UK developer Sam Granger posts information on how WhatsApp authenticates with the web interface under Android. The program generates a key by applying an easily reproducible algorithm to the device’s unique ID (IMEI) According to Granger, this access data can then be used to utilise the WhatsApp service. Despite the recent addition of encryption, WhatsApp continues to send phone numbers – effective user names in plain text. This could enable attackers to send messages that appear to come from a hacked account. How WhatsApp carries out authentication on other platforms is unclear at present.”]

