Refusals That Reveal: Server-Enforced Teen Contact Policies and Their Age-Inference Side Channels in a Production Social Platform
Platforms that admit teenagers increasingly restrict who may contact them: Instagram limits teen accounts to messages from people they follow, and TikTok disables direct messages for users under 16. We show that such protections, if implemented naively, can themselves disclose which accounts belong to minors. We present the child-safety architecture of Kibhi (kibhi.com), a production short-video and messaging platform for users aged 13 and over whose web and Android clients share one API, in which every contact rule is enforced at the server. We define refusal indistinguishability, the requirement that a refusal caused by a protected user's age be indistinguishable in content, status, and latency from refusals any user can trigger, and give a taxonomy of seven age-inference side channels in contact APIs. An attack suite that drives the real HTTP API as a malicious client found two oracles in the deployed system. First, refusals to teens were uniquely worded. Second, after the wording was fixed, a teen's call refusal still took 96 ms longer than a block, letting one probe identify a teen with 96% accuracy. Correcting the call path alone moved the leak to direct messages, where teens' refusals became 41 ms faster. After all paths were made constant-work, refusal latencies were statistically indistinguishable (direct messages p = 0.99, calls p = 0.45) and the suite passed 13 of 13 checks. We also enumerate every server route that creates contact, quantify contact-discovery enumeration (an unkeyed hash of every North American number inverts in about five hours on one laptop core; a new daily cap cuts per-account API probing by 98.75%), and map the design to COPPA and the U.K. Age Appropriate Design Code. The attack and conformance suites are released for reuse.
Authors
- Tafadzwa Tauro
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-05
- DOI
- https://doi.org/10.5281/zenodo.23147335
- Primary Topic
- Privacy, Security, and Data Protection
- Type
- preprint