{"id":21352,"date":"2021-07-06T11:03:36","date_gmt":"2021-07-06T05:33:36","guid":{"rendered":"https:\/\/valeurbit.com\/blog\/?p=21352"},"modified":"2021-07-06T11:03:38","modified_gmt":"2021-07-06T05:33:38","slug":"whatsapp-user-can-have-their-account-taken-away","status":"publish","type":"post","link":"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/","title":{"rendered":"Any WhatsApp user can have their account taken away. You don&#8217;t need to be a hacker to do this"},"content":{"rendered":"\n<p>There is a flaw in WhatsApp that allows attackers with zero hacking and programming skills to permanently block any user&#8217;s account.They only need to know their phone number, and nothing else, and it is impossible to protect against potential blocking.\u00a0The WhatsApp developers have been slow to fix the problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">New flaw in WhatsApp<\/h2>\n\n\n\n<p>Every WhatsApp user can lose their profile at any second with a minimal chance of recovery.&nbsp;As Forbes writes, it is simply impossible to protect against this, and an attacker will not even need to hack the gadget &#8211; he just needs to know the user&#8217;s phone number, after which he can initiate the blocking procedure without the possibility of re-authorization in the system.<\/p>\n\n\n\n<p>Possibility to deprive any person to use WhatsApp &#8211; this is a consequence giant vulnerability discovered in the messenger information security specialists\u00a0<strong>Luis Kartintero<\/strong>\u00a0(Luis Carpintero) and\u00a0<strong>Ernesto Perrin<\/strong>\u00a0(Ernesto Canales Pere\u00f1a).\u00a0They notified the WhatsApp developers of their find, but they have not yet released a patch to fix the breach, leaving 2 billion users at risk of losing their account.<\/p>\n\n\n\n<p>WhatsApp is the most popular messenger in the world.\u00a0According to Statista.com, in terms of the number of monthly active users in January 2021, it was ahead of Facebook Messenger (1.3 billion) and Chinese WeChat (1.21 billion) with its more than 2 billion, along with QQ (617 million).\u00a0Since February 2014, WhatsApp has been\u00a0owned by\u00a0Facebook.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How the vulnerability works<\/h2>\n\n\n\n<p>The vulnerability in WhatsApp allows a complete blocking of the victim&#8217;s account and is carried out in two very simple steps, at each of which the performer does not even need hacking or social engineering skills &#8211; he will not contact the owner of the profile at all.<\/p>\n\n\n\n<p>At the first stage, the attacker simply needs to install WhatsApp on the smartphone and try to log in with the desired phone number.\u00a0The messenger will send an SMS with a confirmation code to him, and here it is calculated that the owner of the number will ignore them.\u00a0After several such attempts, the application on the attacker&#8217;s device will report too frequent authorization attempts and will allow the next one only after 12 hours.\u00a0At the same time, WhatsApp on the victim&#8217;s device will continue to work as before.<\/p>\n\n\n\n<p>At the second stage, the attacker registers a new email address and writes a letter to WhatsApp technical support, in which he says that his account has been lost or stolen.\u00a0He asks to turn it off and indicates the victim&#8217;s number.\u00a0WhatsApp can send an automated email asking you to rewrite the number, and the attacker will do so.<\/p>\n\n\n\n<p>Further, WhatsApp, without making sure that the real owner of the account wrote to technical support, initiates the blocking procedure.\u00a0After about an hour, the messenger will suddenly stop working on the victim&#8217;s device &#8211; she will see a message that her number is no longer registered in the system.\u00a0\u201cIt could have happened because you registered it on another phone.\u00a0If you have not done so, please confirm your phone number to log in to your account again, \u201dthe notification will say.<\/p>\n\n\n\n<p>All of this will work even if the user has activated two-factor authentication.&nbsp;An attempt to request a new code will fail &#8211; WhatsApp will only allow you to do this after 12 hours.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Bonus stage and complete blocking<\/h2>\n\n\n\n<p>If the attacker decides to stop at the second stage, then everything will end with just the inability of the user to connect to WhatsApp with his number for several hours.&nbsp;After a maximum of 12 hours, the user will be able to regain control over his account and continue working in the messenger exactly as long as someone does not want to repeat the &#8220;trick&#8221; with blocking.<\/p>\n\n\n\n<p>But in fact, there is an additional, third stage, leading to a complete blocking of the account.<\/p>\n\n\n\n<p>In fact, this stage can become the second &#8211; the attacker does not have to send a letter in support of WhatsApp, he can simply wait 12 hours, and then again make several attempts to register someone else&#8217;s number on his phone.\u00a0After the third 12-hour blocking, WhatsApp will break, and instead of a timer counting down the time until the next authorization attempt, it will show &#8220;-1 second&#8221;, moreover, constantly.\u00a0This is a malfunction of the messenger that cannot be bypassed.<\/p>\n\n\n\n<p>This picture will be observed both on the hacker&#8217;s device and on the victim&#8217;s smartphone, and as a result, no one else will be able to log in to the messenger using this phone number.&nbsp;The only thing that remains is to try to contact WhatsApp technical support and look for solutions to the problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WhatsApp does not solve the problem<\/h2>\n\n\n\n<p>An article in Forbes shedding light on a new issue in WhatsApp was published on April 10, 2021.By April 13, 2021, the developers had not released an update that fixes it and did not set a timeline for its release.<\/p>\n\n\n\n<p>Instead, they are preparing for the implementation of a new privacy policy, according to which the messenger will automatically transfer huge amounts of personal data of users to Facebook for better ad targeting.<\/p>\n\n\n\n<p>WhatsApp intended to introduce this policy on February 8, 2021, but was forced to temporarily abandon this idea due to a barrage of criticism.&nbsp;The new date of its entry into force is May 15, 2021, and all those who are not going to agree with it will face a very serious punishment.