I’ve got your number: Harvesting users’ personal data via contacts sync for the Kakaotalk messenger

1Citations
Citations of this article
16Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Instant messaging (IM) is increasingly popular among not only Internet but also smartphone users. In this paper, we analyze the security issue of an IM application, KakaoTalk, which is the most widely used in South Korea, with a focus on automated friends registration based on contacts sync. We demonstrate that there are multiple ways of collecting victims’ personal information such as their names, phone numbers and photos, which can be potentially misused for a variety of cyber criminal activities. Our experimental results show that a user’s personal data can be obtained automatically (0.26 s on average), and a large portion of KakaoTalk users (around 73%) uses their real names as display names. Finally, we suggest reasonable countermeasures to mitigate the discovered attacks, which have been confirmed and patched by the developers.

Cite

CITATION STYLE

APA

Kim, E., Park, K., Kim, H., & Song, J. (2015). I’ve got your number: Harvesting users’ personal data via contacts sync for the Kakaotalk messenger. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 8909, pp. 55–67). Springer Verlag. https://doi.org/10.1007/978-3-319-15087-1_5

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free