Close Menu
NewsFile GH
  • Home
  • Local News
  • Politics
  • Business
  • Sports
  • Showbiz
  • Odd News
  • Opinion
What's Hot

GMTF launches nationwide specialist training initiative to strengthen healthcare delivery

Ghana, UAE to strengthen strategic energy ties as Mahama expresses solidarity with Abu Dhabi

Annoh-Dompreh sues Bono Region Minister over alleged cocoa smuggling claims for GH¢20m

Facebook X (Twitter) Instagram
Trending
  • GMTF launches nationwide specialist training initiative to strengthen healthcare delivery
  • Ghana, UAE to strengthen strategic energy ties as Mahama expresses solidarity with Abu Dhabi
  • Annoh-Dompreh sues Bono Region Minister over alleged cocoa smuggling claims for GH¢20m
  • Perception of corruption widespread among citizens – APL
  • Macroeconomic progress not reflecting on living conditions of Ghanaians – APL report
  • Carlos Queiroz names 23-man squad for Mexico friendly
  • This impunity must stop – Afenyo-Markin slams EOCO on re-arrest of ex-NABFCO boss
  • Opoku-Agyemang visits Ghana Medical Trust Fund
Facebook X (Twitter) Instagram
NewsFile GH
Demo
  • Home
  • Local News

    Perception of corruption widespread among citizens – APL

    May 6, 2026

    BNI nabs four over PDS payments

    May 4, 2026

    Mahama adrives in Gabon for Libreville Int’l Forum

    May 3, 2026

    Be agents of change, not just title holders – NYA CEO urges youth

    April 30, 2026

    STMA highlights funding constraints, demands Sanitation Courts during Parliamentary Oversight visit

    April 29, 2026
  • Politics

    Annoh-Dompreh sues Bono Region Minister over alleged cocoa smuggling claims for GH¢20m

    May 6, 2026

    This impunity must stop – Afenyo-Markin slams EOCO on re-arrest of ex-NABFCO boss

    May 6, 2026

    Boakye Agyarko calls on Bawumia ahead of nationwide tour for NPP Chairmanship bid

    May 1, 2026

    The agenda to weaken NPP as a political force will fail – Afenyo-Markin

    April 29, 2026

    Minority condemns arrest of Kofi Jumah by EOCO

    April 29, 2026
  • Business

    Ghana, UAE to strengthen strategic energy ties as Mahama expresses solidarity with Abu Dhabi

    May 7, 2026

    Macroeconomic progress not reflecting on living conditions of Ghanaians – APL report

    May 6, 2026

    Amin Adam petitions IMF over BoG’s 2025 accounts, flags fiscal risks

    May 5, 2026

    Amin Adam calls for IMF action on BoG recapitalisation, gold sales & monetary risks

    May 5, 2026

    IERPP: Is the IMF complicit in Bank of Ghana’s massive 2025 losses?

    May 5, 2026
  • Sports

    Carlos Queiroz names 23-man squad for Mexico friendly

    May 6, 2026

    GFA sets September 4 for start of next season

    April 29, 2026

    Ten ‘sins’ Carlos Queiroz needs no repeating as Black Stars coach

    April 27, 2026

    Carlos Queiroz outdoored

    April 23, 2026

    Asante Kotoko’s interim coach Yaw Owusu resigns after barely two months

    April 21, 2026
  • Showbiz

    Agri-value addition takes centre stage at Ghana Cake Festival 2026

    May 5, 2026

    Kwahu Easter a national tourism asset that needs infrastructure support – Mpraeso MP

    March 27, 2026

    Gyankroma Akufo-Addo denies $25m interchange painting claims; threatens legal action

    March 27, 2026

    OnlyFans owner Leonid Radvinsky dies at 43

    March 23, 2026

    Liizzy Gordon sings about the Blood of Jesus

    March 23, 2026
  • Odd News

    Indian man carries sister’s skeleton to bank to prove her death

    April 30, 2026

    Stranded whale ferried out of German waters in barge

    April 29, 2026

    We had sex in a Chinese hotel, then found we had been broadcast to thousands

    February 6, 2026

    Nsawam Female Prison inmates showcase talents, proving rehabilitation thrives through discipline, culture and self-expression

    January 6, 2026

    Drunk raccoon found passed out on liquor store floor after breaking in

    December 3, 2025
  • Opinion

    Tithing Wahala: The Methodist Church’s ‘Robbers’ & the ‘Brave’ Woman – My Judgement!

    April 28, 2026

    Ten ‘sins’ Carlos Queiroz needs no repeating as Black Stars coach

    April 27, 2026

    Stop blaming the Banku. . .are we eating wrong or just living wrong?

    April 27, 2026

    My eight True Dare: ICUMS vs Truedare – Why is Truedare more expensive than ICUMS?

