gommzystudio/device-activity-tracker: A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive de
A proof-of-concept tool demonstrates a privacy vulnerability in WhatsApp and Signal by measuring Round-Trip Time (RTT) of message delivery receipts to detect device activity states. By sending probe messages and analyzing response times, the tool can determine whether a device is actively in use, in standby mode, or offline, revealing user activity patterns. The implementation is based on academic research from the University of Vienna and includes both web and CLI interfaces. The project highlights significant privacy concerns in messaging apps that can be exploited for surveillance, though mitigation options like blocking unknown accounts provide limited protection.