File‑Change Alerts May Expose User Behavior Across Major OS Platforms, Researchers Find
A new study has demonstrated that the mechanisms operating behind file‑change notifications on Windows, Linux and Android can inadvertently reveal details about a user’s activity, including the rhythm of keystrokes, web‑browsing patterns and the timing of WhatsApp media exchanges.
File‑change notification APIs – such as Windows’ ReadDirectoryChangesW, Linux’s inotify and Android’s FileObserver – are designed to inform applications when files or directories are modified, created, deleted or renamed. They are widely used by backup tools, security software and productivity apps to react quickly to changes without constantly scanning the file system.
The researchers behind the work, whose findings were first published on SecurityWeek, showed that the timestamps produced by these APIs can be correlated with user actions. By measuring the intervals between successive notifications, an observer can infer keystroke cadence, deduce when a browser loads a new page, or detect when a WhatsApp image or video is saved, even though the content itself remains encrypted.
Because the leakage does not require privileged access – any app that can subscribe to the notification feed can collect the timing data – the attack surface is broader than previously assumed. Malicious software could use the side‑channel to build a behavioral profile of a victim, potentially augmenting credential‑stealing or surveillance campaigns with high‑resolution activity cues.
Security experts have noted that the issue highlights a classic trade‑off between system responsiveness and privacy. While the notification services are essential for performance, the unintended exposure of timing information calls for mitigations such as adding jitter, restricting API access to trusted applications, or providing user‑controlled opt‑out mechanisms. Vendors have not yet issued formal patches, but the disclosure is expected to prompt reviews of default permission settings.
In the meantime, users are advised to limit the number of applications that request file‑system monitoring privileges and to keep devices updated with the latest security updates. As the research community continues to probe side‑channel vulnerabilities, the episode serves as a reminder that even low‑level system utilities can become vectors for privacy erosion if their design does not account for indirect data leakage.
Comments (0)
Be the first to comment.
Join the discussion