Israeli Cybersecurity Firm Says Whatsapp Flaw Allows Hacking of Messages

Check Point says weakness in popular messaging app enables attackers to modify and send false missives to individuals and groups.

Check Point says weakness in popular messaging app enables attackers to modify and send false missives to individuals and groups.

It said the flaw allows bad actors to use the ‘quote’ feature in a group conversation to change the identity of the sender, even if that person is not a member of the group; to alter the text of someone else’s reply, essentially putting words in their mouth; to send a private message to another group participant that is disguised as a public message for all, so when the targeted individual responds, it’s visible to everyone in the conversation.

Hackers could use such weaknesses for various criminal activities, causing personal and financial harm to users worldwide.

Check Point’s Oded Vanunu said the company had notified WhatsApp of the issues, but the latter had responded that it could not immediately fix the matter due to the way the app is constructed.

“Since people have been murdered in India and Brazil due to fake WhatsApp messages, and since WhatsApp is admissible evidence in courts around the world, we decided we couldn’t keep it to ourselves,” he said. 

“WhatsApp has long since stopped being simply an app — it has become an infrastructure that serves institutions, organizations, schools and industry.” 

Check Point could not say whether the flaws had been taken advantage of thus far.
Women pressing their phones
A WhatsApp spokesperson said: “We carefully reviewed this issue and it’s the equivalent of altering an e-mail to make it look like something a person never wrote.

“This claim has nothing to do with the security of end-to-end encryption, which ensures only the sender and recipient can read messages sent on WhatsApp.” 

The app noted it recently placed a limit on forwarding content, added a label to forwarded messages, and made a series of changes to group chats in order to tackle the challenge of misinformation. 

The report of the flaw comes as the Facebook-owned company is coming under increasing scrutiny as a means of spreading misinformation due to its popularity and convenience for forwarding messages to groups. 

Last month, the app announced limits of forwarding messages following threats by the Indian government to take action after more than 20 people were butchered by crazed mobs after being accused of child kidnapping and other crimes in viral messages circulated wildly on WhatsApp. 

Founded in 2009 and purchased by Facebook in 2014, WhatsApp said that at the beginning of the year it had more than 1.5 billion users who exchanged 65 billion messages per day.


Read original article at Times Of Israel

COMMENTS

Name

Africa,13,Android,10,app,17,App of the week,12,Apple,1,Arts,1,Bitcademy,2,Blockchain,2,Crypto,1,Data Security,11,Developer,2,Facebook,4,Fintech,1,Games,1,Gmail,1,Google,10,How Tos,16,instagram,1,iOS,3,Mac,1,News,57,Photo,2,programming,4,Reviews,33,Rwanda,1,tech,7,Twitter,2,WhatsApp,1,YouTube,1,
ltr
item
ROTechnica: Israeli Cybersecurity Firm Says Whatsapp Flaw Allows Hacking of Messages
Israeli Cybersecurity Firm Says Whatsapp Flaw Allows Hacking of Messages
Check Point says weakness in popular messaging app enables attackers to modify and send false missives to individuals and groups.
https://images.pexels.com/photos/46924/pexels-photo-46924.jpeg?cs=srgb&dl=app-apple-chat-46924.jpg&fm=jpg
https://i.ytimg.com/vi/rtSFaHPA0C4/0.jpg
ROTechnica
https://www.rotechnica.com/2018/09/israeli-cybersecurity-firm-says.html
https://www.rotechnica.com/
https://www.rotechnica.com/
https://www.rotechnica.com/2018/09/israeli-cybersecurity-firm-says.html
true
4516553652693735627
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy