Live data from Hacker News

We Chat, They Watch

citizenlab.ca

91–100 of 555 posts

Re: We Chat, They Watch

#91

Looking at the comments I think that most of commenters missed an important point. It's not just that the app is tracking users, but the messages sent by any non-Chinese user help the regime censor the content for Chinese users. In other words, if you use WeChat, and you send a photo of something that happened in Hong Kong along with some text that explains it, then you actually help Chinese authorities to censor thi…

Many Chinese-Americans have no choice when they need to communicate with family and friend living in China. No outside communication tools allowed in China.

Re: We Chat, They Watch

#92
post #55

Earlier quoted context omitted.

>> WhatsApp is end-to-end encrypted so the service providers themselves can't read the message content, yes, definitely. Although, technically the security guarantees are nil unless you verify safety numbers which I can guarantee almost nobody actually does. Except that there is no way to prove this. There is no way to prove that it isn't also sending a copy from the client back to the server. Whatsapp could deploy i…

That's still not a full answer, of course, your proprietary operating system or closed chipsets can spy on you. Absolutism isn't helpful IMHO, there is no true security in this world only degrees of trust and risk. You can always go one step further in securing a product but the first step still matters. I think there's real value in companies implementing e2e (and it's hard! it's super hard politically to get this d…

Verifying the software one is running is not absolutism. Just because one cannot provide 'perfect' security isn't a reason to give up trying to provide some security by elevating the effort requires to conduct an attack. That locks can be picked isn't an excuse to not bother locking the door.

Re: We Chat, They Watch

#95
post #16

Earlier quoted context omitted.

There are degrees of security between "I personally built it from source using a compiler I personally built from source" and "Xi Jinping is CC'ed a plaintext copy of every message". The allegation here is that WeChat is basically the latter. No one makes any remotely similar claim about iMessage or WhatsApp.

If you have never read "Reflections on Trusting Trust" by Ken Thompson, I wholeheartedly recommend it. It's a short read (3 pages), but absolutely worht your time. https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...

Why is your link downvoted?

Re: We Chat, They Watch

#96
Regardless of what nationality an app is created under, in today's day and age, why is not just assumed that any website/app is not slurping in all of your data (usage, messages, location, wifi name, etc)? To me, all apps are guilty until proven innocent.

Re: We Chat, They Watch

#97
post #36

Earlier quoted context omitted.

This narrative of false equivalency is dangerous, IMO. WeChat has been proven to be a heavily monitored and censored network. Whatever security failings iMessage and WhatsApp have, they pale in comparison to what's in place for WeChat.

The false equivalency also begs a deeper moral analysis. Let's assume the US government has as complete access to iMessage and WhatsApp as the CCP does to WeChat. The story doesn't end there, since you have to examine the nature of the entities that have access to your information. Would I prefer that access be held by the US Government, which for all its faults is extremely engaged with and integrated into the globa…

> extremely engaged with and integrated into the global system, beholden to Law and a robust court system

Uhm yeah but countries do nothing when Russia annexes Crimea, what do you think they’d do if the US simply spies on them? Absolutely nothing. It’s literally happening right now and it’s public knowledge and “it’s just a matter of national security.” Case closed.

Re: We Chat, They Watch

#98
It’s worth noting that Facebook Messenger also intercepts and filters messages. For example, it’s impossible to send a message containing the link “joebiden.info”. On the mobile app, it will simply say “failed to send.” On desktop, it will tell you the link violates its “community standards” and cannot be shared.

Re: We Chat, They Watch

#99

Regardless of what nationality an app is created under, in today's day and age, why is not just assumed that any website/app is not slurping in all of your data (usage, messages, location, wifi name, etc)? To me, all apps are guilty until proven innocent.

What is the incentive for any app to do the right thing then?

It seems to me that coloring all apps the same regardless means that all apps may as well just do exactly as you describe...

Anyone who doesn't isn't thought of as any better...

Re: We Chat, They Watch

#100
post #87
post #71

Earlier quoted context omitted.

I think the assumption behind your claim of false equivalency is exactly what the parent comment wanted to discuss. You say the security failings of iMessage and WhatsApp pale in comparison to WeChat; I agree with parent comment and ask - in light of PRISM etc. - on what grounds can you say we should not be just as suspicious?

Whether or not compromised, I am sure my messages on iMessage are not used to train censorship applications by the NSA. Messages on WeChat are used for censorship. I also, separately, think that in aggregate Apple has incentives to make iMessage secure. While Tencent has incentives to share WeChat data with CCP. These are among many reasons why the comparison was false equivalence. The world is not just black and whi…

> I am sure my messages on iMessage are not used to train censorship applications by the NSA

What basis do you have for this certainty?

Post reply on HN