Connecting the Dots: An Investigative Study on Linking Private User Data Across Messaging Apps
Junkyu Kang, Soyoung Lee, Yonghwi Kwon, Sooel Son
摘要
Mobile messaging apps have become an integral part of daily communication with massive user bases (e.g., over 950 million on Telegram and 48.7 million on KakaoTalk). To boost user engagement and user base, messaging apps offer diverse context-rich and platform-specific features, such as nearby user search, contact discovery, and single sign-on (SSO)-based account linking. While these features enable users to adopt multiple messaging apps on a single mobile device, they also introduce privacy risks of linking private user information across multiple message apps, which remains understudied. This paper presents an in-depth analysis of privacy threats in widely used messaging apps in South Korea, including Kakao-Talk, Telegram, WhatsApp, Signal and Tinder, demonstrating concrete attacks exploiting their contact discovery, SSO-based account linking, and nearby user search features to compromise user privacy. More importantly, we chain the attacks to conduct the first cross-platform linking attack, which enables adversaries to deanonymize user names and infer users' physical locations with an average error margin of 324 meters for a large number of untargeted and targeted users. Our findings highlight that securing contact discovery is crucial as permissive contact discovery policies allow adversaries to exploit phone numbers and profile images as linking keys to connect private user information across multiple messaging apps. We discuss and propose mitigation strategies to alleviate the presented threats.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Searching for MobileNetV3Andrew Howard, Ruoming Pang, Hartwig Adam, Quoc V. Le 等ICCV 2019 · 被引用 9,163 次
- The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization FlawsKostas Drakonakis, Sotiris Ioannidis, Jason PolakisCCS 2020 · 被引用 56 次
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 被引用 14 次
- Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating AppsKarel Dhondt, Victor Le Pochat, Yana Dimova, Wouter Joosen 等USENIX Security 2024 · 被引用 4 次
- All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile MessengersChristoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko 等NDSS 2021
相关 Paper
- Hope of Delivery: Extracting User Locations From Mobile Instant MessengersTheodor Schnitzler, Katharina Kohls, Evangelos Bitsikas, Christina PöpperNDSS 2023
- Message Injection Attacks Against SignalKien Tuong Truong, Noemi Terzo, Kenneth G. PatersonUSENIX Security 2026
- Lie to Me: Abusing the Mobile Content Sharing Service for Fun and ProfitGuosheng Xu, Siyi Li, Hao Zhou, Shucen Liu 等WWW 2022 · 被引用 5 次
- Mobile Private Contact Discovery at ScaleDaniel Kales, Christian Rechberger, Thomas Schneider, Matthias Senker 等USENIX Security 2019 · 被引用 157 次
- Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group ChatsKai-Hsiang Chou, Yi-Min Lin, Yi-An Wang, Jonathan Weiping Li 等USENIX Security 2025
