Whatsapp flaw could allow hackers to alter and manipulate messages

Sheri Evans
August 13, 2019

Experts warn, however, that such a setup would require WhatsApp to transmit prohibited messages to developers in order to improve the AI's training. In the sample, the boss's message was altered to increase the supposed raise from $500 to $1,500.

Israel-based Check Point Software, which provides security for computer networks, said it discovered three potential ways of altering conversations on WhatsApp.

Facebook said the WhatsApp bugs were due to "limitations that can't be solved due to their structure and architecture", according to the Financial Times.

This gives the attackers the power to "create and spread misinformation from what appear to be trusted sources", Check Point said. Not only that, but it can also change the identity of users and completely change the sent messages with WhatsApp's "quote" function.

The tool was demonstrated at Black Hat, a cyber-security conference in Las Vegas, as a follow up to a research paper published by Checkpoint a year ago. Furthermore, the spokesperson stated that addressing the concerns, perhaps by way of storing information on the origin of the text messages, would make WhatsApp less private.

In a blog detailing their findings, Check Point Research said that the security flaw means people can edit someone's reply, "essentially replacing words in their mouth".

We hope Neymar comes back: Barcelona midfielder Carles Alena
The Qatari-owned club has won Ligue 1 for six of the last seven campaigns, with only AS Monaco interrupting the run in 2016-17. PSG coach Thomas Tuchel said: " Neymar did not complete training and it's not possible that he plays tomorrow".

Escaped prisoner suspected of murdering, sexually assaulting warden is captured
When Johnson didn't show up for work, co-workers discovered Johnson's body at her home at 11:30 a.m., according to the affidavit. The TBI said it has received 369 tips and zero credible sightings of him by late Saturday, and is offering a reward of $57,000.

Tottenham Hotspur fans react to Philippe Coutinho transfer link
However, ESPN's Moi Llorens claims that Manchester United and Tottenham have recently made enquiries about Coutinho's future. He would have preferred to rejoin Liverpool given his history at the club, but has accepted that move is not on the cards.

Send a private message to another group participant that is disguised as a public message for all, so when the targeted individual responds, it's visible to everyone in the conversation.

"We think this is our obligation to escalate this", Oded Vanunu, head of product vulnerability research at Check Point Research, told FT.

In particular, the encryption technology used by WhatsApp made it extremely hard - perhaps impossible - for the company to monitor and verify the authenticity of messages being sent by users.

Facebook is considering using on-device AI algorithms to scan and moderate content in its WhatsApp messaging service to enforce its acceptable speech policy. According to them, instant messaging technology, like WhatsApp, has become an integral part of lives, both at a professional and personal level. We also work to ban accounts trying to change WhatsApp and use it to spam users.

Researchers demonstrated that hackers can access encrypted traffic to impersonate another group member and then send it an extension to decrypt the content. Hackers can then reply to a spoofed message in a group, even though an original message to the reply never existed.

A third issue highlighted by researchers has been successfully fixed by Facebook.

Other reports by

Discuss This Article

FOLLOW OUR NEWSPAPER