Swiss perspectives in 10 languages

WhatsApp security test identifies weakness

WhatsApp
Keystone / Zacharie Scheurer

The messenger service WhatsApp no longer has access to the more than 100 billion daily messages on its platform, a comprehensive security test funded by the Swiss National Science Foundation (SNSF) has concluded. One identified weakness can be resolved with a strong password.

An end-to-end encryption is used to ensure the confidentiality of WhatsApp. However, until recently, the automatic backup of the chats did not offer the same security, according to a statementExternal link by the SNSF. This is because the personal key to the data stored in the cloud was known to the company.

“Backups were safe from everyone apart from WhatsApp itself,” said Julia Hesse, a cryptographer from the IBM Research Institute in Zurich who has received funding from the SNSF.

This could also be why the messenger service launched a new backup protocol at the end of 2021, which Hesse and researchers from the federal technology institute ETH Zurich and the University of Wuppertal in Germany have now examined in detail. The study showed that the company itself is no longer able to access the backups.

The study found that with the new system the copy of the key is no longer stored at the company but on a separate, particularly secure computer to which WhatsApp has no access and whose code cannot be subsequently changed.

If a user loses their smartphone, they can now access the key themselves by entering a password and restore their own chats.

“It’s like the key is stored in a chest that can only be opened with the password,” Hesse said.

The protocol also protects the backup from “brute force” attacks, which keep trying passwords until they find the right one. “Even if a powerful attacker manages to gain control of the WhatsApp servers, the system would only allow them ten attempts, after which the key would be destroyed,” Hesse said. But the data is then lost for the user too.

Password vulnerability

However, the researchers discovered a possible vulnerability: in normal operation mode the system deletes old versions of the backup when a new version is created, such as when changing the password.

“An attack on WhatsApp or elsewhere could result in the old versions being retained, meaning that another ten attempts would be possible for each existing version,” Hesse said. But this loophole can be closed by choosing a strong password. “If, rather than taking their Swiss postcode, the user chooses eight characters with a special character, it doesn’t matter whether the attacker has ten or 200 goes.”

More

Popular Stories

Most Discussed

News

The site of the fatal glider crash in canton Valais.

More

Two dead after glider crash in southern Switzerland

This content was published on Two people died after their glider crashed in canton Valais on Friday afternoon. The police said the victims were Swiss nationals, aged 72 and 46, who had apparently taken off from canton Aargau.

Read more: Two dead after glider crash in southern Switzerland
Nestle's CEO Mark Schneider, left, and Nestle chairman Paul Bulcke, right, speak during the general meeting of the world's biggest food and beverage company, Nestle Group, on April 18, 2024.

More

Nestle Chair says CEO change was prompted by growth concerns

This content was published on The abrupt replacement of Nestle SA’s chief executive officer was prompted by worries over the food and beverage company’s growth outlook, Nestlé Chair Paul Bulcke told Swiss newspaper Le Temps. 

Read more: Nestle Chair says CEO change was prompted by growth concerns
Alpinist fatally injured in a fall on the Matterhorn

More

Climber dies on the Matterhorn in southern Switzerland

This content was published on A climber died on Thursday after falling with a partner while descending the Matterhorn, near Zermatt, in southern Switzerland. The other mountaineer suffered minor injuries.

Read more: Climber dies on the Matterhorn in southern Switzerland
Hundreds of Tibetans receive Dalai Lama in front of Zurich hotel

More

Hundreds of Tibetans welcome Dalai Lama in Zurich

This content was published on The Dalai Lama has arrived in Switzerland for a short visit. Hundreds of Tibetans welcomed him at an airport hotel in Opfikon, near Zurich, on Friday.

Read more: Hundreds of Tibetans welcome Dalai Lama in Zurich

In compliance with the JTI standards

More: SWI swissinfo.ch certified by the Journalism Trust Initiative

You can find an overview of ongoing debates with our journalists here . Please join us!

If you want to start a conversation about a topic raised in this article or want to report factual errors, email us at english@swissinfo.ch.

SWI swissinfo.ch - a branch of Swiss Broadcasting Corporation SRG SSR

SWI swissinfo.ch - a branch of Swiss Broadcasting Corporation SRG SSR