Live data from Hacker News

Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

ndss-symposium.org

61–70 of 206 posts

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#61
The paper claims that stricter rate limits are a possible solution to this issue, and that with stricter limits in place "crawling entire countries would only be feasible for very powerful attackers". I don't think I agree. Take Signal: the authors managed to crawl all US phone numbers in 25 days, using 100 accounts. Their proposed stricter rate limits force an approx 50x slowdown on an attacker (Table V), which seems to imply that over the same crawl period an attacker would require 5000 accounts. If we assume that virtual SMS numbers are around $5 each, then the attack now costs about $25k, which is about 0.001% the GDP of East Timor.

They also propose a global salt as a mitigation. I'm a little confused there too, because wouldn't the salt need to be present in the endpoint application? If so it would be trivial to extract.

Their proposal of using a key stretching hash algorithm (e.g. Argon2) seems reasonable? At a significant increase in cost on the server side.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#63

This scientifically-looking paper could have been written by Captain Obvious himself. It is beyond obvious that contact discovery in any major messenger or social network is facilitated by uploading all contacts from the user’s address book, with all the implied drawbacks. If users' behaviour has shown us anything, it's that they love it. And for all the dangers of their privacy loss, they happily trade it for the co…

It doesn’t show that we love it. I hate it. But it’s the cost of entry if you want to communicate with a group on any of those platforms (which I refuse to do outside of Signal). I didn’t love giving Signal my contacts list, but I did it.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#64
People will complain about the meta-information leakage of email but then turn around and suggest we should instead use something based on your phone number[1]. I guess this is a reminder that phone number based contact discovery has issues as well ... perhaps worse ones in practice.

With email the server operators know who is talking to who but do not necessarily know who any of those people are. Email clients will not show who has you in their contact list. There is no practical way to enumerate every active email address in use.

[1] https://latacora.micro.blog/2020/02/19/stop-using-encrypted....

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#65
Imagine my surprise when one can actually give up MORE revealing information about yourself and your contacts just by installing BOTH Telegram and Signal apps.

Signal: when you’re most concerned about privacy of your message content.

Telegram: when you’re most concerned about association with contacts.

WhatsApp: when you’re most concerned about losing your ability to reach out and contact someone.

Nothing is absolute.

But don’t tell our politicians and lobbyists that. Oh wait.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#66

This scientifically-looking paper could have been written by Captain Obvious himself. It is beyond obvious that contact discovery in any major messenger or social network is facilitated by uploading all contacts from the user’s address book, with all the implied drawbacks. If users' behaviour has shown us anything, it's that they love it. And for all the dangers of their privacy loss, they happily trade it for the co…

> It is beyond obvious that contact discovery in any major messenger or social network is facilitated by uploading all contacts from the user’s address book, with all the implied drawbacks.

Mass uploading contacts should be limited, like Telgram rightfully implemented. Signal should do the same.

Also, for signal you have to give the list of your contacts. And you don't have with Telegram (and I didn't).

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#67

I will criticize how Contacts are implemented on Android for this. For example, I don't want any person who I interact with once or twice a month to have access to my WhatsApp or any other social media app. But I can't do this in Android because once you add contact every damn app has access to that contact list. It's full access or no access if app uses permissions. I need something where I can label contacts to not…

Android Work Mode has this contact-separating feature: https://f-droid.org/packages/net.typeblog.shelter/

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#68

The reason this abuse of privacy is so widespread is because there are no bad consequences for the perpetrators. Governments don't enforce privacy acts in this circumstance. Users just roll their eyes, knowing there is no way for them to complain except though boycotts, which are difficult to organise and might not work unless coordinated on a massive scale which has never been tried. And so it goes.

And yet people are still bitching about the GDPR. The only problem with the GDPR is the lack of enforcement.

However, it isn't really surprising considering a large chunk of this very community makes their money off large-scale stalking and the same unethical things they complain about.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#69
post #43

I will criticize how Contacts are implemented on Android for this. For example, I don't want any person who I interact with once or twice a month to have access to my WhatsApp or any other social media app. But I can't do this in Android because once you add contact every damn app has access to that contact list. It's full access or no access if app uses permissions. I need something where I can label contacts to not…

That is not correct. In Android you have two ways of accessing most things: full access or use the system to access one entry. You should blame WhatsApp for not supporting the second method.

The fact that an app can choose to "support" a method is a flaw. The app should be completely oblivious to whether what it's seeing is the full list of accounts or a carefully selected one.

Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]

#70

Earlier quoted context omitted.

It requires payment - so google account or your paypal/credit card are on record.

You can pay by Wire transfer, MasterCard, Visa, PayPal or even Bitcoin[1] so there is at least one anonymous payment option available 1: https://shop.threema.ch/terms

Who said Bitcoin is anonymous?
Post reply on HN