Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is a way to show profile pictures to only contacts. It's a setting.


Yes, and those people didn't get their profile pictures exposed through this phone number enumeration. If they had, then maybe it would have qualified as a security breach.


> Yes, and those people didn't get their profile pictures exposed through this phone number enumeration.

They did and this was not enumeration, did you read post?


The post with the headline “Worldwide enumeration of accounts was possible?”


OK... but it's not phone number enumeration. You need to give it a phone number to check if whatsapp acc is registered for it. So you need to have a collection of phone numbers first. If you have a collection of all phone numebrs in the world then you could enumerate whatsapp accounts.

And yes the pictures were leaked in the process.


It's trivial to enumerate all the phone numbers in the world.


exactly. to claim enumerating phone numbers is a whatsapp bug is stupid. and to say profile pictures were not revealed = not reading tfa.


"The accessible data items used in the study are the same that are public for anyone who knows a user's phone number and consist of: phone number, public keys, timestamps, and, if set to public, about text and profile picture." Source: TFA, which I read.


From my understanding the accessible data items meant they got them through the bug? Maybe I read wrong




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: