WhatsApp Flaw leaves User Location Vulnerable to Hackers and Spy Agencies



WhatsApp location hacking If you are using WhatsApp to chit-chat with your friends or relatives, then you should be careful about sharing your location with them using WhatsApp ‘Location Share’ feature.

No doubt, WhatsApp communication between your phone and company’s server is now encrypted with SSL, which means whatever you are sharing with your friends, is secured from the man-in-the-middle attacks.

But the extremely popular instant messaging service for Smartphones that delivers more than 1 billion messages per day has another serious security issue. According to Researchers at UNH Cyber Forensics Research & Education Group, WhatsApp location sharing service could expose your location to hackers or Spy Agencies. While sharing the location on WhatsApp users need to first locate themselves on Google Map within the app window, as shown: WhatsApp location hacking

Once selected, WhatsApp fetches the location and thumbnail (an image) from the Google Map service to share it as the message icon, but unfortunately WhatsApp downloads this image through an unencrypted channel from Google that could be sniffed during a Man-in-the-middle attack, as shown in the video demo.

“The main issue is that the location image is unencrypted, leaving it open for interception through either a Rouge AP, or any man-in-the middle attacks,” the reports read.

http://thehackernews.com/2014/04/whatsapp-flaw-leaves-user-location.html
1

View comments

    Loading