Researchers Find Critical Flaws in Popular Encrypted Messaging App Confide

Advertisement
By Sanket Vijayasarathy | Updated: 9 March 2017 16:10 IST
Highlights
  • The app is reportedly popular in the White House
  • Attackers can intercept messages and change its contents
  • Confide team has since reportedly fixed several flaws
Researchers Find Critical Flaws in Popular Encrypted Messaging App Confide

While the world is still talking about the recent WikiLeaks reveal involving the CIA's hacking of Android and iOS devices, it looks like the White House is facing its own privacy issues. A recent report has revealed that the end-to-end encrypted messaging app, Confide, which has grown popular among White House officials under Trump's Administration, has some bugs that can render it potentially vulnerable.

Security researches at Seattle-based IOActive have discovered a number of critical flaws in the app that can allow hackers to intercept messages before the user decrypts them. The app's popularity is based on its military-grade encryption and the ability to self-destruct messages once read, leaving no trace of it on the Internet or server.

IOActive security researchers Mike Davis and Ryan O'Horo reported after an audit last month that an attacker could intercept the messages while they are in transit. If breached, the hacker can impersonate a user by hijacking their account or by guessing their password and gain access to the Confide user's address book. The attacker can also decrypt or change the contents of the message before it reaches the recipient.

The team at Confide have since reportedly fixed some of the flaws that were reported after the audit. As of now, it is still not known whether the flaws discovered have been used by hackers and whether some Confide users have been targeted already. The researchers were able to access around 7,000 Confide accounts, which included a member of Trump administration and some Department of Homeland Security employees.

Advertisement

Confide has said that "not only have these issues been addressed, but we also have no detection of them being exploited by any other party," in a statement to The Register.

Researchers at Axios last month revealed that a number of members in Trump's Administration have downloaded Confide. The disappearing message feature of the app also means that communication between the members cannot be archived, which is something that is mandatory for White House officials.

Advertisement

The recent WikiLeaks documents told us that the CIA had the tools to hack into messaging apps like WhatsApp, Telegram and others, if the underlying device that hosted them was hacked. With a supposedly "confidential messenger" app like Confide also facing privacy issues, there seems to be no app that is safe from being breached. This raises a serious concern as to how far users are left vulnerable and whether they are risking it all when communicating online.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 14 Series to Arrive With Integrated Google Gemini Features
  2. Asus ExpertBook P3 Series Launched at Computex 2025
  3. Google I/O 2025: Here Are All the Major AI Announcements
  4. Retro OTT Release Reportedly Revealed: When and Where to Watch it Online?
  1. Trump Memecoin Holders Set to Dine With US President, Tron Founder Justin Sun Confirms Attendance 
  2. Amazon Working on Large Foldable Device Similar to Huawei MateBook Fold Ultimate: Ming-Chi Kuo
  3. Infinix GT 30 Pro 5G With MediaTek Dimensity 8350 Ultimate SoC, 5,500mAh Battery Launched: Price, Features
  4. Google Announces SynthID Detector That Can Identify Gemini-Generated Content at Google I/O 2025
  5. Realme Buds Air 7 Pro Global Launch Set for May 27; Colours, Key Features Revealed
  6. iQOO Watch 5 With 1.43-Inch AMOLED Display and TWS Air 3 With Up to 45 Hours of Total Battery Life Launched
  7. Google Outlines Vision for Universal AI Assistant, Expands Project Astra and Project Mariner
  8. Xiaomi to Equip Premium Smartphones With Snapdragon 8-Series Chips as Part of Multi-Year Agreement
  9. Hong Kong Passes stablecoin Bill, One Step Closer to Issuance
  10. CyberPowerPC India Announces ‘Play Guarantee’ for a Transparent Buying Experience
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.