Live data from Hacker News

WhatsApp Messaging Interoperability

developers.facebook.com

111–120 of 152 posts

Re: WhatsApp Messaging Interoperability

#111
post #65

Gosh, all of this is so locked down. I've been waiting for this, and hoping I could "just" cook up some of my own code to use with WhatsApp, and/or integrate it with Pidgin or bridge to email or whatever. But the entire process is about as hostile as possible. For example "Partner shall have in place a dedicated security team" basically excludes most startups, or most smaller companies. It's not clear to me if this i…

I think it's quite fair to demand basic security compliance for implementing an E2EE messenger.

That said, I'm sure we'll see open source libraries pop up everywhere to communicate with WhatsApp directly. There already are unofficial WhatsApp clients in various forms, but now they can use the protocol without risking breakage because they reverse engineered the contents of the protocol itself.

I think there will be plenty of space for the Beeper Minis out there right now.

Re: WhatsApp Messaging Interoperability

#112
post #38

Earlier quoted context omitted.

You literally have an option in WhatsApp do disable loading of audio/image/video.

Oh yes, it's there, thanks. I wonder when they added it... Edit: Waaait a bit. I have it on iOS and I have it on some laptop where whatsapp desktop is an old version. I can't find it on my desktop where their desktop app is the latest and greatest... They probably "improved my whatsapp experience". Edit 2: besides, that just doesn't download the photos, I think? They still take half the screen that could be used for…

> I wonder when they added it...

At least 7-8 years. Probably from whenever it became possible to send media messages.

Re: WhatsApp Messaging Interoperability

#113
post #65

Gosh, all of this is so locked down. I've been waiting for this, and hoping I could "just" cook up some of my own code to use with WhatsApp, and/or integrate it with Pidgin or bridge to email or whatever. But the entire process is about as hostile as possible. For example "Partner shall have in place a dedicated security team" basically excludes most startups, or most smaller companies. It's not clear to me if this i…

I think it's quite fair to demand basic security compliance for implementing an E2EE messenger. That said, I'm sure we'll see open source libraries pop up everywhere to communicate with WhatsApp directly. There already are unofficial WhatsApp clients in various forms, but now they can use the protocol without risking breakage because they reverse engineered the contents of the protocol itself. I think there will be p…

> I'm sure we'll see open source libraries pop up everywhere to communicate with WhatsApp directly.

How so? Each of them would need approval by Meta + signing an NDA, and I can easily see that ruling out open source libraries.

Re: WhatsApp Messaging Interoperability

#114

Sigh Just...use Matrix or XMPP or something ffs. The open protocols _already exist_.

They don't provide the same level of privacy that the Signal protocol does, though. Plus, I'm not sure why WhatsApp would implement a whole second protocol in the first place, they're doing this out of legal obligation, of out of free will.

I have some minor hope that WhatsApp will eventually switch to MLS+MIMI, as someone from Facebook does take part in the design process, but that could also be because of Facebook Messenger really.

Re: WhatsApp Messaging Interoperability

#115
post #103
post #36

Earlier quoted context omitted.

And that they are reluctantly complying in bad faith in the most hostile way they found. Is this going to fly? Where do these 60 days come from for instance? How is it any useful and who is going to want to implement such interoperability under such terms? This reads like a lot of words to say Fuck You Europe to me. Well, feelings are mutual, at least we are on the same page, them and me.

Sounds less like "bad faith" and more like "I was hoping that Meta would cave and offer this to everyone, but turns out they don't have to do that because EU jurisdiction ends at EU borders"?

Fair enough.

Now, not sure what I was hoping for. None of my messages currently go through Meta and I'm quite happy with this.

As an implementer, I certainly wouldn't want to police and track my users and their location for a chat service, and as a user I wouldn't want a chat service to track me.

I also certainly don't want to depend on a system which is unreliable because it artificially depends on my or my contacts position on Earth

This whole thing sounds like something I will not want to use anyway.

Re: WhatsApp Messaging Interoperability

#116

Earlier quoted context omitted.

Hey I can shed light on this. It’s the iCloud keychain. Disabling the keychain doesn’t delete existing entries. There is no way to modify the keychain on iOS (you can on Mac). Lots of apps store sign on data in the keychain for obvious reasons. It would be really great to have a keychain section in iOS’s settings, like Keychain Access on Mac. The dev can build in-app functionality to delete keys from the keychain, bu…

It's not specific to iCloud Keychain--it applies to on-device Keychain on iOS devices, too, even if you don't use iCloud. Any developer can store data there with no way for the user to know or see what it's saving, and it's shared among all apps from the same developer. Keychain is quite a misnomer here--it's really "store any (short) data you want on a user's device without them ever being able to see or remove it".…

This is also used heavily for abuse / spam / fraud prevention.

If you detect that a user is abusing your service, the ability to put a permanent cookie on their device is very useful.

This isn't effective against organized crime groups (they can just get Macs / use the web / whatever), but works well against your average troll or internet racist.

Still tracking, but a very different kind of tracking.

Re: WhatsApp Messaging Interoperability

#117
post #101
post #98

Earlier quoted context omitted.

The preview sends a request to some server on a Facebook subdomain. I know because I was sniffing traffic on my phone without any Facebook app installed other than WhatsApp.

Did you see the content of that domain? It might be spam/phishing protection, which can be done in a privacy-preserving way (e.g. sending only a truncated hash of the link TLD to a server and downloading a larger set of blocked domains for local filtering). At least on my Mac, I also only see connections to the URL domain, nothing to a Facebook subdomain.

Meta and 'privacy-preserving' are a contradiction in terms.

Re: WhatsApp Messaging Interoperability

#118
post #96
post #95

Earlier quoted context omitted.

I don't really see why WhatsApp would care, because once you have developed the interoperability, audited the apps, and done all that, it doesn't really cost WhatsApp anything if a user is using that app. They lose no profit, doesn't cost their servers any more than their own client would, etc. WhatsApp makes their money from the business clients/apps (which aren't covered under this, which I think is fine by the way…

The WhatsApp client does give Meta a window of opportunity to get data from users. The data is otherwise E2E encrypted but when you see a link preview on WhatsApp Meta knows that.

Only the messages are encrypted, but there's a ton of metadata that isn't, e.g. who you talk to, when, where you are when you do so, ...

Re: WhatsApp Messaging Interoperability

#119

Signal or matrix interop would be great. I use WhatsApp as the logistical tool of choice to communicate with my coworkers when away from the company but I wish I could uninstall it. Not my tribe.

Matrix has WhatsApp interop that works excellent. It somehow uses the web client, which I imagine could be replaced by real interop.

You can't uninstall WhatsApp that way though. Not just the web client, but also the app on your phone, which the web client proxies everything through.

Re: WhatsApp Messaging Interoperability

#120
post #62

Earlier quoted context omitted.

You may dislike it, but EU law only applies in the EU; it sounds like full compliance to me, not "bad faith" compliance. Messaging-interoperability is the one aspect of the DMA I don't support. These apps are free to download; and if you care about security (and use Signal) you'll want to avoid cross-service messaging anyway.

> These apps are free to download Yes but you aren’t truly free to choose which app you download. You have to use the one being used by the people you want to message. That is of strong benefit to incumbents.

> you aren’t truly free to choose which app you download. You have to use the one

Singular? You'd just use whichever app a given person is on (everyone here has 3+ chat apps installed). Wouldn't network effects only kick in when group chats are involved?

Post reply on HN