    April 23, 2026

    Ghana’s Investment Revolution: Open for business, protected for citizens

    April 20, 2026
NewsFile GH
Home»Tech»WHATSAPP SECURITY FLAWS COULD ALLOW SNOOPS TO SLIDE INTO GROUP CHAT
Tech

WHATSAPP SECURITY FLAWS COULD ALLOW SNOOPS TO SLIDE INTO GROUP CHAT

By newsfileghJanuary 11, 20188 Mins Read
Share Facebook Twitter LinkedIn Email WhatsApp Telegram Copy Link
Share
Facebook Twitter LinkedIn WhatsApp Copy Link Email

When WhatsApp added end-to-end encryption to every conversation for its billion users two years ago, the mobile messaging giant significantly raised the bar for the privacy of digital communications worldwide. But one of the tricky elements of encryption—and even trickier in a group chat setting—has always been ensuring that a secure conversation reaches only the intended audience, rather than some impostor or infiltrator. And according to new research from one team of German cryptographers, flaws in WhatsApp make infiltrating the app’s group chats much easier than ought to be possible.

At the Real World Crypto security conference Wednesday in Zurich, Switzerland, a group of researchers from the Ruhr University Bochum in Germany plan to describe a series of flaws in encrypted messaging apps including WhatsApp, Signal, and Threema. The team argues their findings undermine each app’s security claims for multi-person group conversations to varying degrees.

But while the Signal and Threema flaws they found were relatively harmless, the researchers unearthed far more significant gaps in WhatsApp’s security: They say that anyone who controls WhatsApp’s servers could effortlessly insert new people into an otherwise private group, even without the permission of the administrator who ostensibly controls access to that conversation.

‘It’s just a total screwup. There’s no excuse.’

Matthew Green, Johns Hopkins University

“The confidentiality of the group is broken as soon as the uninvited member can obtain all the new messages and read them,” says Paul Rösler, one of the Ruhr University researchers who co-authored a paper on the group messaging vulnerabilities. “If I hear there’s end-to-end encryption for both groups and two-party communications, that means adding of new members should be protected against. And if not, the value of encryption is very little.”

That any would-be eavesdropper would have to control the WhatsApp server limits the spying method to sophisticated hackers who could compromise those servers, WhatsApp staffers, or governments who legally coerce WhatsApp to give them access. But the premise of so-called end-to-end encryption has always been that even a compromised server shouldn’t expose secrets. Only people in a conversation should be able to read WhatsApp’s messages, not the servers themselves.

“If you build a system where everything comes down to trusting the server, you might as well dispense with all the complexity and forget about end-to-end encryption,” says Matthew Green, a cryptography professor at Johns Hopkins University who reviewed the Ruhr University researchers’ work. “It’s just a total screwup. There’s no excuse.”

Group Threat

The German researchers say their WhatsApp attack takes advantage of a simple bug. Only an administrator of a WhatsApp group can invite new members, but WhatsApp doesn’t use any authentication mechanism for that invitation that its own servers can’t spoof. So the server can simply add a new member to a group with no interaction on the part of the administrator, and the phone of every participant in the group then automatically shares secret keys with that new member, giving him or her full access to any future messages. (Messages sent prior to an illicit invitation, fortunately, still can’t be decrypted.)

Everyone in the group would see a message that a new member had joined, seemingly at the invitation of the unwitting administrator. If the administrator is watching closely, he or she could warn the group’s intended members about the interloper and the spoofed invitation message.

But the Ruhr University researchers and Johns Hopkins’ Green point out several tricks that could be used to delay detection. Once an attacker with control of the WhatsApp server had access to the conversation, he or she could also use the server to selectively block any messages in the group, including those that ask questions, or provide warnings about the new entrant.

“He can cache all the message and then decide which get sent to whom and which not,” says Rösler. And in groups with multiple administrators, the hijacked server could spoof different messages to each administrator, making it appear that another one had invited the eavesdropper, so that none raises an alarm. It could even prevent any administrator’s attempt to remove the eavesdropper from the group if discovered.

Some Limits

In a phone call with WIRED, a WhatsApp spokesperson confirmed the researchers’ findings, but emphasized that no one can secretly add a new member to a group—a notification does go through that a new, unknown member has joined the group. The staffer added that if an administrator spots a fishy new addition to a group, they can always tell other users via another group, or in one-to-one messages. And the WhatsApp spokesperson also noted that preventing the Ruhr University researchers’ attack would likely break a popular WhatsApp feature known as a “group invite link” that allows anyone to join a group simply by clicking on a URL.

“We’ve looked at this issue carefully,” a WhatsApp spokesperson wrote in an email. “Existing members are notified when new people are added to a WhatsApp group. We built WhatsApp so group messages cannot be sent to a hidden user. The privacy and security of our users is incredibly important to WhatsApp. It’s why we collect very little information and all messages sent on WhatsApp are end-to-end encrypted.”

To be fair, this technique wouldn’t be a very stealthy strategy in the long run for government spying. Sooner or later, users would likely notice that unexpected strangers were showing up in their chats. But that possibility of detection isn’t an adequate solution to WhatsApp’s underlying problem, argues John Hopkins’ Green. “That’s like leaving the front door of a bank unlocked and then saying no one will rob it because there’s a security camera,” Green says. “It’s dumb.”

