43
submitted 2 days ago by Joker@sh.itjust.works to c/privacy@lemmy.ml

With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue.

top 1 comments
sorted by: hot top controversial new old
[-] kixik@lemmy.ml 3 points 2 days ago

wow:

We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent

That makes think that 1st, perhaps it would be a good idea to avoid "return receipts" on any messenger, though that breaks ability to know if the destination has actually received, and if the destination has actually read the message.

Perhaps another thing, even though your messenger doesn't identify users with phone numbers at all, still block the messenger to have access to your contact list. Not sure if this affects, for example if a xmpp client has access to a broader contact list, if it can only relate to xmpp addresses it wouldn't pay attention to phone numbers, but I can't really tell.

And of course, don't use any messenger which tights users with phone numbers, no matter if to share among contacts now usernames are used instead of the phone number, when the phone number is still the way to identify the user.

this post was submitted on 20 Nov 2024
43 points (100.0% liked)

Privacy

32103 readers
713 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS