Skip to main content

Hackers may be able to access private WhatsApp conversations

Private conversations beware! Despite end-to-end encryption now being commonplace in WhatApp conversations, German cryptographers have discovered a minor flaw in WhatsApp’s security that could lead to private conversations being gatecrashed by uninvited hackers, bypassing the usual chat admin invitations.

In their paper, More is Less: On the End-to-End Security of Group Chats in Signal, WhatsApp, and Threema, presented to other enthusiasts at the Real World Crypto Symposium in Zurich, Switzerland, the team warned that WhatsApp has no security measures to stop invitations being spoofed from their own servers, leaving a hole that could leave millions of conversations at risk of being snooped on.

Recommended Videos

But it’s not all bad news. Essentially, the hacker would need to be in control of WhatsApp’s main chat servers — a fairly tall order — and only then would they be able to bypass the group’s administrator and insert users into any conversation. However, anyone who did manage to achieve this would then have near limitless power within the chat, being able to selectively block message visibility from accounts, and even block users from participating in the chat.

Please enable Javascript to view this content

However, Facebook-owned WhatsApp doesn’t seem to be too worried about the potential hole in its security. A WhatsApp spokesperson (speaking to Wired) admitted that the flaw was real, but pointed out that there was no way that the added user could be hidden and receive messages from the group. WhatsApp has built-in security measures that stop hidden users from being able to participate in group chats, and anyone who wanted to snoop on a particular chat would find their cover quickly blown when the client announced their arrival to everyone in the chat, making it an inefficient way to spy on users. What’s more, disabling the flaw would likely break the “Group Invite Link” feature that many group chats enjoy — implying that the security issue likely stems from this particular feature.

However, Matthew Green of Johns Hopkins University called WhatsApp’s response “dumb,, likening it to leaving a bank’s vault open and relying on a single security camera to deter criminals. If any really sensitive information was stored in that group chat, then the hacker would have access to it, making WhatsApp’s lauded encryption useless.

WhatsApp has been in the news multiple times for reasons of security. After making all messages sent on its platform fully encrypted in 2016, the chat company has faced criticism from U.K. lawmakers, while action taken by Brazil was of a more serious nature.

Mark Jansen
Mobile Evergreen Editor
Mark Jansen is an avid follower of everything that beeps, bloops, or makes pretty lights. He has a degree in Ancient &…
WhatsApp gets a chat redesign
WhatsApp on iPhone with new themes.

If you’re a fan of WhatsApp, we have some good news for you. The free messaging and video calling app now includes chat themes, which should make your experience a little more customized.

To make the change, go to the Chats menu in Settings. From there, select Choose a new wallpaper, then select one of the preset options under two subcategories: Light or Dark.

Read more
WhatsApp’s upcoming translation tool is a boon for non-obvious reasons
WhatsApp app icon appearing on a phone.

WhatApp might soon automatically detect and translate your text messages. If Meta's recent AI work is anything to go by, voice and video translations shouldn't be too far off. On the surface, it might seem like a simple translation tool, but there's more to it than meets the eye.

Just over a year ago, I reported on an app by the Indian government that is used to record attendance and pay over 150 million daily wage workers, who make as little as three dollars per day. Amid problems such as a laggy UI, poor internet connection, and lack of digital literacy, language emerged as a massive barrier in my interviews with these workers, who often travel hundreds of miles to seek work.

Read more
This music app is doing something different in the Apple App Store
The Practice Pro app.

The iOS App Store is awash with apps using subscriptions and in-app payments, but our attention has been drawn to a brand new release that goes back to the old way of doing things — charging a one-off payment. It’s such a rare approach, the company has even drawn attention to it in the app’s top features list.

The app is Practice Pro, a release from developers Dynamic App Design, and it is made to help musicians practice and improve with use. The studio claims it’s suitable for professional and amateur musicians due to its clever modular design. Using different widgets, the app can be set up to only include the practice tools relevant to you, a better option than either using multiple apps, or having a cluttered, unfocused menu.

Read more