WhatsApp denies 'backdoor' claims

Image
ANI New Delhi [India]
Last Updated : Jan 14 2017 | 6:32 PM IST

Popular messaging app WhatsApp has denied claims of vulnerability, described as 'backdoor', saying that it's a security feature related to message delivery in order to ensure messages don't get lost in transit.

The security issue was flagged in 2016 according to which messages sent via the platform could be intercepted and read.

It was reported that the issue was first identified by a security researcher and upon reporting it to Facebook, it was found out that the company was not actively working on fixing the bug.

WhatsApp has been appreciated for the end-to-end encryption Signal Protocol across its platform. The company's code, however, remains closed source.

The security issue concerns a feature of WhatsApp's Signal implementation that allows it to force the generation of new encryption keys for offline users. This is described as a 'retransmission vulnerability' by Tobias Boelter, who identified the issue in April, 2016, and thereby, can serve as a potential backdoor in WhatsApp's end-to-end encryption.

"WhatsApp does not give governments a 'backdoor' into its systems and would fight any government request to create a backdoor. The design decision referenced in the Guardian story prevents millions of messages from being lost, and WhatsApp offers people security notifications to alert them to potential security risks," the Reddit post of Brian Acton, Co-founder, WhatsApp, read.

Moxie Marlinspike, who designed the WhatsApp encryption, explained in a blog that the implementation offers users an 'opt in to a preference which notifies them every time the security code for a contact changes'.

In the blog post, Marlinspike wrote that WhatsApp users would now get all the benefits of a modern, open source, forward secure, strong encryption protocol for asynchronous messaging systems, designed to make end-to-end encrypted messaging as seamless as possible.

Earlier, a Guardian article had reported a weakness in WhatsApp's encryption, described as a 'backdoor', based on Boelter's claims. The Facebook-owned messaging platform has more than a billion monthly active users at this point.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jan 14 2017 | 6:20 PM IST

Next Story