Categories: Cyber Security

WhatsApp Security Flaw: What Is It, & What Should You Do About It?

Everybody loves WhatsApp: it’s fun, convenient, and best of all, it provides end-to-end encryption for every conversation. Since this privacy feature was announced in 2016, the bar was raised for digital communication privacy across the industry, establishing WhatsApp as a company that prided itself on its security capabilities.

But recent research into the app’s group chat administration uncovered an unusual flaw that has a lot of users concerned. This flaw theoretically makes it possible for total strangers to be added to any group chat, defeating the purpose of those encrypted messages.

Before you uninstall WhatsApp from your phone, let’s take a closer look at this security flaw—and what you can do about it.

A fatal flaw?

One of the trickiest aspects of encryption for WhatsApp has always been the group chat feature. Ensuring that a secure series of messages with multiple recipients is only shared with its intended audience and remains safe from infiltration—this was paramount to WhatsApp’s promises about high-end security. It’s no small feat, and the company may have overlooked a strange potential flaw.

Earlier this month at the Real World Crypto security conference in Zurich, Switzerland, a group of German cryptographers from Ruhr University Bochum revealed that anyone who has access to or controls WhatsApp’s servers could easily insert a new user into any private group.

Technically, only an administrator is allowed to invite new members into a group. But WhatsApp doesn’t currently have a mechanism in place for invite authentication. This means that using the server to spoof an invitation would allow the addition of new members to the group—without the approval of an administrator. The smartphones of other members in the group would then automatically share secret keys with the newly added individual, providing them full access to all future communications.

Even more concerning, the researchers discovered methods of delaying the detection of a new participant in the group by caching messages and blocking communications warning of an intrusion.

WhatsApp has over a billion users, so it’s no surprise that people are worried. But what does this security flaw really mean for you?

Staying secure

In a statement published in WIRED, a WhatsApp spokesperson advised users that they’ll still receive a notification when an unknown user joins a group chat, making it easy to spot an intruder. The company has also stated that the flaw is just theoretical.

Since an intruder can only enter through a server, the chances of a breach occurring without WhatsApp’s knowledge are reduced. But some worry that this flaw could be exploited by official bodies demanding access to data from encrypted group chats. For those who use the messaging system to send sensitive communications, that’s a big concern.

From infiltrated group chats to hacked emails and more, top-notch data security is more important now than ever. We can help. Contact the data security professionals at eMazzanti today to find out more about keeping your most sensitive data safe and sound.

eMazzanti Technologies

Recent Posts

How to Manage Remote Workers

With a global customer base, eMazzanti Technologies positions engineers and project managers in various locations…

4 years ago

Tips for Transitioning to Remote Work

Over a period of three weeks, most of the workforce in the United States found…

4 years ago

Collaborate with Exceptional Security and Privacy Using Microsoft 365 for Remote Work

Three years ago, Microsoft launched Teams, a powerful component of Office 365 (now Microsoft 365),…

4 years ago

You Look Marvelous! The Sprint to Video-based Team Interaction

In our new work-from-home (WFH) world, the requirement for on demand video conferencing has exploded…

4 years ago

5 Endpoint Security Best Practices When Remote Work Takes Center Stage

With the majority of employees working from home this spring, organizations have encountered new challenges.…

4 years ago

Cloud-based Security Solutions Deliver Powerful, Scalable Protection for SMBs

The average small to medium business (SMB) has most likely migrated at least some essential…

4 years ago