Skip to main content

To Possess or Not to Possess - WhatsApp for Android Revisited with a Focus on Stickers

  • Conference paper
  • First Online:
Secure IT Systems (NordSec 2023)

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 14324))

Included in the following conference series:

  • 225 Accesses

Abstract

WhatsApp stickers are a popular hybrid of images and emoticons that can contain user-created content. Stickers are mostly sent for legitimate reasons, but are also used to distribute illicit content such as Child Sexual Abuse Material (CSAM). As the process of creating stickers becomes easier for users from version to version, a digital forensic analysis is still lacking. Therefore, we present the first comprehensive digital forensic analysis of WhatsApp’s sticker handling on Android, with a special focus on the legal context, i.e. the definition of possession of illicit content. Our analysis is based on 40 scenarios that reflect the full lifecycle of community-created stickers. We show how the distribution channel of a sticker found on a device can be reconstructed, partially even when its traces have been removed from WhatsApp and are not visible through WhatsApp’s user interface. In addition, we show that Google Drive backups recover stickers, making device seizure dispensable; however, stickers can still be permanently deleted. Most importantly, we show that simply finding a sticker on a device is not sufficient to meet the requirements of the legal definition of possession. Therefore, prosecution for possession of a sticker requires additional evidence, which we provide.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 89.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 119.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Notes

  1. 1.

    Using: Android Studio Electric Eel | 2022.1.1 Patch 2.

  2. 2.

    https://www.whatsapp.com/android/?lang=en.

  3. 3.

    The deleted sticker in the respective chat is replaced by a button that allows the user to re-download a missing sticker.

  4. 4.

    Under the condition that the sticker is not used in another chat.

  5. 5.

    WhatsApp on Android 13 asks the user if “keep app data” is desired. Irrespective of the users’ choice on Android 13 the user stays in control of the sticker files.

References

  1. Anglano, C.: Forensic analysis of whatsapp messenger on android smartphones. Digit. Investig. 11(3), 201–213 (2014)

    Article  Google Scholar 

  2. Baden-Württemberg, L.: Strafbare inhalte bei whatsapp und co. Technical report, Polizei Baden-Württemberg (2019)

    Google Scholar 

  3. Casey, E.: Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet. Academic Press, Cambridge (2011)

    Google Scholar 

  4. Chang, Y.C.: Law and Economics of Possession. Cambridge University Press, Cambridge (2015)

    Book  Google Scholar 

  5. Europol: Operation chemosh: how encrypted chat groups exchanged emoji “stickers” of child sexual abuse (2019)

    Google Scholar 

  6. Fayyad-Kazan, H., Kassem-Moussa, S., Hejase, H.J., Hejase, A.J.: Forensic analysis of whatsapp sqlite databases on the unrooted android phones. HighTech Innov. J. 3(2), 175–195 (2022)

    Article  Google Scholar 

  7. Google: Mediastore (2023). https://developer.android.com/reference/android/provider/MediaStore#MEDIA_IGNORE_FILENAME

  8. Google: Webp container specification (2023). https://developers.google.com/speed/webp/docs/riff_container

  9. Horsman, G.: I didn’t see that! an examination of internet browser cache behaviour following website visits. Digit. Investig. 25, 105–113 (2018)

    Article  Google Scholar 

  10. Horsman, G.: Reconstructing streamed video content: a case study on youtube and facebook live stream content in the chrome web browser cache. Digit. Investig. 26, S30–S37 (2018)

    Article  Google Scholar 

  11. Howard, T.E.: Don’t cache out your case: Prosecuting child pornograpy possession laws based on images located in temporary internet files. Berkeley Tech. LJ 19, 1227 (2004)

    Google Scholar 

  12. International Centre for Missing & Exploited Children: Child sexual abuse material: Model legislation & global review (2018)

