{"id":284543,"date":"2017-01-13T11:45:19","date_gmt":"2017-01-13T11:45:19","guid":{"rendered":"http:\/\/citifmonline.com\/?p=284543"},"modified":"2017-01-13T11:45:19","modified_gmt":"2017-01-13T11:45:19","slug":"whatsapp-backdoor-allows-snooping-on-encrypted-messages","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/","title":{"rendered":"WhatsApp backdoor allows snooping on encrypted messages"},"content":{"rendered":"

A security backdoor that can be used to allow Facebook and others to intercept and read encrypted messages has been found within its WhatsApp messaging service.<\/p>\n

Facebook claims that no one can intercept WhatsApp messages, not even the company and its staff, ensuring privacy for its billion-plus users. But new research shows that the company could in fact read messages due to the way WhatsApphas implemented its end-to-end encryption protocol.<\/p>\n

Privacy campaigners said the vulnerability is a \u201chuge threat to freedom of speech\u201d and warned it can be used by government agencies to snoop on users who believe their messages to be secure. WhatsApp has made privacy and security a primary selling point, and has become a go to communications tool of activists, dissidents and diplomats.<\/p>\n

WhatsApp\u2019s end-to-end encryption relies on the generation of unique security keys, using the acclaimed Signal protocol, developed by Open Whisper Systems, that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman. However, WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages with new keys and send them again for any messages that have not been marked as delivered.<\/p>\n

The recipient is not made aware of this change in encryption, while the sender is only notified if they have opted-in to encryption warnings in settings, and only after the messages have been resent. This re-encryption and rebroadcasting effectively allows WhatsApp to intercept and read users\u2019 messages.<\/p>\n

The security backdoor was discovered by Tobias Boelter, a cryptography and security researcher at the University of California, Berkeley. He told the Guardian: \u201cIf WhatsApp is asked by a government agency to disclose its messaging records, it can effectively grant access due to the change in keys.\u201d<\/p>\n

The backdoor is not inherent to the Signal protocol. Open Whisper Systems\u2019 messaging app, Signal, the app used and recommended by whistleblower Edward Snowden, does not suffer from the same vulnerability. If a recipient changes the security key while offline, for instance, a sent message will fail to be delivered and the sender will be notified of the change in security keys without automatically resending the message.<\/p>\n

WhatsApp\u2019s implementation automatically resends an undelivered message with a new key without warning the user in advance or giving them the ability to prevent it.<\/p>\n

Boelter reported the backdoor vulnerability to Facebook in April 2016, but was told that Facebook was aware of the issue, that it was \u201cexpected behaviour\u201d and wasn\u2019t being actively worked on. The Guardian has verified the backdoor still exists.<\/p>\n

\n
\"The<\/picture><\/div>\n
Facebook<\/span>Twitter<\/span>Pinterest<\/span><\/div>
The WhatsApp vulnerability calls into question the privacy of messages sent across the service used around the world, including by people living in oppressive regimes. Photograph: Marcelo Say\u00e3o\/EPA<\/figcaption><\/figure>\n

Steffen Tor Jensen, head of information security and digital counter-surveillance at the European-Bahraini Organisation for Human Rights, verified Boelter\u2019s findings. He said: \u201cWhatsApp can effectively continue flipping the security keys when devices are offline and re-sending the message, without letting users know of the change till after it has been made, providing an extremely insecure platform.\u201d<\/p>\n

<\/div>\n

Boelter said: \u201c[Some] might say that this vulnerability could only be abused to snoop on \u2018single\u2019 targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the \u2018message was received by recipient\u2019 notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.\u201d<\/p>\n

The vulnerability calls into question the privacy of messages sent across the service, which is used around the world, including by people living in oppressive regimes.<\/p>\n

Professor Kirstie Ball, co-director and founder of the Centre for Research into Information, Surveillance and Privacy, called the existence of a backdoor within WhatsApp\u2019s encryption \u201ca gold mine for security agencies\u201d and \u201ca huge betrayal of user trust\u201d. She added: \u201cIt is a huge threat to freedom of speech, for it to be able to look at what you\u2019re saying if it wants to. Consumers will say, I\u2019ve got nothing to hide, but you don\u2019t know what information is looked for and what connections are being made.\u201d<\/p>\n

