16C
Delhi
Saturday, January 16, 2021

WhatsApp, Telegram messengers are extremely insecure: Study

Utilizing very few resources, the researchers were able to perform practical crawling attacks on the popular messengers WhatsApp, Signal and Telegram.

- Advertisement -

WhatsApp, Telegram messengers are extremely insecure: StudyLondon, Sep 16 (IANS) Popular mobile messengers like WhatsApp expose personal data via discovery services that allow users to find contacts based on phone numbers from their address book, say researchers.

When installing a mobile messenger like WhatsApp, new users can instantly start texting existing contacts based on the phone numbers stored on their device.

For this to happen, users must grant the app permission to access and regularly upload their address book to company servers in a process called mobile contact discovery.

The study from the Technical University of Darmstadt and the University of W?rzburg in Germany, shows that currently deployed contact discovery services severely threaten the privacy of billions of users.

Utilizing very few resources, the researchers were able to perform practical crawling attacks on the popular messengers WhatsApp, Signal and Telegram.

The results of the experiments demonstrate that malicious users or hackers can collect sensitive data on a large scale and without noteworthy restrictions by querying contact discovery services for random phone numbers.

READ ALSO:  Shah slams Congress, Trinamool for 'misleading' nation on CAA

For the study, the researchers queried 10 per cent of all US mobile phone numbers for WhatsApp and 100 per cent for Signal.

Thereby, they were able to gather personal (meta) data commonly stored in the messengers’ user profiles, including profile pictures, nicknames, status texts and the “last online” time.

The analyzed data also reveals interesting statistics about user behaviour. For example, very few users change the default privacy settings, which for most messengers are not privacy-friendly at all.

The researchers found that about 50 per cent of WhatsApp users in the US have a public profile picture and 90 per cent a public “About” text.

Interestingly, 40 per cent of Signal users, which can be assumed to be more privacy concerned in general, are also using WhatsApp, and every other of those Signal users has a public profile picture on WhatsApp.

Tracking such data over time enables attackers to build accurate behaviour models.

When the data is matched across social networks and public data sources, third parties can also build detailed profiles, for example to scam users.

READ ALSO:  WC set to see first time winner as England beat Australia by 8 wickets
READ ALSO:  Elon Musk mocks Bezos' moon, space colony plans

For Telegram, the researchers found that its contact discovery service exposes sensitive information even about owners of phone numbers who are not registered with the service.

“Which information is revealed during contact discovery and can be collected via crawling attacks depends on the service provider and the privacy settings of the user,” the researchers wrote.

Since there are no noteworthy restrictions for signing up with messaging services, any third party can create a large number of accounts to crawl the user database of a messenger for information by requesting data for random phone numbers.

“We strongly advise all users of messenger apps to revisit their privacy settings,” the team said.

The study is scheduled to be released in February 2021 at the 28th Annual Network and Distributed System Security Symposium (NDSS), a top conference for IT security.

Source: IANS

India Updates
India Updates is an independent news & Information website. Follow us for regular updates on News and Information.

Follow Us On

Related News

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Trending Topics In India

Covid 19 India Updates

Trending News In India

Trending Showbiz

Trending Sports

Latest Trending News In India

Covaxin consent form says vax administered without ph-3 trial

New Delhi, Jan 16 (IANS) Amid the vaccinaton drive against Covid-19, it has emerged that there is a separate consent form for those who...

Covid vax will work like ‘Sanjeevani’: Harsh Vardhan

New Delhi, Jan 16 (IANS) With the launch of the world's largest vaccination drive in India, Union Health Minister Harsh Vardhan on Saturday said...

Indian military doctors, paramedics get Covid-19 vax shots

New Delhi, Jan 16 (IANS): Indian military doctors, paramedics and hospital staff are being vaccinated against the coronavirus disease across the country as inoculation drive...

WHO hopes Covid vaccination ‘underway in every country in next 100 days’

Geneva, Jan 16 (IANS) World Health Organization (WHO) Director-General Tedros Adhanom Ghebreyesus has urged fairness to the access of COovid-19 vaccines, saying he wants...