'WhatsApp security and encryption not ideal'

Advertisement
By Agence France-Presse | Updated: 22 February 2014 12:47 IST
'WhatsApp security and encryption not ideal'
The Facebook deal for WhatsApp drew attention for its whopping price tag, but has also brought out fresh criticism over security for the billions of messages delivered on the platform.

WhatsApp, which is to be acquired for $19 billion, says on its website that "communication between your phone and our server is fully encrypted."

The company warns users need to be aware that when they send messages, the recipient's device may not be secure. But it says it does not store any chat history and that messages are wiped off its system after delivery.

Yet security researchers and others point out that there may be vulnerabilities in the system used by some 450 million people globally.

Paul Jauregui at the security firm Praetorian said in a blog post Thursday that WhatsApp security and encryption are not ideal, citing vulnerabilities in the way it handles SSL, the secure socket layer protocol for communications.

Advertisement

The group's mobile security test "picked up on several SSL-related security issues affecting the confidentiality of WhatsApp user data that passes in transit to back-end servers," Jauregui said.

"This is the kind of stuff the NSA (National Security Agency) would love. It basically allows them - or an attacker - to man-in-the-middle the connection and then downgrade the encryption so they can break it and sniff the traffic. These security issues put WhatsApp user information and communications at risk."

Advertisement

Jauregui noted that Praetorian would need authorization from Facebook and WhatsApp to do a more thorough security evaluation.

He added that it would be "not very difficult" to patch the security flaws.

Advertisement

Serious Privacy Concerns
Meanwhile in Germany, the data commissioner in the state of Schleswig-Holstein, said in a statement this week the deal raises serious privacy concerns and that WhatsApp does not comply with European data protection rules.

The official, Thilo Weichert, said in a statement that people should opt out of WhatsApp for more "trusted services."

Last October, Dutch security researcher Thijs Alkemade posted a blog saying that the encryption can be circumvented, making it feasible "that anyone who is able to eavesdrop on your WhatsApp connection is capable of decrypting your messages, given enough effort."

WhatsApp did not respond to an AFP query on the security claims.

But some rival services say the Facebook-WhatsApp tie-up is likely to hurt confidence in the messaging app.

Nico Sell, co-founder of the security-focused app Wickr said it has seen "thousands more people than normal" downloading its app since Facebook's announcement.

"I think people will swap quickly out of WhatsApp now that it's part of Facebook," she told AFP.

Sell said Facebook's core business is monetizing data, while Wickr aims at protecting user anonymity and privacy, by using top-grade encryption and paying bounties to hackers who discover any security flaws.

'Tons of data vulnerable'
"They say they won't put ads on WhatsApp. But that doesn't mean they can't feed the beast with the data they are sitting on," she said. "There are tons of data that can be analyzed from conversations with your friends and family."

Sell said that in light of documents leaked about NSA surveillance in the past year, "people are becoming more aware of how easy it is to abuse your conversations and your data."

Serge Malenkovich at the security firm Kaspersky said however users should not panic over WhatsApp and Facebook.

"There are no new reasons to worry about messaging privacy," he said in a blog post.

"Honestly speaking, WhatsApp was never meant to be a true confidential messaging tool... confidential data shouldn't be sent unencrypted over standard communication channels, be it Facebook, WhatsApp or e-mail. Use dedicated security tools to protect your data from prying eyes."

But he said a bigger threat is scammers who send messages urging you to "confirm your WhatsApp account" or "opt out of Facebook ads inside WhatsApp."

"Those messages will definitely contain a malicious link and clicking on it may infect your device or lead you to a phishing page trying to steal personal data from you," Malenkovich said.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Canva Code Review: Vibe Coding Meets Creative User Experience Design
  2. CMF Watch 3 Pro Launched With Up to 13 Days Battery Life: Price, Features
  3. Samsung Galaxy Z Fold 7 Pre-Orders Reportedly Outpace the Galaxy Z Flip 7
  4. BSNL Rs. 197 Prepaid Plan's Validity Reduced: Old vs. New Benefits
  5. Google Pixel 10 Pro Design Officially Revealed Ahead of August 20 Launch
  6. Honor Pad GT 2 Pro With 10,100mAh Battery Goes Official
  7. CMF Buds 2, CMF Buds 2 Plus Can Be Purchased for a Limited Time Today
  8. Vivo V60 Price in India, Features Tipped; Said to Launch on August 12
  9. ViewSonic X1-4K Pro, X2-4K Pro and SP7 Projectors Launched in India
  10. iQOO Neo 11 and Neo 11 Pro Key Specifications Tipped
  1. Samsung Galaxy Watch Ultra Gets One UI 8 Watch Update With Wear OS 6 Features
  2. AMD Unveils Stable Diffusion 3 Medium Model With Support for 4-Megapixel Image Generation on Ryzen AI Laptops
  3. Samsung Galaxy Z Fold 7 Reportedly Outpaces Galaxy Z Flip 7 in Pre-Orders in South Korea
  4. Lava Blaze Dragon 5G Price Range, Key Features Revealed Ahead of July 25 Launch in India
  5. Samsung Galaxy Z Fold 6 Price in India Slashed After Galaxy Z Fold 7 Launch
  6. Honor Pad GT 2 Pro With Snapdragon 8 Gen 3 SoC, 10,100mAh Battery Launched: Price, Specifications
  7. CMF Watch 3 Pro Launched With 1.43-Inch AMOLED Screen, Up to 13 Days Battery Life: Price, Features
  8. Netflix Reportedly Testing Runway’s AI Video Tools in Content Production
  9. Vivo V60 Could Launch in India on August 12; Key Specifications and Price Tipped
  10. iOS 18.6 Release Candidate Beta Released Alongside macOS 15.6 RC and More for Both Public and Developers
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.