WhatsApp Message Hacked by John McAfee and Crew
cybersecurityventures.com
cybersecurityventures.com
The bar for "hacking WhatsApp" should be dramatically higher than installing an app on the very device that decrypts the message. Heck, you could probably just use the NotificationListenerService[0]. There, I hacked all messaging apps that use notifications. I didn't even need "servers deep in the remote mountains of Colorado".
[0]: https://developer.android.com/reference/android/service/noti...
Edit: Even though perhaps this hack isn't WhatsApp specific, the end result is the same - full compromise of WhatsApp privacy. Which is what matters to end users.
That said, this is quite useful for services like PushBullet for forwarding your notifications etc.
For governments (the groups that ostensibly WhatsApp cares about the most) and "hackers" it is fairly trivial to get an install on both ends of a communications chain - especially if the target/mark is high enough priority. So that doesn't absolve them.
If I can use the carrier/hardware system to implement an attack, then the entire system is not secure. As a result you can't claim that {system{sub-system in question}} is secure because the system security is implied.
This is the whole point of defense in depth.
That is exactly how exploits work in the wild, so the distinction is false. If I can get the info I need through a side-channel, no matter what it is, it's still a vulnerability. Full stop.
If it really is just an Android problem and doesn't carry over to iOS, then if WhatsApp is truly dedicated to security over everything, then they should disable on Android until the vulnerability is fixed on the Android side.
Given that that course of action would kill the vast majority of WhatsApp's base I don't foresee that happening.
edit: Also if you read the article again you'll see that the focus is on Android/Google vulnerabilities - and they used WhatsApp to demonstrate it as it's the widest distributed and used "secure" system on Android.
As a developer you generally have to assume that the end-user devices are trustworthy, since that is where you render the message into something the end user can see/read/use. You can assume the network is hostile, and that the sender may be hostile, but if your phone/PC is also hostile it's pretty much game over.
Related -- never check your email or bank accounts on a public kiosk.
Absolutely not. If you are designing for security, literally nothing in the chain is assumed to be secure by default - including the BTS and carrier networks.
As someone who has designed these systems I ALWAYS take the device security into consideration, for this exact reason. As I mentioned elsewhere, the defense in depth model covers this in detail.
[1] https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%...