WeChat IM Application Could Disclose Your Password To Attackers
New submitter soulflyz writes "Security researchers found some security issues in WeChat, a popular instant messaging application developed by the Chinese company Tencet. By exploiting these vulnerabilities, any other application installed on the user's phone can force WeChat to send the user's password hash (in plain MD5 format) to an external web server, controlled by the attacker. Android versions of WeChat up to 4.5.1 are confirmed to be vulnerable, but similar issues could interest also other versions of the application. According to recent statistics, WeChat should have about 300 million registered users."
I've been using wechat for over a year on two phones and had no idea that I had a password.
God damn, it's the fucken middle ages. nothing but crazy ass fears of fraud and cons and hacker and trojens and so much ignorance and fears and crazy crazy tin-foil hat
my husband turned into a frog cause I haven't seen him
everybody is a basket case. they misclick and think their computer is hijacked by the FSB. Crazy-ass thinking. Chilll. Who's creating all this hysteria? The trusted companies who are refuge stand to benefit. The fucken CIA is evil fuckers.
Seriously? Is every individual vulnerability in any piece of software going to make it on here now?
Keyboard Error: No keyboard detected. Press any key to continue...
They should use SRP (Secure Remote Password).
If they don't want to bother with something good (like SRP), they should at least drop in SCrypt in place of MD5. Using MD5 these days for anything secure is stupid.
Queue all the hunter2 jokes: http://www.bash.org/?244321
Things you think are in the Constitution, but are not.
At least WeChat doesn't have lead in it.
We*What? WeChat! Well, I use GoSMS
Ohh wiat, it too, has Asian origins. Anyone see a trend here? I see one.
If it didn't make news then it had been sold as an exploit to NSA. If it makes news then it failed to sell. So 'newsworthy' is important.
I'm happy this is public and disclosed because now it can be fixed.
Me upload your unprotected password to a 3rd-party website and hope you use that same password for your online banking so that we can steal funds from your accounts.
Oh, and we put peepee in your coke.
with 2 'N's
Same company that developes QQ
your thin skin doesn't make me a troll
Maybe this is a backdoor.
For this to be exploited, the attacker already successfully installed their own software on your phone.
Your WeChat password hash should be the least of your concerns at this point.
I won't be surprised if the Chinese government is doing what the governments of all other large countries are doing, spying on its own citizens.
That's funny, just like what a stupid narrow minded American would write! Now do the Brittish!
Chinese know shit about secure anything.
According to Edward Snowden, neither does any American.
Software and Chinese? Have you ever seen anyone code in Chinese? No! Code is always in American. How can you expect Chinese to code? You can't.
"300 million users" begs to differ.
Yeah, sounds like the pinnacle of security...
it might be weak, or alreadyy broken, but by definition it is not "plain"
bickerdyke
This is in the article
"We tried to contact developers to notify our findings, but with no luck: we wrote an e-mail to Tencent technical support both on August 30th and on September 3th, but we got no reply."
This is a common problem when dealing with Chinese companies. They are so accustomed to dealing face to face that they forget to check other means of communication. I frequently find that I need to send an SMS to a Chinese person if I have sent them email, asking them to check their email.
hmm.. imagine that. china not really any different than the good ol' us of a in that regard.
Android security is a joke.