2 min read

WhatsApp doesn't properly erase your deleted messages, researcher reveals

Graham CLULEY

July 29, 2016

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
WhatsApp doesn't properly erase your deleted messages, researcher reveals

There were cheers a few months ago when WhatsApp announced that it was using end-to-end encryption for all messages by default, boosting the privacy and security of users.

But now respected iOS security researcher Jonathan Zdziarski claims to have found a worrying weakness in WhatsApp, that could open a door for intelligence agencies and other prying eyes to snoop upon your private conversations, even after they have been “deleted” from the app.

In a blog post, Zdziarski describes how he found a “forensic trace” of supposedly-deleted conversations on his iPhone’s disk image:

Sorry, folks, while experts are saying the encryption checks out in WhatsApp, it looks like the latest version of the app tested leaves forensic trace of all of your chats, even after you”ve deleted, cleared, or archived them… even if you “Clear All Chats”. In fact, the only way to get rid of them appears to be to delete the app entirely.

What this means is that the WhatsApp app itself won’t show you any evidence of cleared chats, but your iPhone’s physical hardware preserves a record of the conversations on its disk because the data is not automatically overwritten. This means that someone who has physical access to your iPhone could use data forensic tools to recover private conversations that you believed had been wiped.

forensic-trace

Furthermore, conversations you believe to have been wiped might actually be being backed up unencrypted to the cloud:

And even if you *do* backup your phone to your desktop computer with a password, cracking tools are available to help hackers in their attempts to break into the backup or recover your password from your keychain.

Should millions of WhatsApp users be panicking right now? No, probably not. But if you are in the habit of having sensitive conversations, and believe you might be at risk, live in an oppressive country, or work in the field of human rights then it might be wise to consider switching messaging apps.

But beware – it turns out that WhatsApp may not be alone in lulling its users into a false sense of security. iMessage suffers in a similar manner:

Apple”s iMessage has this problem and it”s just as bad, if not worse. Your SMS.db is stored in an iCloud backup, but copies of it also exist on your iPad, your desktop, and anywhere else you receive iMessages. Deleted content also suffers the same fate.

Signal, endorsed by no less an authority than Edward Snowden, does not not suffer from leaving sensitive information lying around on an iPhone, according to Zdziarski:

“Signal leaves virtually nothing, so there”s nothing to worry about.”

Zdziarski’s blog post describes steps that WhatsApp’s development team might like to consider if it wishes to do a better job of securing users’ private conversations.

Seeing as WhatsApp introduced end-to-end encryption to such a rapturous reception, one imagines that they are keen to support the privacy of their users and will work hard to address this flaw as quickly as possible.

tags


Author



Right now

Top posts

August Spam Debrief: Bitdefender Labs Warns of Fraud Campaigns Exploiting the Russia-Ukraine War

August Spam Debrief: Bitdefender Labs Warns of Fraud Campaigns Exploiting the Russia-Ukraine War

August 31, 2022

4 min read
Snake Keylogger Returns in Malspam Campaign Disguised as Business Portfolio from IT Vendor

Snake Keylogger Returns in Malspam Campaign Disguised as Business Portfolio from IT Vendor

August 30, 2022

2 min read
What is medical identity theft and how to protect against it

What is medical identity theft and how to protect against it

July 27, 2022

2 min read
Curious about Omegle? Here’s how the roulette-style chat platform can threaten your online privacy and security

Curious about Omegle? Here’s how the roulette-style chat platform can threaten your online privacy and security

July 07, 2022

5 min read
Identifying and Dealing with Online Bullying Is Not Impossible - School Presentation Inside

Identifying and Dealing with Online Bullying Is Not Impossible - School Presentation Inside

June 28, 2022

2 min read
Let’s Celebrate World Social Media Day by Improving Your Privacy and Security Online

Let’s Celebrate World Social Media Day by Improving Your Privacy and Security Online

June 28, 2022

3 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Prison for ex-eBay staff who aggressively cyberstalked company's critics with Craigslist sex party ads and funeral wreaths Prison for ex-eBay staff who aggressively cyberstalked company's critics with Craigslist sex party ads and funeral wreaths
Graham CLULEY

September 30, 2022

2 min read
Honolulu Man Sabotaged Former Employer’s Network and Business Using Still-Active Credentials Honolulu Man Sabotaged Former Employer’s Network and Business Using Still-Active Credentials
Silviu STAHIE

September 30, 2022

1 min read
North Korean Gang Uses Compromised Open Source Software to Distribute Malware, Researchers Find North Korean Gang Uses Compromised Open Source Software to Distribute Malware, Researchers Find
Silviu STAHIE

September 30, 2022

1 min read