Vulnerability in the WhatsApp application
German experts from Ruhr University published a technical analysis on January 6th showing a security vulnerability in the application WhatsApp. This would be a vulnerability allowing anyone with control over the servers to WhatsApp d’add a user, without further permission, in a private discussion group.
Once added to the group, the user would automatically receive the encryption keys for the conversation from all participants, allowing them to’to have access to all messages exchanged within the group.
German researchers say they have warned WhatsApp of this vulnerability last July. Facebook's (owner of) Head of Security WhatsApp) indicated on January 10, via Twitter, that it was aware of the problem, assuring that all means of verification to ensure the confidentiality of conversations are properly implemented.
Going further (technical document)
