Connecting to LinkedIn...

W1siziisijiwmtuvmdqvmtuvmdgvntqvmzgvnzi1l01ptlrbu0hfqkxpr19vtljftkrfukvex0lnqudfx3jlc2l6zwrfyw5kx3jlbmrlcmvklmpwzyjdlfsiccisinrodw1iiiwimtkymhgxmjuwiyjdxq

Blog

WhatsApp conversations can be stolen on Android devices

13/03/2014 by

W1siziisijiwmtqvmtavmjgvmtuvndgvmzivmtc2l2zpbguixsxbinailcj0ahvtyiisijywmhg0mdbcdtawm2uixv0

A Dutch researcher published a proof of concepton Tuesday that shows how a malicious application can be used to steal WhatsApp conversations on Android devices – which is particularly disconcerting considering a reported 400 million people use the cross-platform instant messaging service each month.

In this instance, the WhatsApp database being stored to the Android device’s SD card can be accessed by another app, so long as the user allows it, according to a blog post by Bas Bosschert. The root of the problem lies in the Android Application Sandbox, which is meant to isolate app data and code execution.

In his proof of concept, Bosschert created an app that can access the SD card and can be used to upload the WhatsApp databases to a web server he established. The app displays a loading screen during the WhatsApp database upload, ultimately tricking users into thinking something is going on in the background.

“The WhatsApp database is a SQLite3 database which can be converted to Excel for easier access,” Bosschert wrote. “Lately WhatsApp is using encryption to encrypt the database, so it can no longer be opened by SQLite. But we can simply decrypt this database using a simple python script. This script converts the crypted database to a plain SQLite3 database (got key from Whatsapp Xtract).”

On Monday, WhatsApp – which was acquired by Facebook in February for $19 billion – launched an update for its app, but this issue still persists, according to Bosschert.

“I think this is a significant issue since it shows how poor security and programming practices can affect all of us as users, even when there is no malicious intent,” Domingo Guerra, president and founder of Appthority, said.

This article has been extracted from http://www.scmagazine.com/, please click on this link to read the article in full http://www.scmagazine.com/whatsapp-conversations-can-be-stolen-on-android-devices/article/338015/

Montash is a multi-award winning , global IT recruitment firm. Specialising in permanent and contract positions across mid-senior appointments across a wide range of industry sectors and IT functions including:

ERP, BI & Data, Information Security, IT Architecture & Strategy, Scientific Technologies, Demand IT and Business Engagement, Digital and E-commerce, Infrastructure and Service Delivery, Project and Programme Delivery.

For more information please contact us on +44 (0) 20 7014 0230 or alternatively send us an email on info@montash.com.

comments powered by Disqus

Social Stream

Latest News

W1siziisijiwmtcvmdgvmtqvmtmvmjcvmjgvnja2l2nsb3rozxmuanbnil0swyjwiiwidgh1bwiilcizodb4mtawiyjdxq

In Her Shoes... From Market Stall to Recruitment

2017-08-14 14:00:00 +0100

From the melee of the market stall to placing candidates in high-flying IT roles, life's always on the up from market-trader-turned-recruiter, Lois Hinken (22). She took the time to talk to us about how her experience in the cut throat world of the market has helped her in the world of global talent acquisition. As a 360 recruitment consultant for Montash, her negotiation skills and "go get it" attitude have helped her thrive. "I started working on the ...

W1siziisijiwmtcvmdgvmdcvmtmvmtcvntqvnze3l1vudgl0bgvkigrlc2lnbiaomikuanbnil0swyjwiiwidgh1bwiilcizodb4mtawiyjdxq

Will AI Cost Us Our Humanity?

2017-08-07 15:00:00 +0100

As technology evolves, artificial intelligence is becoming increasingly mainstream, and it will inevitably start to impact the way we interact. On the one hand, AI has the potential to solve a variety of problems and streamline our lives and our work. But will this come at the cost of the all-important human touch? A foreshadowing statistic claims that by 2020, 85% of client interactions will be managed without a human[1]. But can there really be an alg...