TechCrunch News 2024年12月09日
WhatsApp fixes bug that let users bypass ‘View Once’ privacy feature
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

WhatsApp修复了一个允许恶意用户保存本应阅后即焚的图片和视频的漏洞。该漏洞存在于“阅后即焚”隐私功能的Web应用程序实现中,使用户能够显示并保存媒体。WhatsApp已推出长期修复方案,解决了该问题。WhatsApp发言人表示,公司不断构建隐私保护层,并鼓励用户仅向他们认识和信任的人发送阅后即焚消息,并确保他们使用的是最新版本的应用程序。

🔐WhatsApp的“阅后即焚”功能旨在防止接收者保存、共享、转发、复制甚至截屏或录屏媒体。

💻安全研究人员Tal Be'ery发现并向WhatsApp报告了一个漏洞,该漏洞允许用户在使用WhatsApp基于浏览器的Web应用程序时绕过“阅后即焚”的隐私保护,从而显示和保存媒体。

📢在WhatsApp修复该漏洞后,一些声称可以绕过“阅后即焚”功能的浏览器扩展程序已失效,用户抱怨这些扩展程序不再起作用。

📱WhatsApp现在在其Web应用程序上显示与桌面应用程序相同的警告消息,提醒用户“阅后即焚”媒体的隐私保护。

🛡️Tal Be'ery表示,公开披露漏洞有时是负责任的做法,很高兴他们的研究和发布促使WhatsApp修复了该问题并保护了用户的隐私。

WhatsApp fixed a bug that allowed malicious users to save pictures and videos that were supposed to be viewed only once and then vanish. 

In September, TechCrunch reported that a bug in the implementation of the “View Once” privacy  feature allowed people using WhatsApp’s browser-based web app to display and then keep the picture or video. The View Once feature is designed to prevent recipients from saving, sharing, forwarding, copying, and even screenshotting or screen recording media sent as “View Once,” given that in normal circumstances, the pictures or videos disappear after being viewed.

On Friday, WhatsApp spokesperson Zade Alsawah told TechCrunch that the company has rolled out a longer-term fix that resolved the issue. 

“We’re constantly building in layers of privacy protection, and that includes rolling out key updates to view once on web,” Alsawah said in an email. “As always, we continue to encourage users to only send View Once messages to people they know and trust, and make sure they’re on the latest version of the app.”

Do you have more information about bugs in WhatsApp or other messaging apps? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Tal Be’ery, a security researcher, who has been looking into WhatsApp’s privacy issues this year, alerted WhatsApp and TechCrunch of the bug. But Be’ery wasn’t the only one who found the flaw. When he found it, there were also several browser extensions and posts on social media that advertised easy solutions to circumvent the privacy feature, allowing users to just install an extension and automatically be able to display and save media sent as View Once. 

After WhatsApp’s fix, which appears to have been pushed in the last couple of weeks, users of those browser extensions, some of which require a paid subscription, are complaining that they don’t work anymore. “Does not work AT ALL. Don’t waste your time” complained one user. 

Now, in a test performed by TechCrunch on Friday, when we received a View Once Message on WhatsApp’s web app, the app displayed the following message, which is the same message that it usually displays on the desktop app.

The warning that WhatsApp displays on its desktop app and web app when a user receives a “View Once” media. (Image Credits: TechCrunch/Screenshot)

In another test performed by TechCrunch and Be’ery last week, the researcher saw a different message: “Waiting for this message. Check your phone.”

In any case, Be’ery wasn’t able to save the picture using the technique he has been using for months. “Sometimes, when a vulnerability is exploited in the wild, a responsible disclosure is to go public,” Tal Be’ery told TechCrunch. “We are very happy that our research and publication drove WhatsApp to fix the issue and protect the privacy of their users.” 

Be’ery, who is the CTO and co-founder of crypto wallet Zengo, published a blog post on Monday analyzing the fix.

View Once was launched in 2021 and is designed to work only on WhatsApp’s iOS and Android apps, and not on the web or desktop app.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

WhatsApp 隐私 漏洞 安全 阅后即焚
相关文章