Security

Messaging app JusTalk is spilling millions of unencrypted messages

Comment

JusTalk data spill exposed millions of unencrypted messages.
Image Credits: JusTalk (screenshot)

Popular video calling and messaging app JusTalk claims to be both secure and encrypted. But a security lapse has proven the app to be neither secure nor encrypted after a huge cache of users’ unencrypted private messages was found online.

The messaging app is widely used across Asia and has a booming international audience with 20 million users globally. Google Play lists JusTalk Kids, billed as its child-friendly and compatible version of its messaging app, as having more than 1 million Android downloads.

JusTalk says both its apps are end-to-end encrypted — where only the people in the conversation can read its messages — and boasts on its website that “only you and the person you communicate with can see, read or listen to them: Even the JusTalk team won’t access your data!”

But a review of the huge cache of internal data, seen by TechCrunch, proves those claims are not true. The data includes millions of JusTalk user messages, along with the precise date and time they were sent and the phone numbers of both the sender and recipient. The data also contained records of calls that were placed using the app.

JusTalk's website that claims it uses end-to-end encryption, but a cache of spilled user data proves otherwise.
JusTalk’s website claims it uses end-to-end encryption, but a cache of spilled user data shows otherwise. Image Credits: TechCrunch (screenshot)

Security researcher Anurag Sen found the data this week and asked TechCrunch for help in reporting it to the company. Juphoon, the China-based cloud company behind the messaging app said it spun out the service in 2016 and is now owned and operated by Ningbo Jus, a company that appears to share the same office as listed on Juphoon’s website. But despite multiple efforts to reach JusTalk’s founder Leo Lv and other executives, our emails were not acknowledged or returned, and the company has shown no attempt to remediate the spill. A text message to Lv’s phone was marked as delivered but not read.

Because each message recorded in the data contained every phone number in the same chat, it was possible to follow entire conversations, including from children who were using the JusTalk Kids app to chat with their parents.

The internal data also included the granular locations of thousands of users collected from users’ phones, with large clusters of users in the United States, United Kingdom, India, Saudi Arabia, Thailand and mainland China.

According to Sen, the data also contained records from a third app, JusTalk 2nd Phone Number, which allows users to generate virtual, ephemeral phone numbers to use instead of giving out their private cell phone number. A review of some of these records reveal both the user’s cell phone number as well as every ephemeral phone number they generated.

We’re not disclosing where or how the data is obtainable but are weighing in favor of public disclosure after we found evidence that Sen was not alone in discovering the data.

This is the latest in a spate of data spills in China. Earlier this month a huge database of some 1 billion Chinese residents was siphoned from a Shanghai police database stored in Alibaba’s cloud and portions of the data were published online. Beijing has yet to comment publicly on the leak, but references to the breach on social media have been widely censored.

A huge data leak of 1 billion records exposes China’s vast surveillance state

More TechCrunch

Tags

Asia, China, computing, database, Google, Instant Messaging, logging, Media & Entertainment, Saudi Arabia, Security, technology, United Kingdom, United States, web browser, WhatsApp
Startups

Ibotta’s CEO explains why startups shouldn’t try to time the IPO market

Rebecca Szkutak

The IPO market has not roared back in 2024 as many investors hoped it would — not yet, at least. Elevated interest rates (this week’s 50 bps rate cut notwithstanding)…

Ibotta’s CEO explains why startups shouldn’t try to time the IPO market
Apps

A guide to iOS 18’s hidden features and smaller updates

Ivan Mehta

We put together a list of some of our favorite under-the-radar features that you might have missed.

A guide to iOS 18’s hidden features and smaller updates

Featured Article

Linus Torvalds explains why aging Linux developers are a good thing

Linux’s luminary linchpin, Linus Torvalds, says that despite longstanding reports of burnout in the open source software development realm, Linux is as strong as ever.

Paul Sawers
Linus Torvalds explains why aging Linux developers are a good thing
Security

The TechCrunch Cyber Glossary

Lorenzo Franceschi-Bicchierai
Zack Whittaker

This glossary includes some of the most common terms and expressions we use in our articles, and explanations of how — and why — we use them.

The TechCrunch Cyber Glossary

Featured Article

Some startups are going ‘fair source’ to avoid the pitfalls of open source licensing

The fair source concept is designed to help companies align themselves with the “open” software development sphere, without encroaching into existing licensing landscapes.

