All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile Messengers
Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider
摘要
— Contact discovery allows users of mobile messengers to conveniently connect with people in their address book. In this work, we demonstrate that severe privacy issues exist in currently deployed contact discovery methods. Our study of three popular mobile messengers (WhatsApp, Signal, and Telegram) shows that, contrary to expectations, large-scale crawling attacks are (still) possible. Using an accurate database of mobile phone number prefixes and very few resources, we have queried 10% of US mobile phone numbers for WhatsApp and 100% for Signal. For Telegram we find that its API exposes a wide range of sensitive information, even about numbers not registered with the service. We present interesting (cross-messenger) usage statistics, which also reveal that very few users change the default privacy settings. Regarding mitigations, we propose novel techniques to significantly limit the feasibility of our crawling attacks, especially a new incremental contact discovery scheme that strictly improves over Signal’s current approach. Furthermore, we show that currently deployed hashing-based contact discovery protocols are severely broken by comparing three methods for efficient hash reversal of mobile phone numbers. For this, we also propose a significantly improved rainbow table construction for non-uniformly distributed inputs that is of independent interest.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDropAlexander Heinrich, Matthias Hollick, Thomas Schneider, Milan Stute 等USENIX Security 2021 · 被引用 32 次
- Pudding: Private User Discovery in Anonymity NetworksCeren Kocaogullar, Daniel Hugenroth, Martin Kleppmann, Alastair R. BeresfordS&P 2024 · 被引用 5 次
- Labeled PSI from Homomorphic Encryption with Reduced Computation and CommunicationKelong Cong, Radames Cruz Moreno, Mariana Botelho da Gama, Wei Dai 等CCS 2021 · 被引用 3 次
- Simple, Fast Malicious Multiparty Private Set IntersectionOfri Nevo, Ni Trieu, Avishay YanaiCCS 2021 · 被引用 2 次
- Arke: Scalable and Byzantine Fault Tolerant Privacy-Preserving Contact DiscoveryNicolas Mohnblatt, Alberto Sonnino, Kobi Gurkan, Philipp JovanovicCCS 2024 · 被引用 2 次
它引用的顶会 Paper8
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Fast Private Set Intersection from Homomorphic EncryptionHao Chen, Kim Laine, Peter RindalCCS 2017 · 被引用 446 次
- Efficient Batched Oblivious PRF with Applications to Private Set IntersectionVladimir Kolesnikov, Ranjit Kumaresan, Mike Rosulek, Ni TrieuCCS 2016 · 被引用 429 次
- Labeled PSI from Fully Homomorphic Encryption with Malicious SecurityHao Chen, Zhicong Huang, Kim Laine, Peter RindalCCS 2018 · 被引用 242 次
- Mobile Private Contact Discovery at ScaleDaniel Kales, Christian Rechberger, Thomas Schneider, Matthias Senker 等USENIX Security 2019 · 被引用 157 次
相关 Paper
- Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging AppsJunkyu Kang, Soyoung Lee, Yonghwi Kwon, Sooel SonNDSS 2026
- Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and PrivacyGabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich 等NDSS 2026 · 被引用 5 次
- Practical Traffic Analysis Attacks on Secure Messaging ApplicationsAlireza Bahramali, Amir Houmansadr, Ramin Soltani, Dennis Goeckel 等NDSS 2020
- Message Injection Attacks Against SignalKien Tuong Truong, Noemi Terzo, Kenneth G. PatersonUSENIX Security 2026
- Hope of Delivery: Extracting User Locations From Mobile Instant MessengersTheodor Schnitzler, Katharina Kohls, Evangelos Bitsikas, Christina PöpperNDSS 2023
