Monday, 02 March 2020 05:18

WhatsApp security: Is this hidden flaw a new reason to quit?

Rate this item
(0 votes)

Consumer-friendly and encrypted, WhatsApp is one of the most popular apps in use today with a whopping 1.5 billion users. But over recent months, an increasing number of questions are being raised about the encrypted app’s security. 

Sure, WhatsApp is end-to-end encrypted, but the most recently discovered flaw doesn’t affect that aspect of the service. Last week, I detailed how WhatsApp group chats are easily found via a Google search, because the search engine was indexing links to conversations intended to be private. 

Privacy advocates were soon up in arms as tech site Vice found phone numbers belonging to 48 participants in a group chat between non-governmental organizations accredited by the United Nations. 

But suddenly, the links to chats were no longer available on Google. A source told me this is due to a quiet change made by WhatsApp owner Facebook, which prevented the conversations being indexed by Google. 

Links to chats are still available–and a new report finds some sensitive groups online

It was a welcome move, albeit one performed without transparency. However, the links to WhatsApp chats are still available on other search engines. Worse, Facebook told the security researcher who found this issue, @HackrzVijay that the problem is an “intentional product decision”, and group admins “can invalidate the link if so desired.”

This problem isn’t going away. The multimedia journalist for the German outlet Deutsche Welle, Jordan Wildon, who first found this issue, has this week revealed that over 60,000 groups still accessible online. 

The article details how a security researcher, Lav Kumar discovered the information was still being stored on publicly available internet archives. Wildon tested a randomly selected 1,000 of the unique links and found nearly half were active chats. 

“Even without actively joining a group, its title, description, image and creator's phone number are available for all,” the article reads. Worse, when entering a group, “it is possible to also see the phone numbers of up to 256 participants, as well as other information, and adding these numbers to one's contacts can reveal their names in the app.”

WhatsApp told DW in a statement: "We show all numbers in groups for people's safety that way they know who will receive their messages." 

However, the WhatsApp “feature” is not always that safe. Wildon found groups including people who might be in danger if their identity was revealed. For example, one chat containing hundreds of members was labelled as an LGBTQ+ group based in a Latin American country with a high rate of homophobic members.

I have contacted Facebook owner WhatsApp for comment and will update this story if I hear back.

A new reason to leave WhatsApp?

WhatsApp is owned by Facebook, which is integrating the messaging service at the back end with Facebook Messenger and Instagram. The move is intended to support the end-to end-encryption needed for secure communications, but many see it as a cause for concern.

Big organizations have already started to move away from WhatsApp. If you use the group function for work chats, you’d be very sensible to look elsewhere. The EU is already doing this, banning WhatsApp and instructing staffers to use Signal, and a mysterious other app for secure communications.

You can try and secure your group chats using this advice from Wildon, who recommends going into group settings, tapping “Invite to Group via Link” then “Reset link.” This doesn’t turn the link off: it generates a new one. 

But the most secure thing you can do, if you care about your security at least in group chats, is to look at alternatives to WhatsApp, such as Signal and Wickr. Signal is adding a number of cool new features that will make the switch much easier. 

If it’s a business chat perhaps try out Wickr, while to speak to your friends, Signal is probably best. 

 

Compiled by Olalekan Adeleye

Forbes

April 26, 2024

Super tanker carrying 2m barrels of crude stranded on Nigerian waters due to payment issues…

Chinese state energy major PetroChina has been waiting to unload a cargo of U.S. crude…
April 25, 2024

Probe of El-Rufai begins as Kaduna Assembly orders for financial documents from Finance Ministry

The Kaduna State House of Assembly has requested the Ministry of Finance, Kaduna State to…
April 27, 2024

Adults are sharing the things they are no longer interested in now that they're older

It's natural for our preferences to change as we get older. So when asked, "What…
April 13, 2024

A new camera can undress people almost in real time—to send a message about AI

Nuca, a new deepfake camera, is an art project that shows how artificial intelligence can…
April 26, 2024

Residents flee as terrorists invade Niger communities in reprisal attacks

Gunmen attacked a military base in Allawa town, Niger State, causing residents to flee for…
April 27, 2024

What to know after Day 793 of Russia-Ukraine war

WESTERN PERSPECTIVE Russia attacks Ukraine's rail lines to disrupt supply of U.S. arms, source says…
April 15, 2024

Winning funding proposals written by generative AI: Should that matter to you?

Generative AI is getting better every day. We now have ChatGPT4, Claude 3, Gemini, Perplexity,…
April 10, 2024

Nigeria’s Super Falcons qualify for 2024 Olympics at South Africa’s expense

Super Falcons of Nigeria have qualified for the women’s football event of the 2024 Olympics…

NEWSSCROLL TEAM: 'Sina Kawonise: Publisher/Editor-in-Chief; Prof Wale Are Olaitan: Editorial Consultant; Femi Kawonise: Head, Production & Administration; Afolabi Ajibola: IT Manager;
Contact Us: [email protected] Tel/WhatsApp: +234 811 395 4049

Copyright © 2015 - 2024 NewsScroll. All rights reserved.