• bitcoinBitcoin (BTC) $ 89,989.00
  • ethereumEthereum (ETH) $ 3,124.47
  • tetherTether (USDT) $ 0.999584
  • bnbBNB (BNB) $ 881.49
  • xrpXRP (XRP) $ 1.99
  • usd-coinUSDC (USDC) $ 0.999842
  • staked-etherLido Staked Ether (STETH) $ 3,120.99
  • tronTRON (TRX) $ 0.286894
  • dogecoinDogecoin (DOGE) $ 0.139055
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.388157
  • bitcoin-cashBitcoin Cash (BCH) $ 613.71
  • whitebitWhiteBIT Coin (WBT) $ 57.29
  • wrapped-stethWrapped stETH (WSTETH) $ 3,821.92
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 89,859.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,395.68
  • wrapped-eethWrapped eETH (WEETH) $ 3,389.37
  • chainlinkChainlink (LINK) $ 13.28
  • usdsUSDS (USDS) $ 0.999777
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999513
  • leo-tokenLEO Token (LEO) $ 9.60
  • wethWETH (WETH) $ 3,125.01
  • zcashZcash (ZEC) $ 485.37
  • moneroMonero (XMR) $ 420.40
  • stellarStellar (XLM) $ 0.215444
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 89,947.00
  • ethena-usdeEthena USDe (USDE) $ 0.999846
  • litecoinLitecoin (LTC) $ 81.23
  • suiSui (SUI) $ 1.58
  • hyperliquidHyperliquid (HYPE) $ 24.58
  • avalanche-2Avalanche (AVAX) $ 13.63
  • canton-networkCanton (CC) $ 0.148705
  • hedera-hashgraphHedera (HBAR) $ 0.119865
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • usdt0USDT0 (USDT0) $ 0.999551
  • the-open-networkToncoin (TON) $ 1.81
  • daiDai (DAI) $ 0.999702
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.153329
  • susdssUSDS (SUSDS) $ 1.08
  • uniswapUniswap (UNI) $ 6.01
  • crypto-com-chainCronos (CRO) $ 0.096068
  • paypal-usdPayPal USD (PYUSD) $ 0.999978
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • polkadotPolkadot (DOT) $ 2.10
  • usd1-wlfiUSD1 (USD1) $ 0.999751
  • mantleMantle (MNT) $ 1.01
  • rainRain (RAIN) $ 0.008175
  • memecoreMemeCore (M) $ 1.53
  • pepePepe (PEPE) $ 0.000006
  • bitget-tokenBitget Token (BGB) $ 3.49
  • aaveAave (AAVE) $ 156.55
  • bittensorBittensor (TAO) $ 246.06
  • okbOKB (OKB) $ 112.49
  • tether-goldTether Gold (XAUT) $ 4,321.51
  • falcon-financeFalcon USD (USDF) $ 0.998428
  • nearNEAR Protocol (NEAR) $ 1.69
  • ethereum-classicEthereum Classic (ETC) $ 12.38
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,124.32
  • jito-staked-solJito Staked SOL (JITOSOL) $ 164.64
  • ethenaEthena (ENA) $ 0.235949
  • aster-2Aster (ASTER) $ 0.748286
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.206855
  • internet-computerInternet Computer (ICP) $ 3.08
  • solanaSolana (SOL) $ 131.52
  • pax-goldPAX Gold (PAXG) $ 4,335.10
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • htx-daoHTX DAO (HTX) $ 0.000002
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.65
  • global-dollarGlobal Dollar (USDG) $ 0.999533
  • midnight-3Midnight (NIGHT) $ 0.090853
  • worldcoin-wldWorldcoin (WLD) $ 0.547197
  • kucoin-sharesKuCoin (KCS) $ 10.99
  • hash-2Provenance Blockchain (HASH) $ 0.027199
  • skySky (SKY) $ 0.062709
  • aptosAptos (APT) $ 1.88
  • binance-staked-solBinance Staked SOL (BNSOL) $ 143.63
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.14
  • pump-funPump.fun (PUMP) $ 0.002243
  • ondo-financeOndo (ONDO) $ 0.417721
  • bfusdBFUSD (BFUSD) $ 0.999162
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,605.36
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999773
  • ripple-usdRipple USD (RLUSD) $ 0.999496
  • wbnbWrapped BNB (WBNB) $ 881.77
  • gatechain-tokenGate (GT) $ 10.49
  • kaspaKaspa (KAS) $ 0.045918
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.111783
  • arbitrumArbitrum (ARB) $ 0.206636
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,312.67
  • algorandAlgorand (ALGO) $ 0.125892
  • filecoinFilecoin (FIL) $ 1.46
  • cosmosCosmos Hub (ATOM) $ 2.15
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,807.45
  • ignition-fbtcFunction FBTC (FBTC) $ 91,476.00
  • official-trumpOfficial Trump (TRUMP) $ 5.01
  • vechainVeChain (VET) $ 0.011539
  • xdce-crowd-saleXDC Network (XDC) $ 0.051844
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 90,366.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 89,893.00
  • nexoNEXO (NEXO) $ 0.920562
  • flare-networksFlare (FLR) $ 0.010893
