WhatsApp Flaw Allows an Attacker to Insert Someone into a Private Group Chat...

 
 
 
WhatsApp Flaw Allows an Attacker to Insert Someone into a Private Group Chat...

 
xda-developers
Jan 12, 2018 2:25 AM • by Doug Lynch
WhatsApp Flaw Allows an Attacker to Insert Someone into a Private Group Chat

End-to-end encrypted messaging technology is in demand, and WhatsApp implemented a solution from Open Whisper System's a couple of years ago. But a new research paper shows there are some significant gaps in the Facebook-owned platform's security.

At the recent Real World Crypto security conference in Zurich, Switzerland, cybersecurity analysts from Ruhr University Bochum in Germany presented a paper about security flaws in encrypted messaging apps including WhatsApp, Signal, and Threema. All three advertise secure and encrypted messaging, but the team's findings undermined those claims to varying degrees.

The flaws the team discovered in Signal and Threema were relatively harmless, but WhatsApp's vulnerabilities were cause for concern. According to the paper, anyone who controls WhatsApp's servers can insert new people into an otherwise private group even without the permission of the administrator.  "[It's] like leaving the front door of a bank unlocked and then saying no one will rob it because there's a security camera," Matthew Green, a researcher at Johns Hopkins University, told Wired. "It's dumb."

The bug has to do with how WhatsApp handles groups chats. The app doesn't use an authentication mechanism for inviting new members to a group chat, which means that its servers can spoof said invitation. The spoofed invitation adds the new, uninvited person to the group chat and automatically shares secret keys with the member, giving him or her full access to any future messages.

It might not be the most effective way to eavesdrop on WhatsApp group conversations — you'd need access to WhatsApp's servers, and any unexpected invitee is bound to attract suspicion. But here's hoping for a quick patch all the same.


Source: Wired Source 2: PDF




Android Advices
Jan 10, 2018 10:12 AM • by Jennifer
CENTRiC L3 Smartphone with 5″ HD Display & 3050mAh Battery Launched in India

In the last couple of months, we have seen very few smartphones launches in the Sub Rs. 10,000 price range. Now, a new smartphone from CENTRiC Mobiles called CENTRiC L3 is launched in India. The latest CENTRiC L3 is priced at Rs. 6,749 and offers great value for money specifications. At this price, the device comes with a polycarbonate shell and we can't complain much about that. The CENTRiC L3 will be available in Quartz Grey and Raisin Black color options.

On the front is a 5-inch IPS Oncell display with HD (1280 x 720 pixels) resolution. There is also a 2.5D curved glass laid on the top. It also includes a 64-bit MediaTek MT6737 quad-core processor clocked at 1.3GHz and it comes coupled with Mali T720MP GPU. There is 2GB of RAM and 16GB of onboard storage. The CENTRiC L3 includes a dedicated MicroSD card slot for expanding the storage upto 256GB. It runs on Android 7.0 Nougat out of the box.

The device also supports dual SIM dual standby and offers VoLTE and ViLTE connectivity. In terms of optics, there is a 13MP shooter on the rear with LED flash and a 5MP shooter on the front for selfies. Both the cameras can record videos only upto 720p resolution. It is backed by a 3050mAh non-removable battery that is rated to give up to 23 hours of talk time and lasts up to 80 hours in standby mode. Beneath the display is the front-facing fingerprint sensor.

The CENTRiC L3 also includes 3-axis accelerometer, proximity, and light sensors. It measures 141 x 70.5 x 8.6 mm and weighs 143 grams. Connectivity options include 4G, Wi-Fi, Bluetooth 4.0, FM Radio, GPS, USB OTG, 3.5mm audio jack, and a MicroUSB 2.0 port. Instead of the capacitive navigation buttons, the smartphone comes with on-screen buttons. Compared to other smartphones in this price range, the CENTRiC L3 offers a bigger battery and better cameras. Let us know your opinion about this new CENTRiC smartphone by leaving a comment down below.




 
 

This email has been sent by Froze ONE (isnanmm0@gmail.com). It is the potion result of 'Tech: Topic watch' from the dashboard 'Personal Dashboard', tab 'Tech > Android'. Unsubscribe

 
 
 

Subscribe to receive free email updates:

0 Response to "WhatsApp Flaw Allows an Attacker to Insert Someone into a Private Group Chat..."

Post a Comment