Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gegenhuber, Gabriel K., Günther, Maximilian, Maier, Markus, Judmayer, Aljosha, Holzbauer, Florian, Frenzel, Philipp É., Ullrich, Johanna
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911241634578432
author Gegenhuber, Gabriel K.
Günther, Maximilian
Maier, Markus
Judmayer, Aljosha
Holzbauer, Florian
Frenzel, Philipp É.
Ullrich, Johanna
author_facet Gegenhuber, Gabriel K.
Günther, Maximilian
Maier, Markus
Judmayer, Aljosha
Holzbauer, Florian
Frenzel, Philipp É.
Ullrich, Johanna
contents With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue.
format Preprint
id arxiv_https___arxiv_org_abs_2411_11194
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers
Gegenhuber, Gabriel K.
Günther, Maximilian
Maier, Markus
Judmayer, Aljosha
Holzbauer, Florian
Frenzel, Philipp É.
Ullrich, Johanna
Cryptography and Security
Networking and Internet Architecture
With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue.
title Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2411.11194