Skip to content
General

Serious flaws have been discovered in WhatsApp

By Sarah Chen
2 min read
us it internet technology telecommunication facebo 46010783
us it internet technology telecommunication facebo 46010783
In this article (5)

During the Black Hat security conference held last week in Las Vegas, security researchers at Check Point discussed several flaws that they found in popular messaging app WhatsApp. The latter, as many of you probably already know, was acquired by Facebook in 2014 for a price north of $21 billion. One of the features that drive users to WhatsApp is its use of end-to-end encryption; this means that a message posted by a user cannot be read by anyone but the recipient. Even Facebook can’t see the message. But the flaws found by Check Point have some serious consequences for users.

The security team noted that one of the flaws it found in WhatsApp could allow a hacker to not just read a message sent by a member, but change the message as well. I would imagine that we don’t have to tell you the implications of this. Another flaw could allow a hacker to attribute a message to another person instead of the actual sender. Again, we don’t have to spell out the chaos that could result should some attacker actually exploit this vulnerability. After all, WhatsApp has over 1.5 billion users in more than 180 countries. By 2021, WhatsApp is expected to have 25.6 million users in the states.
Check Point also discovered that yet another flaw in WhatsApp could allow a hacker to disguise a public message as a private message. This could lull the recipient into thinking that his or her response will be private when in fact, it would be visible to others. When Check Point originally discovered these three issues last year and pointed them out to Facebook, the company was able to fix this particular problem although the first two flaws remain available for what Check Point calls “threat actors.”
So keep in mind that just because WhatsApp has end-to-end encryption, it doesn’t mean that there aren’t any flaws that can’t be exploited for evil reasons.

Questions & Answers

Q.

What specific types of message manipulation could a hacker perform using the identified flaws?

A.

A hacker could read and change a message sent by a user. They could also attribute a message to someone other than the actual sender, or disguise a public message as a private one.

Q.

When were these security issues first brought to Facebook's attention?

A.

Check Point originally discovered these three issues and pointed them out to Facebook last year. One specific problem was fixed by Facebook following this disclosure.

Q.

Which of the discovered flaws have been addressed by WhatsApp?

A.

Only one of the three flaws, where a public message could be disguised as private, has been fixed. The other two flaws concerning message alteration and false attribution remain unaddressed.

Q.

What was Facebook's response when these vulnerabilities were raised?

A.

Facebook stated they reviewed the issue a year ago and consider it false to suggest a vulnerability. They likened the scenario to altering email replies and expressed concern about compromising privacy.

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready