Archiv der Kategorie: Social Media

Whatsapp spies on your encrypted messages

Exclusive: Privacy campaigners criticise WhatsApp vulnerability as a ‘huge threat to freedom of speech’ and warn it could be exploited by government agencies

Research shows that the company can read messages due to the way WhatsApp has implemented its end-to-end encryption protocol.
Research shows that WhatsApp can read messages due to the way the company has implemented its end-to-end encryption protocol. Photograph: Ritchie B Tongo/EPA

A security backdoor that can be used to allow Facebook and others to intercept and read encrypted messages has been found within its WhatsApp messaging service.

Facebook claims that no one can intercept WhatsApp messages, not even the company and its staff, ensuring privacy for its billion-plus users. But new research shows that the company could in fact read messages due to the way WhatsApphas implemented its end-to-end encryption protocol.

Privacy campaigners said the vulnerability is a “huge threat to freedom of speech” and warned it can be used by government agencies to snoop on users who believe their messages to be secure. WhatsApp has made privacy and security a primary selling point, and has become a go to communications tool of activists, dissidents and diplomats.

WhatsApp’s end-to-end encryption relies on the generation of unique security keys, using the acclaimed Signal protocol, developed by Open Whisper Systems, that are traded and verified between users to guarantee communications are secure and cannot be intercepted by a middleman. However, WhatsApp has the ability to force the generation of new encryption keys for offline users, unbeknown to the sender and recipient of the messages, and to make the sender re-encrypt messages with new keys and send them again for any messages that have not been marked as delivered.

The recipient is not made aware of this change in encryption, while the sender is only notified if they have opted-in to encryption warnings in settings, and only after the messages have been resent. This re-encryption and rebroadcasting effectively allows WhatsApp to intercept and read users’ messages.

The security backdoor was discovered by Tobias Boelter, a cryptography and security researcher at the University of California, Berkeley. He told the Guardian: “If WhatsApp is asked by a government agency to disclose its messaging records, it can effectively grant access due to the change in keys.”

The backdoor is not inherent to the Signal protocol. Open Whisper Systems’ messaging app, Signal, the app used and recommended by whistleblower Edward Snowden, does not suffer from the same vulnerability. If a recipient changes the security key while offline, for instance, a sent message will fail to be delivered and the sender will be notified of the change in security keys without automatically resending the message.

WhatsApp’s implementation automatically resends an undelivered message with a new key without warning the user in advance or giving them the ability to prevent it.

Boelter reported the backdoor vulnerability to Facebook in April 2016, but was told that Facebook was aware of the issue, that it was “expected behaviour” and wasn’t being actively worked on. The Guardian has verified the backdoor still exists.

The WhatsApp vulnerability calls into question the privacy of messages sent across the service used around the world, including by people living in oppressive regimes.
Pinterest
The WhatsApp vulnerability calls into question the privacy of messages sent across the service used around the world, including by people living in oppressive regimes. Photograph: Marcelo Sayão/EPA

Steffen Tor Jensen, head of information security and digital counter-surveillance at the European-Bahraini Organisation for Human Rights, verified Boelter’s findings. He said: “WhatsApp can effectively continue flipping the security keys when devices are offline and re-sending the message, without letting users know of the change till after it has been made, providing an extremely insecure platform.”

Boelter said: “[Some] might say that this vulnerability could only be abused to snoop on ‘single’ targeted messages, not entire conversations. This is not true if you consider that the WhatsApp server can just forward messages without sending the ‘message was received by recipient’ notification (or the double tick), which users might not notice. Using the retransmission vulnerability, the WhatsApp server can then later get a transcript of the whole conversation, not just a single message.”

The vulnerability calls into question the privacy of messages sent across the service, which is used around the world, including by people living in oppressive regimes.

Professor Kirstie Ball, co-director and founder of the Centre for Research into Information, Surveillance and Privacy, called the existence of a backdoor within WhatsApp’s encryption “a gold mine for security agencies” and “a huge betrayal of user trust”. She added: “It is a huge threat to freedom of speech, for it to be able to look at what you’re saying if it wants to. Consumers will say, I’ve got nothing to hide, but you don’t know what information is looked for and what connections are being made.”

In the UK, the recently passed Investigatory Powers Act allows the government to intercept bulk data of users held by private companies, without suspicion of criminal activity, similar to the activity of the US National Security Agency uncovered by the Snowden revelations. The government also has the power to force companies to “maintain technical capabilities” that allow data collection through hacking and interception, and requires companies to remove “electronic protection” from data. Intentional or not, WhatsApp’s backdoor to the end-to-end encryption could be used in such a way to facilitate government interception.

Jim Killock, executive director of Open Rights Group, said: “If companies claim to offer end-to-end encryption, they should come clean if it is found to be compromised – whether through deliberately installed backdoors or security flaws. In the UK, the Investigatory Powers Act means that technical capability notices could be used to compel companies to introduce flaws – which could leave people’s data vulnerable.”

