Live data from Hacker News

WhatsApp is broken, really broken

fileperms.org

41–50 of 137 posts

Re: WhatsApp is broken, really broken

#41
post #13

I'd have thought a large majority of what's app users use it for chatting. I can't imagine they're particularly fussed about people sniffing their plans for meeting up that night. There are varying requirements for security...

It isn't the information they can view, it is the things they can do impersonating you. Any application installed on your phone can probably access the two authenticating pieces of information. Then they can impersonate you in messages to, say, your parents and say something like "Hey mom, I need to order something, can you send me your credit card?" and then your mom, under the illusion that WhatsApp is secure, will send it right over.

Re: WhatsApp is broken, really broken

#42

Earlier quoted context omitted.

In this case, I think I disagree. A lot of this not just easy for an attacker to find - it is trivially easy for an attacker to find. Letting people know their communications are vulnerable is important, and it's not like they don't have plenty of alternatives.

Just because a skilled attacker can trivially find the information, doesn't mean that the 15 year old kid living next door to you can find it. Now they can. The problem doesn't stem from giving information to "l33t hax0rz" but rather providing the key information that can be abused by anyone with a computer and half a brain. They are the ones more likely to make use of it in a widespread and destructive manner. But w…

The whole point is that you didn't have to be a skilled attacker to figure out anything mentioned in the post. If the author had discovered an obscure security hole that allowed him to access sensitive information, then yes he's only going to make the problem worse by distributing that information online.

But it does not take a skilled attacker to "hack" a system where messages are being sent in plain text.

Re: WhatsApp is broken, really broken

#43
post #36

Earlier quoted context omitted.

Viber [1] may be a good alternative. It s free on all ecosystems - iOS, Android, WP, Blackberry, Nokia and Bada. [1] http://www.viber.com/

Like WhatsApp, Viber is free to use and has no advertising model. If they are not making money off me directly i have to wonder how safe my data actually is with this service.

WhatsApp is not free to use. iOS users are charged a flat 99c fee while Android users are charged 1$ a year from the second year onwards.

I do not know how secure Viber is but they have been steadilu acquiring good user base. If I was Viber, I would cash on this opportunity to write a blog or advertise their security models.

Re: WhatsApp is broken, really broken

#44

OT, but I'm intrigued by their business model. I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that. Meanwhile, the iOS app is $0.99 straight up. Thoughts: (a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet…

I got the iOS app when it was free, didn't know that they decided to start charging for it.

Re: WhatsApp is broken, really broken

#45
post #14
post #4

I've been seriously considering creating a highly secure text messaging replacement. I'm aware of TextSecure but find it lacking (and only available on Android). I'd love to hear if you guys think it would be a worthwhile project.

Skype would be a decent bet.

I wouldn't consider Skype secure when all traffic for Skype goes through private servers run by Microsoft and there is as far as I am aware no end to end encryption between end users.

Also, Skype's protocol and entire stack is entirely opaque and thus hasn't been nearly as checked for security issues as something like XMPP with SSL for example.

Re: WhatsApp is broken, really broken

#46
post #32

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

I'm no SMS engineer, but I'm pretty sure SMS is stuffed in one of the ping packets used to keep the phone connected to the cell towers.

Re: WhatsApp is broken, really broken

#47
post #37

Earlier quoted context omitted.

Viber [1] may be a good alternative. It s free on all ecosystems - iOS, Android, WP, Blackberry, Nokia and Bada. [1] http://www.viber.com/

But is it more secure?

No way to know. The way I see it I have two otions in te worst case scenario

Option1 - Use an insecure paid app Option2 - Use an insecure free app

I am not sure about you but I will choose Option2 gien the constraints and restrict my use to communications which have no privacy problems.

Re: WhatsApp is broken, really broken

#48
post #32

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

Compared to this? Ridiculously hard. A5/1, while severely compromised, still requires heavy IOPS and computing power to break quickly with rainbow tables (see Kraken).

Even worse: this allows for trivial spoofing. You're far, far away from doing that with SMS.

Re: WhatsApp is broken, really broken

#50
post #32

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

I'm no SMS engineer, but I'm pretty sure SMS is stuffed in one of the ping packets used to keep the phone connected to the cell towers.

It's sent on the control channel, not the payload channel. But that's not the important bit - This is: to sniff wifi you need a computer with wifi and a freely available, easy to use program. To sniff GSM you need a rather elaborate setup.

It's not that it's "hard" to sniff SMS in a crypto-sense, it's just that that bar is a lot higher that sniffing unencrypted wifi traffic.

Post reply on HN