September 16, 2012

WhatsApp Messenger’s Security Flaws

WhatsApp Messenger’s security flaws per fileperms.
WhatsApp is one of the most popular messaging apps on iOS and Android. It is frequently the top paid paid app on App Store.

Per fileperms, due to the security flaws, 3rd parties can intercept WhatsApp conversations.

The security weaknesses

1. WhatsApp Data sent in Plaintext Instead of Encrypted
Earlier versions of WhatsApp sent messages and mobile number in plaintext.
The latest version still sends the phone number in plaintext.

2. WhatsApp’s Weak Authentication
The username is a users mobile phone number. The password is derived from the IMEI number (for Android) and Mac Address for iOS.

3. WhatsApp Pulls Data from your Phone Contacts

