{"id":13843,"date":"2017-01-13T11:17:47","date_gmt":"2017-01-13T16:17:47","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/?p=13843"},"modified":"2019-11-15T22:45:54","modified_gmt":"2019-11-15T11:45:54","slug":"fix-whatsapp-security-hole","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/fix-whatsapp-security-hole\/13843\/","title":{"rendered":"Security hole in WhatsApp and how to fix it"},"content":{"rendered":"<p>Friday the 13th is always a day that superstitious people look to find bad news tied to random events or actions, like a black cat crossing their path or breaking a mirror. However on some occasions, bad news can also break on such an \u201cunlucky\u201d day.<\/p>\n<p>Today, marks one of those occasions as <em>The Guardian<\/em> broke a story entitled <a href=\"https:\/\/www.theguardian.com\/technology\/2017\/jan\/13\/whatsapp-backdoor-allows-snooping-on-encrypted-messages\" target=\"_blank\" rel=\"noopener nofollow\">WhatsApp backdoor allows snooping on encrypted messages<\/a>. The story focuses on a reported security backdoor from researcher <a href=\"https:\/\/www.heise.de\/newsticker\/meldung\/WhatsApp-Bug-erlaubt-Einblick-in-verschluesselte-Nachrichten-3595611.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Tobias Boelter<\/a>.<\/p>\n<p>According to the exclusive in the Guardian:<\/p>\n<p><em>WhatsApp\u2019s end-to-end encryption relies on the generation of unique security keys, using the acclaimed Signal protocol, <a href=\"https:\/\/www.theguardian.com\/technology\/2016\/apr\/05\/whatsapp-rolls-out-full-encryption-to-a-billion-messenger-users\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">developed by Open Whisper Systems<\/a>, that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman. However, WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages with new keys and send them again for any messages that have not been marked as delivered.<\/em><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">How private is that private messenger really? <a href=\"https:\/\/t.co\/V7nGJpEikU\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/V7nGJpEikU<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/mobile?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#mobile<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/messenger?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#messenger<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/privacy?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#privacy<\/a> <a href=\"https:\/\/t.co\/WPESX5lR16\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/WPESX5lR16<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/819234856504881154?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">January 11, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><em>The recipient is not made aware of this change in encryption, while the sender is only notified if they have opted-in to encryption warnings in settings, and only after the messages have been re-sent. This re-encryption and rebroadcasting effectively allows WhatsApp to intercept and read users\u2019 messages.<\/em><\/p>\n<p>https:\/\/twitter.com\/FredericJacobs\/status\/819869917499588608<\/p>\n<p>While there are conflicts around whether this is a <a href=\"https:\/\/threatpost.com\/whatsapp-says-backdoor-claim-bogus\/123072\/\" target=\"_blank\" rel=\"noopener nofollow\">true bug<\/a>\u00a0or feature, the fact remains that this is something that users of WhatsApp can fix themselves. To do this, users need to do the following:<\/p>\n<p>Android: Press <em>Account<\/em>, then <em>Security<\/em>, and then click on <em>Show security notifications<\/em>.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2017\/01\/06021008\/whatsapp-security-notifications-android.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2017\/01\/06021008\/whatsapp-security-notifications-android-169x300.png\" alt=\"\" width=\"169\" height=\"300\" class=\"aligncenter size-medium wp-image-13854\"><\/a><\/p>\n<p>iOS: Click the cog in lower right, then press <em>Account<\/em> \u2192 <em>Security<\/em> \u2192 <em>Show security notifications<\/em>.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2017\/01\/06021007\/whatsapp-security-notifications-iphone.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2017\/01\/06021007\/whatsapp-security-notifications-iphone-169x300.jpg\" alt=\"\" width=\"169\" height=\"300\" class=\"aligncenter size-medium wp-image-13855\"><\/a><\/p>\n<p>If you receive the security alert below (iOS screenshot), and you are having a sensitive conversation and want to be <em>sure<\/em>no one is evesdropping, the best way is to wait until the user comes back online and you can confirm and enable the end-to-end encryption back.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2017\/01\/06021008\/whatsapp-security-code-changed-1.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2017\/01\/06021008\/whatsapp-security-code-changed-1-169x300.jpg\" alt=\"\" width=\"169\" height=\"300\" class=\"aligncenter size-medium wp-image-13847\"><\/a><\/p>\n<p>As we mentioned in our <a href=\"https:\/\/www.kaspersky.com.au\/blog\/33c3-private-messenger-basics\/13820\/\" target=\"_blank\" rel=\"noopener noreferrer\">Private Messenger<\/a> post, these messengers and the notion of true privacy are quite complex. We urge you to make sure that you keep an eye on the security settings to keep your data safe. We will also provide you tips on privacy and security on Kaspersky Daily multiple times per week, so be sure to tune in.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How you can fix the security hole within WhatsApp.<\/p>\n","protected":false},"author":636,"featured_media":13844,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2646,9],"tags":[261,43,211,131,546],"class_list":{"0":"post-13843","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"category-tips","10":"tag-encryption","11":"tag-privacy","12":"tag-social-media","13":"tag-tips","14":"tag-whatsapp"},"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/fix-whatsapp-security-hole\/13843\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/fix-whatsapp-security-hole\/10685\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/fix-whatsapp-security-hole\/8809\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/fix-whatsapp-security-hole\/9870\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/fix-whatsapp-security-hole\/9600\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/fix-whatsapp-security-hole\/13963\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/fix-whatsapp-security-hole\/2858\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/fix-whatsapp-security-hole\/13843\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/fix-whatsapp-security-hole\/6589\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/fix-whatsapp-security-hole\/7059\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/fix-whatsapp-security-hole\/5938\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/fix-whatsapp-security-hole\/9509\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/fix-whatsapp-security-hole\/13963\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/fix-whatsapp-security-hole\/13843\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/privacy\/","name":"privacy"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/13843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/636"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=13843"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/13843\/revisions"}],"predecessor-version":[{"id":24348,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/13843\/revisions\/24348"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/13844"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=13843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=13843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=13843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}