Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy
Gabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich, Aljosha Judmayer
摘要
WhatsApp, with 3.5 billion active accounts as of early 2025, is the world's largest instant messaging platform. Given its massive user base, WhatsApp plays a critical role in global communication. To initiate conversations, users must first discover whether their contacts are registered on the platform. This is achieved by querying WhatsApp's servers with mobile phone numbers extracted from the user's address book (if they allowed access). This architecture inherently enables phone number enumeration, as the service must allow legitimate users to query contact availability. While rate limiting is a standard defense against abuse, we revisit the problem and show that WhatsApp remains highly vulnerable to enumeration at scale. In our study, we were able to probe over a hundred million phone numbers per hour without encountering blocking or effective rate limiting. Our findings demonstrate not only the persistence but the severity of this vulnerability. We further show that nearly half of the phone numbers disclosed in the 2021 Facebook data leak are still active on WhatsApp, underlining the enduring risks associated with such exposures. Moreover, we were able to perform a census of WhatsApp users, providing a glimpse on the macroscopic insights a large messaging service is able to generate even though the messages themselves are end-to-end encrypted. Using the gathered data, we also discovered the re-use of certain X25519 keys across different devices and phone numbers, indicating either insecure (custom) implementations, or fraudulent activity. In this updated version of the paper, we also provide insights into the collaborative remediation process through which we confirmed that the underlying rate-limiting issue had been resolved.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper7
- Mobile Private Contact Discovery at ScaleDaniel Kales, Christian Rechberger, Thomas Schneider, Matthias Senker 等USENIX Security 2019 · 被引用 157 次
- Clone Detection in Secure Messaging: Improving Post-Compromise Security in PracticeCas Cremers, Jaiden Fairoze, Benjamin Kiesl, Aurora NaskaCCS 2020 · 被引用 17 次
- Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi DeploymentsGabriel Karl Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl 等USENIX Security 2024 · 被引用 8 次
- The Signal Private Group System and Anonymous Credentials Supporting Efficient Verifiable EncryptionMelissa Chase, Trevor Perrin, Greg ZaveruchaCCS 2020 · 被引用 5 次
- MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy ResearchGabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian DabrowskiUSENIX Security 2023
相关 Paper
- All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile MessengersChristoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko 等NDSS 2021
- Formal Analysis of Multi-device Group Messaging in WhatsAppMartin R. Albrecht, Benjamin Dowling, Daniel JonesEUROCRYPT 2025 · 被引用 3 次
- Jettisoning Junk Messaging in the Era of End-to-End Encryption: A Case Study of WhatsAppPushkal Agarwal, Aravindh Raman, Damilola Ibosiola, Nishanth Sastry 等WWW 2022 · 被引用 3 次
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk 等CRYPTO 2023 · 被引用 29 次
- Privacy Risks with Facebook's PII-Based Targeting: Auditing a Data Broker's Advertising InterfaceGiridhari Venkatadri, Athanasios Andreou, Yabing Liu, Alan Mislove 等S&P 2018 · 被引用 110 次
