Categories: Digital LifeNews

Be careful what you share on WhatsApp, it may not be as secure as you think

WhatsApp is easily the application I use the most on a daily basis on my smartphones. I use it for work, I use it to reconnect, and I use it to send silly memes to silly people all the time.

Odds are, WhatsApp’s probably super important to you too. But when something’s very important, there will be people who will want to exploit it for malicious purposes — especially considering the amount of information that gets shared via WhatsApp. And the bad news is that these bad people may have a way in if you’re not careful.

It’s easy to lull yourself into a false sense of security when using WhatsApp, especially after the company rolled out end-to-end encryption in all forms of communication across their entire platform. However, a group of researchers found a flaw in WhatsApp that could potentially be a gate into your secure conversations: Group chats.

Yup. According to the researchers, anyone who has control over WhatsApp’s servers could insert new members into private group chats without the permission of the group’s administrator. TechCrunch reports that the flaw takes advantage of “a bug in how WhatsApp handles group chats”. Because only the administrator of a group can invite new people in, WhatsApp doesn’t use any authentication mechanism for invitations that “its own servers cannot spoof”.

This means that once an attacker gains access to WhatsApp’s servers, they can insert themselves into groups, gaining access to any future messages in the group. That said, they won’t be able to read messages sent prior to them joining the group.

Tech Crunch also reports that attackers with access to WhatsApp’s servers could selectively block any messages in the group, preventing participants from warning the others of the intruder.

While this could potentially be a not insignificant vulnerability, the attackers would first have to hack into WhatsApp’s servers, which is no easy task. Cybersecurity company Kaspersky Lab’s security researcher Victor Chebyshev said that hacking Whatsapp’s servers is “not easy from a technical perspective” and that it “takes a lot of time and effort”. Victor says that it’s far easier for attackers to hack and gain control of a group chat member’s mobile device than it is to hack the servers.

Nevertheless, you should be careful with the information you share in WhatsApp group chats. One way would be to pay close attention to the members of your group and verify their security code for extra security. Administrators should also monitor and manually control the addition of new members.

If you absolutely must share sensitive information like passwords or pictures of your junk (why are you doing this in a group chat, btw), do so via private messaging instead.

Recent Posts

Budget 2027: Malaysian Highway Authority to deploy 50 EV charging stations?

The Malaysian Highway Authority (LLM) will deploy 50 EV charging stations next year. This was…

21 hours ago

Anker Soundcore AeroClip 2 with Guinness-certified speech clarity arrived in Malaysia at RM729

Anker has officially introduced its latest open-ear clip-on earbuds to the Malaysian market: the Soundcore…

22 hours ago

Garmin Enduro 4: 1.4-inch MIP display, up to 320 hours of battery life; available on 30 October at RM3,899

Garmin Malaysia has officially announced the Enduro 4, its latest ultra-performance GPS smartwatch designed specifically…

22 hours ago

Spotify Audiobooks with over 350,000 audiobooks coming to Malaysia later this year

Good news for local bookworms: Spotify Audiobooks is finally coming to Malaysia. The feature is…

23 hours ago

Garmin Approach S72 Malaysia: 1.4-inch AMOLED display, ComfortFit band, up to 16 days of battery life for RM3,599

Garmin Malaysia has introduced its latest flagship golf smartwatch, the Garmin Approach S72, which hits…

24 hours ago

Infinix Smart 20e arrives with military-grade shock resistance and IP64 rating, priced from RM499

Infinix has officially launched the SMART 20e in Malaysia and it is their new entry-level…

24 hours ago

This website uses cookies.