Drudge Retort: The Other Side of the News
Sunday, December 14, 2025

A tool for tracking over three billion WhatsApp and Signal users has been publicly released. Just by knowing the phone number, attackers can determine when users come home, when they are actively using the phone, when they go to sleep, or when they are offline. They can also drain batteries and data limits without the users noticing anything.

More

Comments

Admin's note: Participants in this discussion must follow the site's moderation policy. Profanity will be filtered. Abusive conduct is not allowed.

More from the article ...

... The new user activity tracking method exploits how WhatsApp or Signal messaging protocols work at the fundamental level -- it abuses delivery receipts to calculate the signal round-trip time (RTT).

Apparently, anyone can ping your device, the app will respond, and the RTT will vary wildly depending on what the phone is doing and whether it is using WiFi or mobile data.

Security researchers first described this vulnerability, dubbed "Silent Whisper," in a paper released last year.

"An adversary can craft stealthy messages that enable probing a target at high frequency (up to sub-second granularity) while not causing any notification at the target side and also in the absence of an ongoing conversation," warned researchers from Gegenhuber et al., University of Vienna & SBA Research.

However, now one cybersecurity researcher, operating under the alias "gommzystudio" on GitHub, has released a proof-of-concept tool that demonstrates how easy it is to track sensitive user activity.

"A phone number can reveal whether a device is active, in standby, or offline (and more)," the developer writes.

However, now one cybersecurity researcher, operating under the alias "gommzystudio" on GitHub, has released a proof-of-concept tool that demonstrates how easy it is to track sensitive user activity.

"A phone number can reveal whether a device is active, in standby, or offline (and more)," the developer writes. ...


#1 | Posted by LampLighter at 2025-12-14 07:52 PM | Reply

Considering the reported use of Signal by Sec Hegseth, this could be concerning.

#2 | Posted by LampLighter at 2025-12-14 08:46 PM | Reply

The following HTML tags are allowed in comments: a href, b, i, p, br, ul, ol, li and blockquote. Others will be stripped out. Participants in this discussion must follow the site's moderation policy. Profanity will be filtered. Abusive conduct is not allowed.

Anyone can join this site and make comments. To post this comment, you must sign it with your Drudge Retort username. If you can't remember your username or password, use the lost password form to request it.
Username:
Password:

Home | Breaking News | Comments | User Blogs | Stats | Back Page | RSS Feed | RSS Spec | DMCA Compliance | Privacy

Drudge Retort