Location Cheating: The Hidden Security Crisis in Social Networks
Location Cheating: A Security Challenge to Location-Based Social Network Services
The paper investigates "Location Cheating" in Location-Based Social Networks (LBSNs) like Foursquare. It demonstrates how attackers can bypass GPS-based verification using emulators and automated scripts to gain illicit real-world rewards and digital influence.
TL;DR
As Location-Based Services (LBS) like Foursquare grew, so did the incentive to lie about one's coordinates. This paper exposes how easily hackers can "teleport" across the globe using simple emulators and automated scripts to steal real-world rewards. By crawling millions of profiles, the authors prove that location cheating isn't just a theory—it's a large-scale reality that bypasses current algorithmic defenses.
Background: Rewards as a High-Stakes Incentive
The rise of "Mayorships" and real-world perks (like free coffee or discounts) transformed physical locations into digital assets. However, the business model assumes that a "check-in" equals physical presence. This paper identifies a critical flaw: the Trust Gap between the user's phone and the service provider's server.
The Anatomy of a Location Attack
The authors categorize the threat into three escalating levels:
- GPS Manipulation: Using open-source OS (Android) to hijack GPS APIs or using device emulators to feed fake coordinates to the app.
- Automated Cheating: Using SQL databases of crawled venue locations to plan "virtual tours."
- Profile Analysis: Crawling public data to find "weak" venues where Mayorship is easy to steal.

Bypassing the "Cheater Code"
Foursquare implemented a "cheater code" to catch anomalies like:
- Superhuman Speed: Checking in at locations thousands of miles apart in minutes.
- Rapid-fire Check-ins: Multiple venues in seconds.
The authors outsmarted this by building a Virtual Path Generator. By calculating a realistic travel speed (e.g., checking in every 5 minutes for venues <1 mile apart), their bot successfully checked into 25 venues in a row without triggering a single alarm.
Evidence from the Wild: 1.89 Million Users Analyzed
By crawling over 1.89 million users and 5.6 million venues, the authors identified clear signatures of mass cheating:
- The "Low Reward" Paradox: Some users have 10,000+ check-ins but almost zero badges. Why? Because the server invalidated their rewards but still counted the check-in tally—a clear sign of "detected-but-not-stopped" fraud.
- The Impossible Tourist: One suspected cheater "visited" over 30 different cities across the US and Europe in a single year, scattered in a way that defied logical travel patterns.
Fig: Data showing a subset of users with abnormally high recent activity, indicative of automated cheating.
Future-Proofing Location Security
The paper concludes that purely software-based verification is doomed. They suggest:
- Venue-Side Verification: Utilizing local Wi-Fi routers as "witnesses." If a device isn't within the 100m radio range of the shop's Wi-Fi, the check-in is rejected.
- Profile Obfuscation: Hiding user IDs and recent visitor lists from public crawlers to prevent attackers from mapping out "vulnerable" targets.
Conclusion
This study serves as a wake-up call for the LBS industry. When digital status is tied to physical location, the incentive for fraud is inevitable. Moving forward, the industry must shift from "trusting the device" to "verifying via the environment."
Academic Takeaway
The core insight is that temporal-logic (checking speed) is insufficient for security if the attacker understands the underlying heuristic. Robust security requires Infrastructure-based Distance Bounding.
