eprint.iacr.org will be offline for approximately an hour for routine maintenance at 11pm UTC on Tuesday, April 16. We lost some data between April 12 and April 14, and some authors have been notified that they need to resubmit their papers.
You are looking at a specific version 20200921:081541 of this paper. See the latest version.

Paper 2020/1119

All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile Messengers

Christoph Hagen and Christian Weinert and Christoph Sendner and Alexandra Dmitrienko and Thomas Schneider

Abstract

Contact discovery allows users of mobile messengers to conveniently connect with people in their address book. In this work, we demonstrate that severe privacy issues exist in currently deployed contact discovery methods. Our study of three popular mobile messengers (WhatsApp, Signal, and Telegram) shows that, contrary to expectations, large-scale crawling attacks are (still) possible. Using an accurate database of mobile phone number prefixes and very few resources, we have queried 10% of US mobile phone numbers for WhatsApp and 100% for Signal. For Telegram we find that its API exposes a wide range of sensitive information, even about numbers not registered with the service. We present interesting (cross-messenger) usage statistics, which also reveal that very few users change the default privacy settings. Regarding mitigations, we propose novel techniques to significantly limit the feasibility of our crawling attacks, especially a new incremental contact discovery scheme that strictly improves over Signal's current approach. Furthermore, we show that currently deployed hashing-based contact discovery protocols are severely broken by comparing three methods for efficient hash reversal of mobile phone numbers. For this, we also propose a significantly improved rainbow table construction for non-uniformly distributed inputs that is of independent interest.

Metadata
Available format(s)
PDF
Publication info
Published elsewhere. Minor revision. NDSS 2021
Keywords
Mobile Contact DiscoveryHash ReversalRainbow TableCrawlingPrivate Set IntersectionSignal
Contact author(s)
christoph hagen @ uni-wuerzburg de,weinert @ encrypto cs tu-darmstadt de,christoph sendner @ uni-wuerzburg de,alexandra dmitrienko @ uni-wuerzburg de,schneider @ encrypto cs tu-darmstadt de
History
2020-09-21: received
Short URL
https://ia.cr/2020/1119
License
Creative Commons Attribution
CC BY
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.