WhatsApp Threatens Developers of PC Gateway With Legal Action
An anonymous reader writes "In an apparent reaction to the security vulnerabilities demonstrated by The H's associates at heise Security, the company behind WhatsApp Messenger is taking action against the developers of a library of functions for using the WhatsApp service via a PC. The developers have responded by removing the source code from the web. However, the popular texting alternative WhatsApp still has a major security problem. Attackers can compromise other users' accounts with relative ease, and send and receive messages from another user's account. Forked versions of the code are still available on Github."
Sadly Information Security is now more about offloading liability and then seeking damages than actually delivering secure solutions.
Also, let's just all act like github isn't versioned. *whistles*
It's better to vote for what you want and not get it than to vote for what you don't want and get it.
- E. Debs
If WhatsApp doesn't add more security, my prediction, is we will start to see WhatsApp spam. If you know phone number and it's IEMI you can fake the sender using the WhatsApp protocol. All it will take now is someone to acquire a database of IEMI's and the phone numbers before the spam can start flowing.