论文标题
交付希望:从移动即时信使中提取用户位置
Hope of Delivery: Extracting User Locations From Mobile Instant Messengers
论文作者
论文摘要
诸如WhatsApp之类的移动即时信使使用交付状态通知,以告知用户是否已发送消息已成功到达目的地。由于经常使用Messenger服务,这对于发件人来说是有用且重要的信息。但是,正如我们在本文中所展示的那样,此标准功能打开了一个定时侧频道,对用户位置隐私产生了意外的后果。我们在概念和实验上为三个广泛传播的即时信使研究了这一威胁。我们验证了这些信息泄漏甚至存在于信号和Threema等隐私友好的使者中。 我们的结果表明,经过训练阶段,Messenger用户可以区分消息接收器的不同位置。我们的分析涉及多轮测量和评估,表明定时侧渠道一直独立于接收器位置之间的距离 - 攻击既适用于不同国家 /地区的接收者,又适用于一个城市的小规模。例如,在同一城市内的三个地点中,发件人可以确定正确的80%精度。因此,在发送即时消息时,Messenger用户可以暗中监视彼此的下落。正如我们的对策评估所表明的那样,Messenger提供商可以通过在几秒钟内随机延迟交付确认来有效地禁用正时渠道。对于用户自己而言,由于无法选择关闭交货确认,因此很难防止威胁。
Mobile instant messengers such as WhatsApp use delivery status notifications in order to inform users if a sent message has successfully reached its destination. This is useful and important information for the sender due to the often asynchronous use of the messenger service. However, as we demonstrate in this paper, this standard feature opens up a timing side channel with unexpected consequences for user location privacy. We investigate this threat conceptually and experimentally for three widely spread instant messengers. We validate that this information leak even exists in privacy-friendly messengers such as Signal and Threema. Our results show that, after a training phase, a messenger user can distinguish different locations of the message receiver. Our analyses involving multiple rounds of measurements and evaluations show that the timing side channel persists independent of distances between receiver locations -- the attack works both for receivers in different countries as well as at small scale in one city. For instance, out of three locations within the same city, the sender can determine the correct one with more than 80% accuracy. Thus, messenger users can secretly spy on each others' whereabouts when sending instant messages. As our countermeasure evaluation shows, messenger providers could effectively disable the timing side channel by randomly delaying delivery confirmations within the range of a few seconds. For users themselves, the threat is harder to prevent since there is no option to turn off delivery confirmations.