pwshub.com

WhatsApp 'View Once' could be 'View Whenever' due to a flaw

Video A popular privacy feature in WhatsApp is "completely broken and can be trivially bypassed," according to developers at cryptowallet startup Zengo.

According to cofounder Tal Be'ery, his team was building a web interface when they discovered a flaw in WhatsApp's View Once. While the feature was supposed to be limited to platforms where the necessary controls could be enforced, such as mobile clients, the WhatsApp API server didn't properly enforce it.

The server would still send these messages to other platforms, but they couldn't be viewed - unless someone fiddled with the code.

"The View [O]nce media messages are technically the same as regular media messages, only with the “view once” flag set," the technical explanation states.

"Which means it’s the virtual equivalent of putting a note on the picture that says 'don’t look.' All that is required for attackers to circumvent it, is merely to set this flag to false and the media become regular and can be downloaded, forwarded and shared."

You can see this in operation in the video below:

Youtube Video

Three years ago, WhatsApp introduced View Once mode, which allows messages to be sent, looked at, and then deleted without the recipient being able to save a screenshot of the message. It's not a perfect system - the recipient can use another camera to take a picture of the message, but it wasn't bad either, and it would stem privacy violations.

Taking the image directly is far more efficient than snapping a photo of it with another phone, Be'ery told The Register, likening it to using a tape-to-tape recording as opposed to the mass sharing of MP3 à la Napster.

"People can save and copy the image, which invalidates the purpose of the feature. It's privacy theater," he explained. "It's a sloppy design, designed in a very bad way. The design of the whole thing is a dumpster fire."

  • Meta accused of snarfing people's Snapchat data via traffic decryption
  • You'll soon be able to ghost a WhatsApp group without making everyone hate you
  • Researchers find Meta's withdrawal of misinformation tool hard to swallow
  • WhatsApp, Threads, more banished from Apple App Store in China

Additionally, the Zengo team found code examples on GitHub of a modified Android client and a Chrome extension (should people be dumb enough to take the risk of embedded malware and use them) that could allow anyone to exploit the issue. So the team decided to abandon the usual 90-day waiting period for responsible disclosure and go public.

On August 26, Be'ery's team notified WhatsApp about the issue over two weeks ago via Meta's bug bounty program, and a spokesperson confirmed to us that the problem had been logged and was being investigated.

“Our bug bounty program is an important way we receive valuable feedback from external researchers and we are already in the process of rolling out updates to view once on web," we were told. "We continue to encourage users to only send view once messages to people they know and trust.”

Sources familiar with the matter report that a fix for this is being actively worked on and will be available as soon as it has been successfully tested. ®

Source: theregister.com

Related stories
1 day ago - View Forever, more like it, as Meta's privacy feature again revealed to be futile with a little light hacking A fix deployed by Meta to stop people repeatedly viewing WhatsApp’s so-called View Once messages – photos, videos, and voice...
1 week ago - What kind of OS can be hijacked by clicking a link at just the right time? Microsoft's In this week's Patch Tuesday Microsoft alerted users to, among other vulnerabilities, a flaw in Windows Installer that can be exploited by malware or a...
1 month ago - There's a handy tool to facilitate private conversations, and it's built right into your iPhone.
1 month ago - Payment arm of Korean messaging app denies any illegal activity Kakao Pay, a subsidiary of Korea's WhatsApp analog Kakao, handed over data from more than 40 million users to the Singaporean arm of Chinese payment platform Alipay, without...
1 week ago - Russia is cracking down on alternative sources of information, especially online, and is pushing citizens away from foreign-based social media apps.
Other stories
3 minutes ago - To reach that surprisingly conclusion, scientists studied the positions of 21 asteroid impact craters during the Ordovician period – the second of six periods in the Paleozoic Era that spanned 41.6 million years, from roughly 485.4...
3 minutes ago - Confusion arose earlier this week when a Microsoft representative published an official forum post announcing that the next "annual Windows 11 feature update release" will roll out for all users, along with the monthly security update...
3 minutes ago - The Department of State announced Americans with a US mailing address can now fill out a passport renewal application via its website, rather than...
3 minutes ago - Tucson sees plenty of sunshine and has a wide variety of solar companies. Here's what you need to know about getting a solar energy system in the city.
3 minutes ago - After three months of beta testing, the State Department's online passport renewal system has launched for everyone.