Refusals That Reveal: Server-Enforced Teen Contact Policies and Their Age-Inference Side Channels in a Production Social Platform

Platforms that admit teenagers increasingly restrict who may contact them: Instagram limits teen accounts to messages from people they follow, and TikTok disables direct messages for users under 16. We show that such protections, if implemented naively, can themselves disclose which accounts belong to minors. We present the child-safety architecture of Kibhi (kibhi.com), a production short-video and messaging platform for users aged 13 and over whose web and Android clients share one API, in which every contact rule is enforced at the server. We define refusal indistinguishability, the requirement that a refusal caused by a protected user's age be indistinguishable in content, status, and latency from refusals any user can trigger, and give a taxonomy of seven age-inference side channels in contact APIs. An attack suite that drives the real HTTP API as a malicious client found two oracles in the deployed system. First, refusals to teens were uniquely worded. Second, after the wording was fixed, a teen's call refusal still took 96 ms longer than a block, letting one probe identify a teen with 96% accuracy. Correcting the call path alone moved the leak to direct messages, where teens' refusals became 41 ms faster. After all paths were made constant-work, refusal latencies were statistically indistinguishable (direct messages p = 0.99, calls p = 0.45) and the suite passed 13 of 13 checks. We also enumerate every server route that creates contact, quantify contact-discovery enumeration (an unkeyed hash of every North American number inverts in about five hours on one laptop core; a new daily cap cuts per-account API probing by 98.75%), and map the design to COPPA and the U.K. Age Appropriate Design Code. The attack and conformance suites are released for reuse.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-05
DOI
https://doi.org/10.5281/zenodo.23147335
Primary Topic
Privacy, Security, and Data Protection
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Refusals That Reveal: Server-Enforced Teen Contact Policies and Their Age-Inference Side Channels in a Production Social Platform

Tafadzwa Tauro
Zenodo (CERN European Organization for Nuclear Research)
Privacy, Security, and Data Protection
preprint

Refusals That Reveal: Server-Enforced Teen Contact Policies and Their Age-Inference Side Channels in a Production Social Platform

Tafadzwa Tauro
preprint en

Abstract

Platforms that admit teenagers increasingly restrict who may contact them: Instagram limits teen accounts to messages from people they follow, and TikTok disables direct messages for users under 16. We show that such protections, if implemented naively, can themselves disclose which accounts belong to minors. We present the child-safety architecture of Kibhi (kibhi.com), a production short-video and messaging platform for users aged 13 and over whose web and Android clients share one API, in which every contact rule is enforced at the server. We define refusal indistinguishability, the requirement that a refusal caused by a protected user's age be indistinguishable in content, status, and latency from refusals any user can trigger, and give a taxonomy of seven age-inference side channels in contact APIs. An attack suite that drives the real HTTP API as a malicious client found two oracles in the deployed system. First, refusals to teens were uniquely worded. Second, after the wording was fixed, a teen's call refusal still took 96 ms longer than a block, letting one probe identify a teen with 96% accuracy. Correcting the call path alone moved the leak to direct messages, where teens' refusals became 41 ms faster. After all paths were made constant-work, refusal latencies were statistically indistinguishable (direct messages p = 0.99, calls p = 0.45) and the suite passed 13 of 13 checks. We also enumerate every server route that creates contact, quantify contact-discovery enumeration (an unkeyed hash of every North American number inverts in about five hours on one laptop core; a new daily cap cuts per-account API probing by 98.75%), and map the design to COPPA and the U.K. Age Appropriate Design Code. The attack and conformance suites are released for reuse.

Zenodo (CERN European Organization for Nuclear Research)
Privacy, Security, and Data Protection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.