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,335.83
  • usddUSDD (USDD) $ 0.999527
  • usdtbUSDtb (USDTB) $ 0.999666
  • ousgOUSG (OUSG) $ 113.82
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.94
  • render-tokenRender (RENDER) $ 1.52
  • bonkBonk (BONK) $ 0.000009
  • sei-networkSei (SEI) $ 0.120127
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999975
  • myx-financeMYX Finance (MYX) $ 3.95
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999703
  • beldexBeldex (BDX) $ 0.094939
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,384.21
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 89,875.00
  • story-2Story (IP) $ 2.09
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • clbtcclBTC (CLBTC) $ 90,905.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,334.99
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.01
  • lighterLighter (LIT) $ 2.70
  • jupiter-exchange-solanaJupiter (JUP) $ 0.208118
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010580
  • usdaiUSDai (USDAI) $ 1.00
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,290.25
  • wrapped-flareWrapped Flare (WFLR) $ 0.010894
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999709
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 152.64
  • morphoMorpho (MORPHO) $ 1.12
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,122.85
  • curve-dao-tokenCurve DAO (CRV) $ 0.403976
  • optimismOptimism (OP) $ 0.302753
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.79
  • c8ntinuumc8ntinuum (CTM) $ 0.127305
  • tezosTezos (XTZ) $ 0.513414
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • usual-usdUsual USD (USD0) $ 0.990130
  • tbtctBTC (TBTC) $ 89,975.00
  • dashDash (DASH) $ 42.27
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,124.89
  • lido-daoLido DAO (LDO) $ 0.621758
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.225793
  • spx6900SPX6900 (SPX) $ 0.554479
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998969
  • gtethGTETH (GTETH) $ 3,123.04
  • blockstackStacks (STX) $ 0.274045
  • ether-fiEther.fi (ETHFI) $ 0.759559
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.756886
  • ghoGHO (GHO) $ 0.999754
  • true-usdTrueUSD (TUSD) $ 0.998480
  • injective-protocolInjective (INJ) $ 4.86
  • fasttokenFasttoken (FTN) $ 1.09
  • aerodrome-financeAerodrome Finance (AERO) $ 0.511778
  • flokiFLOKI (FLOKI) $ 0.000048
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,369.17
  • stader-ethxStader ETHx (ETHX) $ 3,365.60
  • msolMarinade Staked SOL (MSOL) $ 177.35
  • chilizChiliz (CHZ) $ 0.043764
  • doublezeroDoubleZero (2Z) $ 0.128435
  • celestiaCelestia (TIA) $ 0.511621
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.216294
  • newton-projectAB (AB) $ 0.004531
  • starknetStarknet (STRK) $ 0.084808
  • syrupMaple Finance (SYRUP) $ 0.368767
  • swethSwell Ethereum (SWETH) $ 3,459.73
  • plasmaPlasma (XPL) $ 0.199097
  • sbtc-2sBTC (SBTC) $ 89,706.00
  • usdbUSDB (USDB) $ 0.994203
  • pippinpippin (PIPPIN) $ 0.401178
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,494.60
  • bittorrentBitTorrent (BTT) $ 0.00000040
  • the-graphThe Graph (GRT) $ 0.037291
  • iotaIOTA (IOTA) $ 0.093902
  • conflux-tokenConflux (CFX) $ 0.076628
  • justJUST (JST) $ 0.039188
  • telcoinTelcoin (TEL) $ 0.004061
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.09
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • staked-aaveStaked Aave (STKAAVE) $ 155.68
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.891859
  • pendlePendle (PENDLE) $ 2.18
  • sun-tokenSun Token (SUN) $ 0.019215
  • euro-coinEURC (EURC) $ 1.17
  • olympusOlympus (OHM) $ 22.01
  • pyth-networkPyth Network (PYTH) $ 0.062554
  • bitcoin-svBitcoin SV (BSV) $ 17.97
  • gnosisGnosis (GNO) $ 135.25
  • apenftAINFT (NFT) $ 0.00000036
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.139139
  • riverRiver (RIVER) $ 18.42
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 89,898.00
  • cap-usdCap USD (CUSD) $ 1.00
  • kaiaKaia (KAIA) $ 0.057908
  • crvusdcrvUSD (CRVUSD) $ 1.00
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 16.90
  • basic-attention-tokenBasic Attention (BAT) $ 0.223002
  • kinesis-goldKinesis Gold (KAU) $ 139.34

