HomeSecurityWhatsApp's End-to-End Encryption is a Scam

WhatsApp's End-to-End Encryption is a Scam

end

As Bloomberg, hackers be spying on users through the WhatsApp, proving that end-to-end encryption may sound great, but it also has a dark side. When someone has access to your phone's operating system, they can also read your messages, without having to decrypt them first.

Pegasus spyware, created by Israeli company NSO, was the one that exploited the vulnerability in the app, according to a report by the Financial Times. The malware could access a phone's camera and microphone, open messages, record what's on the device's screen, and also record what the user types, rendering encryption useless. It can affect all operating systems, from Apple's iOS to Google's Android to the less-used version of Microsoft's Windows.

Its existence is well known in the cybersecurity community and there are many who have repeatedly sounded the alarm. However, NSO itself says that it does not have Pegasus anywhere and that it is disabled in the US.

Until recently, it was thought that Pegasus could only affect a user after they clicked on a phishing link to install the malware. However, according to a statement from WhatsApp owner Facebook Inc., it now appears that hackers can install the malware simply by calling their target.

This isn't the only vulnerability of its kind to be discovered in a supposedly secure messaging app. Last year, security researcher Ivan Ariel Barrera Oro from Argentina wrote about a similar flaw in Signal. In this case, a hacker could send a specially crafted URL via a message to the app, which would install malware.

It is important to understand, of course, that spyware that has the ability to install itself without requiring any action on the part of the user can come from anywhere, when there is a vulnerability that has not been patched.

Applications running on top of an operating system can allow malware to control a device in many ways. With a keylogger, a hacker can only see one side of a conversation. But if they gain access to a user's screen, they can monitor their conversations regardless of the security precautions built into the application they're using.

End-to-end encryption is a marketing device used by companies like Facebook to reassure consumers wary of cyber surveillance. Encryption is of course necessary, but it is not a secure way to communicate.

Government and private hackers are working feverishly on new methods to develop malware with operating system privileges. Companies like NSO are at the forefront of this important work, which can help combat terrorism and prevent attacks – or imprison dissidents and stop revolutions against dictatorial regimes.

The WhatsApp incident is likely to increase the backlash against NSO and may affect its export license for Pegasus from the Israeli government. But even if this particular company stops developing the malware, there will certainly be others to take its place.

The harsh truth is that as much as we don't want it to be, the digital world is a dangerous place and no matter how many security measures we take, there will always be a risk that our data will be compromised.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS