Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Tuta
Tuta
@Tutanota@mastodon.social  ·  activity timestamp last month

🚨 3.5 billion users: Entire WhatsApp directory publicly accessible

Source: https://www.theregister.com/2025/11/19/whatsapp_enumeration_flaw/

Here are our best #WhatsApp alternatives: https://tuta.com/blog/best-whatsapp-alternatives-privacy

Conclusion: Choose #Signal

  • Copy link
  • Flag this post
  • Block
meduz'
meduz'
@meduz@m.nintendojo.fr replied  ·  activity timestamp last month

@Tutanota “To our surprise, neither our IP address nor our accounts have been blocked by WhatsApp. Moreover, we did not experience any prohibitive rate-limiting. With our query rate of 7,000 phone numbers per second (and session), we could confirm 3.5 billion phone numbers registered on WhatsApp”

😐

  • Copy link
  • Flag this comment
  • Block
DataBoySu
DataBoySu
@oneinrandomforest@mastodon.social replied  ·  activity timestamp last month

@Tutanota Yes, but its also only the names and profile pictures.
Unfair to claim it as leak since most of it is online anyway

  • Copy link
  • Flag this comment
  • Block
Giorgio Maone 🚫✊🧅
Giorgio Maone 🚫✊🧅
@ma1@todon.eu replied  ·  activity timestamp last month

@Tutanota

  • Copy link
  • Flag this comment
  • Block
Hatemonger
Hatemonger
@civ_downfall@mastodon.social replied  ·  activity timestamp last month

@Tutanota No offense. This seems to be pretty fuddy to me. The data that "leaked" was just the public data, like phone number, status text, pfp, etc.

Don't put anyhting you don't want public on a social media platform.

  • Copy link
  • Flag this comment
  • Block
hi_daniel
hi_daniel
@hi_daniel@mastodon.social replied  ·  activity timestamp last month

@Tutanota I’m not sure if I’m misunderstanding the article but couldn’t you also do this exploit in signal, since it has a look up by phone number option? I guess the main concern is the lack of rate limiting, but this could also be bypassed. The real lesson is that if you want privacy you shouldn’t dox yourself in your accounts.

  • Copy link
  • Flag this comment
  • Block
ĞÖKÜ👻👻™
ĞÖKÜ👻👻™
@GOKUSHRM@mastodon.social replied  ·  activity timestamp last month

@Tutanota #molly #session are best alternative of waatapp 😁

  • Copy link
  • Flag this comment
  • Block
ĞÖKÜ👻👻™
ĞÖKÜ👻👻™
@GOKUSHRM@mastodon.social replied  ·  activity timestamp last month

@Tutanota https://www.youtube.com/watch?v=AUKIEECSKSU

  • Copy link
  • Flag this comment
  • Block
Federation Bot
Federation Bot
@Federation_Bot replied  ·  activity timestamp last month

@Tutanota 🔟 Easy Walmart Shopping Starts Here!
Get a prepaid gift card delivered instantly to your email — join today. Join Now: https://www.effectivegatecpm.com/x3b6hj9h7n?key=ecaa3fc2f2b5a1b27848c4b11300b8d0

https://www.effectivegatecpm.com/x3b6hj9h7n?key=ecaa3fc2f2b5a1b27848c4b11300b8d0
  • Copy link
  • Flag this comment
  • Block
a//:🐙
a//:🐙
@alphaville@infosec.exchange replied  ·  activity timestamp last month

@Tutanota one day you unwrap() what you shouldn't have, another day you again unwrap what you shouldn't have. What should I do with you bigtech?
#cloudflare #whatsapp #bigtech

  • Copy link
  • Flag this comment
  • Block
Héctor Rosales
Héctor Rosales
@hdrc@mastodon.social replied  ·  activity timestamp last month

@Tutanota elegiría mejor #DeltaChat

Quedó comprobado que #Signal utiliza los servidores de Amazon que, al momento de sufrir un colapso, la mensajería quedaría fuera de servicio.

  • Copy link
  • Flag this comment
  • Block
Winston Smith
Winston Smith
@dm29@mastodon.social replied  ·  activity timestamp last month

@Tutanota mmm... Kudos to @signalapp for their work, but they should move their servers outside the US; otherwise there are crucial factors out of their control, I'm afraid.

  • Copy link
  • Flag this comment
  • Block
Joe Cardillo (they/them)
Joe Cardillo (they/them)
@joecardillo@federate.social replied  ·  activity timestamp last month

@Tutanota Wild stuff for a tech company that talks a big game about privacy

Also it took them a year to fully address?!

"He also pointed to the disclosure timeline, as set out in the paper, and how it took Meta nearly a year to provide a meaningful response to the numerous tickets they raised throughout the research process."

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct