WhatsApp introduces new fraud alert feature

WhatsApp introduces new fraud alert feature

WhatsApp has started rolling out a limited beta version of Scam Alert, an optional feature that uses an on-device machine learning model to flag suspicious messages from non-contacts.

The company says the tool is designed to work alongside end-to-end encryption rather than around it, with classification done entirely on the device and no automatic reporting to WhatsApp or parent company Meta.

Once a user activates the feature, a model is downloaded to the device and assesses incoming messages based on conversation structures and linguistic cues for patterns associated with known scams.

When a message is flagged, only the recipient sees a warning in the chat, but the sender is not notified. The user can block the contact, report the message, ignore the warning, or mark the conversation as trusted so that future warnings are suppressed. Users who mark a chat as trusted can separately share the last five received messages to improve the accuracy of the model.

To prevent a scenario where a specific model could be distributed to a specific person, WhatsApp says Each model release must be logged in a third-party, attachment-only transparency ledger before it can be distributed.

Each release is accompanied by a manifest of SHA-256 hashes covering the model weights and associated files, with the manifest digest signed with Ed25519 keys held by Cloudflare, not Meta. Devices verify this signature, compare it to the ledger, and confirm that the downloaded files match the published hashes before the model is allowed to run.

Advertising. Scroll to continue reading.

Since no message content leaves the device, WhatsApp still needs a way to assess whether the feature is working properly. To this end, a so-called confidential federated analytics pipeline was created that collects only two categories of data: counts of how often alerts were triggered and counts of what actions users took afterward, such as: B. blocking or marking a chat as trustworthy.

WhatsApp outlines a threat model that covers external attackers, compromised infrastructure insiders and supply chain risks, and says the pipeline’s defenses are designed to ensure that attacking a single user’s data would require compromising the entire system.

On the verification page, users can view an in-app transparency log, accessible through Account > Request Information > Fraud Alert Activity, that shows which messages were scanned, the result, and which model version made the call.

WhatsApp also announces that it is expanding its bug bounty program to include Scam Alert.

The company describes the release as an early technical preview rather than a finished product, noting that the feature will be further developed during the beta phase based on feedback from researchers and users before a wider rollout.

Signal announces automatic key verification

Signal has introduced automatic key verificationa new feature designed to complement the existing security number system by confirming that there is no unauthorized person between two users in an end-to-end encrypted conversation.

Unlike manual security number checks that require a face-to-face meeting or a secondary communication channel, the new system carries out the verification independently through controls carried out by the user, their contact person and external auditors.

The feature is intended to catch scenarios in which a Signal account’s public key is exchanged without the owner’s knowledge. This could happen, for example, if an attacker compromised Signal’s infrastructure and linked another key to a target’s phone number.

Users can trigger verification from a connection’s profile by opening View Security Number and tapping Auto Verify under the Auto Key Verification heading. A green checkmark that says “Encryption Verified” confirms a match.

The feature is based on a signal call key transparency system that records every registration, phone number change and username change in a cryptographically verifiable log.

Cloudflare and Trail of Bits act as independent auditors of this protocol. All identifiers and keys in the protocol are obfuscated using a verifiable random function and an encrypted hash function, so the verifiers themselves never see plaintext user data.

The function is opt-out. Users who do not wish to rely on Signal or its validators can disable it under Privacy > Advanced > Automatic Key Verification and continue to rely solely on manual security number verification.

Related: WhatsApp introduces username feature to improve phone number privacy

Related: WhatsApp reveals file spoofing and arbitrary URL scheme vulnerabilities

Related: Germany suspects Russia was behind signal phishing targeting top officials

Leave a Reply

Your email address will not be published. Required fields are marked *