<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whatsapp? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17131#M715</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;...Whatsapp account. ...&lt;BR /&gt;Any experience, particularly from the security perspective?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Never used it, Never will: &lt;STRONG&gt;Facebook&lt;/STRONG&gt; owns Whatsapp.&lt;/P&gt;&lt;P&gt;&lt;A href="https://youtu.be/4Kwh3R0YjuQ" target="_blank"&gt;Say no more.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Dec 2018 10:39:41 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2018-12-19T10:39:41Z</dc:date>
    <item>
      <title>Whatsapp?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17109#M709</link>
      <description>&lt;P&gt;OK, I am being asked to get a Whatsapp account.&lt;BR /&gt;&lt;BR /&gt;Any experience, particularly from the security perspective?&lt;BR /&gt;&lt;BR /&gt;(So far the thing seems only tenatively usable.&amp;nbsp; It's supposedly multiple device, but while getting it installed seems doable, utilizing an account on more than one device seems impossible ...)&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 20:09:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17109#M709</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-12-18T20:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17125#M713</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;It's supposedly multiple device, but while getting it installed seems doable, utilizing an account on more than one device seems impossible ...&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;A WhatsApp account is linked to a mobile number. After verification of the number on&amp;nbsp;a mobile device,&amp;nbsp;the account&amp;nbsp;gets&amp;nbsp;linked to the device itself.&amp;nbsp;Should the number expire or the SIM card be removed, the account can still be used&amp;nbsp;--- until it is deleted or set up on another device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still, it's possible to use it on at least 2 devices at&amp;nbsp;once with&amp;nbsp;&lt;A href="https://www.whatsapp.com/" target="_self"&gt;WhatsApp Web&lt;/A&gt;&amp;nbsp;--- which&amp;nbsp;requires an active session on the mobile device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Any experience, particularly from the security perspective?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;No doubt the&amp;nbsp;fact that it's been acquired by Facebook has got a lot of us concerned about privacy.&amp;nbsp;WhatsApp allows&amp;nbsp;&lt;A href="https://www.whatsapp.com/safety/" target="_self"&gt;customization of account settings&lt;/A&gt;&amp;nbsp;to enhance security &amp;amp; privacy, but there have&amp;nbsp;been security issues pointed out --- including one &lt;A href="https://www.standard.co.uk/tech/whatsapp-security-problems-edit-messages-a3907481.html" target="_self"&gt;exploiting group chats&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things can go wrong without all this if you don't manage the account properly.&amp;nbsp;When&amp;nbsp;getting a new number, either &lt;A href="https://faq.whatsapp.com/en/android/27585377/?category=5245246" target="_self"&gt;change the number of the account&lt;/A&gt;, or delete the old account&amp;nbsp;&amp;amp; create a new one. When changing the device,&amp;nbsp;either set up the account on the new device or uninstall it from the old device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In all cases, notify your contacts about the change. If others message an old number using WhatsApp,&amp;nbsp;they'll probably be communicating with the new holder of the number&amp;nbsp;while under the assumption that it's you...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 02:57:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17125#M713</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-12-19T02:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17131#M715</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;...Whatsapp account. ...&lt;BR /&gt;Any experience, particularly from the security perspective?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Never used it, Never will: &lt;STRONG&gt;Facebook&lt;/STRONG&gt; owns Whatsapp.&lt;/P&gt;&lt;P&gt;&lt;A href="https://youtu.be/4Kwh3R0YjuQ" target="_blank"&gt;Say no more.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 10:39:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17131#M715</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-12-19T10:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17143#M717</link>
      <description>&amp;gt; Shannon (Contributor III) posted a new reply in Tech Talk on 12-18-2018 09:57 PM&lt;BR /&gt;&lt;BR /&gt;&amp;gt; WhatsApp account is linked to a mobile number. After&lt;BR /&gt;&amp;gt; verification of the number on&amp;nbsp;a mobile device,&amp;nbsp;the account&amp;nbsp;gets&amp;nbsp;linked to&lt;BR /&gt;&amp;gt; the device itself.&lt;BR /&gt;&lt;BR /&gt;Yeah. Royal pain. I have an old Windows phone that never has been used as a&lt;BR /&gt;phone: I used it as a mini-tablet until it got so old/unsupported that not even&lt;BR /&gt;Twitter would work anymore. (I think that was in the mass swithover to https.)&lt;BR /&gt;It installed Whatsapp all right, and I used my cell number to activate it fine.&lt;BR /&gt;But then when I activated the cell phone itself, the Windows phone immediately&lt;BR /&gt;popped up a message that it was no longer verified. Understandable, I suppose,&lt;BR /&gt;but unsettling.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;Should the number expire or the SIM card be removed, the&lt;BR /&gt;&amp;gt; account can still be used&amp;nbsp;--- until it is deleted or set up on another device.&lt;BR /&gt;&lt;BR /&gt;As noted above. I'm looking into the use of burner numbers, but nothing, so far,&lt;BR /&gt;seems reliable.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; Still, it's possible to use it on at least 2 devices at&amp;nbsp;once with&amp;nbsp;WhatsApp&lt;BR /&gt;&amp;gt; Web&amp;nbsp;--- which&amp;nbsp;requires an active session on the mobile device.&lt;BR /&gt;&lt;BR /&gt;Yeah, mean to test that out when I get a chance. The whole QR code thing seems&lt;BR /&gt;weird: do you have to verify with the QR code rigmarole every time you want to&lt;BR /&gt;use it on the computer? Can you use it on two computers? I've noticed that the&lt;BR /&gt;QR code flickers while sitting on the screen: I assume it is changing (every 15&lt;BR /&gt;seconds?)