News

WhatsApp Built Backdoor into its Encryption

WhatsApp, the Facebook-owned instant messaging app, features a security backdoor that allows the company to intercept and decrypt private messages sent through the platform, in flagrant contradiction of its previous stance that it employed end-to-end encryption. While WhatsApp uses encryption developed by Open Whisper Systems, the company behind end-to-end encryption SMS app Signal, the company has built in a protocol that allows the ability to generate new encryption keys for offline users, which then allows WhatsApp employees to access these messages.

The backdoor was found by University of California researcher Tobias Boelter, who reported the issue to Facebook last year. Facebook responded by assuring Boelter that the backdoor was “expected behaviour,” i.e. deliberate.

“If WhatsApp is asked by a government agency to disclose its messaging records, it can effectively grant access due to the change in keys,” Boelter told The Guardian.

“WhatsApp can effectively continue flipping the security keys when devices are offline and re-sending the message, without letting users know of the change till after it has been made, providing an extremely insecure platform,” said Steffen Tor Jensen, head of information security and digital counter-surveillance at the European-Bahraini Organisation for Human Rights, who verified Boelter’s findings.

“[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations,” Boelter added. “This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”

Boelter has made his findings public in the wake of the UK passing the most oppressive mass surveillance law in the history of democracy, the Investigatory Powers Act, which collects communications data for every resident of the country for up to twelve months.

Ashley Allen

Disqus Comments Loading...

Recent Posts

AMD Launches Ryzen 7 8745H Without AI Processor

AMD has launched (thanks Wccftech) its new Ryzen 7 8745H APU, a part of the…

8 hours ago

MSI to Release New BIOS to Fix Intel Core 13th and 14th Gen CPU Instability

MSI has announced a new BIOS update in mid-August to address stability issues with Intel’s…

9 hours ago

200+ PC Models Compromised Due to Weak BIOS Passwords

Many PC models from top brands have faced security breaches due to a weak BIOS…

9 hours ago

One Piece Odyssey Sets Sail On Nintendo Switch Today!

Ahoy, Straw Hat fans! The wait is finally over. The beloved RPG adventure, ONE PIECE…

13 hours ago

Görvitor Dimmable Wireless Touch Lamps

【Wireless & 1800mAh Battery Operated】Touch lamps bedside use a rechargeable large capacity battery of 1800mAh,…

14 hours ago

Lepro GU10 LED Bulbs

Click to open expanded view F Energy efficiency label  Product Sheet Lepro GU10 LED Bulbs, Warm White…

14 hours ago