
Eine einfache WhatsApp-Sicherheitslücke hat 3,5 Milliarden Telefonnummern offengelegt | Durch die Eingabe von Dutzenden Milliarden Telefonnummern in das Kontakterkennungstool von WhatsApp fanden Forscher „die umfangreichste Offenlegung von Telefonnummern“ aller Zeiten – zusammen mit Profilfotos und mehr
https://www.wired.com/story/a-simple-whatsapp-security-flaw-exposed-billions-phone-numbers/

3 Kommentare
Some pertinent issues:
>Add someone’s phone number, and WhatsApp instantly shows whether they’re on the service, and often their profile picture and name, too.
>
>Repeat that same trick a few billion times with every possible phone number, it turns out, and the same feature can also serve as a convenient way to obtain the cell number of virtually every WhatsApp user on earth—along with, in many cases, profile photos and text that identifies each of those users. The result is a sprawling exposure of personal information for a significant fraction of the world population.
>
>One group of Austrian researchers have now shown that they were able to use that simple method of checking every possible number in WhatsApp’s contact discovery to extract 3.5 billion users’ phone numbers from the messaging service. For about 57 percent of those users, they also found that they could access their profile photos, and for another 29 percent, the text on their profiles. Despite a previous warning about WhatsApp’s exposure of this data from a different researcher in 2017, they say, the service’s parent company, Meta, still failed to limit the speed or number of contact discovery requests the researchers could make by interacting with WhatsApp’s browser-based app, allowing them to check roughly a hundred million numbers an hour.
>
>The result would be “the largest data leak in history, had it not been collated as part of a responsibly conducted research study,” as the researchers describe it in a paper documenting their findings.
>
>“To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented,” says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.
>
>…
>
>In a statement to WIRED, Meta thanked the researchers, who reported their discovery through Meta’s “bug bounty” system, and described the exposed data as “basic publicly available information,” since profile photos and text weren’t exposed for users who opted to make it private. “We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defenses,” writes Nitin Gupta, vice president of engineering at WhatsApp. Gupta adds, “We have found no evidence of malicious actors abusing this vector. As a reminder, user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption, and no non-public data was accessible to the researchers.”
>
>…
>
>One interested audience for the exposed phone number data, the researchers point out, would be scammers and spammers who are seeking a database of potential targets. But the researchers also found millions of phone numbers registered to WhatsApp in countries where it’s officially banned, including 2.3 million in China and 1.6 million in Myanmar. Those countries‘ governments could have used WhatsApp’s exposure to collect those numbers and hunt down illegal app users, the researchers point out. Muslims in China, according to some reports, have been detained merely for having WhatsApp installed on their phones.
>
>The University of Vienna researchers also analyzed the cryptographic keys for the 3.5 billion accounts they found exposed via their enumeration method, the long strings of characters used to receive encrypted messages in WhatsApp’s end-to-end encryption protocol. They found that a surprising number of accounts used duplicate keys—a security issue given that anyone who has the same key as another user would also be able to decrypt messages sent to them.
>
>Some keys were reused hundreds of times, they found, and 20 US numbers used a key of all zeroes, strangely. The researchers speculate, though, that the key duplication was likely the result of unauthorized WhatsApp clients, rather than a flaw in WhatsApp itself. On closer examination of some of the accounts with repeated cryptographic keys, they also noted that they looked like scammer accounts, suggesting that some scam operations that exploit WhatsApp may use a client with broken encryption features.
>
>…
>
>“Phone numbers were not designed to be used as secret identifiers for accounts, but that’s how they’re used in practice,” says Judmayer. “If you have a big service that’s used by more than a third of the world population, and this is the discovery mechanism, that’s a problem.”
In addition to the issues with WhatsApp identified in the article, so many pieces of personal information that were never intended to be secret identifiers have become such in our connected world. It would be useful if governments and other similar systems came up with bona fide secure identifiers that can be used instead, rather than these ad hoc bits that are being used now.
There used to be a giant book that leaked every single phone number, name and address. And the phone company would deliver a copy to every house. They would keep copies of all the books in the libraries. One day they hit on a grand scheme to extort more money from their long suffering victims, and let you pay more money monthly to not be in that book. The „unlisted number“ was born.
Also, after they got broken up they would charge you far more to call across an imaginary line in your own town (local long distance) than all the way across the country (long distance).
Showing all your data to everyone is a feature of whatsapp that you can change in privacy settings. Dunno if it’s really a flaw if it’s by design.