WhatsApp & Signal Activity Tracking via Silent Acknowledgements: New PoC

Your WhatsApp & Signal Activity Isn’t As Private As You Think: A Deep Dive

A recently published open-source project, “Device Activity Tracker,” and the research underpinning it (“Careless Whisper” from the University of Vienna & SBA Research), has revealed a concerning vulnerability in WhatsApp and Signal. It demonstrates how seemingly innocuous “silent acknowledgements” – the signals your phone sends when a message is delivered – can be exploited to infer whether you’re actively using your device.

How Does This Activity Tracking Work?

The core of the technique lies in measuring the Round-Trip Time (RTT) of these acknowledgements. Think of it like this: when your phone is actively in use, the response is quick. When it’s in standby, the response takes longer. The tracker sends “probes” – requests for acknowledgements to non-existent message IDs – and meticulously measures this delay. By analyzing these RTTs, it can distinguish between an active device and one in standby, even detect potential network changes (switching between Wi-Fi and mobile data), and build a pattern of your activity over time.

The project utilizes two methods for sending these probes: “Delete” (the default) and “Reaction.” Crucially, it doesn’t rely on read receipts, meaning blocking read receipts won’t protect you. A dynamic threshold, calculated at 90% of the median RTT, determines whether a device is considered active or idle. This threshold adapts over time to account for fluctuating network conditions.

Beyond the Tech: The Privacy Implications

This isn’t just a theoretical vulnerability. The “Device Activity Tracker” provides a fully functional proof-of-concept, complete with a web interface for real-time monitoring. While the creators emphasize its intended use for research purposes, the potential for misuse is obvious. Imagine a scenario where someone could remotely determine if you’re available based on your WhatsApp activity, or track your general routine. This represents a significant erosion of privacy.

Recent data breaches and privacy scandals (like the Cambridge Analytica affair with Facebook) have heightened public awareness of data security. This research adds another layer of concern, demonstrating that even end-to-end encrypted messaging apps aren’t immune to sophisticated tracking techniques. A 2023 Pew Research Center study found that 79% of Americans are concerned about how companies use their personal data, highlighting the growing demand for privacy-focused solutions.

What Can You Do to Protect Yourself?

Currently, the most effective mitigation is to activate “Block unknown account messages” within WhatsApp’s privacy settings (Settings → Privacy → Advanced). This reduces the volume of probes from unknown numbers, but doesn’t eliminate the attack entirely. The researchers acknowledge that this vulnerability remains exploitable as of December 2025.

Pro Tip: Regularly review your privacy settings on all messaging apps. Enable features like two-factor authentication and be cautious about sharing your phone number with untrusted sources.

Future Trends: The Arms Race for Messaging Privacy

This discovery is likely to accelerate several key trends in messaging security:

  • Increased Focus on RTT Obfuscation: App developers will likely explore techniques to randomize or mask RTTs, making it harder to infer activity levels.
  • End-to-End Encryption Enhancements: Beyond message content, future encryption protocols may focus on protecting metadata, including timing information.
  • Decentralized Messaging Networks: Platforms like Session and Matrix, which prioritize decentralization and privacy, may gain traction as users seek alternatives to centralized messaging apps.
  • AI-Powered Privacy Tools: Artificial intelligence could be used to detect and block malicious probes, or to provide users with personalized privacy recommendations.
  • Regulatory Scrutiny: Governments may introduce stricter regulations regarding data collection and tracking by messaging platforms. The EU’s Digital Markets Act (DMA) is a prime example of this trend.

The development of this tracker highlights a fundamental challenge: the tension between usability and security. Features like silent acknowledgements are convenient, but they also create potential vulnerabilities. Striking the right balance will be crucial in the ongoing effort to protect user privacy.

Did you know?

The “Careless Whisper” research team deliberately chose the name as a nod to the song’s themes of infidelity and surveillance.

FAQ

  • Can this tracker access my message content? No, the tracker only analyzes the timing of acknowledgements, not the content of your messages.
  • Does blocking read receipts protect me? No, this technique doesn’t rely on read receipts.
  • Is Signal more secure than WhatsApp? Both apps are vulnerable to this technique, although Signal generally has a stronger reputation for privacy.
  • What is RTT? Round-Trip Time is the time it takes for a signal to travel from your device to a server and back.
  • Is this an active attack in the wild? While the researchers haven’t identified widespread exploitation, the potential for malicious use exists.

Learn More: Explore the original project on GitHub.

What are your thoughts on this privacy vulnerability? Share your comments below and let’s discuss how we can protect our digital lives.

Leave a Comment