WhatsApp has a massive security problem, but you may be able to avoid it
What you need to know
- Researchers have discovered a worrying vulnerability within WhatsApp.
- Users can be locked out of their accounts thanks to a massive flaw involving just a phone number.
- WhatsApp users are encouraged to enable two-step authentication on their accounts.
WhatsApp has a big security issue right now, and it doesn't seem to be doing much about it. The app has seen its fair share of problems lately, including a mass exodus from the platform after it announced its new privacy policy requiring accounts to be connected to Facebook. It turns out that privacy isn't the only problem WhatsApp has to deal with, not that a huge security flaw has been discovered.
A pair of researchers have uncovered a flaw (via Forbes) that allows attackers to lock anyone out of their WhatsApp account with just their phone number. It works because upon installing the app, the app will ask for a phone number. The attacker can input any number, which will then receive a confirmation text. If your number is at the receiving end of this, you'll notice seemingly unprompted verification texts from WhatsApp that you can't do anything about. And after too many verification attempts, further attempts to log in will be blocked for 12 hours. That shouldn't affect you since you're already logged in, but the real problem comes next.
From there, the attacker can send an email to WhatsApp support asking to deactivate the number due to a lost or stolen phone. Since WhatsApp doesn't know whether or not the phone number truly belongs to the attacker, the support team can comply and deactivate the account, which will force you off the app for the remainder of the 12 hours. The problem is that even if you try to get back on, the attacker can just repeat the process until, eventually, you're completely locked out with no way to attempt to get back into the app.
One of the big problems with this flaw is that it apparently works even with two-factor authentication turned on and highlights one of the main problems with SMS-based 2FA. Forbes questioned WhatsApp about the vulnerability, but there has been no indication that the team would address it.
So what can you do to make sure this doesn't happen to you? Although this attack, unfortunately, works even with 2FA, it's still useful to have on, and we can walk you through how to enable two-factor authentication in WhatsApp on Android. This will require a pin to register your number with the app, but it also gives you the option to add an email which is highly encouraged. WhatsApp states that users should add their email address to their credentials, which should come in handy if someone ever finds themselves in this situation. That said, it's highly problematic that this flaw exists, especially as WhatsApp's new policy for user accounts approaches.
Of course, the other option is to transfer your WhatsApp chats to Telegram or even Signal, some of the best messaging apps around, and both of which offer similar features and end-to-end encryption.
Be an expert in 5 minutes
Get the latest news from Android Central, your trusted companion in the world of Android
Derrek is the managing editor of Android Central, helping to guide the site's editorial content and direction to reach and resonate with readers, old and new, who are just as passionate about tech as we are. He's been obsessed with mobile technology since he was 12, when he discovered the Nokia N90, and his love of flip phones and new form factors continues to this day. As a fitness enthusiast, he has always been curious about the intersection of tech and fitness. When he's not working, he's probably working out.