While they’re known for strongly encrypting messages in transit, apps like WhatsApp and Telegram may not always be able to keep files safe after they’re on your phone. Researchers from Symantec explain how hackers could use a malicious app to subtly alter media files sent through the services.
While they’re known for strongly encrypting messages in transit, apps like WhatsApp and Telegram may not always be able to keep files safe after they’re on your phone. Researchers from Symantec explain how hackers could use a malicious app to subtly alter media files sent through the services.
On Android, apps can choose to save media, like images and audio files, through either internal storage that’s only accessible through the app, or external storage which is more widely available to other apps. WhatsApp, by default, stores media through external storage, and Telegram does so when the app’s “Save to Gallery” feature is enabled.
According to the researchers, the design means malware with external storage access could be used to access WhatsApp and Telegram media files, maybe even before the user sees them. If a user downloads a malicious app, for example, and then receives a photo on WhatsApp, a hacker could manipulate the image without the receiver ever noticing. A hacker could theoretically alter an outgoing multimedia message as well.
The researchers call the attack “Media File Jacking.” In many ways, it’s a known issue and a trade-off between privacy and accessibility for messaging apps on Android. By using the external storage setting, which is widely used, apps are more compatible with others, allowing pictures and other data to move more freely. But that comes with a cost: last year, researchers pointed out similar issues.
Telegram did not immediately respond to a request for comment. A WhatsApp spokesperson said changing its storage system would limit the service’s ability to share media files, and even introduce new privacy issues. “WhatsApp has looked closely at this issue and it’s similar to previous questions about mobile device storage impacting the app ecosystem,” the spokesperson said in a statement. “WhatsApp follows current best practices provided by operating systems for media storage and looks forward to providing updates in line with Android’s ongoing development.”
Still, these aren’t just any messaging apps. As the researchers point out, users generally trust encrypted apps “to protect the integrity of both the identity of the sender and the message content itself.”
“However,” the researchers write, “as we’ve mentioned in the past, no code is immune to security vulnerabilities.”
Central Adoption Resource Authority (CARA) has directed State Adoption Resource Agencies to improve organised counselling before, during, and after adoption
Central Adoption Resource Authority (CARA) has directed State Adoption Resource Agencies to improve organised counselling before, during, and after adoption
UNICEF has recognised Kerala's KITE initiative as a global best practice in responsible EdTech
India successfully tested the Akash Prime missile system at high altitude in Ladakh
Rising dowry-related deaths in states like Chandigarh, Tamil Nadu, and Uttar Pradesh have drawn national attention
Visioning India’s Future: A Conversation with Prof. Prabhat Ranjan on Innovation, Education, and Nation Building
Chilling bomb threat emails hit 40 Bengaluru schools sparking massive police searches
UPSC builds bridge for ‘almost there’ aspirants: New portal links civil services near-misses to private jobs
Bengaluru stampede: Karnataka govt blames RCB and Virat Kohli video for deadly crowd surge
Bihar polls: Nitish Kumar doles out free electricity in early bid to woo voters
Central Adoption Resource Authority (CARA) has directed State Adoption Resource Agencies to improve organised counselling before, during, and after adoption
Central Adoption Resource Authority (CARA) has directed State Adoption Resource Agencies to improve organised counselling before, during, and after adoption
UNICEF has recognised Kerala's KITE initiative as a global best practice in responsible EdTech
India successfully tested the Akash Prime missile system at high altitude in Ladakh
Rising dowry-related deaths in states like Chandigarh, Tamil Nadu, and Uttar Pradesh have drawn national attention
Visioning India’s Future: A Conversation with Prof. Prabhat Ranjan on Innovation, Education, and Nation Building
Chilling bomb threat emails hit 40 Bengaluru schools sparking massive police searches
UPSC builds bridge for ‘almost there’ aspirants: New portal links civil services near-misses to private jobs
Bengaluru stampede: Karnataka govt blames RCB and Virat Kohli video for deadly crowd surge
Bihar polls: Nitish Kumar doles out free electricity in early bid to woo voters
Copyright© educationpost.in 2024 All Rights Reserved.
Designed and Developed by @Pyndertech