    Google Scholar 

  13. Karpisek, F., Baggili, I., Breitinger, F.: Whatsapp network forensics: decrypting and understanding the whatsapp call signaling messages. Digit. Investig. 15, 110–118 (2015)

    Article  Google Scholar 

  14. van Kesteren, M., van Eeten, M., van Wegberg, R.: CSAM data - factcheck of recent European commission statements (2023)

    Google Scholar 

  15. Klier, S., Varenkamp, J., Baier, H.: Back and forth – on automatic exposure of origin and dissemination of files on windows. Digit. Threats Res. Pract. (2023). https://doi.org/10.1145/3609232

  16. Marin, G.: Possession of child pornography: should you be convicted when the computer cache does the saving for you. Fla. L. Rev. 60, 1205 (2008)

    Google Scholar 

  17. Meng, C., Baier, H.: bring2lite: a structural concept and tool for forensic data analysis and recovery of deleted sqlite records. Digit. Investig. 29, S31–S41 (2019)

    Article  Google Scholar 

  18. Nemetz, S., Schmitt, S., Freiling, F.: A standardized corpus for sqlite database forensics. Digit. Investig. 24, S121–S130 (2018)

    Article  Google Scholar 

  19. Pawlaszczyk, D., Hummert, C.: Making the invisible visible-techniques for recovering deleted sqlite data records. Int. J. Cyber Forensics Adv. Threat Investig. 1(1–3), 27–41 (2021)

    Article  Google Scholar 

  20. Rösler, P., Mainka, C., Schwenk, J.: More is less: on the end-to-end security of group chats in signal, whatsapp, and threema. In: 2018 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 415–429. IEEE (2018)

    Google Scholar 

  21. Schmehl, K.: Whatsapp has become a hotbed for spreading nazi propaganda in Germany (2019). https://www.buzzfeednews.com/article/karstenschmehl/whatsapp-groups-nazi-symbol-stickers-germany. Accessed 28 May 2023

  22. Statista: Most popular global mobile messenger apps as of January 2022, based on number of monthly active users (2022). https://www.statista.com/statistics/258749/most-popular-global-mobile-messenger-apps/

  23. Statista: Most popular social networks worldwide as of January 2023, ranked by number of monthly active users (2023). https://www.statista.com/statistics/272014/global-social-networks-ranked-by-number-of-users/

  24. Sticker.ly: Sticker.ly - sticker maker (2023). https://play.google.com/store/apps/details?id=com.snowcorp.stickerly.android. Accessed 30 June 2023

  25. TcitNews: Whatsapp expanding features with in-app sticker creation capability (2023). https://tcitnews.com/whatsapp-expanding-features-with-in-app-sticker-creation-capability/. Accessed 10 July 2023

  26. WhatsApp: How to create stickers for whatsapp (2018). https://faq.whatsapp.com/1056840314992666/. Accessed 29 Mar 2023

  27. WhatsApp: Introducing stickers (2018). https://blog.whatsapp.com/introducing-stickers?lang=en

  28. YouTube: How to create your own whatsapp stickers with iphone | whatsapp sticker new update (2023). https://www.youtube.com/watch?v=0UG-JDt0-1o. Accessed 10 July 2023

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Samantha Klier .

Editor information

Editors and Affiliations

A Detailed Description of Executed Scenarios

A Detailed Description of Executed Scenarios

Table 4. Scenarios executed for this paper.

Rights and permissions

Reprints and permissions

Copyright information

© 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Klier, S., Baier, H. (2024). To Possess or Not to Possess - WhatsApp for Android Revisited with a Focus on Stickers. In: Fritsch, L., Hassan, I., Paintsil, E. (eds) Secure IT Systems. NordSec 2023. Lecture Notes in Computer Science, vol 14324. Springer, Cham. https://doi.org/10.1007/978-3-031-47748-5_16

Download citation

  • DOI: https://doi.org/10.1007/978-3-031-47748-5_16

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-031-47747-8

  • Online ISBN: 978-3-031-47748-5

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics