WhatsApp servicejust purchased by Facebook for $19 billion, has several security vulnerabilities, according to experts, that need to be fixed.
None of the vulnerabilities identified this week by security firm Praetorian are critical. Instead, they involve errors in best practices for securing mobile apps.
“For the most part, these are not high-risk flaws,” says Andrew Hoog, CEO of viaForensics. The flaws, which are common to many mobile apps, do not involve enforcing SSL (Secure Sockets Layer) when WhatsApp establishes the connection between the phone and the company’s backend server. Using SSL involves the client checking the server’s certificate for trusted authentication credentials.
📧
Subscribe to the SecNews Newsletter

