a new WhatsApp security flaw has allowed a group of researchers to list up to 3.5 billion phone numbers and associated data from users around the world. This is not a classic hack with malware or password theft, but rather the massive use of the way in which the app itself manages the function of adding contacts, a function that we use almost without thinking about it.

Researchers at the University of Vienna have shown that by automating the submission of billions of numbers to WhatsApp's contact discovery system, they could know which numbers were registered and partially download the public information of each profile. The result is, in practice, an enormous global directory of WhatsApp userssomething that should worry anyone who values ​​their privacy, even minimally.

What exactly happened with this WhatsApp failure

WhatsApp allows, when adding a number to the phonebook, the app to check if that person uses the service and show their name, photo and other public profile details. The problem is that the platform barely imposed limits on how many checks per minute could be performed, so the researchers automated the process and queried tens of billions of numbers until they identified 3.5 billion active accounts.

In addition to the phone number, they were able to download additional information when the user had it set to public: profile photo, 'Info' text, account type (personal or business), and even certain technical data of the device and public encryption keys. In the United States, they reached collect tens of millions of profile picturesmany with perfectly recognizable faces, making it easy to create databases that associate faces with phone numbers, without the user knowing.

WhatsApp's response and why you should care

Meta, the company that owns WhatsApp, maintains that what the researchers have done is basically “scraping” information that was already public and that at no time were private messages exposed, which continue to be protected by end to end encryption. Still, after being notified, the company has applied countermeasures: stricter limits on number queries, less data accessible by default, and fixes in certain client implementations, especially on Android.

The underlying problem, however, is that WhatsApp uses the phone number as the primary identifier and the numbers are relatively easy to scroll through automatically. Millions of accounts have even been identified in countries where the app is banned, such as China and Iran, which, if a government were to do the same enumeration, could become a list of “illegal” users. And this is where it no longer we only talk about spam or phishingbut very serious risks for some people.

What you can do to improve your privacy on WhatsApp

The vulnerability has been mitigated, but that doesn't mean you should forget about it. If you use WhatsApp daily on your Android mobile, it is worth spending a few minutes reviewing the privacy settings. Under “Privacy > Profile Photo,” “Info,” and “Last Seen & Online,” it is best to choose “Contacts Only” or even “Nobody” if you want to minimize your public footprint.

It's also a good idea to limit who can add you to groups, always keep the app up to date, and be wary of unexpected messages that use your full name or other details that could have been obtained from databases like this one. The phone number is one of the most sensitive pieces of information we carry, and sometimes we only remember it when it's too late. For these reasons, it is important use usernamesas this adds an effective layer of data protection. Are you going to take advantage of this notice to review the privacy of your WhatsApp account or do you prefer to continue as before?

Shares:
Leave a Reply

Your email address will not be published. Required fields are marked *