Waze is a traffic and navigation app that relies on crowd-sourced information to alert you to traffic issues, police presence, weather problems and anything else that can wreak havoc on your journey. Owned by Google, Waze responded earlier this week to an exploit found by UC Santa Barbara researchers. With the exploit, the research team wrote a program allowing them to invade the Waze eco-system with thousands of ghost drivers that could report phony traffic jams and keep tabs of other Waze drivers in real-time.
A writer for Fusion allowed the research team to track her, which they did as she drove through Las Vegas, and while commuting in San Francisco. Because the app shows users other Waze drivers on the road with them, including their username and their speed, the ghost drivers created by the UC Santa Barbara team allowed the researchers to keep track of the author's location.
In addition, the researchers used the ghost drivers to create a made-up traffic jam in a remote area between 2am to 5am every morning for two weeks. The appearance of heavy traffic resulted in Waze recommending alternate directions for drivers to take so that they could avoid the "traffic." According to the leader of the research team, Ben Zhao (who is a professor of computer sciences at UC Santa Barbara) "No real humans were harmed or even interacted with." But the made up traffic could result in detours that can add minutes to the driver's arrival time at his/her destination.
At left, before the phony traffic jam; at right a 15 minute longer route is posted after the fake traffic jam is reported
Waze responded by saying that a stranger cannot find you and track your car. That is because a stranger is not likely to know your username. In addition there is an invisible mode that prevents you from showing up on the map. However, this will result in your friends seeing you as being offline, and prevents you from reporting traffic conditions to fellow Wazers. Still, if you want to go invisible, head to Menu > My Waze (tap your name and icon) >Turn on "Go Invisible."
Waze points out that the writer of the story gave the research team her user name which made it easier for the researchers to figure out her route by using the "ghost riders." Waze says it has made some changes in the last 24 hours that "prevent ghost riders from affecting system behavior and performing similar tracking activities. None of these activities have occurred in real-time and in real-world environments, without knowing participants."
Recommended Stories
"Waze constantly improves its mechanisms and tools to prevent abuse and misuse. To that end, Waze is regularly in contact with the security and privacy research community—we appreciate their help protecting our users. This group of researchers connected with us in 2014, and we have already addressed some of their claims, implementing safeguards in our system to protect the privacy of our users."-Waze spokesman
Alan, an ardent smartphone enthusiast and a veteran writer at PhoneArena since 2009, has witnessed and chronicled the transformative years of mobile technology. Owning iconic phones from the original iPhone to the iPhone 15 Pro Max, he has seen smartphones evolve into a global phenomenon. Beyond smartphones, Alan has covered the emergence of tablets, smartwatches, and smart speakers.
Recommended Stories
Loading Comments...
COMMENT
All comments need to comply with our
Community Guidelines
Phonearena comments rules
A discussion is a place, where people can voice their opinion, no matter if it
is positive, neutral or negative. However, when posting, one must stay true to the topic, and not just share some
random thoughts, which are not directly related to the matter.
Things that are NOT allowed:
Off-topic talk - you must stick to the subject of discussion
Offensive, hate speech - if you want to say something, say it politely
Spam/Advertisements - these posts are deleted
Multiple accounts - one person can have only one account
Impersonations and offensive nicknames - these accounts get banned
Moderation is done by humans. We try to be as objective as possible and moderate with zero bias. If you think a
post should be moderated - please, report it.
Have a question about the rules or why you have been moderated/limited/banned? Please,
contact us.
Things that are NOT allowed: