Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
Get HideMyAss! VPN, PC Mag's Top 10 VPNs of 2016 for 55% off for a Limited Time ×
Security

Submission + - WhatsApp is using IMEI numbers as passwords (samgranger.com)

mpol writes: "In the past WhatsApp has been hightly critisized over their insecure use of the XMPP messaging protocol. Recently new versions of their app have incorporated encryption.

It seems the trouble isn't over yet for WhatsApp and its users. Sam Granger writes on his blog that WhatsApp is using IMEI numbers as passwords. This is at least the case with the Android app, but other platforms are probably using similar methods.
Since it is easily readable what someone's IMEI number is, this isn't really secret information that should be used for authentication.
In the wake of the Apple/FBI UDID fiasco, will we see lists with phone numbers and IMEI numbers appear on the net?"

Government

Submission + - Zero-Day exploit market sells mostly to US government (forbes.com)

mpol writes: "Forbes magazine published a profile of French exploit-selling firm Vupen last April. Now there's a blog article about a broker from South Africa, complete with a price-list of zero-day exploits and their platform. iOS is the highest valued here.
The article also claims most exploits are being sold to agencies of the US government.
It does raise a concern though. What if black-hats got more serious, and the US government would become a victim. When shit hits the fan, how will they react."

Slashdot Top Deals

"It's like deja vu all over again." -- Yogi Berra

Working...