Hack Reactions + Receipts = Track Anyone

Quick Overview

Researchers discovered a surveillance method exploiting WhatsApp and Signal delivery receipts, which cannot be disabled, allowing attackers knowing only a phone number to track a victim's phone status (locked, unlocked, app open), device type, and network connection (Wi-Fi vs. cellular) by silently spamming invisible message reactions, while in a separate news item, a man received over seven years in prison for conducting evil twin Wi-Fi attacks on airplanes to steal social media credentials.

Key Points: Delivery receipts, which are integral to WhatsApp and Signal and cannot be turned off, allow tracking of a recipient's phone state: locked, unlocked, or if the specific app is open. Attackers can differentiate phone states because unlocking the phone lowers delivery receipt time, and having WhatsApp open results in near-instant receipts. The attack is silent because researchers spam non-existent message reactions, which generate delivery receipts but do not create user notifications, with WhatsApp allowing 20 reactions per second due to zero rate limiting. Device fingerprinting is possible as Apple, Samsung, and Xiaomi phones show slightly different average response times, and the method also distinguishes between Wi-Fi and cellular connections. The surveillance technique extends to desktop clients, allowing attackers to map a user's physical location by observing which devices are online based on device-specific read receipts. A separate incident resulted in a 44-year-old man receiving 7 years and 4 months in prison for conducting evil twin Wi-Fi attacks on planes to steal social media credentials, primarily targeting women. Meta and Signal were informed about the receipt vulnerability in September 2024; Meta provided an update a year later, while Signal provided no response.

Context: The video discusses a serious privacy vulnerability discovered by researchers at the University of Vienna, detailed in their paper "Careless Whisper," which weaponizes the delivery receipt mechanism inherent in messaging apps like WhatsApp and Signal. This exploit requires no malware installation, only knowledge of the target's phone number. Additionally, the video covers a recent criminal sentencing related to in-flight Wi-Fi hacking, highlighting unrelated security threats.

Raw markdown version of this recap