Information Security, what an exciting field to be working in. You get to be a part of a global community that secures technology and ensures a safe, digital environment for everyone.Or at least, you get to try. While at the same time juggling half a dozen different, conflicting demands from stakeholders, trying not to get into a Twitter shitstorm just yet, somehow trying to figure out if shelling out some bucks for another industry certification might land you a better job.This talk will take a look at the security industry and community and ask: Is that really what we signed up for? How can we cope with the growing pains of becoming a 124 billion dollar industry - and why? (in)Secure Messaging Apps - A lateral movement into your privacyVitor Ventura N/AN/AIn a always connected world privacy is becoming more and more important. Privacy is important for all kinds of people no matter what business or social status they are in. One of the cornerstones of privacy in our days is the secure messaging applications like Signal, WhatsApp or Telegram, which deploy end-to-end encryption to protect the communications. However, having such a heterogenous userbase means that not everyone will be technologically educated enough to understand all features and defaults of such applications. A deeper look into these applications showed that they lack transparency and bad defaults are the perfect combination to break great crypto. Leading to session hijacking at different levels resulting in different user experiences and privacy exposures.With the intent of showing that these applications are not transparent in the way they advertise their features I will start by doing a quick round-up on the messaging applications. Talking about their defaults, features and claims. This will set the stage for the whole presentation.After which I will explain how the sessions can be hijacked and the limitations that come with it. The process it self is the first hole in some of the applications claims. A demonstration on how each application deals with the hijacked sessions is the second hole. And finally the third hole is how the users are asked to deal with it. While also showing what are the implications on each case for the users privacy. To show that this is not only theoretical I will finally I will show a malware that was found in the wild that explores this method to allow its operators to hijack sessions. The presentation will end with a review of the initial claims of each application and how they can be refuted due to bad defaults and lack of transparency.