In the UK, the recently passed Investigatory Powers Act allows the government to intercept bulk data of users held by private companies, without suspicion of criminal activity, similar to the activity of the US National Security Agency uncovered by the Snowden revelations. The government also has the power to force companies to \u201cmaintain technical capabilities\u201d that allow data collection through hacking and interception, and requires companies to remove \u201celectronic protection\u201d from data. Intentional or not, WhatsApp\u2019s backdoor to the end-to-end encryption could be used in such a way to facilitate government interception.<\/p>\n

Jim Killock, executive director of Open Rights Group, said: \u201cIf companies claim to offer end-to-end encryption, they should come clean if it is found to be compromised \u2013 whether through deliberately installed backdoors or security flaws. In the UK, the Investigatory Powers Act means that technical capability notices could be used to compel companies to introduce flaws \u2013 which could leave people\u2019s data vulnerable.\u201d<\/p>\n

A WhatsApp spokesperson told the Guardian: \u201cOver 1 billion people use WhatsApp today because it is simple, fast, reliable and secure. At WhatsApp, we\u2019ve always believed that people\u2019s conversations should be secure and private. Last year, we gave all our users a better level of security by making every message, photo, video, file and call end-to-end encrypted by default. As we introduce features like end-to-end encryption, we focus on keeping the product simple and take into consideration how it\u2019s used every day around the world.<\/p>\n

\u201cIn WhatsApp\u2019s implementation of the Signal protocol, we have a \u201cShow Security Notifications\u201d setting (option under Settings > Account > Security) that notifies you when a contact\u2019s security code has changed. We know the most common reasons this happens are because someone has switched phones or reinstalled WhatsApp. This is because in many parts of the world, people frequently change devices and sim cards. In these situations, we want to make sure people\u2019s messages are delivered, not lost in transit.\u201d<\/p>\n

Asked to comment specifically on whether Facebook\/WhatApps had accessed users\u2019 messages and whether it had done so at the request of government agencies or other third parties, it directed the Guardian to its site that details aggregate data on government requests by country.<\/p>\n

Concerns over the privacy of WhatsApp users has been repeatedly highlighted since Facebook acquired the company for $22bn in 2014. In August 2015, Facebook announced a change to the privacy policy governing WhatsApp that allowed the social network to merge data from WhatsApp users and Facebook, including phone numbers and app usage, for advertising and development purposes.<\/p>\n

Facebook halted the use of the shared user data for advertising purposes in November after pressure from the pan-European data protection agency groupArticle 29 Working Party in October. The European commission then filed charges against Facebook for providing \u201cmisleading\u201d information in the run-up to the social network\u2019s acquisition of messaging service WhatsApp, following its data-sharing change.<\/p>\n

–<\/p>\n

Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"

