WhatsApp and Messages share a security flaw

messages-whatsapp-security

Perhaps WhatsApp is less secure than we think. They have been commissioned to proclaim to the four winds their point-to-point encryption function, however, it seems that things were left in the pipeline. It is not the first time that the privacy controversy affects WhatsApp, nor will it be the last. However, this time Apple Messages (iMessage) is also affected by the same problem. Computer security engineers have concluded that WhatsApp and Messages share a security flaw and they should fix it ASAP. Apple and WhatsApp have been in a major update spiral lately, so we don't think they're taking too long.

The discoverer was the engineer Jonathan Zdziarski, who said this:

The latest version of WhatsApp allows you to obtain extracts of all your chats, even after they have been deleted, cleaned or archived. Even if you use the "clean all chats" function, we can still access them. In fact, the only way to remove our chats from the device is to completely remove the application from the device.

Jonathan thinks that no matter what disposal method we use, they will stay there. Nevertheless, Apple Messages suffers from the same flaw.

The problems are related to any application that uses SQLite. It does not delete the information, it simply evacuates it to a «Free List», but this data is not overwritten after moving, so it is possible to access this data. Other applications store this data even for months. In the case of Apple Messages, the messages are stored in an iCloud library, so they can be accessed even after they have been deleted, even if you get rid of the phone, they will be there for a certain time.

It seems that these security flaws are not too serious, and I am sure that both Apple and WhatsApp will solve it in the shortest possible time.


You are interested in:
How to have two WhatsApp on the iPhone
Follow us on Google News

Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: AB Internet Networks 2008 SL
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.

  1.   Hack WhatsApp said

    It seems incredible that an application as popular as WhatsApp has such obvious vulnerabilities