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; No&lt;BR /&gt;&amp;gt; doubt the&amp;nbsp;fact that it's been acquired by Facebook has got a lot of us&lt;BR /&gt;&amp;gt; concerned about privacy.&lt;BR /&gt;&lt;BR /&gt;No kidding.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;WhatsApp allows&amp;nbsp;customization of account settings&amp;nbsp;to&lt;BR /&gt;&amp;gt; enhance security &amp;amp; privacy,&lt;BR /&gt;&lt;BR /&gt;&amp;gt;From a first look, those settings seems pretty cosmetic: mostly about who can see&lt;BR /&gt;your profile, etc.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; but there haveÂ&amp;nbsp;been security issues pointed out ---&lt;BR /&gt;&amp;gt; including one exploiting group chats. &amp;nbsp; Things can go wrong without all this if&lt;BR /&gt;&amp;gt; you don't manage the account properly.&lt;BR /&gt;&lt;BR /&gt;One one my concerns: what is "properly"?&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp;When&amp;nbsp;getting a new number, either&lt;BR /&gt;&amp;gt; change the number of the account, or delete the old account&amp;nbsp;&amp;amp; create a new one.&lt;BR /&gt;&amp;gt; When changing the device,&amp;nbsp;either set up the account on the new device or&lt;BR /&gt;&amp;gt; uninstall it from the old device. Â&amp;nbsp; In all cases, notify your contacts about&lt;BR /&gt;&amp;gt; the change. If others message an old number using WhatsApp,&amp;nbsp;they'll probably be&lt;BR /&gt;&amp;gt; communicating with the new holder of the number&amp;nbsp;while under the assumption that&lt;BR /&gt;&amp;gt; it's you...&lt;BR /&gt;&lt;BR /&gt;I remember an old Blackberry bug along those lines ...&lt;BR /&gt;&lt;BR /&gt;You mentioned Whatsapp security groups. Can you give me more info about&lt;BR /&gt;those?&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;This taught me a lesson, but I'm not sure what it is. - John McEnroe&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 19 Dec 2018 18:13:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17143#M717</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-12-19T18:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17159#M720</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;do you have to verify with the QR code rigmarole every time you want to&lt;BR /&gt;use it on the computer? Can you use it on two computers?&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;It's supposed to be limited to a single WhatsApp session per account, but frankly, the session management is confusing. If a specific computer's WhatsApp session ends, it prompts you to re-scan the QR code, but to do that you have to log out from sessions on the WhatsApp phone application --- which makes no sense if it was a single session in the 1st place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;You mentioned Whatsapp security groups. Can you give me more info about&lt;BR /&gt;those?&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Not security groups,&amp;nbsp;just a means of facilitating communication with multiple parties. Seems that joining the groups is mandated --- should anyone add you to a group, you'll be in without even an invitation to accept..! Preventing it from happening requires that you block a group admin --- but to do that you need to know who the admin is in the 1st place,&amp;nbsp;&amp;amp; groups&amp;nbsp;often have many admins. (The only consolation is that you can mute the groups, so that you won't be bothered with notifications)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 05:36:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17159#M720</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2018-12-20T05:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Whatsapp?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17173#M723</link>
      <description>&amp;gt; Shannon (Contributor III) posted a new reply in Tech Talk on 12-20-2018 12:36 AM&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote: do you have to verify with the QR code rigmarole every time you&lt;BR /&gt;&amp;gt; want to use it on the computer? Can you use it on two computers?&lt;BR /&gt;&lt;BR /&gt;&amp;gt; It's supposed&lt;BR /&gt;&amp;gt; to be limited to a single WhatsApp session per account, but frankly, the session&lt;BR /&gt;&amp;gt; management is confusing. If a specific computer's WhatsApp session ends, it&lt;BR /&gt;&amp;gt; prompts you to re-scan the QR code, but to do that you have to log out from&lt;BR /&gt;&amp;gt; sessions on the WhatsApp phone application --- which makes no sense if it was a&lt;BR /&gt;&amp;gt; single session in the 1st place.&lt;BR /&gt;&lt;BR /&gt;Yes, you're right: that does sound odd.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote: You mentioned Whatsapp&lt;BR /&gt;&amp;gt; security groups. Can you give me more info about those?&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Not security&lt;BR /&gt;&amp;gt; groups,&amp;nbsp;just a means of facilitating communication with multiple parties. Seems&lt;BR /&gt;&amp;gt; that joining the groups is mandated --- should anyone add you to a group, you'll&lt;BR /&gt;&amp;gt; be in without even an invitation to accept..! Preventing it from happening&lt;BR /&gt;&amp;gt; requires that you block a group admin --- but to do that you need to know who&lt;BR /&gt;&amp;gt; the admin is in the 1st place,&amp;nbsp;&amp;amp; groups&amp;nbsp;often have many admins. (The only&lt;BR /&gt;&amp;gt; consolation is that you can mute the groups, so that you won't be bothered with&lt;BR /&gt;&amp;gt; notifications)&lt;BR /&gt;&lt;BR /&gt;Ah, I had thought you were talking about specific security resources or sources of&lt;BR /&gt;info. Your notes are interesting on two fronts, particularly since the person who&lt;BR /&gt;wanted me (and others) to get into Whatsapp keeps mentioning groups ...&lt;BR /&gt;&lt;BR /&gt;Thanks, Shannon, your background and experience is helpful.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;The truth shall make ye fret - Terry Pratchett&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Thu, 20 Dec 2018 17:20:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Whatsapp/m-p/17173#M723</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2018-12-20T17:20:42Z</dc:date>
    </item>
  </channel>
</rss>