A security backdoor that can be used to allow Facebook and others to intercept and read encrypted messages has been found within its WhatsApp messaging service. Facebook claims that no one can intercept WhatsApp messages, not even the company and its staff, ensuring privacy for its billion-plus users. But new research shows that the company […]<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[106],"tags":[],"yoast_head":"\nWhatsApp backdoor allows snooping on encrypted messages - Citi 97.3 FM - Relevant Radio. Always<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WhatsApp backdoor allows snooping on encrypted messages - Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"og:description\" content=\"A security backdoor that can be used to allow Facebook and others to intercept and read encrypted messages has been found within its WhatsApp messaging service. Facebook claims that no one can intercept WhatsApp messages, not even the company and its staff, ensuring privacy for its billion-plus users. But new research shows that the company […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/\" \/>\n<meta property=\"og:site_name\" content=\"Citi 97.3 FM - Relevant Radio. Always\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/citi97.3\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-13T11:45:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i.guim.co.uk\/img\/media\/8168bf0de13542fd709bb691c5a643feee74ec0c\/0_112_3364_2019\/master\/3364.jpg?w=300&q=55&auto=format&usm=12&fit=max&s=9f41080db8dc452455b00c48e7399c17\" \/>\n<meta name=\"author\" content=\"Kojo Akoto Boateng\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@citi973\" \/>\n<meta name=\"twitter:site\" content=\"@citi973\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kojo Akoto Boateng\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/\",\"url\":\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/\",\"name\":\"WhatsApp backdoor allows snooping on encrypted messages - Citi 97.3 FM - Relevant Radio. Always\",\"isPartOf\":{\"@id\":\"https:\/\/citifmonline.com\/#website\"},\"datePublished\":\"2017-01-13T11:45:19+00:00\",\"dateModified\":\"2017-01-13T11:45:19+00:00\",\"author\":{\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\"},\"breadcrumb\":{\"@id\":\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/citifmonline.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WhatsApp backdoor allows snooping on encrypted messages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/citifmonline.com\/#website\",\"url\":\"https:\/\/citifmonline.com\/\",\"name\":\"Citi 97.3 FM - Relevant Radio. Always\",\"description\":\"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/citifmonline.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1\",\"name\":\"Kojo Akoto Boateng\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/citifmonline.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g\",\"caption\":\"Kojo Akoto Boateng\"},\"url\":\"https:\/\/citifmonline.com\/author\/kojo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WhatsApp backdoor allows snooping on encrypted messages - Citi 97.3 FM - Relevant Radio. Always","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/","og_locale":"en_US","og_type":"article","og_title":"WhatsApp backdoor allows snooping on encrypted messages - Citi 97.3 FM - Relevant Radio. Always","og_description":"A security backdoor that can be used to allow Facebook and others to intercept and read encrypted messages has been found within its WhatsApp messaging service. Facebook claims that no one can intercept WhatsApp messages, not even the company and its staff, ensuring privacy for its billion-plus users. But new research shows that the company […]","og_url":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/","og_site_name":"Citi 97.3 FM - Relevant Radio. Always","article_publisher":"https:\/\/www.facebook.com\/citi97.3","article_published_time":"2017-01-13T11:45:19+00:00","og_image":[{"url":"https:\/\/i.guim.co.uk\/img\/media\/8168bf0de13542fd709bb691c5a643feee74ec0c\/0_112_3364_2019\/master\/3364.jpg?w=300&q=55&auto=format&usm=12&fit=max&s=9f41080db8dc452455b00c48e7399c17"}],"author":"Kojo Akoto Boateng","twitter_card":"summary_large_image","twitter_creator":"@citi973","twitter_site":"@citi973","twitter_misc":{"Written by":"Kojo Akoto Boateng","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/","url":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/","name":"WhatsApp backdoor allows snooping on encrypted messages - Citi 97.3 FM - Relevant Radio. Always","isPartOf":{"@id":"https:\/\/citifmonline.com\/#website"},"datePublished":"2017-01-13T11:45:19+00:00","dateModified":"2017-01-13T11:45:19+00:00","author":{"@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1"},"breadcrumb":{"@id":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/citifmonline.com\/2017\/01\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/citifmonline.com\/"},{"@type":"ListItem","position":2,"name":"WhatsApp backdoor allows snooping on encrypted messages"}]},{"@type":"WebSite","@id":"https:\/\/citifmonline.com\/#website","url":"https:\/\/citifmonline.com\/","name":"Citi 97.3 FM - Relevant Radio. Always","description":"Ghana News | Ghana Politics | Ghana Soccer | Ghana Showbiz","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/citifmonline.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/1642ef473fe39bf0c4e2f2f252678eb1","name":"Kojo Akoto Boateng","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/citifmonline.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ba51f5385119e83762c67ecd6aa410ab?s=96&d=mm&r=g","caption":"Kojo Akoto Boateng"},"url":"https:\/\/citifmonline.com\/author\/kojo\/"}]}},"_links":{"self":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/284543"}],"collection":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/comments?post=284543"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/posts\/284543\/revisions"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/media?parent=284543"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/categories?post=284543"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/wp-json\/wp\/v2\/tags?post=284543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}