When WhatsApp added end-to-end encryption to every conversation for its billion users two years ago, the mobile messaging significantly raised the bar for the privacy of digital communications worldwide.
But one of the tricky elements of encryption and even trickier in a group chat setting has always been ensuring that a secure conversation reaches only the intended audience, rather than some impostor or infiltrator.
And according to new research, flaws in WhatsApp make infiltrating the app’s group chats much easier than ought to be possible.
Considering protection against three types of attackers malicious user, network attacker, and malicious server an end-to-end encryption protocol plays a vital role in securing instant messaging services.
The primary purpose of having end-to-end encryption is to stop trusting the intermediate servers in such a way that no one, not even the company or the server that transmits the data, can decrypt your messages.
However, so far even the popular end-to-end encrypted messaging services, like WhatsApp, Threema, and Signal, have not entirely achieved zero-knowledge system.
Researchers from Ruhr-Universität Bochum (RUB) in Germany found that anyone who controls WhatsApp/Signal servers can covertly add new members to any private group, allowing them to spy on group conversations, even without the permission of the administrator.
As described by the researchers, in the pairwise communication (when only two users communicate with each other) server plays a limited role, but in case of multi-user chats (group chat where encrypted messages are broadcasted to many users), the role of servers increases to manage the entire process.
That’s where the issue resides, i.e. trusting the company’s servers to manage group members (who eventually have full access to the group conversation) and their actions. If you are wondering that adding a new member to the group will show a visual notification to other members.
In a phone call with WIRED, a WhatsApp spokesperson confirmed the researchers’ findings, but emphasized that no one can secretly add a new member to a group—a notification does go through that a new, unknown member has joined the group.
According to the researchers, a compromised admin or rogue employee with access to the server could manipulate (or block) the group management messages that are supposed to alert group members of a new member.
“The described weaknesses enable attacker A, who controls the WhatsApp server or can break the transport layer security, to take full control over a group. Entering the group, however, leaves traces since this operation is listed in the graphical user interface. The WhatsApp server can, therefore, use the fact that it can stealthily reorder and drop messages in the group,” the paper reads.
“Thereby it can cache sent messages to the group, read their content first and decide in which order they are delivered to the members. Additionally, the WhatsApp server can forward these messages to the members individually such that a subtly chosen combination of messages can help it to cover the traces.”
WhatsApp has acknowledged the issue, but argued that if any new member is added to a group, let’s say by anyone, other group members will get notified for sure.
“We’ve looked at this issue carefully. Existing members are notified when new people are added to a WhatsApp group. We built WhatsApp so group messages cannot be sent to a hidden user,” a WhatsApp spokesperson told Wired.
“The privacy and security of our users are incredibly important to WhatsApp. It’s why we collect very little information and all messages sent on WhatsApp are end-to-end encrypted.”
But if you are not part of a group with very selected members, I’m sure many of you would relatively ignore such notifications easily.
Researchers also advised companies to fix the issue just by adding an authentication mechanism to make sure that the “signed” group management messages come from the group administrator only.
However, this attack is not easy (exception—services under legal pressure) to execute, so users should not be worried about it.
Learn Ethical Hacking from Scratch, Join “Ethical Hacking” course, Enroll Now