Chinese hacker breaks into Clubhouse and records conversations
After the last update to implement the app security, Clubhouse was hacked by a Chinese hacker who managed to record the network's audio conversations. With this, the user was able to prove that the company's main motto (of ensuring that conversations are not recorded) is flawed. And the attack was not limited to that.
In order to hack into the social network, the hacker used the Android operating system and his location was confirmed as China. This demonstrated other flaws in Clubhouse, as the app has not yet been released for Google's OS, much less is it available. available in the country where the invasion took place.
In an article published on the website Yahoo, a representative of the social network claimed that the hacker has already been permanently banned from Clubhouse and new security measures have been applied to the app. However, the claim does not correspond with the flaws already pointed out in the application.
Structural problems
The Stanford Internet Observatory (SIO) has published a article in which it points out errors in the structure of the audio chat app that could allow external access. The analyses posted on February 12 were the reason why Clubhouse decided to apply an update to improve its security.
Providing the infrastructure for the ephemeral audio conversation system for the app of the moment is a Chinese startup called Agora Inc., which has offices in China and Silicon Valley.
According to SIO data, this startup transmits user IDs over the internet in text format, which makes interception easier. In addition, the Observatory pointed out that the company is based in China and is therefore subject to the country's laws, which means it could provide audio from the app to the Chinese government if requested.
In a report by Bloomberg, Agora did not comment on the case, but already spoke before saying that it does not store user data. Clubhouse responded that its app “does not have access to store or share personally identifiable information about users. In addition, user audio does not pass through servers in China.”
Website broadcast conversations
Whoa… someone just sent me this — is this 3rd party website streaming every clubhouse room??? pic.twitter.com/MOTtL4sPf0
— @jason (@Jason) February 21, 2021
Furthermore, Clubhouse’s security issues appear to go further. Investor Jason Calacanis tweeted a screenshot of a website that was allegedly broadcasting Clubhouse conversations. The site, which has since been taken down, broadcast audio from every room in which its creator had participated.
Through which channels you reach those people, classic and out of the box. The Next Web
Image: Xijian (iStock)