Skip to main navigation Skip to search Skip to main content

I’ve got your number: Harvesting users’ personal data via contacts sync for the Kakaotalk messenger

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Instant messaging (IM) is increasingly popular among not only Internet but also smartphone users. In this paper, we analyze the security issue of an IM application, KakaoTalk, which is the most widely used in South Korea, with a focus on automated friends registration based on contacts sync. We demonstrate that there are multiple ways of collecting victims’ personal information such as their names, phone numbers and photos, which can be potentially misused for a variety of cyber criminal activities. Our experimental results show that a user’s personal data can be obtained automatically (0.26 s on average), and a large portion of KakaoTalk users (around 73%) uses their real names as display names. Finally, we suggest reasonable countermeasures to mitigate the discovered attacks, which have been confirmed and patched by the developers.

Original languageEnglish
Title of host publicationInformation Security Applications - 15th International Workshop, WISA 2014, Revised Selected Papers
EditorsKyung-Hyune Rhee, Jeong Hyun Yi
PublisherSpringer Verlag
Pages55-67
Number of pages13
ISBN (Electronic)9783319150864
DOIs
StatePublished - 2015
Event15th International Workshop on Information Security Applications, WISA 2014 - , Korea, Republic of
Duration: 25 Aug 201427 Aug 2014

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume8909
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference15th International Workshop on Information Security Applications, WISA 2014
Country/TerritoryKorea, Republic of
Period25/08/1427/08/14

Keywords

  • Automated friends registration
  • Contacts sync
  • Enumeration attack
  • Information leakage
  • KakaoTalk
  • Privacy
  • Security
  • Smartphone

Fingerprint

Dive into the research topics of 'I’ve got your number: Harvesting users’ personal data via contacts sync for the Kakaotalk messenger'. Together they form a unique fingerprint.

Cite this