Welcome Guest! To access all forums & features, please register an account or sign-in. → Why register?



WhatsApp Accounts Almost Completely Unprotected


5 replies to this topic - - - - -

#1 Intrinsica

    Neowinian DOMINATING

  • 8,839 posts
  • Joined: 28-June 04
  • Location: Switzerland

Posted 08 October 2012 - 08:33

Quote

WhatsApp accounts almost completely unprotected

Tests performed by The H's associates at heise Security have found that popular texting alternative WhatsApp is easily hacked using freely available tools. Anyone using WhatsApp on a public Wi-Fi network risks having their data sniffed and their account used to send and receive messages. Once hacked, there is no way to restore account security – attackers will be able to continue to use the hacked account at their discretion.
Over the last week the lack of security inherent in WhatsApp's authentication has gradually become clear. Researchers have discovered that the client uses an internally generated password to log on to the server; this password is generated on Android devices from the device's serial number (IMEI) and on iOS devices from the MAC address of the Wi-Fi interface. The problem with this is that the information is anything other than secret – the IMEI can often be found on stickers inside of Android phones (usually under the battery) and can also be obtained using a shortcut key combination or by any app.
Source and more.

Considering the age of this article (14th September) I'm assuming this isn't news to anyone? I couldn't find a thread about it though, so figured I'd post to be sure.


#2 Neobond

    Steven Parker

  • 26,203 posts
  • Joined: 09-July 01
  • Location: Neowin HQ
  • OS: Windows 8 Pro

Posted 08 October 2012 - 08:48

Yeah I reported about this in August http://www.neowin.ne...one-marketplace

#3 +sanke1

    Member

  • 2,037 posts
  • Joined: 07-October 07

Posted 08 October 2012 - 08:51

Probably username and password based security may have to be implemented.

#4 OP Intrinsica

    Neowinian DOMINATING

  • 8,839 posts
  • Joined: 28-June 04
  • Location: Switzerland

Posted 08 October 2012 - 08:56

View PostNeobond, on 08 October 2012 - 08:48, said:

Yeah I reported about this in August http://www.neowin.ne...one-marketplace
Oh yeah. Although I'm surprised there isn't an update on this, is there? I thought Whatsapp was quite a widely used app?

#5 InsaneNutter

    Neowinian Wise One

  • 2,783 posts
  • Joined: 15-March 03
  • Location: Yorkshire, England
  • OS: Windows 8 - with ModernMix & Start 8
  • Phone: Galaxy Nexus - Android 4.2.2

Posted 08 October 2012 - 08:58

Now read that myself, however i was aware Whatsapp is very insecure.

Another interesting article from May this year: WhatsAppSniffer Shames WhatsApp's Plaintext, Unprotected Chat Transfer Protocol, Shows Off Just How Much Can Be Sniffed.

It looks like that was finally patched in August: WhatsApp no longer sends plain text

WhatsApp appear to be threating legal action over people creating tools that exploit the service: http://www.h-online....rs-1716912.html ... why not just secure it then surly such tools will be useless?!

#6 The Dark Knight

    Neowinian Senior

  • 1,766 posts
  • Joined: 06-June 04
  • OS: Windows 8 Pro x64
  • Phone: Nexus 4

Posted 08 October 2012 - 09:19

View PostInsaneNutter, on 08 October 2012 - 08:58, said:

WhatsApp appear to be threating legal action over people creating tools that exploit the service: http://www.h-online....rs-1716912.html ... why not just secure it then surly such tools will be useless?!

Because it is a lot easier to sue instead of improving your own stuff. :D

A certain other company is also famous for this. ;)