Live data from Hacker News

WhatsApp is broken, really broken

fileperms.org

21–30 of 137 posts

Re: WhatsApp is broken, really broken

#21
post #4

I've been seriously considering creating a highly secure text messaging replacement. I'm aware of TextSecure but find it lacking (and only available on Android). I'd love to hear if you guys think it would be a worthwhile project.

I like TextSecure, but it has one main drawback as far as I'm concerned. It doesn't hide who is talking to who and when. It only hides the message content.

I imagine a messaging app which works like TextSecure (as far as encryption goes), but integrates with Orbot (Tor for Android). Both phones would set up a Hidden Service so they can communicate directly, over the Tor network, over the Internet without an intermediate server.

That would be the perfect messaging system IMO. Not only would the message content be hidden, but who is talking to who, and when, would also be hidden. And it wouldn't require anyone to run a server to handle the messages either.

Please, somebody make this app.

Re: WhatsApp is broken, really broken

#22

Did the author email the WhatsApp team to give them any chance to fix this before they splashed it across the internet for anyone to abuse? The article makes no mention of it, so I assume not. In my opinion, the obscurity peeled off by this expose did more to endanger WhatsApp users than the bad programming. So, I can only conclude this post's main goal is page views. OP could easily warn them, and at least wait unti…

My opinion - something so trivial as private data sent in plaintext isn't a bug or a security hole, it's bad by design. You shouldn't have to notify someone they've designed their app poorly. If he was taking advantage of a security hole, or something of that nature that wouldn't already be known to the developers, then I could see notifying them before publishing.

Re: WhatsApp is broken, really broken

#23

OT, but I'm intrigued by their business model. I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that. Meanwhile, the iOS app is $0.99 straight up. Thoughts: (a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet…

I think it comes down to it being harder to make money on the android store and ease of piracy vs ios store. The market share / profit tradeoff ratio on android makes it worth more to be free. On iOS they sometimes make the app free too.

Re: WhatsApp is broken, really broken

#24

Did the author email the WhatsApp team to give them any chance to fix this before they splashed it across the internet for anyone to abuse? The article makes no mention of it, so I assume not. In my opinion, the obscurity peeled off by this expose did more to endanger WhatsApp users than the bad programming. So, I can only conclude this post's main goal is page views. OP could easily warn them, and at least wait unti…

I'm usually all for "responsible disclosure", but in this particular case, I don't believe that they weren't already aware of these issues. So shaming them was the right thing to do.

Re: WhatsApp is broken, really broken

#25
No mention of this on their blog (in fact, no new posts since July). And no quick patch that pops up a box asking the user to assign a password. Since it's tied to a phone number/SIM card anyway, you could easily offer a password retrieval option via SMS.

I wonder what happens if a phone number (the login) is tied to a different IMEI (the password). This can happen when you transfer a phone number from one provider to another.

Re: WhatsApp is broken, really broken

#26
post #3

So, what's the best alternative?

It depends on what you want to do. If you want to make sure your little brother isn't spying on what you're saying, any of the IM platforms from established players is likely "good enough" (gtalk, skype, facebook chat, etc). If you're a dissident in the middle-east, your requirements may be difficult to meet.

Re: WhatsApp is broken, really broken

#27
post #20
post #2

Sadly, normal free Jabber/XMPP does not seem to be a viable alternative. On Android, sure (though the clients are not too great at reconnecting/noticing-connection-loss/reporting-message-reception) but on iOS apparently you cannot run such things in the background. At least the situation was dire when I tried to convince some iOS friends to use XMPP instead of SMS last winter. http://monal.im/ looked most promising b…

imo.im on iOS works perfectly fine with google talk and i receive messages when it's not running as well.

imo.im is a web service, not a raw XMPP client.

Re: WhatsApp is broken, really broken

#28
post #6
post #4

I've been seriously considering creating a highly secure text messaging replacement. I'm aware of TextSecure but find it lacking (and only available on Android). I'd love to hear if you guys think it would be a worthwhile project.

What is the target market? I mentally treat all messages as insecure, and no self-proclaimed secure system would change my thoughts.

You can set up your own private XMPP server and use gibberbot, beem or yaxim on android (or any other XMPP client on the platform of your choice). This is the only way to ensure that your communication is really private.

Re: WhatsApp is broken, really broken

#29

Did the author email the WhatsApp team to give them any chance to fix this before they splashed it across the internet for anyone to abuse? The article makes no mention of it, so I assume not. In my opinion, the obscurity peeled off by this expose did more to endanger WhatsApp users than the bad programming. So, I can only conclude this post's main goal is page views. OP could easily warn them, and at least wait unti…

The security history of WhatsApp is so horrible, it does not seem to make any sense to talk to them. Alone the fact that their app is sending your contact list to their server, without asking you, on every app start, disqualifies the service. Their previous security track record just puts it over the edge.
Post reply on HN