Pages

Showing posts with label WhatsApp. Show all posts
Showing posts with label WhatsApp. Show all posts

Wednesday, January 1, 2014

It’s a hoax

WhatsApp to start charging for every message you send? It’s a hoax


WhatsApp blueUsers of WhatsApp, the immensely popular instant messaging app for smartphones, are being duped into spreading a hoax message to their friends and contacts – claiming that the service will begin to charge for every message sent.
The messages say that WhatsApp will charge for each message from 31st December/1st January – and that to avoid charges, users have to forward the message to 10 of their contacts.
According to the hoax, if you follow the instructions the logo on your WhatsApp app will turn blue.
Here’s an example of one duped user, who appears to have entirely misunderstood the idea behind the hoax and shared it with her Facebook friends rather than her WhatsApp contacts:
WhatsApp hoax
31st Dec and 1st Jan whatsapp will become chargeable.
If you have at least 10 contacts.
Send them this messages.
In this way we will see that you are an avid user and your logo will become blue in color and remain free.
Send this messages thru your whatsapp column.
According to Hoax Slayer, other versions of the hoax include the following:
Saturday morning whatsapp will become chargeable. If you have at least 10 contacts send them this message. In this way we will see that you are an avid user and your logo will become blue and will remain free. (As discussed in the paper today. Whatsapp will cost 0.01€ per message. Send this message to 10 people. When you do the light will turn blue otherwise whatsapp activate billing.
The official WhatsApp blog has debunked the hoax, which appears to have been spreading since at least January 2012!
Once again, do your homework before forwarding messages like the hoax above to your internet friends. You are not only wasting time and bandwidth, you are also helping to perpetuate hoaxes that are hard to stamp out.

Wednesday, October 16, 2013

Whats App is not secure due to weak encryption policies

A serious vulnerability in WhatsApp allows anyone who is able to eavesdrop on WhatsApp connection to decrypt users' messages.

Whatsapp, the mobile application for instant messaging platform has become one of the main communication tools of the present day and its popularity makes it attractive for security researchers and hackers.

This time it is debated in the protection of the messages exchanged through the application, thanks to a vulnerability in the crypto implementation they can be intercepted by an attacker.

Thijs Alkemade is a computer science student at Utrecht University in The Netherlands who works on the open source Adium instant messaging project, during its research activity he disclosed a serious issue in the encryption used to secure WhatsApp messages.

In the post titled "Piercing Through WhatsApp’s Encryption" Alkemade remarked that Whatsapp has been plagued by numerous security issues recently, easily stolen passwords, unencrypted messages and even a website that can change anyone’s status.
"You should assume that anyone who is able to eavesdrop on your WhatsApp connection is capable of decrypting your messages, given enough effort. You should consider all your previous WhatsApp conversations compromised. There is nothing a WhatsApp user can do about this but expect to stop using it until the developers can update it." states the researcher.

An attacker sniffing a WhatsApp conversation is able to recover most of the plaintext bytes sent, WhatsApp uses RC4 software stream cipher to generate a stream of bytes that are encrypted with the XOR additive cipher.
Vulnerability in WhatsApp allows decrypting user messages
The mistakes are:
  • The same encryption key in both directions
  • The same HMAC key in both directions
Below the trick used by the researcher to reveal the messages sent with WhatsApp exploiting first issue:

WhatsApp adopts the same key for the incoming and the outgoing RC4 stream, "we know that ciphertext byte i on the incoming stream xored with ciphertext byte i on the outgoing stream will be equal to xoring plaintext byte i on the incoming stream with plaintext byte i of the outgoing stream. By xoring this with either of the plaintext bytes, we can uncover the other byte."

The technique doesn't directly reveal all bytes but works in many cases, another element that advantage the attacker is that messages follow the same structure and are easy to predict starting from the portion of plaintext that is disclosed.

The second issue related to the HMAC id more difficult to exploit, Alkemade said WhatsApp also uses the same HMAC key in both directions, another implementation error that puts messages at risk, but is more difficult to exploit.

The MAC is used to detect data alteration but it is not enough to detect all forms of tampering, the attacker potentially could manipulate any message.

"TLS counters this by including a sequence number in the plaintext of every message and by using a different key for the HMAC for messages from the server to the client and for messages from the client to the server. WhatsApp does not use such a sequence counter and it reuses the key used for RC4 for the HMAC."

Alkemade is very critical to the development team of the popular platform:
“There are many pitfalls when developing a streaming encryption protocol. Considering they don’t know how to use a xor correctly, maybe the WhatsApp developers should stop trying to do this themselves and accept the solution that has been reviewed, updated and fixed for more than 15 years, like TLS,” he said.

I agree with the thinking of the researcher, security for applications such as WhatsApp is crucial given its level of penetration, it is true that the interest of the scientific community and cybercrime will surely lead them to discover new vulnerabilities to which WhatsApp have to provide a quick solution.

Alkemade confirmed that there is no remediation for the flaw in this moment, that's why he suggest to stop using WhatsApp until developers produce a patch.


Read more: http://thehackernews.com/2013/10/vulnerability-in-whatsapp-allows.html#ixzz2hsut182j 
Follow us: @TheHackersNews on Twitter | TheHackerNews on Facebook

Proud Blogger

Powered By Blogger