How Anyone Can Hack Your Instagram Account Via Public Wi-Fi
Ana Verayo | | Jul 31, 2014 08:46 PM EDT |
Photosharing slash social media application Instagram will now transition into HTTPS encryption after the discovery of a dangerous zero-day vulnerability in their software.
This is a security lapse developers are not aware of that can lead to hackers hijacking any user's account.
London-based security expert Stevie Graham discovered hackers can access any targeted account as long as they're connected on the same public Wi-Fi network.
Like Us on Facebook
Instagram hasn't yet applied HTTPS encryption to its websites.
This omission poses a serious risk to mobile devices, especially those that use the app via their Apple devices in public Wi-Fi hotspots.
Graham created a tool called Instasheep capable of quickly hacking numerous Instagram accounts. This tool is inspired by a Firefox "hacking" extension called Firesheep.
Instasheep works by targeting Instagram's API or application programming interface that transmits an unencrypted request in a form of a cookie or data file where it reveals if the user is still logged in.
When a hacker is connected to a public Wi-Fi hotspot that has no encryption or still uses an outdated one, he can collect the network traffic and exploit a man-in-the-middle attack that "eavesdrops" on conversations or impersonates the targeted account's user.
Although Instagram Direct allows users to share photos and videos in private sessions, it is fully encrypted with HTTPS.
Instagram co-founder Mike Krieger reassures Instagram users that the company plans to upgrade the whole application to HTTPS soon.
Krieger confirms this security update by saying they have been steadily increasing their HTTPS coverage over at Instagram Direct.
They are actively rolling out these changes for the remainder of the app such as the news feed and other browsing features.
As for Graham's discovery of this security lapse in the app, this configuration problem compelled many Internet companies to encrypt their websites into full HTTPS.
A fully encrypted website shows "https://" in the URL and a small padlock icon appears beside it.
TagsHow Anyone Can Hack Your Instagram Account Via Public Wi-Fi, Instagram, instagram direct, instasheep, firesheep, instagram security issues, instagram hack, how to hack instagram, https security, https, instagram issues, how to secure instagram, hackers instagram, hackers, social media hack
©2015 Chinatopix All rights reserved. Do not reproduce without permission
EDITOR'S PICKS
-
Did the Trump administration just announce plans for a trade war with ‘hostile’ China and Russia?
-
US Senate passes Taiwan travel bill slammed by China
-
As Yan Sihong’s family grieves, here are other Chinese students who went missing abroad. Some have never been found
-
Beijing blasts Western critics who ‘smear China’ with the term sharp power
-
China Envoy Seeks to Defuse Tensions With U.S. as a Trade War Brews
-
Singapore's Deputy PM Provides Bitcoin Vote of Confidence Amid China's Blanket Bans
-
China warns investors over risks in overseas virtual currency trading
-
Chinese government most trustworthy: survey
-
Kashima Antlers On Course For Back-To-Back Titles
MOST POPULAR
LATEST NEWS
Zhou Yongkang: China's Former Security Chief Sentenced to Life in Prison
China's former Chief of the Ministry of Public Security, Zhou Yongkang, has been given a life sentence after he was found guilty of abusing his office, bribery and deliberately ... Full Article
TRENDING STORY
-
China Pork Prices Expected to Stabilize As The Supplies Recover
-
Elephone P9000 Smartphone is now on Sale on Amazon India
-
There's a Big Chance Cliffhangers Won't Still Be Resolved When Grey's Anatomy Season 13 Returns
-
Supreme Court Ruled on Samsung vs Apple Dispute for Patent Infringement
-
Microsoft Surface Pro 5 Rumors and Release Date: What is the Latest?