Skip to content

Comment on Whatsapp security hole allows changing status message of other usersparent

Comments

Wow it seems there is no security at all:

> By providing any WhatsApp registered telephone number and the text for the status update, it is possible to change a user's status. This action does not require any prior authentication or authorization

> (on registration) The vendor has implemented bruteforce protection by locking a number after 10 tries. This step makes a successful attack on a specific number unlikely but an attacker bruteforcing X00 numbers can still guess X number(s) on average.

> As published in the past several times already the XMPP traffic from WhatsApp is not encrypted.

And they are planning to charge money for it?

edit: perhaps even worse is their response to the security vulnerability seen in the timeline - they knew about the bug since 09-14

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.