<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Whatsapp Archives - L2 Cyber Security Solutions</title>
	<atom:link href="https://www.l2cybersecurity.com/tag/whatsapp/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.l2cybersecurity.com/tag/whatsapp/</link>
	<description>#SecuritySimplified</description>
	<lastBuildDate>Thu, 15 Jul 2021 15:27:12 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.l2cybersecurity.com/wp-content/uploads/2023/03/cropped-Logo-Only-Favicon-Transparent-32x32.png</url>
	<title>Whatsapp Archives - L2 Cyber Security Solutions</title>
	<link>https://www.l2cybersecurity.com/tag/whatsapp/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>#WeekendWisdom 087 WhatsApp Number Recycling</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-087-whatsapp-number-recycling/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 16 Jul 2021 01:15:22 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Multi-Factor Authentication]]></category>
		<category><![CDATA[Number Recycling]]></category>
		<category><![CDATA[Number Reuse]]></category>
		<category><![CDATA[Recovery Email]]></category>
		<category><![CDATA[Tipperary]]></category>
		<category><![CDATA[Two-Factor-Authentication]]></category>
		<category><![CDATA[Whatsapp]]></category>
		<category><![CDATA[WhatsApp Authentication]]></category>
		<category><![CDATA[WhatsApp Number Recycling]]></category>
		<category><![CDATA[WhatsApp Number Reuse]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2568</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 87. This week we&#8217;re going to talk about WhatsApp number recycling. Recycling is good for the environment, isn&#8217;t it? Earlier this week I was in doing a quarterly health check for one of my clients and I went up to one of the new members of staff. She was showing me&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-087-whatsapp-number-recycling/">#WeekendWisdom 087 WhatsApp Number Recycling</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 87. This week we&#8217;re going to talk about WhatsApp number recycling.<span id="more-2568"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2568-1" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-087-lo.mp4?_=1" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-087-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-087-lo.mp4</a></video></div>
<h3>Recycling is good for the environment, isn&#8217;t it?</h3>
<p>Earlier this week I was in doing a quarterly health check for one of my clients and I went up to one of the new members of staff. She was showing me her new phone that she had just gotten with the new number for the business. She had just set up WhatsApp and she was getting these strange messages coming into her and she was wondering how these were happening.</p>
<p>What it looks like is that the phone company they&#8217;re signed up with have reused or recycled a previous mobile number that had been assigned to somebody else.</p>
<h3>How does WhatsApp Number Recycling occur?</h3>
<p>Now if you think about it with WhatsApp when you set up an account all you need to authenticate is your mobile number. So in this case somebody had previously had that mobile number that this new member of staff has got now, people who were sending messages to her old number, to that other person&#8217;s number maybe in WhatsApp groups or whatever, they&#8217;re now going to this new phone that this member of staff has.</p>
<h3>How do you protect against this?</h3>
<p>The first thing I told her that she should do to protect her account is to setup the two factor authentication and there is also a recovery email option in there as well. So if you do find you&#8217;re getting strange messages on a new account or new number then that&#8217;s probably what&#8217;s happening.</p>
<h3>Is this something new?</h3>
<p>This has been going on for quite some time because I actually wrote this back in January 2019 and I have a link to the <a href="https://www.l2cybersecurity.com/whatsapp-authentication-sucks/" target="_blank" rel="noopener">blog post I wrote about it back then</a>. But this is now happening or seems to be happening here now in Ireland.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<div class="fl-post-content clearfix">
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training and Phishing testing.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2actual" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2actual/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
</div>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-087-whatsapp-number-recycling/">#WeekendWisdom 087 WhatsApp Number Recycling</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/07/WeekendWisdom-087-lo.mp4" length="33153128" type="video/mp4" />

			</item>
		<item>
		<title>#WeekendWisdom 068 A Data Breach of Bank Details</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-068-a-data-breach-of-bank-details/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 05 Mar 2021 02:00:57 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Bank Details]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Breach of Bank Details]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[Data Protection Commission Report 2020]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Tipperary]]></category>
		<category><![CDATA[Whatsapp]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2467</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 68. This week we&#8217;re going to talk about a data breach of bank details. Where is this coming from? As I said last week, the Data Protection Commission had issued a report for 2020. I&#8217;ve had a chance to read through it now in a bit more detail. I really love&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-068-a-data-breach-of-bank-details/">#WeekendWisdom 068 A Data Breach of Bank Details</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 68. This week we&#8217;re going to talk about a data breach of bank details.<span id="more-2467"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2467-2" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4?_=2" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4</a></video></div>
<h3>Where is this coming from?</h3>
<p>As I said last week, the Data Protection Commission had issued a report for 2020. I&#8217;ve had a chance to read through it now in a bit more detail. I really love looking at the case studies that they include there because these are real life events that have occurred.</p>
<p>One of them struck me as something that could occur anywhere.</p>
<h3>What? A data breach of bank details??? That&#8217;s serious!</h3>
<p>It was Case Study 15: Bank details sent by WhatsApp. What had occurred was that a customer of a financial institution had gotten in contact with them wanting to get a copy of their BIC and IBAN details. The member of staff that was dealing with the enquiry knew this person. So, because of that, they took a picture of the details on their personal phone and sent them by WhatsApp to the customer.</p>
<h3>WhatsApp is encrypted, so it must be safe. Right?</h3>
<p>But it turns out the details that they took the photo of were for somebody else. So, when the customer reported this incident to the bank, they realised this was a data breach. That customer had seen somebody else&#8217;s personal details.</p>
<h3>How does a business prevent this type of issue?</h3>
<p>This is simply a staff training issue. Staff need to be aware that they should always follow proper protocols when dealing with people&#8217;s personal details. To make sure that they provide the correct details to the correct person.</p>
<p>As I say it could happen to anybody. So use that example with your staff today.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training and Phishing testing.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2actual" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2actual/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-068-a-data-breach-of-bank-details/">#WeekendWisdom 068 A Data Breach of Bank Details</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4" length="31885243" type="video/mp4" />

