Live data from Hacker News

WhatsApp is using your IMEI number as password

samgranger.com

51–60 of 83 posts

Re: WhatsApp is using your IMEI number as password

#51
post #38

Earlier quoted context omitted.

So the only point was in avoiding one time step like adding an account to the client (like users do with e-mail too) / or registering on some XMPP server? Still it hardly justifies creating more walled networks (unless they allow federation and regular XMPP communication with their servers).

Do you think consumers care about walled networks? No.

To a degree they do, since users of one walled network can't communicate with users of other walled ones, and if they want they need to create an account in each of them. While federated XMPP is like e-mail, i.e you can use one ID to communicate with users from many servers. So there is an obvious comfort even for the end user.

Re: WhatsApp is using your IMEI number as password

#52

Earlier quoted context omitted.

I use it to talk to my friends back home because: - it's free (or inexpensive compared to international SMS) - it doesn't require any technical expertise whatsoever - it's cross platform - it already has traction I can't think of any alternative which has this combination of properties..

I hate to be the devil's advocate but I swear by Facebook's messenger app. It does exactly the same things: international, FREE-as-in-beer, really cross platform (can whatsapp do web?), push notifications on iPhone thereby effectively replacing SMS, etc. As long as the other person is on facebook of course! It has come to the point that my wife and I barely use SMS anymore and are actually saving some play money on S…

You see, so what stops them all from implementing their clients and servers using conformant XMPP with enabled federation? Can your Facebook messenger connect you to users of WhatsApp and vice versa? No. With Federated XMPP it'd just work. Is it just their greed, or lack of thinking? Actually Facebook does use XMPP, and I think even WhatsApp in some way internally does, but Facebook server lacks federation, and WhatsApp isn't even conformant to standard XMPP. In the end - you have no way to connect the two.

This situation resembles the early period of the Internet, when users of Compuserve couldn't send e-mails to users of AOL (and other way around). It sounds completely weird today, but how is this situation with IM networks different?

Understandably there are historic isolated networks (AOL, MSN etc.) which predate any serious federation efforts, and even they are slowly enabling XMPP in some ways. But creating new closed ones in the present time is just weird and only serves to make the situation worse.

Re: WhatsApp is using your IMEI number as password

#53
post #37

Earlier quoted context omitted.

I also don't allow any app requiring those details (unless they are needed obviously, like VoIP), but I think what most companies want is the unique serial number, so they can keep a track of how many unique devices are used by them. But since Android does not gives permission at more granular level, I simply don't install any such app, or don't upgrade one which ask for it. As for Facebook, I am using Tinfoil for Fa…

> Tinfoil for Facebook And Tinfoil is better integrated with the Android system than the official Facebook app. Click a Facebook link in an app or browser - you'll get Tinfoil as an option to view the link but not the official app.

What a brilliant name! We need a tinfoil chrome extension.

Re: WhatsApp is using your IMEI number as password

#54
post #39
post #32

Can anyone explain in general what is the point in WhatsApp which isn't compatible with anything except itself, vs normative XMPP/Jingle client through which one can communicate with any user from federated XMPP servers? I have hard time understanding why new closed (walled garden) IM networks appear in these day and age.

It's quite popular in countries where buying SMS credits is not always an afforded cost, but public wifi is everywhere. Basic Android phones are fairly popular and inexpensive given that they double as a web browser and communication device for many.

> It's quite popular in countries where buying SMS credits is not always an afforded cost, but public wifi is everywhere.

What countries are that?

Re: WhatsApp is using your IMEI number as password

#55
No offense but what is the big deal about this...This seems to be extremely low risk if you can even call it a risk, and hardly a vulnerability..

Every method on your website to “exploit” this is retrieving IMEI number through alternative ways which would mean the phone would be compromised anyway...If someone can compromise the phone who cares about this?

Maybe whatsapp can be accessed more easily but isn't that moot if you already have phone access..If you have phone access already why would an attacker care about whatsapp?

Whatsapp is not necessarily insecure based on this..You are giving whatsapp bad publicity for no reason

I don't even think it's a design flaw that they used that as the password because if someone has phone access, and/or access to their number already then they are probably screwed anyway

please correct me if I'm missing the actual vuln here..

Re: WhatsApp is using your IMEI number as password

#56
post #32

Can anyone explain in general what is the point in WhatsApp which isn't compatible with anything except itself, vs normative XMPP/Jingle client through which one can communicate with any user from federated XMPP servers? I have hard time understanding why new closed (walled garden) IM networks appear in these day and age.

Ubiquity; works on every mobile platform. (Including Nokia/Symbian, Windows Phone) So you can talk to any of your friends if they install the app.

Phone numbers are logins. Everybody with a phone already has one, so they don't have to do the whole 'create/verify an ID/password' dance.

If you have friends in other countries, this avoids roaming SMS charges. And if you are from Ireland, or Greece, lots of your friends are in other countries.

Re: WhatsApp is using your IMEI number as password

#57
This is well-known. I'm curious to know how they get the IMEI on iOS cause there isn't a public API but only an undocumented method on the CoreTelephony.framework. Using a private method is one of the easiest ways to be banned from the App Store. BTW on January 13, 2012, Whatsapp was pulled from the iOS App Store for 4 days. I think they were pardoned by Apple because of the popularity of the application.

Re: WhatsApp is using your IMEI number as password

#58

No offense but what is the big deal about this...This seems to be extremely low risk if you can even call it a risk, and hardly a vulnerability.. Every method on your website to “exploit” this is retrieving IMEI number through alternative ways which would mean the phone would be compromised anyway...If someone can compromise the phone who cares about this? Maybe whatsapp can be accessed more easily but isn't that moo…

Your IMEI isn't secret: not random/hard to guess, and not private. It's like a MAC address. Except you can't change it.

Re: WhatsApp is using your IMEI number as password

#59

This actually seems to me like a perfect solution (from WhatsApp's side). This way as long the user has the same phone number, he/she doesn't have to remember any credentials, which is probably the main reason (or one of the top 3) for people using WhatsApp in the first place. And as for the "security problem", if someone has access to your phone they can just maliciously use the app itself. I'm not saying that this…

IMEI isn't related to the phone number (IMSI is). And it's a horrible idea since IMEI isn't secret.
Post reply on HN