Live data from Hacker News

WhatsApp is broken, really broken

fileperms.org

31–40 of 137 posts

Re: WhatsApp is broken, really broken

#31
post #22

Did the author email the WhatsApp team to give them any chance to fix this before they splashed it across the internet for anyone to abuse? The article makes no mention of it, so I assume not. In my opinion, the obscurity peeled off by this expose did more to endanger WhatsApp users than the bad programming. So, I can only conclude this post's main goal is page views. OP could easily warn them, and at least wait unti…

My opinion - something so trivial as private data sent in plaintext isn't a bug or a security hole, it's bad by design. You shouldn't have to notify someone they've designed their app poorly. If he was taking advantage of a security hole, or something of that nature that wouldn't already be known to the developers, then I could see notifying them before publishing.

This is an excellent point. Fixing a design flaw this inherent is going to take more than a weekend of frantic dev time. It could conceivably take weeks to implement an overhaul to their framework, all the while the users are vulnerable.

Re: WhatsApp is broken, really broken

#32
Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

Re: WhatsApp is broken, really broken

#33

OT, but I'm intrigued by their business model. I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that. Meanwhile, the iOS app is $0.99 straight up. Thoughts: (a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet…

I've never had to pay for the Android app - it seems to autorenew.

Re: WhatsApp is broken, really broken

#34
post #32

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

Compared to sniffing data over public wifi, pretty hard.

Re: WhatsApp is broken, really broken

#35
We should all start using our regular XMPP accounts now! Most of us already have one. If you have a Gmail, Fastmail, Lavabit, GMX, Ovi.com, Yandex email address, you are ready to go. All that's left to do: Install Xabber or IM+ on your smartphone! Btw, both support OTR end2end encryption!

If you also want to instant message on your laptop: The latest Thunderbird comes with XMPP support! Or give Jitsi, which supports end2end encryption, or one of the many alternatives a try! Enjoy!

Re: WhatsApp is broken, really broken

#36
post #3

So, what's the best alternative?

Viber [1] may be a good alternative. It s free on all ecosystems - iOS, Android, WP, Blackberry, Nokia and Bada. [1] http://www.viber.com/

Like WhatsApp, Viber is free to use and has no advertising model. If they are not making money off me directly i have to wonder how safe my data actually is with this service.

Re: WhatsApp is broken, really broken

#38
post #13

I'd have thought a large majority of what's app users use it for chatting. I can't imagine they're particularly fussed about people sniffing their plans for meeting up that night. There are varying requirements for security...

So just because 99 percent of SMSs don't contain sensitive information, it's OK to leave the remaining 1 percent insecure?

Re: WhatsApp is broken, really broken

#39
post #23

OT, but I'm intrigued by their business model. I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that. Meanwhile, the iOS app is $0.99 straight up. Thoughts: (a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet…

I think it comes down to it being harder to make money on the android store and ease of piracy vs ios store. The market share / profit tradeoff ratio on android makes it worth more to be free. On iOS they sometimes make the app free too.

Tell me more. I wasn't aware app piracy was a major problem in either store.

Re: WhatsApp is broken, really broken

#40

Earlier quoted context omitted.

In this case, I think I disagree. A lot of this not just easy for an attacker to find - it is trivially easy for an attacker to find. Letting people know their communications are vulnerable is important, and it's not like they don't have plenty of alternatives.

Just because a skilled attacker can trivially find the information, doesn't mean that the 15 year old kid living next door to you can find it. Now they can. The problem doesn't stem from giving information to "l33t hax0rz" but rather providing the key information that can be abused by anyone with a computer and half a brain. They are the ones more likely to make use of it in a widespread and destructive manner. But w…

My point is that most of the threats exposed don't take elite hacker, or even "l33t hax0rz", skills to discover. A hugely greater percentage of people are going to hear about this and say, "oh, I should switch to something else" or "oh, I shouldn't say sensitive things" than are going to fail to hear about this and be snooped on by someone who did and wouldn't have figured it out anyway.
Post reply on HN