WhatsApp privacy bug still not fixed says crypto startup that found it

0 104

WhatsApp privacy bug still not fixed says crypto startup that found it

WhatsApp privacy bug still not fixed says crypto startup that found it

An issue with WhatsApp’s disappearing media feature has finally been fixed, months after it was first discovered by crypto wallet startup Zengo’s technical team.

The View Once feature was introduced by WhatsApp to protect its users’ privacy by allowing them to send pictures and videos that would automatically be wiped once viewed.

However, in August, Zengo’s team discovered that the feature could be “trivially bypassed” when using the platform’s web app. The team says it disclosed the issue to WhatsApp but when it became clear that the issue had already been “exploited in the wild,” it made its findings public “to protect the privacy of WhatsApp’s users.”

WhatsApp responded with a quick patch but this reportedly still allowed the supposedly deleted images to be viewed. Now, the messaging platform says, it’s rolled out a more comprehensive software update.

Zengo detailed its discovery of the problem in a lengthy blog post in September.

“As we continue to develop the world’s pioneering MPC crypto wallet, the Zengo X Research Team is looking into its closest-living relative, the Instant Messaging (IM) apps domain,” wrote Zengo Co-Founder Tal Be’ery. “As a result of such research, we were able to identify and report important privacy issues in the past.”

He added, “When we looked into the implementation details we were very surprised to find that although ‘View Once’ is meant to be limited to platforms in which the app can control its displayed content and prevent other processes from abusing it, it is not enforced by WhatsApp’s API server.

“As a result, a client on any platform can download the message and make the ‘View Once’ promise void.

Be’ery then described how his team built its own unofficial WhatsApp client based on an open-source implementation of WhatsApp’s web client and informed Meta.

Zengo says fix is better but still not perfect

In another blog post from Monday, Be’ery explained how even though the fix is “a great improvement with respect to the original starting point,” it’s not perfect.

“This fix indeed solves the core issue: Recipient’s devices that should not display a View Once message do not get it,” he writes.

“As a result, a trivial exploitation with a modified WhatsApp Web client cannot work.”

However, he adds, “The fix still allows other sender’s devices that should not display a View Once message to get it. This may pose an unnecessary risk as it increases the attack surface for no reason, since these messages are not displayed on such devices.

“For example, a View Once message might be forensically extracted from these devices by attackers.”

Source

Leave A Reply

Your email address will not be published.