SKIP TO MAIN CONTENT

WhatsApp denies information sharing claims

WhatsApp has denied there is a back-door to the application which can allow third parties to see supposedly secure messages.

Whatsapp
Source: Pixabay

3 min read

Published

Updated

Source: AAP


Skip to article content

WhatsApp has denied claims a serious flaw in its encryption could allow messages to be intercepted without user knowledge.

Research from the University of California shown to the Guardian had claimed WhatsApp owners Facebook and others could read messages using a security back door in the system.

But the messaging service has now denied the claims, calling the suggestion "false".

"The Guardian posted a story this morning claiming that an intentional design decision in WhatsApp that prevents people from losing millions of messages is a 'backdoor' allowing governments to force WhatsApp to decrypt message streams," a spokeswoman for the company said.

"This claim is false.

News that makes sense

Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

"WhatsApp does not give governments a 'backdoor' into its systems and would fight any government request to create a backdoor.

"The design decision referenced in the Guardian story prevents millions of messages from being lost, and WhatsApp offers people security notifications to alert them to potential security risks.

"WhatsApp published a technical white paper on its encryption design, and has been transparent about the government requests it receives, publishing data about those requests in the Facebook Government Requests Report."

One of WhatsApp's biggest selling points is its claim that all content sent within the app is "end-to-end encrypted" using a system that generates unique security keys which are then shared and verified between users in order to guarantee communication is secure and cannot be intercepted.

However, security researcher Tobias Boelter said WhatsApp has the ability to force the generation of new security keys for offline users.

This then enables re-encryption and resending of undelivered messages with new keys without the sender's knowledge.

This would effectively allow WhatsApp to intercept and read messages, his research claimed.

But WhatsApp said that it has a 'Show Security Notifications' feature in place that "notifies you when a contact's security code has changed".

Security experts had been divided on the issue, with Kevin Bocek, from security firm Venafi, calling the discovery a "serious vulnerability" and "alarming", while Lee Munson from Comparitech.com said the flaw had raised serious questions over user privacy.

But others were sceptical of the findings, suggesting the issue was already widely known in the security industry and does not amount to a "back door" of the Signal encryption protocol, which WhatsApp uses.

Cryptographer Frederic Jacobs described Mr Boelter's findings as "nothing new".

"Of course, if you don't verify keys Signal/WhatsApp/... can man-in-the-middle your communications", he wrote on Twitter.

"It's ridiculous that this is presented as a backdoor. If you don't verify keys, authenticity of keys is not guaranteed. Well known fact."


Get SBS News straight to your inbox

Sign up now for daily news from Australia and around the world. You can also subscribe to Insight's weekly newsletter for in-depth features and first-person stories.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Follow SBS News

Download our apps

Listen to our podcasts

Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS

SBS World News

Take a global view with Australia's most comprehensive world news service

Stream now

Watch the latest news videos from Australia and across the world