Weaknesses in the app, while not crucial, include not enforcing SSL pinning when WhatsApp establishes connection to backend server WhatsApp, the mobile messaging service Facebook bought for $19 billion, has several security weaknesses that experts say are worth addressing.[WhatsApp could face prosecution on poor privacy]None of the flaws found this week by app security vendor Praetorian are critical. Instead, they represent lapses in best practices for securing mobile apps. “For the most part, these are not high-risk flaws,” Andrew Hoog, chief executive of mobile security vendor viaForensics, said.The weaknesses, which are common in many mobile apps, include not enforcing SSL (Secure Sockets Layer) pinning when WhatsApp establishes the connection between the mobile phone and the company’s backend server. SSL pinning involves having the client check the server’s certificate against trusted validation data. The process adds an extra step to the normal SSL protocol, which is not difficult to implement, but could affect users in an environment like WhatsApp’s, which comprises 450 million people sending messages across many different mobile devices, experts say.Like most security decisions the impact on users has to be weighed against the threat, which in this case is not severe, because of the difficulties an attacker would face in trying to intercept traffic. To exploit the lack of SSL pinning, an attacker would have to make an independent connection capable of eavesdropping on the message traffic, then figure out a way to force the client to downgrade its built-in security for Internet connections and get a rogue certificate to replace the one used by WhatsApp.Nevertheless, SSL pinning is a precaution more developers are taking.“Very few apps did certificate pinning a year ago. We’re seeing more of them do it today,” Hoog said. “It’s definitely a best practice.”Another best practice no-no found with WhatsApp is allowing its backend servers to use weak 40-bit and 56-bit encryption schemes. In a man-in-the-middle attack, a hacker could downgrade communications to the lower schemes, which would make a brute-force attack against the encryption possible.“We would encourage them to get rid of the 40-bit and 56-bit ciphers, but those are just changes they could do server-side,” Hoog said. “It would help improve security, but it might lose a few folks (users).”Whether Facebook will make significant changes in WhatsApp security remains to be seen. The social network has lots of options, given how security is a work in progress in mobile app development, which is relatively new. [Privacy suit against Facebook a warning for businesses]“Mobile is still a new frontier for many developers,” Paul Jauregui, vice president of marketing for Praetorian, said.In general, missing a best practice or two won’t pose a significant risk, but the more mistakes make, the more vulnerable an app becomes, experts say. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe