transmission protocol itself. Contrary to traditional “linear TV” signals, HbbTV allows for bi-directional communication: in addition to receiving TV content, it also allows for transmitting data back to the broadcaster. We describe techniques broadcasters use to measure users’ (viewing) preferences and show how the protocol’s implementation can cause severe privacy risks by studying its deployment by 36 TV channels in five European countries (Italy, Germany, France, Austria, and Finland). We also survey users’ awareness of Smart TV and HbbTV-related risks. Our results show little understanding of the possible threats users are exposed to. Finally, we present a denylist-based mechanism to ensure a safe experience for users when watching TV and to reduce the privacy issues that HbbTV may pose.
en
dc.description.sponsorship
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds
-
dc.description.sponsorship
SBA Research gemeinnützige GmbH
-
dc.language.iso
en
-
dc.subject
Smart TV
en
dc.subject
HbbTV
en
dc.subject
Security and Privacy
en
dc.title
I Still Know What You Watched Last Sunday: Privacy of the HbbTV Protocol in the European Smart TV Landscape
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
University of Twente, Netherlands (the)
-
dc.contributor.affiliation
Guess Europe Sagl, Italy
-
dc.contributor.affiliation
Sababa Security SpA, Italy
-
dc.relation.isbn
1-891562-83-5
-
dc.relation.grantno
ICT19-056
-
dc.relation.grantno
COMET SBA-K1
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
Proceedings Network and Distributed System Security (NDSS) Symposium 2023
-
tuw.project.title
IoTIO: Analyse des Internet der Unsicheren Dinge
-
tuw.project.title
Sicherheits- und Datenschutzgrundlagen von Blockchain-Technologien
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
100
-
tuw.linking
https://github.com/SecPriv/hbbtv-blocker
-
tuw.publication.orgunit
E192-06 - Forschungsbereich Security and Privacy
-
tuw.publisher.doi
10.14722/ndss.2023.24102
-
dc.description.numberOfPages
17
-
tuw.author.orcid
0000-0001-7001-4481
-
tuw.event.name
30th Annual Network and Distributed System Security Symposium (NDSS) 2023
en
tuw.event.startdate
27-02-2023
-
tuw.event.enddate
03-03-2023
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
San Diego
-
tuw.event.country
US
-
tuw.event.presenter
Tagliaro, Carlotta
-
tuw.event.track
Multi Track
-
wb.sciencebranch
Informatik
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.value
100
-
item.languageiso639-1
en
-
item.grantfulltext
restricted
-
item.cerifentitytype
Publications
-
item.openairetype
conference paper
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.fulltext
no Fulltext
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.dept
University of Twente
-
crisitem.author.dept
Guess Europe Sagl, Italy
-
crisitem.author.dept
Sababa Security SpA, Italy
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.orcid
0009-0003-0095-4525
-
crisitem.author.orcid
0000-0001-7001-4481
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.project.funder
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds