Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How to Check Your YouTube Comment History

    February 6, 2023

    How to Turn Off Message Requests on Instagram

    February 4, 2023

    15 Cool Galaxy S9 Features and Tricks You Should Use

    February 4, 2023
    Facebook Twitter Instagram
    FokatechFokatech
    • Home
    • News
    • How To
    • Gaming
    • What is
    • Mobile
    • Tech
    • PC
    • Cool Gadgets
    • Internet
    FokatechFokatech
    Home»Uncategorized»This WhatsApp Flaw Lets Attackers Permanently Deactivate User Accounts Remotely
    Uncategorized

    This WhatsApp Flaw Lets Attackers Permanently Deactivate User Accounts Remotely

    AdminBy AdminNovember 2, 2022No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Despite being one of the most widely used messaging apps, WhatsApp has put users at risk due to a number of vulnerabilities, including an amendment to its privacy policy. Recently, we observed a horrible WhatsApp fraud that allows a user’s contacts to hack them. Now, a deadlier flaw has been discovered that makes use of WhatsApp’s verification process to let hackers permanently cancel a user account.

    Vulnerabilities in WhatsApp s User-Verification System

    This new hack, which was uncovered by security experts Luis Marquez Carpintero and Ernesto Canales Perena and was made public by Forbes, has the potential to prove fatal for WhatsApp users because it just requires a short but laborious procedure. Furthermore, anyone who has your phone number can remotely complete the task. What’s more riskier is that even two-factor authentication (2FA) won’t be able to prevent the termination of your account.

    How Does it Work?

    The new remote-account-deactivation exploit makes use of flaws in WhatsApp’s ID verification architecture on two separate occasions. The first one includes the platform’s log-in through OTP method, and the second one is in the timer that the platform sets on its own following numerous failed login attempts.

    An attacker who has your phone number might begin the process by entering it on WhatsApp’s login screen. Remember that while the attacker carries out his initial acts, you won’t be completely affected and can continue to utilise the platform as normal. However, because the attacker is now inserting random codes into the login procedure to start the second part of the operation, you will receive multiple login codes by SMS.

    Following numerous failed login attempts from your number, WhatsApp will implement a 12-hour timer in the second phase, which will prevent the system from generating any new login codes for the duration of that time. Now, the attacker might delete your account by sending a request to support@whatsapp.com using a bogus email address. As a result, WhatsApp has noted numerous unsuccessful attempts to log in to your account and has received a request to deactivate the account associated with your phone number.

    Image: Forbes

    As a result, you will immediately lose access to your account an hour or so later and get an email from WhatsApp deactivating your account. The amusing part is that you will need to input the OTP issued by WhatsApp when you attempt to re-register your account. However, there is now a 12-hour timer that prevents the platform from generating fresh login codes for your account, therefore that is not possible. Additionally, the assailant who brought about this circumstance and you both share the same timer. Photo: Forbes

    Therefore, once the period has passed, you could try to re-register your account. The procedure could, however, get looped if the attacker uses the same ruse before you can re-register.

    The System Breakdown

    The second flaw in WhatsApp’s core architecture is now apparent. The automatic security system just breaks after a certain amount of looping. So, if the attacker repeatedly attempts to get into your account and fails, the system will eventually display a -1 second timer in place of the 12-hour schedule for generating new codes. This indicates that the automated verification system had malfunctioned due to overload. Photo: Forbes

    Due to the malfunctioning system, you will no longer be able to create new login codes for your phone number for the foreseeable future. Your account will therefore be inactive over the following 30 days, at which point WhatsApp will immediately remove it permanently from its database.

    While tedious, this technique is actually quite easy. These automated security holes in WhatsApp allow anyone with a smartphone to remotely cancel user accounts.

    Is It Fixable?

    Following the discovery of the aforementioned vulnerabilities, security researchers claimed that the problem is simply fixable because to WhatsApp’s long-standing multi-device compatibility. With multi-device compatibility, the platform can validate the devices that customers use to access their accounts via a trusted-device system similar to Apple’s.

    There is, however, currently no workaround for this procedure. As a result, if you begin to receive arbitrary login codes from WhatsApp in the upcoming days, you will be aware that your account is being attempted to be deactivated. To keep your account secure, you can get in touch with WhatsApp’s support team in advance and let them know about the circumstance. Additionally, tell your friends and family about this risky WhatsApp breach by spreading the word to them.

    TAGS
    WhatsApp

    1 Comment

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Admin

    Related Posts

    WhatsApp Will Now Let You Add up to 512 People to a Group

    November 14, 2022

    New iPad Pro with Thunderbolt, Mini-LED Display to Arrive “As Early as April”

    November 11, 2022

    How to Change WhatsApp Background for Individual Chats on iPhone and Android

    November 11, 2022

    Snapchat Keeps Crashing on iPhone? 10 Ways to Fix the Issue

    November 11, 2022
    Add A Comment

    Leave A Reply Cancel Reply

    Editors Picks

    How to Check Your YouTube Comment History

    February 6, 2023

    How to Turn Off Message Requests on Instagram

    February 4, 2023

    15 Cool Galaxy S9 Features and Tricks You Should Use

    February 4, 2023

    How to Restore Missing Features in Windows 10

    February 4, 2023
    Recent Posts
    • How to Check Your YouTube Comment History February 6, 2023
    • How to Turn Off Message Requests on Instagram February 4, 2023
    • 15 Cool Galaxy S9 Features and Tricks You Should Use February 4, 2023
    • How to Restore Missing Features in Windows 10 February 4, 2023
    • How to Turn Off All Sensors on Android Smartphone February 4, 2023
    Top Reviews

    How to Turn Off All Sensors on Android Smartphone

    February 4, 2023

    10 Best Anime Websites to Watch Anime Legally (Free and Paid)

    February 4, 2023

    Dash Charge vs SuperCharge vs Quick Charge vs Turbo Charge: Fast Charging Battle!

    February 4, 2023

    OnePlus 10T Leaked Price Details Hint at Good News!

    February 4, 2023
    About Us
    About Us

    Fokatech is a website that covers the latest news in technology, business, gadgets, and gaming. We aim to provide our readers with the most up-to-date information on all things tech so they can stay informed and ahead of the curve.

    Latest Post

    How to Check Your YouTube Comment History

    February 6, 2023

    How to Turn Off Message Requests on Instagram

    February 4, 2023

    15 Cool Galaxy S9 Features and Tricks You Should Use

    February 4, 2023
    Follow Us
    Follow Us
    Facebook Twitter Instagram Pinterest LinkedIn
    • Contact Us
    • Privacy Policy
    • Editorial Policy
    • Fact Check Policy
    • Write for Us 
    • Disclaimer
    • Terms & Conditions
    • DMCA
    • Our Authors
    © 2023 Fokatech | All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.