‘Anonymous’ Chat App Hijacks Contact Data
bishopfox.com
bishopfox.com
This mindset of "If you havent done anything bad you dont have to worry" is so sad and ignorant of others situation.
It's also why I use multiple profiles in Android to force that compartmentalization since the snoopy apps have no context it's better to just deny them the data entirely.
For example, it's a dark pattern when you use Messenger, at least on iOS, for the first time and it says "Upload your contacts to find friends" with an "OK" button or "Learn More" button, and only after you click "Learn More" can you ignore it. WhatsApp does something worse; you can't initialize a message with anyone without allowing contacts, and the only way to add a contact is thru the phone app (the web app definitely doesn't, and I'm pretty certain the desktop app doesn't have the functionality to add a contact). I have to go thru great pains to prevent WhatsApp from getting my contact info, just to be able to add a new friend (turn off iCloud contacts, enable WhatsApp to see my contacts, then add the contact). Maybe I am paranoid, but I really, really want Facebook to only have the information I give it, and I don't trust WhatsApp at all. At least WhatsApp encrypts the messages.
I really hate this pattern in apps, and I wish there was some way to give it some kind of "blank canvas" without any real contacts in it. Thankfully apps don't lock you completely out if you don't provide contact info, yet, but I fear it may happen soon.
Here's what an app on iOS can read and modify (!) when you allow it to access your contacts: https://developer.apple.com/documentation/contacts/contacts_...
Nothing is really stopping an app with permission switching all of your contact numbers so they point to someone else, whether by accident, or on purpose. It seems like something waiting to go wrong...
While doing some research on similar apps, I didn't find a single app that does not give the user an option to not upload the contacts to the app's servers. Basically if use doesn't give this permission, app is useless.
I'm hoping the app I build will get a sustainable revenue without needing to uploading all contacts.
But in the long run, for contact management apps, there's exponentially more value in handling the contacts data in the cloud, so that its users get the max benefit. But imo any app that's not for contact management (e.g., Facebook etc) should have limited read only access to the contacts data.
It's kinda like bringing a bazooka to a knife fight, but this will get the job done nonetheless.
An implied "find my friend" feature that I assume Sarahah uses.
Edit: Here: https://github.com/WhisperSystems/Signal-Android/issues/4726
The problem, which no one denies, is that the small number of possible valid e164 values leaves the scheme vulnerable. Also, last time I checked you could submit like 10k tokens at once, so using a modest amount of IP addresses and phone numbers to bypass the rate limiting it is feasible to determine every registered number in a city. Restricting this is hard because some people have huge address books.
The Silent Circle method is slightly better in my opinion, but not by much so I understand why Moxie doesn't want to bother changing it.
Back when Redphone was a separate app it used a bloom filter scheme.
There are really no good solutions to this problem. The safer ones currently know just don't scale.
The hashing is so people can't easily get a list of all the phone numbers, which is easy to work around, but, then again, they could just hammer the endpoint querying for all the various numbers anyway.
Silent Circle way: Server keeps hashes of registered users cached. Client hashes all the numbers it has, remembering the hash -> number map for them. Client sends a small number of the most significant bits of its hashes. Server treats this like a mask or wildcard search, returns all matches. Client knows which match, also gets hashes for other users they don't know. Sure, the client can reverse them, but the client could have probed for them anyway. The server maybe/probably doesn't learn enough to preimage what the client sent because of too many collisions. The downside is that the number of bits the client sends needs to be appropriate given the size of the database, though that can be mitigated by sharding by country code/area code/whatever.
Standard OTT messaging architecture guarantees the service will see message envelopes anyway, so it's not worth the trade off of deploying PIR schemes of the differential or computational variety. Look for stuff by Ian Goldberg. Percy++ is a practical example you can run yourself.
For OTT contact sync the reasonable thing to do is just send the phone numbers. Blinding them by truncated hash is a nice gesture. What's not cool is sending all the other fields of the address book along with it.
We know and can easily verify that Signal is being good. But what can we do about less trustworthy services? The phone would need to apply permissions. Like, allow/deny filters of which fields of contacts or contact categories each app may have access to. An address book firewall, essentially. Considering how important messaging apps are in our lives and the amount of time we spend with them I think such granularity is warranted.
„[..] Signal has always done contact intersection with an ephemeral query of truncated hashes of phone numbers.„
If you included the 10 byte phone number, that only adds 100 GB. Then just store each entry as a 26 byte hash/number struct sorted by hash.
What's the full number?
What really bothers me is when the author says ' it’s possible Sarahah has harvested hundreds of millions of names, phone numbers, and email addresses ". I believe I remember Snapchat and other social media apps done before.
What Sarahah should have done is to communicate with their users about what their data and how they plan their security (being an anonymous messaging platform). But, let's not forget how Snapchat dealt with their security and data at its rise.
So in a way, iOS apps are much secure than Android.
And then Facebook acquired it and was able to complete its database of world's relationships.
Without treating mistakes, incompetencies, outright stupidities as malicious, we grow a new generation of technologists (including me, sadly), who do not bother to become adept in problem domain, consult with experts, perform strict analysis, cause tons of technical debt for the sake of moving fast. Good enough is the norm. We still see plain text, hashed without salt, hashed with the same salt password databases leaked. Maybe it was incompetence. Maybe it was stupidity. Maybe it was FIXME. Maybe the loaded gun was left on dinner table near a toddler because "I'm only going to bathroom". This is rhetoric question: can this stupidity be seen as malicious?