4 ms·
This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store: Even with perfect e2e encryp
by kingnight 10y ago
This main flagrant or off-topic, but something that nags at me when thinking about truly secure messaging apps from the App Store:
Even with perfect e2e encryption protocol added, what's preventing WhatsApp developers (FB) from adding in a feature of the app:
if local.user is "TargetUser007" {
takeDeviceSnap();
sendDeviceSnapshotToFBOverSameEncryption();
}
Wouldn't this not be ever verifiable unless you ARE that specific user and it's too late?
- maxerickson 10y agoYou'd also have to make sure they were the only user that received that binary. Otherwise you'd have to hope that no one reverse engineered the binary and noticed the oddly specific comparison there.
- kingnight 10y agoAre reverse engineering techniques currently greater than known ability to obfuscate compiled iOS code?
- dean177 10y agoYes
- deleted 10y ago[deleted]
- MichaelGG 10y agoAnd it'd have to work for other platforms, too. Android is Java right? Which is even easier to RE.
- besselheim 10y agoAndroid apps can also contain native code. Indeed, WhatsApp includes such libraries, to help with Curve25519 encryption, video encoding, voice over IP, and other functionality.
- MichaelGG 10y agoBut it should be straightforward enough to see if text messages or UI elements (suppress key change notification) are being change depending on the output of those libraries.
- jrowley 10y agoYou might be able to disguise it as debugging/development code that was mistakenly left in there. And instead of a hardcoded list of targets it could pull down the values in a more creative way. But at the end of the day that probably wouldn't stop a talented reverse engineer from figuring out what was going on.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- azinman2 10y agoI'm sure some security researcher somewhere has run the app through a debugger/disassembler to verify exactly this.
- nawtacawp 10y agowho's doing that research?
- JamieF1 10y agoSomebody, there's always somebody else. Right?
- praneshp 10y agoSame as if the app was open source, no?
- tedunangst 10y agoThe millions of eyeballs who would otherwise be meticulously studying the source code.
- burntwater 10y agoI think you mean the dozens of eyeballs.
- lima 10y agoThe guy who found this "vulnerability", for example?
- phreack 10y agoHas it happened before in a similar case?
- teddyh 10y agoYes. Richard Stallman calls these “Universal Back Doors”: https://www.gnu.org/proprietary/proprietary-back-doors.en.html https://www.gnu.org/proprietary/proprietary-back-doors.en.ht...