By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.

  • Ludicrous0251@piefed.zip
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 month ago

    When WIRED asked Meta what rate-limiting measures it instituted over the last eight years to prevent the technique Kloeze demonstrated, the company responded that it has, in fact, implemented evolving defenses against scrapers, including rate-limiting and machine-learning techniques to ban scrapers. Yet the University of Vienna researchers were able to not only replicate Kloeze’s work, but take it further, actually enumerating all 3.5 billion registered WhatsApp phone numbers—far more than the service had in 2017.

    A generous rate limit of 1 query per second would have taken 111 years to churn through 3.5 billion users (with 100% success rate on guesses). Meta’s rate limit seems to be “the rate at which our servers can query our contact database”.