Older paper but worth reading: "Our findings reveal that mechanisms embedded in modern E2EE messaging architectures – such as delivery receipts and multi-device support – can have significant implications on user privacy. Consequently, it is essential to balance functional requirements, usability and convenience with privacy and security, particularly in E2EE applications that are inherently privacy-sensitive per design."
https://arxiv.org/abs/2411.11194
#cybersecurity #carelesswhisper #E2EE #chat
Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers

With over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as the online and activity status of a victim, e.g., screen on/off. Moreover, we can infer the number of currently active user devices and their operating system, as well as launch resource exhaustion attacks, such as draining a user's battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue.

arXiv.org
Happy anniversary to Bananarama’s album, ‘Exotica’. Released this week in 2001. #bananarama #exotica #carelesswhisper #if #boom 🍌🍌🍌

✨George Michael✨
"Careless Whisper" no es solo una canción, es una herida elegante.
Ese saxo que entra despacio y te aprieta el pecho, esa voz que confiesa sin alzarla… George Michael sabía convertir la culpa, el deseo y la nostalgia en belleza pura.
Hay canciones que no se escuchan: se quedan.
︶꒦꒷♡꒷꒦︶︶꒦꒷♡꒷꒦︶︶꒦꒷♡꒷꒦︶︶꒦꒷♡꒷꒦

#georgemichael #carelesswhisper #musicaetern a #nostalgia #voz #saxo #emociones #cancionesquesequedan #humanidad

George Michael – Careless Whisper (Lyrics)

YouTube
Careless whisper - Privacy issue with instant messengers. Signal's response - a critique
This paper here
arxiv.org/pdf/2411.11194 revealed the Careless whisper privacy issue with instant messaging platforms like whatsapp and signal. The issue exists because these messengers produce a silent delivery receipt for any message sent to a user. Just by knowing a users phone number a tracker can send some malformed messages and over a period of time create a profile of the users behaviour patterns.

While research papers of these kind keep coming up once in a while, what is different this time is, this is implemented in a tool and is available for people to use. (
github.com/gommzystudio/device-activity-tracker) and this allows anyone to do stealthy tracking of signal and whatsapp users (cyberinsider.com/tool-allows-stealthy-tracking-of-signal-and-whatsapp-users-through-delivery-receipts/).

Here is a medium article explaining this in detail (
medium.com/@coduronin/careless-whisper-stalking-you-in-silence-8d242bfa680a)

While
#signal is known for its gold standard encryption protocol and their penchant determination to collect as little metadata as possible about their users, sometime their response to security issues like this is pretty pathetic.

There had been a patch submitted and discussion happened in the signal github (
github.com/signalapp/Signal-Android/pull/14463), but quite worryingly it's closed. What's more, the signal dev team is saying even technical discussions can't happen on their github. The other alternative for signal related discussions I have seen is the Signal community (community.signalusers.org/). But honestly I have not seen signal developers engaging in any discussions there other than in the beta feedback or special feature feedback threads. Moreover any serious discussion of this kind in that community is normally biased with a bunch of signal fanboys there defending signal's decisions (or the lack of it).

This behaviour of signal team is pretty disappointing. It is fine even if there are no immediate solutions, but the first step of solving a problem is to acknowledge there is one, which the signal team apparently is reluctant to do in this case.

@Mer__edith @signalapp I would expect some serious technical discussion is encouraged on this topic and a solution is arrived at.

#signal #SilentDeliveryReceipt #CarelessWhisper

@kuketzblog Die Einstellung gibt es bei https://molly.im/ jedoch nicht bei Signal(Android), Herr Kuketz.

Um dies gänzlich zu beheben, muss es von Signal (Client + Server) gepatched werden.

Die Molly-Entwickler wollen jedoch ebenfalls Custom-Fixes bereitstellen.

https://github.com/mollyim/mollyim-android/issues/646

Signals Antwort lässt sich hier finden.

https://github.com/signalapp/Signal-Android/pull/14463#issuecomment-3613869569 

https://archive.is/DNZG9

#sidechannel #CarelessWhisper

P.S.: Signal ist nach wie vor sicher. Coole Kids nutzen Molly. 😁 MfG 🙏

Molly

Molly is an improved Signal app for Android

@thenewoil Good summary though lacking some recent issues like tracking through silent delivery reports #CarelessWhisper https://arxiv.org/pdf/2411.11194

Careless Whiskers by George Michael

(Ngl, careless whiskers could be a comment on my mustache. 😭 )

#CarelessWhisper #GeorgeMichael #CorruptedLyrics #whiskers #mustache

Pendant que #signalapp sort son nouveau système de poll.

Des chercheur , ont révélé des vulnérabilités dans les messagerie E2E ( whatsapp et signal )

Vulgarisé ici https://youtu.be/B9Syj555RQc

Pourtant, selon l'auteur. Il y aurait des solutions. Mais @signalapp aurait ignoré ces avertissements.

J'espère qu'il se trompe et que la fondation s'en vient avec des solutions. Dans tous les cas, si l'affaire ne fait pas assez de bruit. Nous ne seront pas entendu.

#cybersecurity #carelesswhisper

Apps REFUSE TO PATCH "Design Flaw" that tracks EVERYTHING you do

YouTube
Happy anniversary to Wham!’s album, ‘Make It Big’. Released this week in 1984. #wham #makeitbig #wakemeupbeforeyougogo #carelesswhisper #everythingshewants #freedom