XCLUB-COOL STUFF AROUND YOU

 找回密码
 Register
查看: 344|回复: 1
打印 上一主题 下一主题

WhatsApp Flaw Allows an Attacker to Insert Someone into a Private Group Chat

[复制链接]

489

主题

9782

帖子

1万

积分

Golden Star LV21

20M2019Xclub Kolpost star1post star2sign star1sign star2sign star3sign star4X'Club badge exclusive for Nigeria

跳转到指定楼层
#1
发表于 2018-01-13 06:54:33 来自手机 | 只看该作者 |只看大图 回帖奖励 |倒序浏览 |阅读模式
[br] [br]End-to-end encrypted messaging technology is in demand, and WhatsApp implemented a solution from Open Whisper System’s a couple of years ago. But a new research paper shows there are some significant gaps in the Facebook-owned platform’s security.[br][br]At the recent Real World Crypto security conference in Zurich, Switzerland, cybersecurity analysts from Ruhr University Bochum in Germany presented a paper about security flaws in encrypted messaging apps including WhatsApp, Signal, and Threema. All three advertise secure and encrypted messaging, but the team’s findings undermined those claims to varying degrees.[br][br]The flaws the team discovered in Signal and Threema were relatively harmless, but WhatsApp’s vulnerabilities were cause for concern. According to the paper, anyone who controls WhatsApp’s servers can insert new people into an otherwise private group even without the permission of the administrator.  “[It’s] like leaving the front door of a bank unlocked and then saying no one will rob it because there’s a security camera,” Matthew Green, a researcher at Johns Hopkins University, told Wired. “It’s dumb.”[br][br]The bug has to do with how WhatsApp handles groups chats. The app doesn’t use an authentication mechanism for inviting new members to a group chat, which means that its servers can spoof said invitation. The spoofed invitation adds the new, uninvited person to the group chat and automatically shares secret keys with the member, giving him or her full access to any future messages.[br][br]It might not be the most effective way to eavesdrop on WhatsApp group conversations — you’d need access to WhatsApp’s servers, and any unexpected invitee is bound to attract suspicion. But here’s hoping for a quick patch all the same.
https://www.evutisblog.com.ng
回复

使用道具 举报

634

主题

9240

帖子

1万

积分

Security Supervisors

ever optimistic, chearfull guy and tech geek

Rank: 8Rank: 8

ACTIVE STARManMaster beta testerCOPYWRITERphotographersmoderatorsuper moderator2019Xclub Koldigest starpost star1sign star1post star2sign star2post star3sign star3sign star4

#2
发表于 2018-01-21 17:03:51 来自手机 | 只看该作者
very bad
回复

使用道具 举报

高级模式
B Color Link Quote Code Smilies |上传

本版积分规则

Infinix Official Website|Infinix official mall|infinix Note 4|XCLUB-COOL STUFF AROUND YOU

GMT+8, 2025-01-27 11:20 , Processed in 0.035752 second(s), 23 queries .

Powered by Discuz! X3.4

© 2001-2017 Comsenz Inc.

快速回复 返回顶部 返回列表