this post was submitted on 19 Dec 2025
59 points (89.3% liked)

Cybersecurity

8810 readers
183 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
 

Three billion WhatsApp users are at risk - an expert has developed a tool that could spy on everyone, and you would never know about it

you are viewing a single comment's thread
view the rest of the comments
[โ€“] Nomad 30 points 9 hours ago (4 children)

Security expert here.... This issa nothing Burger and will be fixed on the server side soon I expect. This is about spreading fear uncertainty and doubt. The research is academic in nature and the results are interesting, but this is only a side channel to reveal things like maybe you rough timezone and maybe a few correlations via connectivity quality. This is what they do if they need to confirm if a person uses the same phone number for example. And the could just look it up in the registry or maybe just call you...

This is not a widespread privacy concern, is not very practical to use, especially at scale and is early fixable. Its comparable to the traffic pattern analysis they do to confirm tor users identity if they found them but need supporting evidence. Its what's left when the technology works as intended. So chill your paranoia.

[โ€“] halfdane@lemmy.world 2 points 2 hours ago

While I appreciate your refusal to spread panic, would you mind explaining what the attack does and why it's a nothingburger, maybe even why it's not practical? Because right now, you assert a lot of things without any explanation.

Not saying you're wrong, but I think it's good practice to not just rely on claims of authority

load more comments (3 replies)