A WhatsApp spokesperson told the Guardian: “Over 1 billion people use WhatsApp today because it is simple, fast, reliable and secure. At WhatsApp, we’ve always believed that people’s conversations should be secure and private. Last year, we gave all our users a better level of security by making every message, photo, video, file and call end-to-end encrypted by default. As we introduce features like end-to-end encryption, we focus on keeping the product simple and take into consideration how it’s used every day around the world.

“In WhatsApp’s implementation of the Signal protocol, we have a “Show Security Notifications” setting (option under Settings > Account > Security) that notifies you when a contact’s security code has changed. We know the most common reasons this happens are because someone has switched phones or reinstalled WhatsApp. This is because in many parts of the world, people frequently change devices and Sim cards. In these situations, we want to make sure people’s messages are delivered, not lost in transit.”

Asked to comment specifically on whether Facebook/WhatApps had accessed users’ messages and whether it had done so at the request of government agencies or other third parties, it directed the Guardian to its site that details aggregate data on government requests by country.

Concerns over the privacy of WhatsApp users has been repeatedly highlighted since Facebook acquired the company for $22bn in 2014. In August 2015, Facebook announced a change to the privacy policy governing WhatsApp that allowed the social network to merge data from WhatsApp users and Facebook, including phone numbers and app usage, for advertising and development purposes.

Facebook halted the use of the shared user data for advertising purposes in November after pressure from the pan-European data protection agency groupArticle 29 Working Party in October. The European commission then filed charges against Facebook for providing “misleading” information in the run-up to the social network’s acquisition of messaging service WhatsApp, following its data-sharing change.

https://www.theguardian.com/technology/2017/jan/13/whatsapp-backdoor-allows-snooping-on-encrypted-messages

Advertisements

How to 10x Your Instagram Marketing

https://i1.wp.com/www.jeffbullas.com/wp-content/uploads/2016/08/How-to-10x-Your-Instagram-Growth-With-Optimization.jpg

There is a question I am asked often.

What social media network should I be using? And guess what? Everyone wants a black and white answer.

The reality?

It is shades of grey. But there is another thing. The goal posts keep moving as the social networks change the rules, the media they offer and their secret algorithms.

It is often confusing and overwhelming.

What all digital marketers need to do

But there is something that is an absolute core tactic for all marketers and entrepreneurs in a digital world.

And many don’t focus on this.

“Growing digital media distribution networks“.

This is one of the 10 commandments of any successful media company. It is also what all brands and digital entrepreneurs should be doing. Because all need to think like publishers.

Without this the content will not get the attention and engagement that it deserves. Without distribution, content is often hidden in the nooks and crannies of the web and is never seen, heard or viewed.

My initial tactic to reach the world with my content and get noticed was to use Twitter.

In the last 7 years I have focused on building a large following and tribe on Twitter and now we are approaching half a million followers.

How important has this been?

It has been the difference between anonymity and high global visibility.

The power of having hundreds of thousands of people being able to share your content for free is what made social media so exciting. It was the key to my success.

Crowd sourced marketing!

This was not available before the rise of the social web. It has been my secret sauce.

New kids on the block

But that was then and there has been a fast evolution of choices. More revolution than evolution. Shiny new social networks. And they are often visual and mobile.

We all know how overwhelming it can be to jump into a new social media platform, considering how rapidly new ones appear, and how competitive they can be. On top of that, to master your new channel – as you’ve probably learned, can be really frustrating if you don’t have a clear guide.

But you have no choice if you want to remain relevant and not end up in the social media backwater.

The Instagram kid

Ever since Facebook acquired Instagram, it’s quickly evolved into something more than just a photo sharing app. And it has over half a billion active users.

With all the noise on Facebook and other social media platforms… Instagram still manages to keep it simple and elegant.

That’s part of why people migrated to Instagram so quick, and use it so regularly – it’s beautiful, fun and engaging.

These deeply engaged users make great customers, if you can captivate them.

And since your website link is in your bio, increasing the number of eyes on your account equates to more website traffic.

So, if you can master how to attract your target audience to your account, it not only leads to increased traffic, but also conversions.

So why do so many people have trouble getting momentum on Instagram?

First, let’s debug one big misconception: You don’t have to set an advertising budget to grow your account. And you don’t need a large budget to do Instagram marketing well…

Where to start:

Study your target market and industry on Instagram.

  • Which accounts do they follow?
  • What hashtags are they using?
  • What are the most popular hashtags in your niche?

Get involved.

  • Join Instagram engagement communities where you exchange comments with each other.

This alone can

10x your engagement rate.

Choose a theme for your Instagram.

  • Pick a specific color palette that matches your brand image
  • Stick to the same type of filter style for every picture.

Next, gain your audience’s attention

I have an intimate understanding of the frustrations with working really hard and long on these channels, and not seeing results.

So I studied the trends and most successful Instagram accounts, and developed a scientific approach to hacking audience growth.

Let’s be clear: Optimizing your Instagram shouldn’t mean you simply put more hours into it.

