A vulnerability in how Facebook-owned WhatsApp handles encrypted messages could allow someone besides the intended recipient to intercept and read a sender’s private messages, according to a cryptography researcher at the University of California-Berkeley.
Tobias Boelter, a PhD candidate, first reported the vulnerability to Facebook in April. A month later, he noted that Facebook said it was aware of the issue but was not actively working to make changes. A report in today’s Guardian newspaper said that vulnerability still exists.
Since the Guardian article was published, several security researchers have acknowledged that they are concerned about the WhatsApp flaw, but criticized the newspaper for calling it a “backdoor.”
A backdoor is generally considered to be an intentionally introduced vulnerability that lets someone other than the intended user control a program, device or network. A WhatsApp spokesperson told us today that the description of the vulnerability as a backdoor is “false.”
‘Not a Backdoor’
In a post on his blog on April 16, Boelter described how the WhatsApp vulnerability works: when an encrypted message is sent but not delivered, a third party can intervene and get the WhatsApp server to re-encrypt the original message using a new encryption key, enabling the third party to receive the original message.
Nadim Kobeissi, a PhD candidate at France’s Inria Prosecco lab, said on Twitter this morning that he has verified that vulnerability. “I’ve been producing this result since October 2015,” Kobeissi said. “Not a ‘backdoor’ but equally intolerable.”
Matthew Green, a cryptographer and professor at Johns Hopkins University, echoed those comments in several tweets of his own. “I wish we could put the word ‘backdoor’ in a glass case and only bring it out when something is really deserving,” Green said. In another comment, he added, “It is totally stupid. I wish WhatsApp didn’t have this issue…