Viber is transmitting files unencrypted readable to anyone

April 25, 2014

 Ibrahim Baggili and Jason Moore from University of New Haven have tested the protocol of sending files and location data between clients of popular messaging service Viber. They found out that all the files are transmitted unencrypted leaving them vulnerable to all sorts of MITM attacks. Moreover, the media files (images, videos) are stored unencrypted on Viber server leaving them freely accessible to anyone who possesses the correct URL address. Viber claims that this vulnerability has been already fixed but this probably concerns only Viber clients for iOS and Android leaving vulnerable clients on all other platforms as well as the files on Viber servers.

