Live data from Hacker News

Reverse Engineering WhatsApp Web

github.com

31–40 of 127 posts

Re: Reverse Engineering WhatsApp Web

#31
post #6

Earlier quoted context omitted.

Better? Yes. Easier? No. Besides, what's more open, as usable and secure?

[Riot]( https://riot.im ), native mobile clients for all platforms plus web client. It's self hostable or you can just login on their Matrix server. Ah, and no phone number needed.

I have high hopes for Riot, but last I checked there was no end to end encryption (or maybe it was a proposal). Is it farther along now?

Re: Reverse Engineering WhatsApp Web

#32
post #8

Wow that's impressive. But I would imagine WhatsApp/Facebook can just change their protocol at any time since it is easy to redeploy a new version of the WhatsApp Web client, thus breaking any 3p clients built on the original protocol. That would require yet another reverse engineering effort that can take a while. And by the time its reverse engineered again, they can yet again change the protocol. So the only relia…

I've wanted to create my own WhatsApp client that's and actual native desktop application. If this reverse-engineering process continues, it might now be possible. It's irritating when people say "Signal/WhatsApp has a desktop app!" because technically, they're right, but I have enough web browsers on my system already, thank you very much

Re: Reverse Engineering WhatsApp Web

#33
post #29

Earlier quoted context omitted.

Just use telegram. Open source, native clients for every platform. No phone number necessary.

"No phone number necessary" is only true if Google Voice is available in your country. A phone number is necessary to create a Telegram account.

> "No phone number necessary" is only true if Google Voice is available in your country. A phone number is necessary to create a Telegram account.

To add to that I can use Signal just fine with Google Voice. So if both Telegram and Signal require a Google voice number, might as well go with Signal.

Re: Reverse Engineering WhatsApp Web

#34
post #23

Earlier quoted context omitted.

Just use telegram. Open source, native clients for every platform. No phone number necessary.

I would like to use Signal, but I am forced to use Telegram for the same reason. (I have also to say that Telegram mac client is pretty awesome). It makes no sense to create a "secure" chat app, and then to force your users to use cellphones, which is the most unsafe technology I can imagine... Why this cellphone fetish?

Cellphones are far more safe than your computer - especially iPhones. All apps are run in a sandboxed environment and are vetted before being released. Further, the secure enclave is far better at protecting secrets than anything on a typical laptop/desktop machine.

Re: Reverse Engineering WhatsApp Web

#35

Earlier quoted context omitted.

Signal is open source both client and server. To my knowledge the same isn't true for WhatsApp.

It's open source, but Moxie has said he doesn't want federation. I don't think he'd be okay with someone writing a third-party client, for example.

He doesn't, but only because of the maintenance burden that would bring: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

I'm sure if a third-party client would contribute to support the maintenance (both financially and in terms of the time and effort investment) he might be open to that, but obviously that's not going to happen.

Re: Reverse Engineering WhatsApp Web

#36

Earlier quoted context omitted.

Signal is open source both client and server. To my knowledge the same isn't true for WhatsApp.

It's open source, but Moxie has said he doesn't want federation. I don't think he'd be okay with someone writing a third-party client, for example.

Federation is a completely different story from a third-party client.

Re: Reverse Engineering WhatsApp Web

#37

Earlier quoted context omitted.

[Riot]( https://riot.im ), native mobile clients for all platforms plus web client. It's self hostable or you can just login on their Matrix server. Ah, and no phone number needed.

I have high hopes for Riot, but last I checked there was no end to end encryption (or maybe it was a proposal). Is it farther along now?

e2e encryption landed a while back and works pretty well (although technically is still in beta). the UX has some warts which we're working on :)

Re: Reverse Engineering WhatsApp Web

#39

I'm very hopeful this reverse engineering effort will enable the creation of a tool to export my conversations (WhatsApp can do email export, which let's be real, doesn't cut it for most cases). A point to those that support migrating to alternatives such as Signal. Signal is good, but far from great for a single reason: you need a phone number. This is very bad in necsec and reliability terms, my case: Reliability:…

which platform? On iOS “export chat” exports a .zip file which you can send to any app that accepts it, or to a comp using airdrop. Works pretty well for exporting all photos and videos from a chat.

Re: Reverse Engineering WhatsApp Web

#40
post #10
post #7

Earlier quoted context omitted.

Signal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.

Out of curiosity: I’ve noticed a long-term sceptical attitude to telegram in HN audience and have seen multiple arguments against it. Something like that their crypto can’t be trusted, that it’s not time-proven. Don’t you know any good source with some sort of domain expert explanation, why shouldn’t it be used or trusted? No intention to start any flame against Signal, only curiosity regarding telegram flaws. Person…

It's Russian. You know, like: hand over the encryption keys or you, or someone you love will disappear.
Post reply on HN