The multiple-vehicle collision took place during morning hours on the road linking Ibra and Al Mudhaibi
gulf1 hour ago
Popular mobile messengers like WhatsApp expose personal data via discovery services that allow users to find contacts based on phone numbers from their address book, say researchers.
When installing a mobile messenger like WhatsApp, new users can instantly start texting existing contacts based on the phone numbers stored on their device.
For this to happen, users must grant the app permission to access and regularly upload their address book to company servers in a process called mobile contact discovery.
The study from the Technical University of Darmstadt and the University of Würzburg in Germany shows that currently deployed contact discovery services severely threaten the privacy of billions of users.
Utilising very few resources, the researchers were able to perform practical crawling attacks on the popular messengers WhatsApp, Signal and Telegram.
The results of the experiments demonstrate that malicious users or hackers can collect sensitive data on a large scale and without noteworthy restrictions by querying contact discovery services for random phone numbers.
For the study, the researchers queried 10 per cent of all US mobile phone numbers for WhatsApp and 100 per cent for Signal.
Thereby, they were able to gather personal (meta) data commonly stored in the messengers' user profiles, including profile pictures, nicknames, status texts and the "last online" time.
The analysed data also reveals interesting statistics about user behaviour. For example, very few users change the default privacy settings, which for most messengers are not privacy-friendly at all.
The researchers found that about 50 per cent of WhatsApp users in the US have a public profile picture and 90 per cent a public "About" text.
Interestingly, 40 per cent of Signal users, which can be assumed to be more privacy concerned in general, are also using WhatsApp, and every other of those Signal users has a public profile picture on WhatsApp.
Tracking such data over time enables attackers to build accurate behaviour models.
When the data is matched across social networks and public data sources, third parties can also build detailed profiles, for example to scam users.
For Telegram, the researchers found that its contact discovery service exposes sensitive information even about owners of phone numbers who are not registered with the service.
"Which information is revealed during contact discovery and can be collected via crawling attacks depends on the service provider and the privacy settings of the user," the researchers wrote.
Since there are no noteworthy restrictions for signing up with messaging services, any third party can create a large number of accounts to crawl the user database of a messenger for information by requesting data for random phone numbers.
"We strongly advise all users of messenger apps to revisit their privacy settings," the team said.
The study is scheduled to be released in February 2021 at the 28th Annual Network and Distributed System Security Symposium (NDSS), a top conference for IT security.
The multiple-vehicle collision took place during morning hours on the road linking Ibra and Al Mudhaibi
gulf1 hour ago
Moscow has already ramped up military spending to levels not seen since the Soviet era
europe1 hour ago
Ronaghi accuses security personnel who arrested him earlier this week of subjecting him to sexual abuse and insults
mena2 hours ago
The 16-year-old Welsh golfing prodigy claims both the Overall title and the Boys' Under-16 Division title at Al Ain Equestrian, Shooting & Golf Club
sports2 hours ago
Adani Group denied the allegations as baseless, while Indian government officials haven't commented so far
business2 hours ago
Thursday's attacks targeted two separate convoys of Shiite Muslims travelling in Kurram, Javed ullah Mehsud
asia2 hours ago
NIC sold 6.5 million shares, representing a 3.2% stake in Boursa Kuwait
markets2 hours ago
The RTA offered alternative routes for motorists to reach their destination during this time
transport2 hours ago