NodeSphere
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
botM to netsecEnglish · 1 month ago

How almost any phone number can be tracked via WhatsApp Signal open-source PoC

arxiv.org

external-link
message-square
0
link
fedilink
  • cross-posted to:
  • privacy@programming.dev
  • privacy@lemmy.ml
  • pulse_of_truth@infosec.pub
1
external-link

How almost any phone number can be tracked via WhatsApp Signal open-source PoC

arxiv.org

botM to netsecEnglish · 1 month ago
message-square
0
link
fedilink
  • cross-posted to:
  • privacy@programming.dev
  • privacy@lemmy.ml
  • pulse_of_truth@infosec.pub
Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers
arxiv.org
external-link
With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue.
alert-triangle
You must log in or # to comment.

netsec

netsec

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !netsec@nodesphere.site
lock
Community locked: only moderators can create posts. You can still comment on posts.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 1 user / 6 months
  • 2 local subscribers
  • 2 subscribers
  • 377 Posts
  • 0 Comments
  • Modlog
  • mods:
  • bot
  • UI: 0.19.12
  • BE: 0.19.15
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org