Live data from Hacker News

“Someone was typing in a URL and WhatsApp was fetching it off my server”

twitter.com

31–40 of 69 posts

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#31

Did you all know that chrome does this too? May sound obvious but I always had assumed that nothing is sent until you press enter for some reason (yeah I know, search prediction would be impossible without that). But one day I was type in a path on a test URL and noticing my server getting hit on - every single letter.

Yes, Chrome does it as well, but I expect that as it's a web browser. I know the tradeoffs when browsing the web and expect that my requests will be visible across the Internet. That's just how web browsing works. However, WhatsApp is selling a solution that is meant to provide privacy. When I write a URL in an SMS, my phone does not try to preemptively retrieve it to display a preview. WhatsApp may be encrypting the…

Maybe not SMS but newer versions of iMessage will prefetch urls to generate a preview. I don't recall if it happens as you type (like WhatsApp) or after you hit send though.

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#32

Did you all know that chrome does this too? May sound obvious but I always had assumed that nothing is sent until you press enter for some reason (yeah I know, search prediction would be impossible without that). But one day I was type in a path on a test URL and noticing my server getting hit on - every single letter.

Yes, I did know that. The difference is WhatsApp is selling encrypted-onboard privacy. Which is now, prima facie, a lie. Facebook has literally told courts they can't decrypt WhatApp traffic. I wonder if that court case in Brazil is still pending. By comparison, no one ever said "There's no way Google could read my search terms". A more accurate comparison would be regarding Allo.

You've got me angrily reading the article while asking myself if WatsApp would be stupid enough to lose that mostly won case. (It's in our supreme court, I hope they will announce it illegal to widely block a communication channel and to coerce companies into releasing broken crypto.)

No, WatsApp didn't get informed of what URL you entered on the message. The site owner gets a notice, as does the user's ISP, and a lot of people in between. But WatsApp can not tell what URL was typed.

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#33
post #22

In order to produce the link preview, probably. As far as why it's character by character, I don't know, but that doesn't seem very sinister to me. Checking URLs letter by letter is sloppy, especially if you're not even trying to do auto completion, but it doesn't reveal any more information than a complete url could. Anyway, I would think they are expecting people to paste URLs in, not type them. I've written code t…

It's not sinister so much as that Whatsapp is sending the requests directly from the user's phone (not through a proxy, etc) which is exposing the end user's IP address and full user agent string to the website hosting the page. This information could be used to identify the end user which goes against Whatsapp's whole "Privacy and Security is in our DNA" thing. ( https://www.whatsapp.com/security/ ) See this tweet f…

The alternative would be telling WhatsApp what everybody was typing, so they could proxy the requests.

They did the right thing here. It might be good to add a "do not show URL previews" option, but it's not currently broken.

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#34
post #22

In order to produce the link preview, probably. As far as why it's character by character, I don't know, but that doesn't seem very sinister to me. Checking URLs letter by letter is sloppy, especially if you're not even trying to do auto completion, but it doesn't reveal any more information than a complete url could. Anyway, I would think they are expecting people to paste URLs in, not type them. I've written code t…

It's not sinister so much as that Whatsapp is sending the requests directly from the user's phone (not through a proxy, etc) which is exposing the end user's IP address and full user agent string to the website hosting the page. This information could be used to identify the end user which goes against Whatsapp's whole "Privacy and Security is in our DNA" thing. ( https://www.whatsapp.com/security/ ) See this tweet f…

Knowing that WhatsApp produces link preview cards, I frankly don't see anything here that I didn't already expect and assume was happening - these cards come from somewhere that is neither me nor my conversation partner. This can't be a surprise to anyone who was concerned about privacy.

If WA proxied the request, it would be WA snooping on the conversation, and that would be a way larger problem because they would accumulate that metadata for EVERYONE.

If you don't want cards or external requests in the conversation, you obfuscate the url with any of the myriad methods people use to get past anti-url filters in forums etc.

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#35
post #22

In order to produce the link preview, probably. As far as why it's character by character, I don't know, but that doesn't seem very sinister to me. Checking URLs letter by letter is sloppy, especially if you're not even trying to do auto completion, but it doesn't reveal any more information than a complete url could. Anyway, I would think they are expecting people to paste URLs in, not type them. I've written code t…

It's not sinister so much as that Whatsapp is sending the requests directly from the user's phone (not through a proxy, etc) which is exposing the end user's IP address and full user agent string to the website hosting the page. This information could be used to identify the end user which goes against Whatsapp's whole "Privacy and Security is in our DNA" thing. ( https://www.whatsapp.com/security/ ) See this tweet f…

I see, thanks. So, the lookup is done from the sender's client, not the recipient, correct?

I was actually looking at it from the perspective of it was being done on the server, rather than the client, and people were concerned about information collection about where they're linking to (or something).

This is a good heads up for people with special security needs using proxies to access HTTP. Most people are willing to visit URLs they send in messages from their IP addresses in a browser, or already have before they send the message, but I can see how it's worth knowing about, especially with the additional information disclosure.

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#36

Earlier quoted context omitted.

The app obviously can see the messages, this happens on the clients.

Yeah, just tested. I assumed Whatsapp would fetch serverside but no and thus expose client IPs. Telegram seems to proxy the requests. So Whatsapp wins with crypto here.

Telegram does not encrypt by default. Would be interesting to see, what's happening in encrypted chat there.

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#37
post #13

Earlier quoted context omitted.

Because the preview is displayed as you type, not when you hit Send

But still... why every character? Wait a couple hundred ms after each keystroke to see if they are done.

Because instant > wait a couple hundred ms

simple really

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#39

Did you all know that chrome does this too? May sound obvious but I always had assumed that nothing is sent until you press enter for some reason (yeah I know, search prediction would be impossible without that). But one day I was type in a path on a test URL and noticing my server getting hit on - every single letter.

Yes, I did know that. The difference is WhatsApp is selling encrypted-onboard privacy. Which is now, prima facie, a lie. Facebook has literally told courts they can't decrypt WhatApp traffic. I wonder if that court case in Brazil is still pending. By comparison, no one ever said "There's no way Google could read my search terms". A more accurate comparison would be regarding Allo.

If my sleuthing is on point, the case in Brazil is still in progress, with the latest notation on 09/06/2017 (May 9th).

http://www.stf.jus.br/portal/processo/verProcessoAndamento.a...

Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”

#40

Did you all know that chrome does this too? May sound obvious but I always had assumed that nothing is sent until you press enter for some reason (yeah I know, search prediction would be impossible without that). But one day I was type in a path on a test URL and noticing my server getting hit on - every single letter.

Yes, Chrome does it as well, but I expect that as it's a web browser. I know the tradeoffs when browsing the web and expect that my requests will be visible across the Internet. That's just how web browsing works. However, WhatsApp is selling a solution that is meant to provide privacy. When I write a URL in an SMS, my phone does not try to preemptively retrieve it to display a preview. WhatsApp may be encrypting the…

> WhatsApp is selling a solution that is meant to provide privacy.

Yep you are right. They even tout this in their Security Page.

https://www.whatsapp.com/security/

> WhatsApp's end-to-end encryption ensures only you and the person you're communicating with can read what is sent, and nobody in between, not even WhatsApp. This is because your messages are secured with a lock, and only the recipient and you have the special key needed to unlock and read them.

Post reply on HN