In February, we published an article titled 'Not Just a VPN. A Guide on How to Safeguard Yourself and Your Data.' prompted us to write a follow-up article. This part is a fully autonomous source of information, but we still recommend reading both posts.
The new post focuses on the security of data (messaging, photos, videos, and all that) in messaging apps and the devices used to work with those apps.
Messaging Apps
Telegram
Back in October 2018, Wake Technical Community College freshman Nathaniel Sachi discovered that the messaging app Telegram stores messages and media files on the local hard drive of computers in plain text.
The student was able to access his own messages, including text and images. He examined the application's databases stored on the HDD. It turned out that the data was hard to read but not encrypted. Access could be gained even if the user had set a password for the app.
The retrieved data contained the names and phone numbers of contacts that could be correlated if desired. Information from private chats is also stored in plain text.
Later, Durov claimed that this is not a problem, as if a malicious actor has access to a user's PC, they can obtain encryption keys and decode all messages without issues. However, many information security specialists argue that this is indeed serious.

Additionally, Telegram was found to be vulnerable to key-stealing attacks, which a user on Habr noted. It is possible to crack local password codes of any length and complexity.
As far as we know, this messaging app also stores data on the user's computer in an unencrypted format. Thus, if a malicious actor has access to the user's device, all data is also exposed.
But there is a more global problem. Currently, all backups from WhatsApp installed on Android OS devices are stored on Google Drive, as Google and Facebook agreed last year. However, backups of messages, media files, and so on It seems that personnel from law enforcement agencies in the USA , so there is a possibility that they can view any stored data.
Data can be encrypted, but neither company does this. Perhaps simply because unencrypted backups can be easily transferred and used by users themselves. Most likely, the lack of encryption is not due to technical difficulties in implementation: on the contrary, protecting backups can be done without any effort. The problem is that Google has its own reasons to work with WhatsApp — the company is presumably and using it to display personalized ads. If Facebook suddenly introduced encryption for WhatsApp backups, Google would immediately lose interest in such a partnership, losing a valuable source of data on WhatsApp users' preferences. This is, of course, merely a speculation, but quite plausible in the world of hi-tech marketing.
As for WhatsApp for iOS, backups are saved in iCloud. But even here, information is stored in an unencrypted form, as mentioned in the app's settings. Whether Apple analyzes this data is known only to the corporation itself. However, the Cupertino company does not have an advertising network like Google, so we can assume that the likelihood of them analyzing the personal data of WhatsApp users is significantly lower.
Everything said can be summarized as follows — yes, your WhatsApp correspondence is accessible not only to you.
TikTok and other messengers
This short video exchange service could have quickly become popular. The developers promised to ensure full data security for their users. It turned out that the service used this data without notifying users. Worse, the service collected personal data from children under 13 without parental consent. Personal information of minors — names, emails, phone numbers, photos, and videos were left exposed.
The service millions of dollars, and regulators also demanded the removal of all videos made by children under 13. TikTok complied. Nevertheless, other messengers and services use personal data for their own purposes, so one cannot be sure of their security.
This list can go on indefinitely — most messengers have some vulnerability that allows intruders to eavesdrop on users. — Viber, although it seems to have all been fixed) or steal their data. Moreover, almost all top 5 applications store user data in an unprotected manner on the hard drive of the computer or in the phone's memory. And that's not to mention various countries' intelligence services, which may have access to user data due to legislation. The same Skype, VKontakte, TamTam, and others provide any information about any user upon request from authorities (for example, in the Russian Federation).
Good protection at the protocol level? No problem, we break the device
A few years ago between Apple and the U.S. government. The corporation refused to unlock an encrypted smartphone that was involved in the case of terrorist attacks in San Bernardino. At that time, it seemed like a real problem: the data was well protected, and hacking the smartphone was either impossible or very difficult.
Now the situation is different. For instance, the Israeli company Cellebrite sells a software-hardware complex to legal entities in Russia and other countries that allows them to hack all models of iPhone and Android. Last year, a with relatively detailed information on this topic.

Magadan investigator Popov hacks smartphones using the same technology as the U.S. Federal Bureau of Investigation. Source: BBC
The device is relatively inexpensive by state standards. The Volgograd department of the Investigative Committee of Russia paid 800,000 rubles for the UFED Touch2, while Khabarovsk paid 1.2 million rubles. In 2017, Alexander Bastrykin, head of the Investigative Committee of Russia, confirmed that his agency from the Israeli company.
Such devices are also purchased by Sberbank — although not for conducting investigations, but for fighting viruses on devices running Android OS. "In case of suspicion of mobile devices being infected with unknown malicious code, and after obtaining mandatory consent from the owners of the infected phones, analysis will be conducted to detect continually emerging and evolving new viruses using various tools, including the use of UFED Touch2," — in the company.
Americans also have technologies that allow them to hack any smartphones. Grayshift claims it can hack 300 smartphones for $15,000 (that's $50 per unit compared to $1,500 with Cellbrite).
It's quite possible that similar devices exist among cybercriminals. These devices are constantly being improved — their size is decreasing, and their performance is increasing.
Right now, we are talking about relatively well-known phones from major manufacturers that are concerned about protecting their users' data. However, when it comes to smaller companies or no-name organizations, data can be extracted without any issues. The HS-USB mode works even when the bootloader is locked. Service modes are typically a 'backdoor' through which data can be extracted. If not, one can connect to a JTAG port or even extract the eMMC chip and insert it into a cheap adapter. If the data is not encrypted, everything can be extracted from the phone. everything, including authentication tokens that provide access to cloud storage and other services.
If someone has personal access to a smartphone with important information, it can be hacked if desired, regardless of what manufacturers might say.
It's clear that all of this also applies to computers and laptops running various operating systems. If advanced protective measures are not taken, and one relies on basic methods like a username and password, the data remains at risk. An experienced hacker with physical access to the device can obtain virtually any information — it's just a matter of time.
So, what should you do?
The topic of data security on personal devices has been discussed multiple times on Habr, so we won't reinvent the wheel. We will only mention the main methods that reduce the likelihood of unauthorized access to your data:
- Make sure to use data encryption both on smartphones and PCs. Different operating systems often provide decent tools by default. For example, the cryptographic container in macOS with standard tools.
- Set passwords everywhere, including the history of conversations in Telegram and other messaging apps. Naturally, passwords should be complex.
- Two-factor authentication may be inconvenient, but when security is a top priority, we have to adapt.
- Controlling the physical security of your devices is crucial. Taking a corporate laptop to a cafe and forgetting it there? It's a classic mistake. Security standards, including corporate ones, are often written in the tears of those who have suffered from their own negligence.
Let's discuss in the comments your methods that help reduce the likelihood of data breaches when a third party gains access to a physical device. We will later add the suggested methods to the article or publish them in our , where we regularly write about security and life hacks for usage. and internet censorship.
Source: habr.com
