Live data from Hacker News

Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

ndss-symposium.org

11–20 of 206 posts

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#11

100% of signal scrapped - ugh

They have been too busy with integrating crypto payments instead of fixing long standing issues or planned features (allow to register without a phone number). But - to Signal's defense - while you can scrape the phone numbers, there is not much you can gain from it, you can only tell that a specific number is a Signal user. And sometimes you can see the username (if the user chooses to not encrypt it).

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#13
post #12

There needs to be two lists of contacts. One which I allow to be shared with apps And another which are my contacts I use with my dialer. People don't need their messenger apps knowing the phone number of their doctor

An alternative would be to make it similar to the iOS photo gallery permissions:

When an app requests permission to all photos the user gets the option to share only a subset of photos with the app. (This subset can be different for each app.)

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#14
post #12

There needs to be two lists of contacts. One which I allow to be shared with apps And another which are my contacts I use with my dialer. People don't need their messenger apps knowing the phone number of their doctor

Or the number of the VD clinic, or the number of the an oncology ward, or the number of the pawnbroker, ...

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#15

Earlier quoted context omitted.

For those who want end-to-end encrypted messages, it's a feature that the server doesn't have a persistent archive of message history. Wire messages are on the server for a few weeks, long enough to relay those messages to transiently offline devices. Telegram is great at what it does, different use case from Wire.

Matrix does have end-to-end encrypted persistent history.

Yes, it's possible. Depending on your threat model, it may or may not be a good idea to have a long-term archive of encrypted data be subject to legal process. Matrix has plans to support IETF MLS, which is a necessary precursor to messenger interoperability.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#17
post #12

There needs to be two lists of contacts. One which I allow to be shared with apps And another which are my contacts I use with my dialer. People don't need their messenger apps knowing the phone number of their doctor

on ios if one does not grant addressbook permission for the app:

* telegram uses an "internal" contact list for which one can add contacts via the desktop client and then works as expected.

* whatsapp let's the user freely initiate contact by phone numbers, but then only shows the number (no name).

don't know about signal.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#18
The practical consequence of this is that your phone number + name is public information. Almost as if it were listed in a phone book. That was pretty much the case already so it's not really a new threat. Of course people with unlisted numbers will be a bit annoyed by this. Likewise, your email address probably is part of numerous databases, including those owned by spammers/scammers.

I'm not saying this is good. But merely that assuming otherwise was always a bit naive. Now in terms of GDPR and similar laws in the US, leaking information via a scrapable API is of course still a problem.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#19
"Interestingly, if the number provided by Hushed was previously registered by another user, the WhatsApp account is "inherited", including group memberships. A non-negligible percentage of the accounts we registered had been in active use, with personal and/or group messages arriving after account takeover."

Did not know that taking over a WhatsApp account is that easy.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#20
post #13
post #12

There needs to be two lists of contacts. One which I allow to be shared with apps And another which are my contacts I use with my dialer. People don't need their messenger apps knowing the phone number of their doctor

An alternative would be to make it similar to the iOS photo gallery permissions: When an app requests permission to all photos the user gets the option to share only a subset of photos with the app. (This subset can be different for each app.)

While I agree with you, the current way this functionality works is really terrible.
Post reply on HN