PoC Tool Tracks Device Status via WhatsApp & Signal Delivery Receipts
tom_doerr · x · 2026-08-13
An open-source project named Device Activity Tracker (5.1k Stars) demonstrates a severe privacy vulnerability in WhatsApp and Signal.
Based on the paper Careless Whisper from the University of Vienna, the tool measures the Round-Trip Time (RTT) of message delivery receipts. This allows an attacker to determine a target device's real-time status (active, standby, or offline) and infer sensitive activity patterns without any user interaction.
- Mechanism: Exploits silent delivery receipts and timing differences as a side-channel attack.
- Impact: Anyone with the target's phone number could potentially track their device usage habits.
- Disclaimer: Provided as a Proof-of-Concept (PoC) for security research and educational purposes only.
More from Safety
- OpenAI Researcher Warns: AI Agents Will Easily Bypass Passive Cyber Defenses — idavidrein · 2026-08-13
- After Hugging Face Incident, AI Safety Proposal Gains Urgency — idavidrein · 2026-08-13
- SRE-Bench: A New Benchmark for Testing LLM Binary Reverse Engineering — teortaxesTex · 2026-08-13
- Samsung Adopts Claude for Chip Design, Anthropic Adds Invisible Watermarks — 创业邦 · 2026-08-13
- Ex-US Army Cyber Expert: Traditional 7-Layer Network Defense Has Failed in the AI Era — herbiebradley · 2026-08-13
- Meta and TikTok Launch AI Content Detectors for Watermarks — luisdans · 2026-08-13