Earlier quoted context omitted.
Force interoperability one way or another. WhatsApp is a closed system, if I want to use an alternative I'm stuck with adversarial interoperability, so stuff like Beeper (which is great, but...) which might get my account banned. Or waiting for some legislation to force WhatsApp to open it's API and let me interact with my contacts there without being locked into their apps
There is legislation in the EU, and BirdyChat announced compatibility. https://www.birdy.chat/blog/first-to-interoperate-with-whats...
Rust at Scale: An Added Layer of Security for WhatsApp
121–130 of 151 posts
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#122> over 3 billion people to message securely each and every day. Whatsapp is a chat application with 3 billion daily active users. For those of you in the US (where Whatsapp is seldom used), this is a fact worth remembering. If you want to build products for the rest of the world, you need to know how those users think and breathe - and for 3 billion of them, Whatsapp is how they talk.
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#123Earlier quoted context omitted.
> Weight equipment should be able to last decades. "should" or "actually can"? Do you have references to show that's the actual lifespan of the equipment, mechanically?
Weight training equipment lasts decades all the time. It's just big piles of metal, it's not hard to get right. What actually prompted the engineering-CYA "should" is if the Android tablet is controlling some sort of robotic system for selecting weight sizes, that that system might have an expected life span on par with a tablet, being a physical thing moving around some pins or something in a potentially hostile use…
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#124Earlier quoted context omitted.
> Weight equipment should be able to last decades. "should" or "actually can"? Do you have references to show that's the actual lifespan of the equipment, mechanically?
Weight training equipment lasts decades all the time. It's just big piles of metal, it's not hard to get right. What actually prompted the engineering-CYA "should" is if the Android tablet is controlling some sort of robotic system for selecting weight sizes, that that system might have an expected life span on par with a tablet, being a physical thing moving around some pins or something in a potentially hostile use…
I'm just going to ignore this.
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#125> Two major hurdles were the initial binary size increase due to bringing in the Rust standard library [...]. They don't say what they did about it, do they? Did they just accept it?
We invested a lot into build system optimizations to bring this number down over time, although we did accept on the order of 200 KiB size overhead initially for the stdlib. We initially launched using a Gradle + CMake + Cargo with static linking of the stdlib and some basic linker optimizations. Transitioning WhatsApp Android to Buck2 has helped tremendously to bring the size down, for instance by improving LTO and…
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#126Earlier quoted context omitted.
One could imagine a design where even the app vendor is untrusted... You would send an encrypted chunk direct to the GPU, which would then decrypt and render the message text in some secure environment onto the screen. Neither the OS nor the application would know the contents of your message beyond "it's 500x700 pixels". Similar things are done for DRM video, and widevine level 1 or 2 haven't seen many breaches desp…
Oh it's definitely possible. The (dis)incentives tend to be strongly against such secure systems, though.
If you can have an e2e chat between two iphones locked in a big glass box with a sign that says "Anyone who can hack into this conversation gets $100M", that's a really good marketing campaign.
If you can make the app use secure enclaves or whatever to take the ~100k people who write the source code of the libraries, app and OS out of the attack surface, that $100M becomes much safer.
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#127Earlier quoted context omitted.
The default hello world stripped with one codegen unit and panic=abort was 342kB both nightly and stable. Adding lto dropped it 42kB in stable and 40kB in nightly. Adding build-std and only building core did not reduce it any further in size.
I assume OP is taking about using -Zbuild-std on nightly. This will drop it much more.
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#128Earlier quoted context omitted.
The point of articles like this is to help build credibility for rust adoption. Rust is still not very widely adopted industry wide, and a lot of smaller players only use established technologies that bigger firms have shown works well. Rust is not inevitable, and articles like this are necessary for its future industry adoption.
I had already said it’s a PR piece, you’re merely rephrasing that and making it sound like a good thing. This and the Google blogs offer zero technical insights and I haven’t learned anything from any of them.
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#129Earlier quoted context omitted.
The size is not fixed. It changes based on how much of the standard library you use. Dynamically linking the standard library is also a valid option in many cases.
Posted elsewhere but The default hello world stripped with one codegen unit and panic=abort was 342kB both nightly and stable. Adding lto dropped it 42kB in stable and 40kB in nightly. Adding build-std and only building core did not reduce it any further in size.
Re: Rust at Scale: An Added Layer of Security for WhatsApp
#130> over 3 billion people to message securely each and every day. Whatsapp is a chat application with 3 billion daily active users. For those of you in the US (where Whatsapp is seldom used), this is a fact worth remembering. If you want to build products for the rest of the world, you need to know how those users think and breathe - and for 3 billion of them, Whatsapp is how they talk.
What one should do about this? I mean, beside working on lowering that number. (Asking as a European who quite stubbornly refuses to install it - there are dozens of us. Dozens!) Edit: please don't participate in making WhatsApp even more inescapable as it is today.
Every business in Brazil has an whatsapp to talk to their clients. Sometimes this whatsapp goes into the phone or computer of a real human being. Other times, it's manned by a bot (usually a dumb choose-your-own-adventure bot - I don't see business using LLMs for this here)
Indeed I use food delivery apps (ifood here) only to check out the menu of delivery restaurants, then I search for them in Google so I can order directly from them through whatsapp. This won't work for some dark kitchens, but other than that it's pretty reliable and avoid the middleman