Cybersecurity Agency Finds Technique to Alter WhatsApp Messages
von Satoshi Nakamoto

SAN FRANCISCO — A cybersecurity firm mentioned it had found a flaw in WhatsApp, the Fb-owned messaging service with 1.5 billion customers, that enables scammers to change the content material or change the identification of the sender of a beforehand delivered message.
By making a hacked model of the WhatsApp utility, scammers can change a “quote” — a characteristic that enables individuals inside a chat to show a previous message and reply to it — to provide the impression that somebody despatched a message they didn't really ship, in keeping with the corporate, Test Level Software program Applied sciences.
WhatsApp acknowledged that it was doable for somebody to control the quote characteristic, however the firm disagreed that it was a flaw. WhatsApp mentioned the system was working because it had meant, as a result of the trade-offs to stop such a deception by verifying each message on the platform would create an infinite privateness threat or lavatory down the service. The corporate mentioned it labored to search out and take away anybody utilizing a faux WhatsApp utility to spoof the service.
“We rigorously reviewed this concern and it’s the equal of altering an e mail,” Carl Woog, a spokesman for WhatsApp, mentioned in an announcement. What Test Level found had nothing to do with the safety of WhatsApp’s so-called end-to-end encryption, which ensures solely the sender and recipient can learn messages, he mentioned.
WhatsApp has 1.5 billion customers on its platform, making it the world’s most generally used messaging app. It has gained reputation for the simplicity and safety of its service, offering encryption in order that even the corporate doesn't know the content material of its customers’ messages. Fb acquired WhatsApp in 2014 for $19 billion.
However it has come below hearth in current months for the unfold of misinformation on its platform. In India, false rumors about youngster kidnappers circulating by way of WhatsApp led to mob violence. In Brazil, false stories about deadly reactions to vaccines for the yellow fever spread over the messaging service.
Mr. Woog of WhatsApp said the company was taking “the challenge of misinformation seriously,” putting limits on how widely a message can be shared to different groups and attaching labels when a message has been forwarded. However, WhatsApp said the issue raised by Check Point was unrelated to its efforts to curb misinformation.
Oded Vanunu, head of vulnerability research at Check Point, said the ability to alter messages gave attackers a powerful tool to spread misinformation from what appeared to be a trusted source. It is especially problematic in group chats, which can include up to 256 people. Multiple messages can come in at once and it can be easy to lose track of what someone has said, he said.
“The public relies on the integrity of the message,” said Mr. Vanunu. “WhatsApp needs to adjust to prevent this simple manipulation.”
For now, the issue appears limited to a discussion among security experts. Both WhatsApp and Check Point Software said they had not seen regular users creating fake quote messages in chats.
Check Point said it also discovered a way within group chats to send a message to a specific individual within the discussion. That individual is tricked into believing that the whole group saw the message and responds accordingly.
WhatsApp played down the concerns raised by Check Point, saying most people know the person who they are messaging on the service. The company said 90 percent of all messages on the service are sent in one-on-one conversations, and the majority of groups are six people or less — making it less likely that an unknown person can infiltrate a conversation to trick other users.
A person can check the validity of a quote message by clicking on it. Doing so will take you back to the point in the chat when the message was sent unless the message was deleted or the person was not a participant in the chat when the message was sent.
WhatsApp said the potential fixes to this issue were not worth trying. One solution would be to create transcripts of every message exchange to verify the accuracy of every quote. Creating such a transcript is a significant privacy risk because those accounts of what people wrote to each other must be stored somewhere, the company said.
Follow Daisuke Wakabayashi on Twitter: @daiwaka
A model of this text seems in print on , on Web page B3 of the New York version with the headline: Cybersecurity Agency Finds Technique to Alter WhatsApp Messages. Order Reprints | At present’s Paper | SubscribeSource link
Read the full article
Satoshi Nakamoto
Keine Verbindung
Verbindung wird wiederhergestellt
Etwas ist schiefgelaufen
Wir sind gleich wieder da