Earlier quoted context omitted.
Yeah but tbh, its still not e2e encrypted. It just means WhatsApp is ignorant. So they are in the clear legally, but morally, its still dubious to do that given its effectively disclosing what is often a substantial portion of the conversation.
The message contents are e2e encrypted. And, transmitting an URL usually has no use beyond accessing it. They are doing what the user expects, it's just lacking some communication and power-user tools to override the default behavior.
“Someone was typing in a URL and WhatsApp was fetching it off my server”
61–69 of 69 posts
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#62Hi HN, op here. I posted this not because I was angry on having a GET request sent to my server on a char by char basis. My main concerns were privacy related, since I posted this some additional things came to light: 1) This leaks the IP address of the person writing the msg 2) When property="og:image" is used it also leaks the User Agent and Android version [1] 3) When presented with invalid headers as a reply it c…
If the connection was not made from the client (aka 'leaks the IP address') then it would need to be proxied (aka central point for 5eyes to monitor to get all WA client urls) or the servers would need to know the contents of the messages (aka break e2e and we are still back to a central monitoring point.)
Of course it will send user agent info, so that it can provide a better preview card if the site supports taking advantage of this info. If it only provides this when you explicitly try to send the info then it is doing what the user told it to do.
The header bug is interesting and if it is actually a WA problem you should report it.
Of course it leaks the exact time a URL is typed into chat. I can't even imagine what you are trying to say here since this is a point that is without a point. We have already established what it is trying to do and in that context this point makes no sense.
It is on by default and is the default behavior because this is what users expect. The secure features of WA are a bonus, but are not the raison d'etre here and when it comes down to it WA is a messaging app and it prioritizes usability when the feature is not an egregious security problem. In this case it is not a major security problem so usability and expectations win.
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#63Skype scans messages for URLs and downloads them. Microsoft claims is that they are checking for malware, still creepy.
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#64Earlier quoted context omitted.
Because the preview is displayed as you type, not when you hit Send
But still... why every character? Wait a couple hundred ms after each keystroke to see if they are done.
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#65Hi HN, op here. I posted this not because I was angry on having a GET request sent to my server on a char by char basis. My main concerns were privacy related, since I posted this some additional things came to light: 1) This leaks the IP address of the person writing the msg 2) When property="og:image" is used it also leaks the User Agent and Android version [1] 3) When presented with invalid headers as a reply it c…
These are all expected behaviors and are the correct decisions if the user expectation is that URLs generate preview cards. If the connection was not made from the client (aka 'leaks the IP address') then it would need to be proxied (aka central point for 5eyes to monitor to get all WA client urls) or the servers would need to know the contents of the messages (aka break e2e and we are still back to a central monitor…
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#66On the one hand it provides a greater user-experience if Whatsapp can figure out the URL and preview information about the posted URL (like any social network does today, even we do it at STOMT when you attach an URL to your feedback). On the other hand i do not get why they send it after every character. Makes it even faster but creates a bunch of unnecessary requests. Not very user friendly. They could do it after…
They're probably trying to prefetch the URLs so they're loaded by the time you want it, just not a nice way of doing it.
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#67Earlier quoted context omitted.
> WhatsApp is selling a solution that is meant to provide privacy. Yep you are right. They even tout this in their Security Page. https://www.whatsapp.com/security/ > WhatsApp's end-to-end encryption ensures only you and the person you're communicating with can read what is sent, and nobody in between, not even WhatsApp. This is because your messages are secured with a lock, and only the recipient and you have the sp…
I suppose that I'm not surprised. You can't audit WhatsApp's source code, and even if you could, you can't guarantee what you're putting on your device matches the source code. Yet another closed source, inherently untrustable system.
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#68Did you all know that chrome does this too? May sound obvious but I always had assumed that nothing is sent until you press enter for some reason (yeah I know, search prediction would be impossible without that). But one day I was type in a path on a test URL and noticing my server getting hit on - every single letter.
Re: “Someone was typing in a URL and WhatsApp was fetching it off my server”
#69Earlier quoted context omitted.
Yeah but tbh, its still not e2e encrypted. It just means WhatsApp is ignorant. So they are in the clear legally, but morally, its still dubious to do that given its effectively disclosing what is often a substantial portion of the conversation.
The message contents are e2e encrypted. And, transmitting an URL usually has no use beyond accessing it. They are doing what the user expects, it's just lacking some communication and power-user tools to override the default behavior.
Let us just say there are certain things that can cause legal complications merely accessing it and not reporting it is technically still a crime.