What you need to know
- WhatsApp group chats may be far less private than one would imagine.
- Invite links for private WhatsApp groups can be easily found via a Google Search, meaning anyone could potentially join a private chat.
- The issue likely stems from a mistake on WhatsApp's part.
A journalist for DW News this week tweeted out a grim warning: "Your WhatsApp groups may not be as secure as you think they are."
The reason for his concern? Invite links for WhatsApp groups are being indexed by Google's search engine, meaning that if a link to your private group exists anywhere on the internet, anyone could potentially find the link and join your group with just a quick Google search.
Your WhatsApp groups may not be as secure as you think they are.— Jordan Wildon (@JordanWildon) February 21, 2020
The "Invite to Group via Link" feature allows groups to be indexed by Google and they are generally available across the internet. With some wildcard search terms you can easily find some… interesting… groups. pic.twitter.com/hbDlyN6g3q
Doing so is as simple as typing in "site:chat.whatsapp.com" into the search bar on Google. Once you do, you can see that Google has indexed up to 470,000 such links, meaning hundreds of thousands of groups could potentially be accessible this way.
Admittedly, some of these links could have been intended for public sharing by their group administrators, but as discovered by Vice News and some Twitter users, some of the groups indexed by Google almost certainly weren't meant to be public.
You can find groups belonging to NGOs and other organizations. Some of the indexed groups possibly also contain illegal material, with one Twitter user even identifying groups that seemingly pertain to child pornography.
WhatsApp has issued the following statement to Vice:
Group admins in WhatsApp groups are able to invite any WhatsApp user to join that group by sharing a link that they have generated. Like all content that is shared in searchable, public channels, invite links that are posted publicly on the internet can be found by other WhatsApp users. Links that users wish to share privately with people they know and trust should not be posted on a publicly accessible website.
However, as app reverse-engineer Jane Manchun Wong points out, WhatsApp could have avoided many of these groups being indexed by changing some of the settings associated with group invite links, such as by using the 'noindex' meta tag.
I reported to facebook security in early november pic.twitter.com/KSfsd8SYxt— HackrzVijay 💻 (@hackrzvijay) February 21, 2020
The issue had been pointed out to Facebook's bug bounty program by a researcher last year, but the company ruled that it did not warrant a bounty with a statement similar to the one given to Vice.
We may earn a commission for purchases using our links. Learn more.
Eero Pro review: An excellent mesh router, but overkill for small spaces
Eero is one of the best-known names in mesh networking, and for good reason. It's a router system that's both simple and powerful, and one that makes it easy to configure as big as your house (and beyond) requires without adding needless complication.
Can Houseparty make it easier than ever to have the greatest parties?
There are a lot of different applications that make it easy to video chat with your friends and family, regardless of whether you are next door, or halfway around the world. With Houseparty, you can turn those video chats into fully-fledged parties, and it's quickly becoming more and more popular.
Meet our new favorite affordable Chromebook: the Lenovo C340-11
Want a Chromebook that looks good, can keep up with you when you’re in the middle of a manic Monday morning shift, and will last for years to come? Meet the new best Chromebook: the Lenovo C340.
These are the best smart locks that you can use with Alexa
Looking to make your home smarter? Check out these smart locks!