Live data from Hacker News

WhatsApp is broken, really broken

fileperms.org

131–137 of 137 posts

Re: WhatsApp is broken, really broken

#131

Earlier quoted context omitted.

I presume because the list of potential people who you could connect to might change. I guess they could re-scan it on a schedule but that wouldn't solve your issue and might annoy their user base who are using it because it "just works." Plus removing a permission isn't something any app supports that I am aware of. It isn't even something you're meant to be able to do on Android.

point being, it's a stupid idea. every half decent programmer would just update the diff.

Nope, I wouldn't even consider that. Firstly because K.I.S.S. and secondly because you've exchanged a relatively small data "cost" with a much larger storage and processing "cost."

You've had to have a database of everyone's contacts and then be comparing X with Y every few connections...

Re: WhatsApp is broken, really broken

#133

Earlier quoted context omitted.

App piracy is actually a substantial issue on both stores: On Android, sideloading of apps from unauthorized sources (not the store), and frail DRM makes piracy really easy. The US government has been targeting these sources[1], but as you can imagine, there are many. Some have said that Android app piracy may be up to 60%[2], but I think there's some sample bias in these figures and suspect it's a fair bit lower. On…

Thanks. I imagine this varies a lot with app category/demographic. I'm not a gamer, but I've heard that many gamers have a large, ongoing appetite for new games, and perhaps this makes them more sensitive to price. Even a $0.99 price tag can seem high if you want to play a half dozen new games every month. Meanwhile, a non-gamer who downloads that many apps in a whole year might not mind paying as much. Also, gamers…

In addition to the ongoing appetite for new stuff, I guess in terms of games one could add that these audiences are more likely to be younger, less willing or able to spend and generally a little less caring about bills a developer has to pay. At least in contrast to apps, which might be connected to professional interests and needs - games are very likely to be a matter of fun, which may make it easier to justify piracy in a consumer's mind.

I don't want to generalize and it's certainly not a good idea to put everyone into categories, but in my opinion piracy is heavily tied to psychological characteristics and the personality of users - in addition to a user's financial limits of course.

This comment touches an aspect that is hard to sum up in a few sentences as it doesn't come down to one single reason, but generally speaking I guess Android users are more likely to engage in piracy.

Re: WhatsApp is broken, really broken

#134
post #87
post #32

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

Armed with this blog post and a laptop, you could start spying on IM traffic in your local coffee shop in five minutes. I don't know where you'd even begin with spying on SMS, but I bet that in the least it requires substantially more specialized equipment.

Yeah, it requires specialized equipment, but that's really the biggest barrier. From a protocol standpoint it isn't really any better.

Re: WhatsApp is broken, really broken

#135
post #32

Yes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?

Compared to this? Ridiculously hard. A5/1, while severely compromised, still requires heavy IOPS and computing power to break quickly with rainbow tables (see Kraken). Even worse: this allows for trivial spoofing. You're far, far away from doing that with SMS.

Actually, SMS spoofing is arguably easier than WhatsApp spoofing.

Re: WhatsApp is broken, really broken

#136

OT, but I'm intrigued by their business model. I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that. Meanwhile, the iOS app is $0.99 straight up. Thoughts: (a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet…

I didn't even know it was going to be $0.99 a year after the first year. I only started using it a few months ago and I already feel a little locked in, I doubt 9 months from now I would bother switching to something else for the sake of a buck a year. Very clever, but I wonder if such a small amount of revenue will add up to enough.

Re: WhatsApp is broken, really broken

#137
post #2

Sadly, normal free Jabber/XMPP does not seem to be a viable alternative. On Android, sure (though the clients are not too great at reconnecting/noticing-connection-loss/reporting-message-reception) but on iOS apparently you cannot run such things in the background. At least the situation was dire when I tried to convince some iOS friends to use XMPP instead of SMS last winter. http://monal.im/ looked most promising b…

Hi, I am the developer of monal. It is a real, direct xmpp client and remains open in the background as long as you have an internet connection. It even has preliminary support for Jingle voip.
Post reply on HN