Startup World

The flow of adding new members to a WhatsApp group message is:A group member sends an unsigned message to the WhatsApp server that designates which users are group members, for instance, Alice, Bob, and CharlieThe server informs all existing group members that Alice, Bob, and Charlie have been addedThe existing members have the option of deciding whether to accept messages from Alice, Bob, and Charlie, and whether messages exchanged with them should be encryptedWith no cryptographic signatures verifying an existing member wants to add a new member, additions can be made by anyone with the ability to control the server or messages that flow into it.
Using the common fictional scenario for illustrating end-to-end encryption, this lack of cryptographic assurance leaves open the possibility that Malory can join a group and gain access to the human-readable messages exchanged there.WhatsApp isnt the only messenger lacking cryptographic assurances for new group members.
In 2022, a team that included some of the same researchers that analyzed WhatsApp found that Matrixan open source and proprietary platform for chat and collaboration clients and serversalso provided no cryptographic means for ensuring only authorized members join a group.
The Telegram messenger, meanwhile, offers no end-to-end encryption for group messages, making the app among the weakest for ensuring the confidentiality of group messages.In contrast, the open source Signal messenger provides a cryptographic assurance that only an existing group member designated as the group admin can add new members.
In an email, researcher Benjamin Dowling, also of Kings College, explained:Signal implements cryptographic group management.
Roughly this means that the administrator of a group, a user, signs a message along the lines of Alice, Bob and Charley are in this group to everyone else.
Then, everybody else in the group makes their decision on who to encrypt to and who to accept messages from based on these cryptographically signed messages, [meaning] who to accept as a group member.
The system used by Signal is a bit different [than WhatsApp], since [Signal] makes additional efforts to avoid revealing the group membership to the server, but the core principles remain the same.On a high-level, in Signal, groups are associated with group membership lists that are stored on the Signal server.
An administrator of the group generates a GroupMasterKey that is used to make changes to this group membership list.
In particular, the GroupMasterKey is sent to other group members via Signal, and so is unknown to the server.
Thus, whenever an administrator wants to make a change to the group (for instance, invite another user), they need to create an updated membership list (authenticated with the GroupMasterKey) telling other users of the group who to add.
Existing users are notified of the change and update their group list, and perform the appropriate cryptographic operations with the new member so the existing member can begin sending messages to the new members as part of the group.Most messaging apps, including Signal, dont certify the identity of their users.
That means theres no way Signal can verify that the person using an account named Alice does, in fact, belong to Alice.
Its fully possible that Malory could create an account and name it Alice.
(As an aside, and in sharp contrast to Signal, the account members that belong to a given WhatsApp group are visible to insiders, hackers, and to anyone with a valid subpoena.)





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


A cloud-seeding startup did not trigger the Texas floods


Hugging Face's new robot is the Seinfeld of AI gadgets


Goldman Sachs is testing viral AI agent Devin as a ‘new employee’


Medium’s CEO explains what it took to stop losing $2.6M monthly


Startups Weekly: Still running


Julie Wainwright is building what comes next — join her fireside chat at A Technology NewsRoom Disrupt 2025


Humanoids, AVs, and what's next in AI hardware at A Technology NewsRoom Disrupt 2025


Helios wants to be the AI operating system for public policy professionals


Just 4 days until A Technology NewsRoom All Stage kicks off in Boston-- and the lowest ticket rates disappear


Where AI fulfills style: Runway co-founder Alejandro Matamala Ortiz takes the AI Stage at A Technology NewsRoom Disrupt 2025


How to really raise a seed round: Actionable advice from leading investors at A Technology NewsRoom Disrupt 2025


5 days till A Technology NewsRoom All Stage-- save as much as $475 before costs increase


Knox lands $6.5M to compete with Palantir in the federal compliance market


Why Cluely’s Roy Lee isn’t sweating cheating detectors


SaaS is in the past. The future belongs to representatives, states Narada AI's CEO.


Pinecone founder Edo Liberty checks out the genuine missing link in enterprise AI at A Technology NewsRoom Disrupt 2025


Get your exhibit table at A Technology NewsRoom Disrupt 2025


Discover how to prevent the mistakes that stall start-up fundraising at A Technology NewsRoom All Stage on July 15


Rivian spinoff Also raises another $200M to build e-bikes and more


LangChain is about to become a unicorn, sources state


Thank you to the visionaries: Celebrating the partners behind A Technology NewsRoom All Stage


Wayve CEO Alex Kendall brings the future of autonomous AI to A Technology NewsRoom Disrupt 2025


The complete Side Events lineup at A Technology NewsRoom All Stage 2025


Exploring the future of voice AI with Mati Staniszewski at A Technology NewsRoom Disrupt 2025


Moonvalley's 'ethical' AI video design for filmmakers is now publicly readily available


Jeff Chow of Miro shares how group intelligence drives better product-building at A Technology NewsRoom All Stage


