WhatsApp flaw allows hackers to edit your messages and completely change what you sent

SHARE:

After discovering iOS flaws that let hackers break into iPhones by just sending a text, a WhatsApp flaw has been revealed by security resear...

After discovering iOS flaws that let hackers break into iPhones by just sending a text, a WhatsApp flaw has been revealed by security researchers at the Black Hat conference 2019. The Facebook-owned messaging app is used by 1.5 billion users across the world, and the discovered vulnerabilities can be used to exploit the platform to manipulate chat messages. In simpler terms, the flaw can literally be used to put “words into your mouth.” 

The vulnerabilities allow hackers to “intercept and manipulate messages sent in both private and group conversations, giving attackers the power to create and spread misinformation from what appear to be trusted sources,” the researchers noted. 

Details of the WhatsApp vulnerabilities were discovered by an Israeli cybersecurity firm Checkpoint Research on August 7 at the conference. However, the researchers said they alerted WhatsApp about the flaws in August last year, and the company addressed only one of the below-mentioned three vulnerabilities:

Use the ‘quote’ feature in a group conversation to change the identity of the sender, even if that person is not a member of the group. Alter the text of someone else’s reply, essentially putting words in their mouth. Send a private message to another group participant that is disguised as a public message for all, so when the targeted individual responds, it is visible to everyone in the conversation.

In the first case, something written by some other person could be changed to appear as if it was written by you. Moreover, in the second, something written by you can be edited and altered when quoted by anyone else in the group chat. However, the original tech remains unchanged, but anyone viewing the quoted text will see the altered version. This one has been demonstrated in the video at the end of this article. 

The third vulnerability relies on the fact that WhatsApp uses end-to-end encryption. Hence, a participant in the group can access the decrypted version of the messages. Basically, the researchers exploited the web version of WhatApp. As explained by TNW, “By obtaining the private and public key pair created before a QR code is generated, and the “secret” parameter that is sent by the mobile phone to WhatsApp Web while the user scans the QR code, the extension makes it easy to monitor and decrypt communications on the fly.”

According to Checkpoint Research, “WhatsApp fixed the 3rd vulnerability,” but “we found that it is still possible to manipulate quoted messages and spread misinformation from what appear to be trusted sources.” 

In a reply given to TNW, Facebook said, “We carefully reviewed this issue a year ago and it is false to suggest there is a vulnerability with the security we provide on WhatsApp. The scenario described here is merely the mobile equivalent of altering replies in an email thread to make it look like something a person didn’t write. We need to be mindful that addressing the concerns raised by these researchers could make WhatsApp less private — such as storing information about the origin of messages.”

The real-life exploitation will not be a major problem for most users, but the more people in a chat, the greater the threat. 

On Facebook’s end, the other two vulnerabilities could not be resolved due to “infrastructure limitations” on WhatsApp.

 



from Latest Technology News https://ift.tt/2YOWI5a

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: WhatsApp flaw allows hackers to edit your messages and completely change what you sent
WhatsApp flaw allows hackers to edit your messages and completely change what you sent
https://i.ytimg.com/vi/Ybr7DdXkGLo/hqdefault.jpg
https://i.ytimg.com/vi/Ybr7DdXkGLo/default.jpg
Genius Baba
https://geniusbabaa.blogspot.com/2019/08/whatsapp-flaw-allows-hackers-to-edit.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2019/08/whatsapp-flaw-allows-hackers-to-edit.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy