13 ms·
Reverse Engineering WhatsApp Web
- anonu 8y agoImpressive work. Obviously, WhatsApp/Facebook would want to avoid a bunch of third party apps connecting to their service. How long until they make changes to make this more difficult/impossible?
- throwafk81 8y agoLet's hope it does not take them much, because I don't like spam.
- lima 8y agoThere are much easier methods to spam, and they're very good at dealing with them. This is only useful for real users who want to write custom applications that connect to their phones.
- Thaxll 8y agoIf you have a web API it's impossible to secure it, especially when you have many platforms that access it ( web / mobile ect ... )
- detaro 8y agoYou can change it often enough to be really annoying though. And Whatsapp bans users of third-party clients it can detect. At least the users I know stopped trying these things after a while.
- cookiecaper 8y agoThey "secure" it through legal force. Many startups are shut down by legal threats based on the CFAA, which effectively makes it illegal to talk to a server after you've been informed that you aren't allowed to do so (ordinarily, this information is conveyed through the Terms of Service -- a C&D is typical but not strictly required).
- ktosobcy 8y agoWouldn't it be better to simply start convincing your friends to use something more open, where you have choice of the client? It feels like solving the problem from the wrong angle…
- StavrosK 8y agoBetter? Yes. Easier? No. Besides, what's more open, as usable and secure?
- aylons 8y agoSignal. It is at least as secure as Whats App by design, has pratically the same interface and also a Chrome-based desktop app that works untethered from the phone app.
- StavrosK 8y agoIt's also exactly as open as WhatsApp, but not as usable.
- blueplanet200 8y agoSignal is open source both client and server. To my knowledge the same isn't true for WhatsApp.
- StavrosK 8y agoIt's open source, but Moxie has said he doesn't want federation. I don't think he'd be okay with someone writing a third-party client, for example.
- Vinnl 8y agoHe doesn't, but only because of the maintenance burden that would bring: https://github.com/LibreSignal/LibreSignal/issues/37#issuecomment-217231557 https://github.com/LibreSignal/LibreSignal/issues/37#issueco... I'm sure if a third-party client would contribute to support the maintenance (both financially and in terms of the time and effort investment) he might be open to that, but obviously that's not going to happen.
- salqadri 8y agoWow that's impressive. But I would imagine WhatsApp/Facebook can just change their protocol at any time since it is easy to redeploy a new version of the WhatsApp Web client, thus breaking any 3p clients built on the original protocol. That would require yet another reverse engineering effort that can take a while. And by the time its reverse engineered again, they can yet again change the protocol. So the only reliable way to create 3p clients would be if WhatsApp itself publicly publishes its protocol.
- scardine 8y agoThey have a closed beta program for an "Enterprise" version that is supposed to have an API. Seems like a good way to monetize.
- salqadri 8y agoOn really? In that case they definitely would not want to allow this project to cannibalize their revenue. On the other hand, it makes it harder for them to change their APIs then as it impacts clients not directly under their control.
- hazelnut 8y agothey still have to support older clients. so it is not that easy to just change the protocol.
- gustavmarwin 8y agoI'm very hopeful this reverse engineering effort will enable the creation of a tool to export my conversations (WhatsApp can do email export, which let's be real, doesn't cut it for most cases). A point to those that support migrating to alternatives such as Signal. Signal is good, but far from great for a single reason: you need a phone number. This is very bad in necsec and reliability terms, my case: Reliability: like more and more people, I travel all the time between countries and live out of Airbnbs. Hence my pre-paid phone numbers changes very regularly. If I lose my phone, I lose the phone number, I also lose my Whatsapp/Signal key associated with my phone number. Netsec: A phone number is associated with your physical identity, you might not care, but more and more people do care about this stuff. Yes there are ways around that, but nothing straightforward and actually practical. I'm patiently, but eagerly, looking forward to status.im .
- dingo_bat 8y agoJust use telegram. Open source, native clients for every platform. No phone number necessary.
- kome 8y agoI would like to use Signal, but I am forced to use Telegram for the same reason. (I have also to say that Telegram mac client is pretty awesome). It makes no sense to create a "secure" chat app, and then to force your users to use cellphones, which is the most unsafe technology I can imagine... Why this cellphone fetish?
- Turm 8y agoNoob question: Is traffic going through the websocket-servers properly end-to-end encrypted? That's what always held me back about using Whatsapp Web
- sigalor 8y agoHi, that's definitely not a noob question. I'm already having plans on investigating this, but this topic is even more difficult than WhatsApp Web itself (see https://github.com/sigalor/whatsapp-web-reveng/issues/10#issuecomment-377193932 https://github.com/sigalor/whatsapp-web-reveng/issues/10#iss... ). Thus, at this time, I am not able to give you a definite answer, though, to put it informally, "it looks good" (at least on the surface).
- andjd 8y agoI'm missing why this needs both a python and a node backend.
- letslightafire 8y agoI'm wondering how they actually reverse engineered WhatsApp in the first place. Is there a specific type of software that does this or was it just built from scratch using already available information?
- sigalor 8y agoHi, I'm sigalor, the original creator of the project. The reverse engineering was almost entirely done using the Chrome debugging tools. That is, pretty-printing the JS source files, setting breakpoints and stepping through the code for hours. When I started, all of this was incredibly difficult, but the longer you do it, the more you get used to it. Additionally, the debugging tools also provide you with looking at what is sent through websockets, which makes it rather easy to see which JSON data is sent (e.g. for login).
