AI 中文总结
本研究发现主流端到端加密群聊信使无法保证转录一致性,恶意成员可篡改内容,还揭示了相关设计与实现问题,并提出低开销缓解措施。
AI 中文摘要
端到端加密(E2EE)消息应用因安全性广受赞誉,也被用于群聊中的敏感协调(如政治决策者的协作)。继Threema和WhatsApp之后,Signal和iMessage近期也推出了投票功能以辅助群组达成共识。这隐含地让用户期望所有参与者看到相同的结果,即对对话有一致的视图,该属性被称为转录一致性(TC)。本研究表明,当前主流E2EE信使无法为群聊提供任何形式的TC保障,恶意群成员可选择性向不同接收者省略、重排或呈现篡改内容,且不会在用户界面触发警告。我们在针对共享转录完整性或用户关联设备间不一致交付的恶意参与者威胁模型下,系统研究了该问题的严重程度,识别出从协议回退路径到群组内成对交付通道的多种歧义向量。我们展示了具体利用场景,如社会工程、规避审核,尤其是操纵投票。除这些跨服务设计问题外,我们还发现具有隐私影响的特定实现行为(如设备操作系统指纹识别)。最后,我们将研究结果置于先前转录一致性研究的背景下,概述了可集成到先进E2EE群组协议中的低开销实用缓解措施及UI信号策略。
英文摘要
End-to-end encrypted (E2EE) messaging apps are widely praised for their security and thus also used for sensitive coordination in group chats (e.g., by political decision makers). After Threema and WhatsApp, also Signal and iMessage have recently introduced polls to aid agreement processes in groups. This implicitly sets the expectation that all participants see the same outcome and thus have the same view of the conversation. This property is commonly referred to as transcript consistency (TC). In this work, we demonstrate that today's major E2EE messengers do not guarantee any form of TC for group chats, allowing a malicious group member to selectively omit, reorder, or present altered content to different recipients without triggering warnings in their user interface. We systematically investigate the extent of the problem under a malicious-participant threat model that targets the integrity of the shared transcript, or inconsistent delivery across a user's linked devices. We identify multiple equivocation vectors that range from protocol fallback paths to deliberate use of pairwise delivery channels within groups. We demonstrate concrete exploitation scenarios such as social engineering, evading moderation, and, in particular, rigging polls. Beyond these cross-service design issues, we also uncover implementation-specific behaviors with privacy implications (e.g., device OS fingerprinting). Finally, we contextualize our findings within prior transcript-consistency research and outline practical low-overhead mitigations and UI signaling strategies that can be integrated into state-of-the-art E2EE group protocols.
CommentsAccepted to USENIX Security 2026; Artifacts available at https://github.com/sbaresearch/transcript-consistency
Journal refUSENIX Security 2026