Liking pictures, following people, unfollowing in a targeted and strategic way can consume hours of every day. It’s tedious, and frankly not a great use of your time.

Whether it’s you, or a social media agency that handles your account, this type of thing should be outsourced.

You and your agency know your brand best and for this reason, content should be your #1 focus.

It’s competitive, seriously.

Instagram is at about 500 million monthly active users and growing. This means you need an aggressive activity strategy to stand out.

Does the task of following and unfollowing hundreds of accounts in a day sound overwhelming? It is. I know because I used to do this manually on Twitter until I discovered how to do it via automation.

So let me show you exactly how to overcome this time-suck with Instagram with what till now has been a little known Instagram growth hacking platform.

Use an Instagram growth hacking service

Finding a reliable service for Instagram growth can be tricky. However, through a friend, I heard about a service that not only saves me a bunch of time, but can growth accounts 10x – in a very real way. Not spammy, not shady.

It essentially puts Instagram to work for me by gaining me real followers in my niche. It worked for me on Twitter so I decided to start testing it.

The results?

In just 7 days I have grown my Instagram account by nearly 1,000 followers using an Instagram growth hacking service. At this run rate I will hit over 55,000 followers in the next 12 months.

>>>> Grab your FREE trial now

It does this by automating the monotonous activity of choosing users to interact and engage, but does so in the most targeted manner.

How do you use it?

Let me introduce SociallyRich

The best part about their Service was that unlike other Instagram services out there, there’s no confusing dashboard to interact with.

You just provide your hashtags of interest, and the usernames of accounts to target, and they take care of the rest.

This saved me so much time to the point I no longer had to go on my Instagram, other than to post images.

https://i2.wp.com/www.jeffbullas.com/wp-content/uploads/2016/07/socially-rich-for-Instagram-Growth-With-Optimization-768x283.png

Your Instagram should be growing while you sleep, that will lead to an end result of monetizing your account whether you use your Instagram account for personal purposes, for your business, or blog.

SociallyRich was unlike any service of its kind, simply based on the results. I’d wake up, check my Instagram accounts and have 100+ new targeted followers daily.

Their customer support was also unlike many in the industry, even the CEO (Ramon Berrios) answered my emails immediately.

Next – 3 Tips on Retaining Engagement and Building a Community

Now that I’ve given you the tools for growing, you now have to build an engaged community that stays active on your page.

1. Turn on post notifications

Instagram has a new feature where users can turn on post notifications for their favorite account. Notify your followers to do this with a beautiful text image pointing to where the settings for this feature is on the screen.

turn on notifications for Instagram Growth With Optimization

2. Hashtag away

When researching hashtags in your niche, don’t worry whether you should use the popular hashtags or the smaller more focused ones. They both have upsides and downsides.

  • When you use a hashtag that millions of people are using, your picture can quickly get lost in the feed. However, in that short time frame, a lot of people that are also searching that hashtag may have seen it and engaged with it.
  • As for smaller and more focused hashtags, these are great to use because you can dominate that area, and stay on top of that feed. If you dominate this strategy you can make it to the popular page.

The only downside of using smaller hashtags is that you miss out on the thousands that could’ve also seen the image by using the popular hashtags.

https://i2.wp.com/www.jeffbullas.com/wp-content/uploads/2016/07/hashtags-for-Instagram-Growth-With-Optimization.jpg

The solution to this?

Use both. Hashtag away, it won’t hurt anyone.

The amount of people that will be turned off by the amount of hashtags you’re using are irrelevant compared to the amount of people that will see it for you using them all.

Although, keep in mind Instagram has a limit of 30 hashtags per post.

There is a strategy to this. So your caption doesn’t look like a mess:

  • Open up your notes and type down your caption in the following format: Caption, stars, hashtags (see image below)

https://i0.wp.com/www.jeffbullas.com/wp-content/uploads/2016/07/hashtags-2-for-Instagram-Growth-With-Optimization-673x1024.jpg

Having these hashtags in your notes will keep them handy and easy to use by just copying and pasting them every time you post.

Remember, consistency always beats a lack of activity when it comes to Instagram, so the easier you make it for yourself to post the more you will do so.

3. Instagram community groups

This is a game changer when it comes to engagement and activity on your page.

With a simple Google search of how to join Instagram community groups, you will find yourself joining a group in your niche (often called an “Instagram engagement community” that help each other grow).

These groups have methods in which you will comment on their pictures, and in return everyone in your group will comment on your pictures whenever you post. This can add a lot of value to your account when someone sees your pictures.

On top of that, whenever someone comments it will also show on the news feed of that person’s activity.

Put your Instagram marketing on steroids

I have given you the inside scoop and it’s over to you. Growing your digital distribution on one of the world’s fastest growing social networks is essential.

Now you have the blueprint for how to grow and monetize your Instagram account, as well as the steps on how to proceed. If you want some help, I would highly recommend giving SociallyRich a try.

There is nothing to lose.