WhatsApp wants to increase security, but forgets a crucial point


WhatsApp logo (Image source: GIGA)

WhatsApp is becoming more and more secure. At least that’s what the company tries to convey to us again and again. In fact, a lot has happened in this regard lately. Now you should be able to change the most important security settings on the PC and on the web. However, this reveals a weakness that has existed for a long time.

WhatsApp: Two-factor authentication is being expanded

WhatsApp has been secured with two-factor authentication for several years. You have to assign a six-digit PIN and enter an e-mail address. If you lose your cell phone, this should ensure that you can access your WhatsApp account again. For some time now, WhatsApp has also been able to be used on multiple devices at the same time. That’s why the company wants them Security settings soon also accessible from the PC and in WhatsApp Web do:

So if you lose your smartphone, you can still access and change the settings via the app or on the web. If you have forgotten to activate the PIN, you can do it in the worst case and hope that the WhatsApp account is secured in this way.

The problem with the story, however, is that the PIN is not always requested. You only have to enter the six-digit PIN when using WhatsApp at irregular intervals – for me it feels like once or twice a week, if at all. But the worst thing is that you PIN and email address can be easily changed in WhatsApp without having to enter the PIN. So if you get access to a smartphone, you can change both without the consent of the owner and hijack the account. WhatsApp would definitely have to ask for the PIN before changing the settings. Otherwise attackers have an easy time.

The Best WhatsApp Alternatives:

WhatsApp backups finally encrypted

For a few months, it has also been possible to encrypt the backup in WhatsApp that is stored on Google Drive or in Apple’s iCloud. You should definitely do that, otherwise the data can simply be viewed there. Unfortunately, this does not work automatically, so you have to take action yourself.



Source link -65