Paul Sawers
Some startups are going ‘fair source’ to avoid the pitfalls of open source licensing
AI

Google CEO Sundar Pichai announces $120M fund for global AI education

Anthony Ha

Speaking Saturday at the UN Summit of the Future, Google CEO Sundar Pichai described AI as “the most transformative technology yet” and announced a new fund for AI education and…

Google CEO Sundar Pichai announces $120M fund for global AI education
Social

X reverses course in Brazil

Anthony Ha

It seems that Elon Musk-owned social network X (formerly Twitter) is backing down from a confrontation with Brazil’s Supreme Court. The New York Times reported on a new court filing…

X reverses course in Brazil
Social

Amazon says no to remote work

Cody Corrall

Amazon CEO Andy Jassy is calling for a full return to office at the start of 2025. For the last 15 months, employees have been expected to work in the…

Amazon says no to remote work
Hardware

Qualcomm may be trying to buy Intel

Anthony Ha

Chipmaker Qualcomm is trying to buy rival Intel, according to multiple reports. The Wall Street Journal broke the news late Friday that Qualcomm had approached Intel about a takeover. The…

Qualcomm may be trying to buy Intel
Startups

India’s Oyo acquires Motel 6 for $525M

Anthony Ha

One of India’s largest startups, budget hotel company Oyo, has reached a deal to acquire G6 Hospitality, which operates Motel 6. Oyo says it will pay Blackstone Real Estate $525…

India’s Oyo acquires Motel 6 for $525M
Climate

Electric outboard startup Pure Watercraft is selling itself for parts

Devin Coldewey

A tough market seems to have put an end to Pure’s ambitions.

Electric outboard startup Pure Watercraft is selling itself for parts
Gadgets

Moksha, the gamified meditation device, makes breath work exercises more engaging

Lauren Forristal

Moksha’s meditation tool aims to kick traditional breath work exercises to the curb.  As most breathing tools on the market are designed to do, Moksha aims to help train you to…

Moksha, the gamified meditation device, makes breath work exercises more engaging

Featured Article

Tesla Superchargers: All the EV brands that have access

EV owners of GM vehicles like the Chevrolet Silverado EV and Cadillac Lyriq will now officially have access to Tesla’s Superchargers.

Rebecca Bellan
Tesla Superchargers: All the EV brands that have access
Apps

Shelf is a social network based on the media you consume

Jagmeet Singh

Shelf lets you show what you listen to, play, read and watch online through your dedicated digital storefront.

Shelf is a social network based on the media you consume
Government & Policy

The EU’s 10 biggest antitrust actions on tech

Natasha Lomas

While it’s fair to say the EU’s antitrust tech enforcement outcomes have varied, one lasting legacy is that some of these major cases served as inspiration for the bloc’s Digital…

The EU’s 10 biggest antitrust actions on tech
Social

Elon Musk threatened with SEC sanctions for failing to appear in court

Kyle Wiggers

Elon Musk, the CEO of X and various other companies with the letter “X” in their names, is in regulators’ crosshairs after skipping testimony this month in an investigation related…

Elon Musk threatened with SEC sanctions for failing to appear in court
Venture

Adam Neumann’s startup Flow opens co-living community in Saudi Arabia

Marina Temkin

Flow, Adam Neumann’s co-living startup, opened a compound with 238 apartments in Saudi Arabia’s capital, Riyadh, and Forbes has some details. The opening included an Aztec-themed hot chocolate ceremony and…

Adam Neumann’s startup Flow opens co-living community in Saudi Arabia
Media & Entertainment

Musk dodged Brazil’s X ban by ‘coincidence,’ says Cloudflare CEO

Maxwell Zeff

X went back online in Brazil earlier this week, three weeks after Elon Musk’s platform was blocked under orders from Brazil’s Supreme Court. That prompted Brazil’s top court to fine…

Musk dodged Brazil’s X ban by ‘coincidence,’ says Cloudflare CEO
Space

Cards Against Humanity sues Elon Musk’s SpaceX for trespassing

Rebecca Bellan

Cards Against Humanity (CAH) is suing Elon Musk’s space exploration company, SpaceX, for $15 million after it allegedly dumped construction equipment all over the game company’s private land in Texas. …

Cards Against Humanity sues Elon Musk’s SpaceX  for trespassing
AI

Grok’s image generator, Black Forest Labs, is raising $100M at a $1B valuation, say sources

Ingrid Lunden

Black Forest Labs, an image GenAI startup that only came out of stealth two months ago, has closed a a monster new round, sources say.

Grok’s image generator, Black Forest Labs, is raising $100M at a $1B valuation, say sources
Gadgets

Here are the hottest product announcements from Apple, Google, Microsoft and others so far in 2024

Christine Hall
Henry Pickavet

We’ve poked through the many product announcements made by the biggest tech companies and product trade shows of the year, so far, and compiled them into this list.

Here are the hottest product announcements from Apple, Google, Microsoft and others so far in 2024
Hardware

Apple breaks down iPhone 16 repair process

Brian Heater

Apple published step-by-step instructions for swapping out the new handset’s battery.

Apple breaks down iPhone 16 repair process
Government & Policy

The 25 battery tech startups that just got a piece of $3B in federal funds  

Rebecca Bellan

This tranche of funding went to startups across 14 states, but there were certain winners that will see the bulk of the expected 18,000 jobs to be created as a…

The 25 battery tech startups that just got a piece of $3B in federal funds  
Hardware

The iPhone 16 launches today without its most hyped feature: Apple Intelligence

Ivan Mehta

The iPhone 16 officially goes on sale Friday. But for its earliest adopters, it arrives with a fundamental compromise baked into the deal. Put simply, this is not the iPhone…

The iPhone 16 launches today without its most hyped feature: Apple Intelligence
Security

Internet surveillance firm Sandvine says it’s leaving 56 ‘non-democratic’ countries

Lorenzo Franceschi-Bicchierai

Sandvine sold its internet surveillance products to authoritarian regimes, including Belarus, Egypt, Eritrea, the United Arab Emirates, and Uzbekistan.

