Researchers Find Critical Flaws in Popular Encrypted Messaging App Confide

Advertisement
By Sanket Vijayasarathy | Updated: 9 March 2017 16:10 IST
Highlights
  • The app is reportedly popular in the White House
  • Attackers can intercept messages and change its contents
  • Confide team has since reportedly fixed several flaws

While the world is still talking about the recent WikiLeaks reveal involving the CIA's hacking of Android and iOS devices, it looks like the White House is facing its own privacy issues. A recent report has revealed that the end-to-end encrypted messaging app, Confide, which has grown popular among White House officials under Trump's Administration, has some bugs that can render it potentially vulnerable.

Security researches at Seattle-based IOActive have discovered a number of critical flaws in the app that can allow hackers to intercept messages before the user decrypts them. The app's popularity is based on its military-grade encryption and the ability to self-destruct messages once read, leaving no trace of it on the Internet or server.

IOActive security researchers Mike Davis and Ryan O'Horo reported after an audit last month that an attacker could intercept the messages while they are in transit. If breached, the hacker can impersonate a user by hijacking their account or by guessing their password and gain access to the Confide user's address book. The attacker can also decrypt or change the contents of the message before it reaches the recipient.

Advertisement

The team at Confide have since reportedly fixed some of the flaws that were reported after the audit. As of now, it is still not known whether the flaws discovered have been used by hackers and whether some Confide users have been targeted already. The researchers were able to access around 7,000 Confide accounts, which included a member of Trump administration and some Department of Homeland Security employees.

Advertisement

Confide has said that "not only have these issues been addressed, but we also have no detection of them being exploited by any other party," in a statement to The Register.

Researchers at Axios last month revealed that a number of members in Trump's Administration have downloaded Confide. The disappearing message feature of the app also means that communication between the members cannot be archived, which is something that is mandatory for White House officials.

Advertisement

The recent WikiLeaks documents told us that the CIA had the tools to hack into messaging apps like WhatsApp, Telegram and others, if the underlying device that hosted them was hacked. With a supposedly "confidential messenger" app like Confide also facing privacy issues, there seems to be no app that is safe from being breached. This raises a serious concern as to how far users are left vulnerable and whether they are risking it all when communicating online.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Ultra Camera Configuration, Other Key Features Leaked
  2. Dominic and the Ladies' Purse OTT Release Date: When and Where to Watch it Online?
  3. Hogwarts Legacy Is Currently Free on Epic Games Store: How to Redeem
  4. The Game Awards 2025: See the Full List of Winners
  5. Nothing Phone 4a Series Price and Key Specs Tipped
  6. WhatsApp Brings a Voicemail-like Feature for Missed Voice and Video Calls
  7. The Rookie Season 7 OTT Release Date: When and Where to Watch it Online?
  8. Galaxy Mergers Can Switch On Supermassive Black Holes, Euclid Finds
  1. Astronomers Observe Star’s Wobbling Orbit, Confirming Einstein’s Frame-Dragging
  2. Galaxy Collisions Found to Activate Supermassive Black Holes, Euclid Data Shows
  3. JWST Detects Oldest Supernova Ever Seen, Linked to GRB 250314A
  4. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
  5. Blue Origin to Fly First Wheelchair User to Space on New Shepard NS-37
  6. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
  7. Sasivadane Now Streaming on Amazon Prime Video: Everything You Need to Know
  8. Kuttram Purindhavan Now Streaming Online: What You Need to Know?
  9. Lyne Lancer 19 Pro With 2.01-Inch Display, SpO2 Monitoring Launched in India
  10. OpenAI and Disney Reach Licensing Agreement to Bring Its Characters to the Sora App
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.