About a week after invitation-only chatroom app Clubhouse announced security measures to protect user data , a hacker is proving he can hack into audio conversations.

According to a Clubhouse spokesperson, an unknown user was able to stream Clubhouse audio feeds from “multiple rooms” to their own site. The company says the user has been “permanently banned” and that new measures have been taken to prevent this from happening again, but researchers say the platform may not be able to keep that promise.
According to the Stanford Internet Observatory (SIO), all users of the iOS app should be aware that their conversations are being recorded. “Clubhouse cannot make promises of privacy for conversations that take place anywhere in the world,” said Alex Stamos, director of the SIO and former chief security officer at Facebook Inc.
Stamos and his team confirmed that many of Clubhouse’s back-end functions are handled by a startup called Agora Inc., based in Shanghai. While Clubhouse is responsible for the user experience, such as adding new friends, finding rooms, and so on, the platform relies on Chinese company Agora to process data traffic and produce audio.
According to Stamos, Clubhouse's reliance on Agora raises privacy concerns, especially for Chinese citizens and dissidents, as their conversations are likely being monitored by the state.
Agora said it was unable to comment on security or privacy protocols and insisted that it “does not store or share personal information” about any of customers , nor about Clubhouse. “We are committed to making our products as secure as we can,” the company said.

Over the weekend, security researchers noticed that audio conversations and metadata were being sent from the Clubhouse app to another website. “A user found a way to remotely share their login details with the rest of the world,” said Robert Potter, CEO of Internet 2.0, based in Canberra, Australia. “The real problem was that people thought these conversations were private.”
The hacker behind this incident created his own system around the JavaScript toolkit used to create the application and managed to breach the platform.
Clubhouse developers did not explain the measures they took to prevent a similar breach.
A week ago, the SIO published a report stating that it observed metadata from Clubhouse chatrooms “being transmitted to servers we believe are hosted in China.”
Source: Bloomberg
