Live data from Hacker News

Reverse Engineering WhatsApp Web

github.com

11–20 of 127 posts

Re: Reverse Engineering WhatsApp Web

#11
post #10
post #7

Earlier quoted context omitted.

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

Out of curiosity: I’ve noticed a long-term sceptical attitude to telegram in HN audience and have seen multiple arguments against it. Something like that their crypto can’t be trusted, that it’s not time-proven. Don’t you know any good source with some sort of domain expert explanation, why shouldn’t it be used or trusted? No intention to start any flame against Signal, only curiosity regarding telegram flaws. Person…

It's not even end to end encrypted by default. That's the main reason why you shouldn't use it.

Re: Reverse Engineering WhatsApp Web

#12
post #9
post #7

Earlier quoted context omitted.

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

It's also exactly as open as WhatsApp, but not as usable.

Signal is open source both client and server. To my knowledge the same isn't true for WhatsApp.

Re: Reverse Engineering WhatsApp Web

#13
post #7
post #6

Earlier quoted context omitted.

Better? Yes. Easier? No. Besides, what's more open, as usable and secure?

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

I wish signal had a webapp.

Re: Reverse Engineering WhatsApp Web

#14
post #8

Wow that's impressive. But I would imagine WhatsApp/Facebook can just change their protocol at any time since it is easy to redeploy a new version of the WhatsApp Web client, thus breaking any 3p clients built on the original protocol. That would require yet another reverse engineering effort that can take a while. And by the time its reverse engineered again, they can yet again change the protocol. So the only relia…

They have a closed beta program for an "Enterprise" version that is supposed to have an API. Seems like a good way to monetize.

Re: Reverse Engineering WhatsApp Web

#15
post #13
post #7

Earlier quoted context omitted.

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

I wish signal had a webapp.

It has a desktop app for MacOS, Linux and Windows. https://github.com/signalapp/Signal-Desktop

Re: Reverse Engineering WhatsApp Web

#16
post #11
post #10

Earlier quoted context omitted.

Out of curiosity: I’ve noticed a long-term sceptical attitude to telegram in HN audience and have seen multiple arguments against it. Something like that their crypto can’t be trusted, that it’s not time-proven. Don’t you know any good source with some sort of domain expert explanation, why shouldn’t it be used or trusted? No intention to start any flame against Signal, only curiosity regarding telegram flaws. Person…

It's not even end to end encrypted by default. That's the main reason why you shouldn't use it.

This right here, how can such a basic step to protect your users be skipped?

Re: Reverse Engineering WhatsApp Web

#17
post #9
post #7

Earlier quoted context omitted.

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

It's also exactly as open as WhatsApp, but not as usable.

https://github.com/signalapp

Re: Reverse Engineering WhatsApp Web

#18
I'm very hopeful this reverse engineering effort will enable the creation of a tool to export my conversations (WhatsApp can do email export, which let's be real, doesn't cut it for most cases).

A point to those that support migrating to alternatives such as Signal. Signal is good, but far from great for a single reason: you need a phone number. This is very bad in necsec and reliability terms, my case:

Reliability: like more and more people, I travel all the time between countries and live out of Airbnbs. Hence my pre-paid phone numbers changes very regularly. If I lose my phone, I lose the phone number, I also lose my Whatsapp/Signal key associated with my phone number.

Netsec: A phone number is associated with your physical identity, you might not care, but more and more people do care about this stuff. Yes there are ways around that, but nothing straightforward and actually practical.

I'm patiently, but eagerly, looking forward to status.im .

Re: Reverse Engineering WhatsApp Web

#19
post #13
post #7

Earlier quoted context omitted.

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

I wish signal had a webapp.

Not very likely any time soon. There was a long debate about it and they decided that putting your trust entirely in the CA system and Signal's servers every time to not serve a malicious client that couldn't be validated by the user wasn't acceptable.

Re: Reverse Engineering WhatsApp Web

#20
post #9

Earlier quoted context omitted.

It's also exactly as open as WhatsApp, but not as usable.

Signal is open source both client and server. To my knowledge the same isn't true for WhatsApp.

It's open source, but Moxie has said he doesn't want federation. I don't think he'd be okay with someone writing a third-party client, for example.
Post reply on HN