			</item>
		<item>
		<title>Whatsapp Authentication Sucks</title>
		<link>https://www.l2cybersecurity.com/whatsapp-authentication-sucks/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 11 Jan 2019 16:56:07 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Whatsapp]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1570</guid>

					<description><![CDATA[<p>Whatsapp Authentication sucks. It sucks really badly. I&#8217;d never thought about it before, but then I saw this tweet yesterday. A lady got a new phone number and when she set up Whatsapp, she had a load of messages on there from the previous owner of the number. &#8220;Wait a minute!&#8221; I hear you cry &#8220;Surely&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/whatsapp-authentication-sucks/">Whatsapp Authentication Sucks</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-thumbnail wp-image-1571" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/01/Whatsapp-Authentication-Sucks-150x150.png" alt="Whatsapp authentication sucks" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/01/Whatsapp-Authentication-Sucks-150x150.png 150w, https://www.l2cybersecurity.com/wp-content/uploads/2019/01/Whatsapp-Authentication-Sucks.png 300w" sizes="(max-width: 150px) 100vw, 150px" />Whatsapp Authentication sucks. It sucks really badly. I&#8217;d never thought about it before, but then I saw <a href="https://twitter.com/abbyfuller/status/1083560674884694017?s=19" target="_blank" rel="noopener">this tweet yesterday</a>. A lady got a new phone number and when she set up Whatsapp, she had a load of messages on there from the previous owner of the number. <span id="more-1570"></span>&#8220;Wait a minute!&#8221; I hear you cry &#8220;Surely Whatsapp, owned by Facebook and used by millions of people, has super security?&#8221; Well I&#8217;m sure it&#8217;s back-end systems are all well protected. The messages between users are all properly encrypted and secure. But to authenticate to the service &#8230; all you need is a telephone number. If you use the telephone number of another user or a former user, you get their messages!!! There is a way to prevent this, which I&#8217;ll get to later.</p>
<h3>Setting up an account is sooo easy</h3>
<p>Cast your mind back to when you set up Whatsapp on your phone for the first time and you set up your account with them. Did you specify a User ID or Username? Did you give it a password? The answer is no. The only authentication was your telephone number, which your phone was giving the app.</p>
<h3>Recycling is good for the planet, but not good for security</h3>
<p>Mobile telephone numbers get recycled by telephone companies all the time. This is because they don&#8217;t have an unlimited amount of numbers that they can issue. If you watch enough crime programmes on the TV, you will see a lot of &#8220;burner&#8221; phones being used. These are basically a cheap phone and number that might only be used once or twice and then is disposed of forever. Also, people having affairs would sometimes have a second &#8220;secret&#8221; phone for communicating with their paramour. If the affair doesn&#8217;t last long, that phone number will be disposed of.</p>
<p>So phone companies that have old numbers, where a contract hasn&#8217;t been renewed or a prepaid number has not been topped up in some time, they will simply assign them to new SIM cards and push them out through their retail channels. Thus the number is recycled and reused.</p>
<p>This is what happened to <a href="https://twitter.com/abbyfuller/status/1083560674884694017?s=19" target="_blank" rel="noopener">Abby Fuller</a>. She got a new number and when she installed Whatsapp, she had all of the messages from that telephone number&#8217;s previous owner restored onto her device. Because the number is the only means of identifying an account, this is why Whatsapp authentication sucks.</p>
<p>She took the correct course of action and deleted everything. However if she had a bad side, she could have downloaded all of the messages or even worse, she could have impersonated that number&#8217;s previous owner in those messages and caused all sorts of issues.</p>
<h3>So Whatsapp authentication sucks. What can I do about it?</h3>
<p>You can set up, what Whatsapp calls, two step verification. With this enabled, if you (or somebody else), try to setup Whatsapp with your number on a different phone, you (or they) will be asked for a PIN number, which only you should know.</p>
<p>It&#8217;s really easy to set up:</p>
<ol>
<li>Go into your Whatsapp settings</li>
<li>Select Account -&gt; Two step verification</li>
<li>It will have an explanation screen. Click Enable</li>
<li>Provide a 6 digit PIN number and then confirm it</li>
<li>Optionally (but recommended) you can provide an email address should you forget the PIN number, where a PIN reset request can be sent. You will need to confirm that email address</li>
<li>That&#8217;s it</li>
</ol>
<p>If somebody gets your number or they try to take over your phone number, when they try to set up Whatsapp, they will need to input the PIN you just set up. It&#8217;s not really the best <a href="http://www.l2cybersecurity.com/vii-use-two-factor-authentication/" target="_blank" rel="noopener">two step verification</a> in the world, but it should be effective.</p>
<p>I must try and persuade the few Whatsapp groups that I am involved in to switch to something more secure like <a href="https://signal.org/" target="_blank" rel="noopener">Signal</a>.</p>
<p>Lets be careful out there.</p>
<p>#SecuritySimplified #GDPR #SimpleGDPR</p>
<p>The post <a href="https://www.l2cybersecurity.com/whatsapp-authentication-sucks/">Whatsapp Authentication Sucks</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