<\/p>\n\n\n\n<p>In February 2021, CNews\u00a0wrote\u00a0that those who disagree with the new WhatsApp privacy policy will no longer be able to send and receive text messages.\u00a0The developers will leave them with only voice calls.\u00a0Moreover, the profiles of those users who stop using WhatsApp and switch to other messengers are guaranteed to be completely deleted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Other WhatsApp problems<\/h2>\n\n\n\n<p>WhatsApp is known not only for the fact that it is used by billions of people, but also for the fact that it does not always value its users.\u00a0For example, in June 2020, it became known that some phone numbers associated with user profiles in WhatsApp had been in the public domain for a long time and even got into Google search results.\u00a0In total, with the help of Google, it was possible to find up to the number of about 300 thousand messenger users, and this problem was of a global nature.<\/p>\n\n\n\n<p>In November 2019, CNews\u00a0reported\u00a0that WhatsApp users were automatically permanently blocked for participating in harmless group chats.\u00a0It turned out to be possible to fall under the sanctions for changing the name of the chat to something that would seem to the moderators of the service to be something sinister, illegal, or malicious.<\/p>\n\n\n\n<p>At the same time, WhatsApp was in no hurry to fix this failure.\u00a0To all inquiries from victims about the reasons for the blocking, the messenger employees answered that the users themselves violated the rules of the service, and the blame for the blocking lies solely with them.\u00a0As a result, people had to either change their phone number to register a new profile or go to other services &#8211; Telegram, Viber, Signal, and others.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is a flaw in WhatsApp that allows attackers with zero hacking and programming skills to permanently block any user&#8217;s account.They only need to know their phone number, and nothing else, and it is impossible to protect against potential blocking.\u00a0The WhatsApp developers have been slow to fix the problem. New flaw in WhatsApp Every WhatsApp&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Any WhatsApp user can have their account taken away. You don&#039;t need to be a hacker to do this | ValeurBit Infosec<\/title>\n<meta name=\"description\" content=\"There is a flaw in WhatsApp that allows attackers with zero hacking and programming skills to permanently block any user&#039;s account.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Any WhatsApp user can have their account taken away. You don&#039;t need to be a hacker to do this | ValeurBit Infosec\" \/>\n<meta property=\"og:description\" content=\"There is a flaw in WhatsApp that allows attackers with zero hacking and programming skills to permanently block any user&#039;s account.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/\" \/>\n<meta property=\"og:site_name\" content=\"ValeurBit Infosec\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/valeurbitinfo\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-06T05:33:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-06T05:33:38+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@valeurbit\" \/>\n<meta name=\"twitter:site\" content=\"@valeurbit\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\",\"name\":\"Valeurbit Infosec\",\"url\":\"https:\/\/valeurbit.com\/blog\/\",\"sameAs\":[\"https:\/\/www.facebook.com\/valeurbitinfo\/\",\"https:\/\/www.instagram.com\/valeurbit\",\"https:\/\/www.linkedin.com\/company\/valeurbit-infosec\/\",\"https:\/\/twitter.com\/valeurbit\"],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/02\/Valeurbit-new-logo-center.png\",\"contentUrl\":\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/02\/Valeurbit-new-logo-center.png\",\"width\":1080,\"height\":512,\"caption\":\"Valeurbit Infosec\"},\"image\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#website\",\"url\":\"https:\/\/valeurbit.com\/blog\/\",\"name\":\"ValeurBit Infosec\",\"description\":\"Cyber Security Company\",\"publisher\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/valeurbit.com\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/#webpage\",\"url\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/\",\"name\":\"Any WhatsApp user can have their account taken away. You don't need to be a hacker to do this | ValeurBit Infosec\",\"isPartOf\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#website\"},\"datePublished\":\"2021-07-06T05:33:36+00:00\",\"dateModified\":\"2021-07-06T05:33:38+00:00\",\"description\":\"There is a flaw in WhatsApp that allows attackers with zero hacking and programming skills to permanently block any user's account.\",\"breadcrumb\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/valeurbit.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Any WhatsApp user can have their account taken away. You don&#8217;t need to be a hacker to do this\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/#webpage\"},\"author\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#\/schema\/person\/df20c1cd317765fa8677a3056caeccfa\"},\"headline\":\"Any WhatsApp user can have their account taken away. You don&#8217;t need to be a hacker to do this\",\"datePublished\":\"2021-07-06T05:33:36+00:00\",\"dateModified\":\"2021-07-06T05:33:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/whatsapp-user-can-have-their-account-taken-away\/#webpage\"},\"wordCount\":1203,\"publisher\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\"},\"articleSection\":[\"Valeurbit\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#\/schema\/person\/df20c1cd317765fa8677a3056caeccfa\",\"name\":\"ValeurBit\",\"sameAs\":[\"https:\/\/valeurbit.com\/blog\"],\"url\":\"https:\/\/valeurbit.com\/blog\/author\/valeurbit\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/21352"}],"collection":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/comments?post=21352"}],"version-history":[{"count":1,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/21352\/revisions"}],"predecessor-version":[{"id":21353,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/21352\/revisions\/21353"}],"wp:attachment":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/media?parent=21352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/categories?post=21352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/tags?post=21352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}