Researchers find privacy flaws in Chatroulette
IDG News Service - Perhaps there is finally something to deter Chatroulette.com users from their more offensive behavior: University researchers say that users of the popular video-chat site may not be as anonymous, or as private, as they think.
In a paper posted online this week, researchers from the University of Colorado at Boulder and McGill University outline three different types of attacks that could be launched against Chatroulette users.
Founded just last year by 17-year-old Russian entrepreneur Andrey Ternovskiy, Chatroulette links Web surfers randomly into one-on-one video chat conversations. The site has come under fire, however, because of nudity and inappropriate behavior.
The new research doesn't expose any gaping privacy holes, but showa how the service could be misused by determined criminals. For example, researchers describe a type of video phishing attack, where the criminals would simply play a video of an attractive woman who appears to be chatting with the victim, with audio disabled.
In a test, they were able to trick users into thinking they were actually chatting with a prerecorded video of a pretty woman. They did this by making the video choppy, as if it came from a low-bandwidth network and using text-based chat, instead of audio chat. Only one of the 15 users who chatted with the video asked the researchers to prove that it was of a real, live person. Otherwise, the researchers were regularly able to get people to chat for an hour using this technique.
The novelty and apparent intimacy of a chat session could make it easier to con people into friending scammers on Facebook or even visiting malicious Web sites, said Richard Han, an associate professor with the University of Colorado who co-authored the paper. "If you can present an attractive persona there," he said, "people start to trust the person on the other side and they lower their guard and they start to reveal information about themselves."
They also found a way to make Chatroulette's anonymous chats much less anonymous.
Because Chatroulette's back-end system shares user IP addresses, researchers were able to use IP-mapping services to get a general idea of user's location (a public Web site, called Chatroulettemap.com already does this). Then by searching Facebook using information obtained in chats and comparing pictures, researchers were able to identify chatters.
"Even in a city as big as Chicago, you can drill down and find the person you're actually talking to," Han said.
Privacy takes a hit too, in the paper.
Han and his team also believe that it would be easy to listen in on chat conversations by writing a simple computer program that could act as a middleman between Chatroulette conversations, connecting two users and recording what they say. Though Han believes it would be easy to do, his team didn't write the software to conduct this attack. "We did not implement this attack because we thought it was so dangerous," he said.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Privacy White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Privacy Webcasts