# Hack Reactions + Receipts = Track Anyone

Source: https://www.youtube.com/watch?v=HHEQVXNCrW8
Recap page: https://rapidrecap.app/video/HHEQVXNCrW8
Generated: 2025-12-03T18:52:12.075+00:00

---
## Quick Overview

Researchers discovered a surveillance method exploiting WhatsApp and Signal delivery receipts, which cannot be disabled, allowing attackers knowing only a phone number to track a victim's phone status (locked, unlocked, app open), device type, and network connection (Wi-Fi vs. cellular) by silently spamming invisible message reactions, while in a separate news item, a man received over seven years in prison for conducting evil twin Wi-Fi attacks on airplanes to steal social media credentials.

**Key Points:**
- Delivery receipts, which are integral to WhatsApp and Signal and cannot be turned off, allow tracking of a recipient's phone state: locked, unlocked, or if the specific app is open.
- Attackers can differentiate phone states because unlocking the phone lowers delivery receipt time, and having WhatsApp open results in near-instant receipts.
- The attack is silent because researchers spam non-existent message reactions, which generate delivery receipts but do not create user notifications, with WhatsApp allowing 20 reactions per second due to zero rate limiting.
- Device fingerprinting is possible as Apple, Samsung, and Xiaomi phones show slightly different average response times, and the method also distinguishes between Wi-Fi and cellular connections.
- The surveillance technique extends to desktop clients, allowing attackers to map a user's physical location by observing which devices are online based on device-specific read receipts.
- A separate incident resulted in a 44-year-old man receiving 7 years and 4 months in prison for conducting evil twin Wi-Fi attacks on planes to steal social media credentials, primarily targeting women.
- Meta and Signal were informed about the receipt vulnerability in September 2024; Meta provided an update a year later, while Signal provided no response.

**Context:** The video discusses a serious privacy vulnerability discovered by researchers at the University of Vienna, detailed in their paper "Careless Whisper," which weaponizes the delivery receipt mechanism inherent in messaging apps like WhatsApp and Signal. This exploit requires no malware installation, only knowledge of the target's phone number. Additionally, the video covers a recent criminal sentencing related to in-flight Wi-Fi hacking, highlighting unrelated security threats.

## Detailed Analysis

The primary focus is the discovery that timing delivery receipts from message reactions allows surveillance. Since delivery receipts are mandatory, an attacker spams the target with invisible reactions (sent to non-existent messages via open-source clients on WhatsApp) which generate timing data without alerting the user. When the victim's phone is locked, the time delay for the receipt increases; when the app is open, the receipt is nearly instantaneous, revealing the phone's status. This method also enables device fingerprinting based on slight variations in response times between brands like Apple, Samsung, and Xiaomi, and can determine if the user is on Wi-Fi versus cellular due to predictable versus erratic ping times. If desktop clients are used, an attacker can overlay data to track which specific devices are online. Furthermore, the lack of rate limiting on WhatsApp allows attackers to consume massive amounts of data (up to 13 GB per hour) and drain the battery by 18% per hour through constant reaction spam. In contrast, Signal's rate limiting mitigates this data drain significantly. Disclosure efforts were met with minimal action from Meta, which responded a year later, and no response from Signal. Preventative measures suggested include changing Signal privacy settings and enabling WhatsApp's setting to block high volumes of messages from unknown accounts. Separately, a man was sentenced to over seven years for using an evil twin Wi-Fi attack on flights to create fake portals demanding social media logins, subsequently stealing intimate images and data from thousands of victims.

### Delivery Receipt Surveillance Exploit

- Attack requires only a phone number
- Exploits timing differences between locked, unlocked, and app-open states
- Invisible spamming is achieved using reactions to non-existent messages on WhatsApp

### Tracking Capabilities Revealed

- Attackers determine phone status, device brand (Apple, Samsung, Xiaomi show different latencies), and network type (Wi-Fi vs. cellular)
- Desktop clients multiply tracking data by providing device-specific read receipt information

### Impact of Reaction Spamming

- WhatsApp users face 13 GB/hour data consumption and 18%/hour battery drain due to zero rate limiting
- Signal limits this impact to 360 MB/hour due to rate limiting

### Company Response and Mitigation

- Meta responded to the September 2024 report a year later; Signal provided no feedback
- Users should change Signal phone number privacy settings and enable WhatsApp's setting to block high volumes of messages

### In-Flight Wi-Fi Hacking Case

- A 44-year-old man received 7 years and 4 months for operating an evil twin Wi-Fi attack on planes
- He stole social media credentials, targeting women and acquiring thousands of intimate images
- The attacker attempted to destroy evidence after being discovered