- letslightafire 8y agoThat must've taken forever. Do you have any plans to reverse engineer other apps? I know people like you are in short supply and high demand.
- sigalor 8y agoIt certainly did, but after all it was just a fun spare time project. I guess there would be a lot of interesting software to reverse engineer; I am always open to suggestions that are able to extend my knowledge. And well, if you mean it in context of a job... I don't have any experience regarding the job market yet, but that also sounds quite striking :)
- letslightafire 8y agoI don't know much about the job market, I was talking about the internet in general. Too many applications are locked black boxes and reverse engineering them basically keeps them alive after their demise. However, not a lot of people actually put in the effort to reverse engineer this stuff, so keep up the good work for this stuff!
- alpb 8y agoFWIW Repos like these that reverse engineer a proprietary API that post stuff on GitHub are usually taken down with a DMCA enforcement. The same thing happened multiple times when folks reverse engineered and documented the Snapchat API. https://news.ycombinator.com/item?id=6083812 https://news.ycombinator.com/item?id=6083812
- gsich 8y agoyowsup has been online for years.
- ape4 8y agoA pidgin plugin would be nice. Oh there seems to be one already - https://github.com/davidgfnet/whatsapp-purple/ https://github.com/davidgfnet/whatsapp-purple/
- severine 8y agoThere's also a Python library: https://github.com/tgalal/yowsup https://github.com/tgalal/yowsup
- mikkelam 8y agoDon't even bother with yowsup, you will be banned after wasting a lot of time setting it up
- rhamzeh 8y agoYeah, but it hasn't been maintained in a long while. Unless someone steps up to maintain it, not sure it'll be usable for long.
- deleted 8y ago[deleted]
- 0x0 8y agoCurious to know why they chose to require python in addition to node, wouldn't node with npmjs/yarn be sufficient and require less setup? Does python/pip provide any benefits here?
- sigalor 8y agoHi, I'm sigalor, the original creator of the project. Actually, now I also regret using Python in addition to NodeJS. When I started all of this back in November, I originally chose Python, because it's, well, "quick and dirty". Especially trimming arrays and working with byte strings requires a lot more code in JS than it does in Python. I even wrote a reimplementation of the decryption routines in JavaScript, but it's not working entirely (the HMAC authentication of received messages fails, though login works).
- deleted 8y ago[deleted]
- StavrosK 8y agoFunny, I had the exact opposite question.
- firefoxd 8y agoI see a lot of "just use X instead." Unfortunately, unlike the old chat protocols, switching to any other platform means convincing your contacts to use a new platform. They like you and all, but that means they also have to use a special app just to talk with you now.
- spronkey 8y agoIt astounds me that something as simple as talking to people is in some ways objectively more difficult now than it was in 1990. What the hell are we doing?
- mratzloff 8y agoMany of the vendors we partner with (tourism industry) live in countries where the main communication channel is WhatsApp. There's a lot of communication we want to automate in the near future—eagerly looking forward to seeing this progress!
- mikkelam 8y agoWere you inspired by this repository https://github.com/mukulhase/WebWhatsAPI https://github.com/mukulhase/WebWhatsAPI? Do you need a phone running to use this project?
- Jaruzel 8y agoFrom the GitHub readme: > An UI that is not that technical, but rather starts to emulate the actual WhatsApp Web UI. No, no, no. This trend of 'Phone UI' chat interfaces on desktop/laptop screens needs to stop. If you are going to all this effort to reverse engineer the protocol, at least make your front end customisable or at the very least IRCish in style.
- pankajdoharey 8y agoWhy did they not write the backend server for Whatsapp web in Erlang, which the original Whatsapp was mostly written in?
- sigalor 8y agoWell, I don't know Erlang (yet) and AFAIK, Erlang is rather focused on fail tolerance, high availability etc., which wasn't really a concern when I started the project. Python and NodeJS are quite good for quickly trying out ideas though.
- ampersand3 8y agoHave I missed something or is the only thing protecting the encryption scheme from impersonation of the phone the fact that the web-component's public key is (hopefully) never send to the WhatsApp servers? The public key of the phone (the first 32 bytes of the variable "secret") is never authenticated by the web-component. Assuming they have the public key of the web-component, the WA Servers could hijack the whole scheme by sending their own public key in the "secret" instead of the phones. MITM doesn't seems possible though as the phone verifies the web-components public key by QR code. I am no expert so, as I said, maybe I missed something, but relying on keeping a public key secret for security seems icky to me. Or maybe it's stupid to think about that too much, considering that both the phone-application and the servers including the Web API are closed-source anyway and will thus always remain icky security-wise.
- quantized1 8y agoLet's bring some more misery to Zuckerberg
- Laura_McPherson 8y agoIf you think your spouse may be cheating, you can contact phonespyapps01@gmail.com He’s a real hacker and was very reliable in helping me spy on my cheating husband’s cell phone remotely.
- Laura_McPherson 8y agoIf you think your spouse may be cheating, you can contact phonespyapps01[at]gmail[.]com He’s a real hacker and was very reliable in helping me spy on my cheating husband’s cell phone remotely.