The Ruhr University researchers say they alerted WhatsApp to the problem with group messaging security last July. In response to their report, WhatsApp’s staff say they fixed one problem with a feature of their encryption that made it harder to crack future messages even after an attacker obtained one decryption key. But they told the researchers the group invitation bug they’d found was merely “theoretical” and didn’t even qualify for the so-called bug bounty program run by Facebook, WhatsApp’s corporate owner, in which security researchers are paid for reporting hackable flaws in the company’s software.

‘If I hear there’s end-to-end encryption for both groups and two-party communications, that means adding of new members should be protected against.’

Paul Rösler, Ruhr University

For some of WhatsApp’s users, the stakes of the app’s security could be high. WhatsApp’s convenient group messaging system, in combination with its encryption promises, have made it a popular tool for “whisper networks” of grassroots organizing around sensitive or dangerous topics. Victims of sexual abuse and harassment have used it to organize the campaign against abusers, for instance. So have political insiders and Syria’s embattled White Helmets, volunteer rescue brigades in Syria who are often targeted by the ruling regime.

But the shoddy security around WhatsApp’s group chats should make its most sensitive users wary of interlopers, Rösler argues. If WhatsApp were to comply with a government request—in the US or abroad—agents could join any private group and listen along.

Smaller Problems

The researchers dug up less serious flaws in the more specialized secure messaging apps Signal and Threema, too. They warn that Signal allows the same group chat attack as WhatsApp, letting uninvited eavesdroppers join groups. But in Signal’s case, that eavesdropper would have to not only control the Signal server, but also know a virtually unguessable number called the Group ID. That essentially blocks the attack, unless the Group ID can be obtained from one of the group member’s phones—in which case the group is likely already compromised. The researchers say that Open Whisper Systems, the non-profit that runs and maintains Signal, nonetheless responded to their work, saying that it’s currently redesigning how Signal handles group messaging. Open Whisper Systems declined to comment on the record to WIRED about the Ruhr researchers’ findings.

For Threema, the researchers found even smaller bugs: An attacker who controls the server can replay messages or add users back into a group who have been removed. The researchers say Threema responded to their findings with a fix in an earlier version of its software.

As for WhatsApp, the researchers write that the company could fix its more egregious group chat flaw by adding an authentication mechanism for new group invitations. Using a secret key only the administrator possesses to sign those invitations could let the admin prove his or her identity and prevent the spoofed invites, locking out uninvited guests. WhatsApp has yet to take their advice.

Until they do, WhatsApp’s most sensitive users should consider sticking with one-to-one conversations, or switching to a more secure group messaging app like Signal. Otherwise, they’d be wise to keep a vigilant eye out for any new entrants sliding into their private conversations. Until an administrator actively vouches for that newcomer, there’s a small chance he or she might just be something other than a new friend.

 

 

Source: Wired

Share. Facebook Twitter LinkedIn Email Copy Link WhatsApp

Related Posts

Ghana Health Ministry orders enhanced security across all health facilities

February 19, 2026By Esi Abokomah2 Mins Read

Ghana Police Service has interdicted 5 officers for acts of misconduct on social media

December 16, 2025By newsfilegh1 Min Read

Western Regional Police command investigates fatal shooting incident at Adelekezu

December 14, 2025By newsfilegh2 Mins Read
Follow Us
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Recent Posts
  • GMTF launches nationwide specialist training initiative to strengthen healthcare delivery
  • Ghana, UAE to strengthen strategic energy ties as Mahama expresses solidarity with Abu Dhabi
  • Annoh-Dompreh sues Bono Region Minister over alleged cocoa smuggling claims for GH¢20m
  • Perception of corruption widespread among citizens – APL
  • Macroeconomic progress not reflecting on living conditions of Ghanaians – APL report
  • Carlos Queiroz names 23-man squad for Mexico friendly
Top Posts

GMTF launches nationwide specialist training initiative to strengthen healthcare delivery

Ghana, UAE to strengthen strategic energy ties as Mahama expresses solidarity with Abu Dhabi

Annoh-Dompreh sues Bono Region Minister over alleged cocoa smuggling claims for GH¢20m

Perception of corruption widespread among citizens – APL

About Us
About Us

NewsFile Gh is a comprehensive news portal that delivers up-to-date information on a wide range of topics, including politics, business, sports, entertainment etc. It provides users with real-time news updates accessible anytime and anywhere...

Email Us: news@newsfilegh.com

Facebook X (Twitter) YouTube RSS
Recent

GMTF launches nationwide specialist training initiative to strengthen healthcare delivery

Ghana, UAE to strengthen strategic energy ties as Mahama expresses solidarity with Abu Dhabi

Annoh-Dompreh sues Bono Region Minister over alleged cocoa smuggling claims for GH¢20m

Most Popular

IS leader in Afghanistan ‘killed’

July 11, 2015

‘Oldest’ Koran found at UK university

July 22, 2015

Gunman in Mahama’s church for court today

July 28, 2015
© 2026 NewsFile GH. All Rights Reserved.
  • Home
  • Politics

Type above and press Enter to search. Press Esc to cancel.