Monday, 2 February 2015

Gap in the web-version of WhatsApp jeopardize the privacy of users

According to researchers, sent, and after removal of the photo is still available for viewing by the recipient WhatsApp Web.

Not so long ago  WhatsApp developers introduced a new service called WhatsApp Web, with which users can synchronize the message history in the mobile and desktop versions of the program. Despite the fact that after the appearance of new options less than two weeks, security researchers have discovered a flaw that affects the privacy of user data.


According to the publication Naked Security with reference to IT-expert Indrazhita Bhuyana (Indrajeet Bhuyan), in some cases, users are able to WhatsApp Web access to photos of other users, despite the obstacles to this privacy settings. In this case, the mobile version of messenger such errors do not occur.

We are talking about when a user sends a service to one of your contacts image, and then deletes it. In the mobile version, the recipient will not be able to see the photo, but will still see her "fuzzy" thumbnail. However, when viewing the image through WhatsApp Web, blur effect is not imposed.

Moreover, according to Bhuyana, the desktop version of the service allows third-party users to view photos and profile data even if they were hidden.

Source: securitylab.ru
TRANSLATION

No comments:

Post a Comment