7 days until doors open at A Technology NewsRoom All Stage-- and approximately $475 in ticket cost savings disappear


Unless users do something about it, Android will let Gemini access third-party apps


What would a cheap, Apple A18-powered MacBook actually be good at


Samsung and Epic Games call a truce in app shop suit


Ancient skull may have been half human, half Neanderthal child


Measles cases reach 33-year high as RFK Jr. pursues anti-vaccine agenda


Trump and Congress finalize law that could hurt your Wi-Fi


Fubo pays $3.4 M to settle claims it unlawfully shared user data with marketers


&No honor among thieves&: M S hacking group starts turf war


US may get its own glitchy version of TikTok if Trump’s deal works out


Oldest wood tools in East Asia may have originated from any of three species


F1 in Britain: Terrible English summer weather equates to amusing race


How a huge shift in training LLMs resulted in an ability explosion


U.S. Air Force F-16C and F-15E Control Multiple XQ-58 Drones


Plane Prepares A400M for FCAS and Mothership Drone Operations


AeroVironment's Wildcat Reaches Key Milestones in DARPA's ANCILLARY Program's EVADE Demonstration


Ukrainian Manufacturers Scale Up to Produce 4M Drones per Year


United States Soldiers Drop Live Grenades from Drones in Germany


GoPro teases Max 2, its brand-new 360 action electronic camera


DJI releases new update for its drone flying app


Get drone-like footage anywhere with this 8K camera, now 16% off


NEURA Robotics partners with HD Hyundai on shipbuilding robots


Indian drone designer Raphe mPhibr raises $100M


Attabotics lays off staff as robotic storage supplier declare insolvency


UAE proptech Huspy raises $59M to scale in Europe


AI is requiring the data industry to consolidate-- however that's not the entire story


Figuring out why a nap might assist individuals see things in new methods


Ukraine and Eric Schmidt’s Swift Beat to Expand Production of Unmanned Systems


Northrop Grumman's Latest MQ-4C Triton Undergoes Testing with the United States Navy


da Vinci’s 500-Year-Old Aerial Screw Drawing Could Inform New, Quieter Drone Design


Ukraine’s Unmanned Surface Vessels Launch Bomber Drones to Attack Crimea


First Drone Parcel Delivery Flight in Abu Dhabi


binder releases M9 circular connectors for space-constrained applications


How Brex is keeping up with AI by accepting the 'messiness'


Dusty Robotics designs FieldPrinter 2 robot with PMD motion controllers


Tesollo to present humanoid robot hand at AI for Good Global Summit 2025


The curious rise of giant tablets on wheels


Rocket Report: Japan’s workhorse booster takes a bow; you can invest in SpaceX now


World-first: DJI drone movies whole Everest path in one go


DJI’s ultimate phone gimbal gets early Prime Day discount


SEW-EURODRIVE now assembles planetary gear units in the U.S.


Ready-made stem cell therapies for pets could be coming


Supplier of concealed security app spills passwords for 62,000 users


Judge: You can’t ban DEI grants without bothering to define DEI


Meta's AI superintelligence effort sounds just like its failed metaverse


The Last of Us co-creator Neil Druckmann exits HBO show


2025 VW ID Buzz review: If you want an electric minivan, this is it


Man’s ghastly festering ulcer stumps doctors—until they cut out a wedge of flesh


xAI data center gets air authorization to run 15 turbines, but imaging reveals 24 on site


Sky Elements Drone Show Aims for World Records on July 4 Celebrations


Quantum Systems and Fraunhofer FHR to Integrate State-of-the-Art Radar Technology into UAVs


The Number Of P-51 Mustangs Are LeftThe newest survivor census maintained by the lover site MustangsMustangs pegs general numbers at 311 complete airframes. Of these, 29 remain in long-lasting storage, 54 remain in active restoration hangars, 159 are sti


Buyers still waiting: DJI drones face ongoing US Customs snag


How to Set Up a Planetary Gear Motion with SOLIDWORKS


Intuitive Surgical obtains CE mark for da Vinci 5 robot


Pittsburgh Robotics Network introduces Deep Tech Institute for Leadership and Innovation


Cluely’s ARR doubled in a week to $7M, founder Roy Lee says. But rivals are coming.


Who is Soham Parekh, the serial moonlighter Silicon Valley startups can’t stop hiring


Stripe’s first employee, the founder of fintech Increase, sort of bought a bank


Why Cloudflare desires AI business to pay for content


Pinwheel introduces a smartwatch for kids that includes an AI chatbot


Castelion is raising a $350M Series B to scale hypersonic rocket service


Tighten up your cap table with Fidelity, Cimulate, and DepositLink at A Technology NewsRoom All Stage 2025


Writer CEO May Habib to take the AI Stage at A Technology NewsRoom Disrupt 2025


Israeli quantum startup Qedma just raised $26M, with IBM joining in