Tuesday, March 9, 2021
Home Lead Story Questions Raised On End-to-End Encryption Of WhatsApp For Snooping

Questions Raised On End-to-End Encryption Of WhatsApp For Snooping

End-to-end encryption on Whatsapp is being blamed for the Israeli spyware Pegasus

If we blame end-to-end encryption of WhatsApp for the Israeli spyware Pegasus that affected 1,400 select users of the Facebook-owned messaging app globally, including 121 in India, we will be barking up the wrong tree, say experts.

WhatsApp provides end-to-end encryption by default, which means only the sender and recipient can view the messages. But the piece of NSO Group software exploited WhatsApp’s video calling system by installing the spyware via missed calls to snoop on the selected users.

This raised questions about the utility of encryption, which also prohibits security agencies from tracing the origin of messages. Traceability of WhatsApp messages is a key demand that India has put forward.

But security experts have warned that blaming end-to-end encryption for the spyware would not be right.

“WhatsApp as well as other leading instant messaging apps have recently adopted an end-to-end encryption. The encryption process itself is solid, messages that leave your device are encrypted and they stay that way until they reach their final destination,” Yaniv Balmas, Head of Cyber Research, Check Point Software Technologies, told IANS.

“However, on your device, as well as on the receiving device the messages are decrypted so you can read them. A malicious application running on your device can inspect them, change or delete them just as well as you could. So the issue here is not in the applications or in their encryption protocol, but in the environment they are installed in,” Balmas said.

According to leading tech policy and media consultant Prasanto K. Roy, end-to-end encrypted apps (E2EE) do provide security, and messages or calls cannot be intercepted and decrypted en route without enormous computing resources.

“But once anyone can get to your handset, whether a human or a piece of software, the encryption doesn’t matter any more. Because on your handset, it’s all decrypted,” he explained.

Whatsapp
Security experts have warned that blaming Whatsapp for the spyware would not be right. Pixabay

“There’s plain text on your screen, and plain audio or video in your camera. The right kind of spyware in your handset can read those messages or even listen in on your phone’s mic to what someone is saying in the room, or see what’s happening around, with the camera.

“If that happens then all apps are affected, not just WhatsApp. The spyware doesn’t care about the app — it just reads the screen. So, the recent incident has not changed the fact that E2EE apps/platforms are secure. Or the fact that spyware on your handset (which has many vectors: this time it was WhatsApp, but it is usually SMS or email) can compromise your entire handset and all its apps,” Roy said.

In his memoir “Permanent Record”, whistleblower Edward Snowden wrote that the Internet is currently more secure now than it was in 2013, especially given the sudden global recognition of the need for encrypted tools and apps.

Snowden, who served as an officer of the Central Intelligence Agency (CIA) and worked as a contractor for the National Security Agency (NSA), rocked the world in 2013 after he revealed that the US was secretly building a way to collect the data of every person in the world, including phone calls, text messages and email.

“Perhaps the most important private sector change occurred when businesses throughout the world set about switching their website platforms, replacing http (Hypertext Transfer Protocol) with the encrypted https (the S signifies security), which helps prevent third party interception of Web traffic,” Snowden wrote.

Also Read- Photos-only Mode On Facebook’s Mobile App Under Testing

Balmas agreed the move to embrace encryption by chat applications marked a “good progress” in terms of user security and privacy.

“The encryption is solid and the algorithms behave as expected, however risks are still there, especially ones that originate from the surrounding operating system, which cannot be controlled or expected by any of the instant messaging software providers,” he said. (IANS)

STAY CONNECTED

19,120FansLike
362FollowersFollow
1,773FollowersFollow

Most Popular

Upcoming B-Town Films Inspired From The Great Epics Ramayana and Mahabharata

The epics Ramayana and Mahabharata seem to be the latest favourites of our filmmakers. A host of new films have been launched, with plots...

Representation of Women on Cinema Can Alter How People Percieve Them in Real: Anushka Sharma

On the occasion of International Women's Day, actress Anushka Sharma promises to make sure all her films have progressive women characters. She says it...

Tech Review (Realme Watch S): Affordable Yet Stylish

The love for fitness and style is increasing among the millennials in the country. Keeping this in mind, popular smartphone brand realme has launched...

Women Photographers Making An Impact In Today’s World

"People always call me 'sir' when they first call as they don't expect a woman to be behind the camera" are the words of...

One-Hour One Word Literacy Challenge: A Challenge To Promote Female Literacy

To mark International Women's Day, Indian educationist Sunita Gandhi has invited volunteers from all sections of society to take up the one-hour one Word...

How Multilayered Masks Will Help in Preventing Aerosol Generation

As triple-layered and N95 masks offer best protection from Covid, they must be used where health officials have made it mandatory to prevent aerosol...

Retinal Implants Can Give Artificial Vision To Blind

Researchers are developing a retinal implant that works with camera-equipped smart glasses and a microcomputer that may help blind people in getting an artificial...

Google Advises To Go For “Mental Health Counselling” Over Racism/Harassment Complaints By Employees

Several Google employees have said that the company allegedly suggested them to go for mental health counselling or apply for leave when they complained...

Recent Comments