SpinSafe
  • Cloud Backup Solutions
  • Torrents
    • Are Torrent Websites Safe?
    • How to Torrent
    • Popular Torrent Website List
  • Best VPN
  • Security Alerts
    • National Cyber Alerts
    • NIST
  • How To
    • How can I protect against Ransomware?
    • Secure Your Wireless Network
    • Home Network Security
  • News
    • Active Threat Alerts
    • Computer Security News
    • Internet Security News
    • Mobile Security News
    • Tech Video News
  • Search
  • Menu Menu

WhatsApp Introduces New Device Verification Feature to Prevent Account Takeover Attacks

April 13, 2023/in Mobile Security


Apr 13, 2023Ravie LakshmananMobile Security / Privacy

WhatsApp Device Verification

Popular instant messaging app WhatsApp on Thursday announced a new account verification feature that ensures that malware running on a user’s mobile device doesn’t impact their account.

“Mobile device malware is one of the biggest threats to people’s privacy and security today because it can take advantage of your phone without your permission and use your WhatsApp to send unwanted messages,” the Meta-owned company said in an announcement.

Called Device Verification, the security measure is designed to help prevent account takeover (ATO) attacks by blocking the threat actor’s connection and allowing the target to use the app without any interruption.

In other words, the goal is to deter attackers’ use of malware to steal authentication keys and hijack victim accounts, and subsequently impersonate them to distribute spam and phishing links.

This, in turn, is achieved by introducing a security-token that’s stored locally on the device, a cryptographic nonce to identify if a WhatsApp client is contacting the server to retrieve incoming messages, and an authentication-challenge that acts as an “invisible ping” from the server to a user’s device.

The client is required to send the security-token every time it connects to the server. The security-token, for its part, is updated every time it fetches an offline message from the server.

An authentication-challenge is considered a failure when the client responds to the challenge from a different device, indicating an anomalous connection originating from an attacker. This causes the connection to be blocked.

Should there be no response from the client, the process is retried a “few more times,” after which the connection will be blocked if the client still doesn’t respond.

WhatsApp said Device Verification has been rolled out to all Android users and that it’s in the process of being rolled out to iOS users.

The feature is part of a broader set of new enhancements that are designed to authenticate and verify users’ identities, including displaying alerts when there is an attempt to migrate a WhatsApp account from one device to another.

Also launched by WhatsApp is a “Key…

Source…

Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on Tumblr
  • Share on Reddit
https://spinsafe.com/wp-content/uploads/2023/04/WhatsApp-Introduces-New-Device-Verification-Feature-to-Prevent-Account-Takeover.png 380 728 SecureTech https://spinsafe.com/wp-content/uploads/2016/11/spinsafelogo-1.png SecureTech2023-04-13 09:30:072023-04-13 09:30:07WhatsApp Introduces New Device Verification Feature to Prevent Account Takeover Attacks

Archives

© 2023 SpinSafe
SpinSafe may be compensated by providing links to products, services, websites, and various other options.
  • Rss
  • Privacy Policy
  • Terms of Service
don’t go mobile repairing shop before watching this video ! charging problem...New Chameleon banking trojan is stealing account info — what you need to ...
Scroll to top