Internet surveillance firm Sandvine says it’s leaving 56 ‘non-democratic’ countries

Featured Article

Plaud’s $169 ChatGPT-powered NotePin has a permanent place in my travel bag

The $169 Plaud NotePin is a tiny magnetic recording device. Recordings are transcribed and AI provide summaries of meetings.

Brian Heater
Plaud’s $169 ChatGPT-powered NotePin has a permanent place in my travel bag
Startups

M&As and AI are in the spotlight, but there’s still capital left for quick commerce and more

Anna Heim

This week brought reassuring signs that dealmaking is still happening on both sides of the table. New unicorns are being minted, and more capital is flowing into AI.

M&As and AI are in the spotlight, but there’s still capital left for quick commerce and more
TechCrunch Disrupt 2024

Last day to apply: Boost your brand at TechCrunch Disrupt 2024

TechCrunch Events

Keep the energy of TechCrunch Disrupt 2024 alive and leverage your brand by hosting an after-hours Side Event.  Act fast — today is your last chance to apply! Showcase your…

Last day to apply: Boost your brand at TechCrunch Disrupt 2024
Gadgets

Apple Intelligence: Its biggest features and when you can expect them

Ivan Mehta

If you’re not using the beta version of Apple Intelligence, here’s when you can expect to get the new features.

Apple Intelligence: Its biggest features and when you can expect them

Featured Article

A comprehensive list of 2024 tech layoffs

A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024.

Cody Corrall
Alyssa Stringer
A comprehensive list of 2024 tech layoffs

玻璃钢生产厂家玻璃钢花盆设计摘要德阳推荐成都商场美陈上海主题商场美陈乐清玻璃钢雕塑厂南京多彩玻璃钢雕塑供应商鞍山玻璃钢雕塑公司硚口玻璃钢花盆花器长治广场玻璃钢雕塑设计商场 美陈 儿童安阳优质玻璃钢人物雕塑厂家运城校园玻璃钢雕塑定制云南玻璃钢浮雕房地产水景雕塑雅安创意成都商场美陈池州玻璃钢雕塑公司铸造玻璃钢人物雕塑定制中山卡通玻璃钢雕塑价格玻璃钢不锈钢花盆巫山县玻璃钢雕塑江西城市标志玻璃钢雕塑廊坊节日商场美陈商场美陈装饰哪家好玻璃钢蝴蝶雕塑大理市玻璃钢雕塑设计吉林多彩玻璃钢雕塑销售厂家杭州富阳区商场美陈布置工厂家院子里摆放玻璃钢雕塑麒麟湖北玻璃钢香蕉雕塑临潼玻璃钢雕塑价格西安玻璃钢雕塑厂设计河北万硕玻璃钢工艺品雕塑香港通过《维护国家安全条例》两大学生合买彩票中奖一人不认账让美丽中国“从细节出发”19岁小伙救下5人后溺亡 多方发声单亲妈妈陷入热恋 14岁儿子报警汪小菲曝离婚始末遭遇山火的松茸之乡雅江山火三名扑火人员牺牲系谣言何赛飞追着代拍打萧美琴窜访捷克 外交部回应卫健委通报少年有偿捐血浆16次猝死手机成瘾是影响睡眠质量重要因素高校汽车撞人致3死16伤 司机系学生315晚会后胖东来又人满为患了小米汽车超级工厂正式揭幕中国拥有亿元资产的家庭达13.3万户周杰伦一审败诉网易男孩8年未见母亲被告知被遗忘许家印被限制高消费饲养员用铁锨驱打大熊猫被辞退男子被猫抓伤后确诊“猫抓病”特朗普无法缴纳4.54亿美元罚金倪萍分享减重40斤方法联合利华开始重组张家界的山上“长”满了韩国人?张立群任西安交通大学校长杨倩无缘巴黎奥运“重生之我在北大当嫡校长”黑马情侣提车了专访95后高颜值猪保姆考生莫言也上北大硕士复试名单了网友洛杉矶偶遇贾玲专家建议不必谈骨泥色变沉迷短剧的人就像掉进了杀猪盘奥巴马现身唐宁街 黑色着装引猜测七年后宇文玥被薅头发捞上岸事业单位女子向同事水杯投不明物质凯特王妃现身!外出购物视频曝光河南驻马店通报西平中学跳楼事件王树国卸任西安交大校长 师生送别恒大被罚41.75亿到底怎么缴男子被流浪猫绊倒 投喂者赔24万房客欠租失踪 房东直发愁西双版纳热带植物园回应蜉蝣大爆发钱人豪晒法院裁定实锤抄袭外国人感慨凌晨的中国很安全胖东来员工每周单休无小长假白宫:哈马斯三号人物被杀测试车高速逃费 小米:已补缴老人退休金被冒领16年 金额超20万

玻璃钢生产厂家 XML地图 TXT地图 虚拟主机 SEO 网站制作 网站优化