Get the latest tech news

WhatsApp provides no cryptographic management for group messages


The weakness creates the possibility of an insider or hacker adding rogue members.

Using the common fictional scenario for illustrating end-to-end encryption, this lack of cryptographic assurance leaves open the possibility that Malory can join a group and gain access to the human-readable messages exchanged there. In 2022, a team that included some of the same researchers that analyzed WhatsApp found that Matrix—an open source and proprietary platform for chat and collaboration clients and servers—also provided no cryptographic means for ensuring only authorized members join a group. Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords.

Get the Android app

Or read this on ArsTechnica

Read more on:

Photo of WhatsApp

WhatsApp

Photo of group messages

group messages

Related news:

News photo

iPhone spyware company NSO must pay Meta $167M for WhatsApp attack [U]

News photo

NSO Group fined $167M for spyware attacks on 1,400 WhatsApp users

News photo

Maker of Pegasus spyware told to pay $167m for WhatsApp hack