12 ms·
WhatsApp Messaging Interoperability
- brink 3y agoWhy do all Meta websites intentionally break the back button? It makes me irrationally angry every time I visit facebook or instagram for how disrespectful it is, it's like it springs a trap where I'm not allowed to leave in the browser tab I arrived in.
- HumblyTossed 3y agoI find any site that does this to be user hostile and minimize my time spent there.
- layer8 3y ago> It makes me irrationally angry That’s pretty much the purpose of Facebook? ;)
- BeetleB 3y agoAt least on Firefox, the back button continues to work on this site.
- bombcar 3y agoDoes Microsoft's discussion forums work too? Because I wonder if Firefox has code to ignore backbitten pages.
- _ink_ 3y agoA random feature I didn't know for too long is long pressing the back button, which opens a menu containig the last few locations. Typically that helps with sits who hijack the back button. Works also on desktop.
- lxgr 3y agoWhat I'd love is a crowdsourced database for known back button hijackers in e.g. Firefox: If too many people report a site as being broken that way, the back button API could be made opt-in for everybody in the site settings.
- deleted 3y ago[deleted]
- pvg 3y agoPlease don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- TremendousJudge 3y agoChances they'll make this available in any place where it's not required by law? zero? Or have they mentioned it at some point?
- f1refly 3y agoI'm sure the free market will handle it ;)
- datanut 3y agoI wonder how desirable and feasible a [matrix] interop would be.
- Arathorn 3y agohttps://element.io/blog/the-eu-digital-markets-act-is-here/ https://element.io/blog/the-eu-digital-markets-act-is-here/ gives some answers :)
- input_sh 3y ago> Matthew Hodgson, the cofounder of Matrix, which is building an open source standard for encryption and operates the messaging app Element, confirms that his company has worked with WhatsApp on interoperability in an “experimental” way but that he cannot say any more due to signing a nondisclosure agreement. In a talk last weekend, Hodgson demonstrated “hypothetical” architectures for ways that Matrix could connect to the systems of two gatekeepers that don’t use the same encryption protocols. https://www.wired.com/story/whatsapp-interoperability-messaging/ https://www.wired.com/story/whatsapp-interoperability-messag... Matthew also did a Fosdem talk about it about a month ago: https://fosdem.org/2024/schedule/event/fosdem-2024-3345-opening-up-communication-silos-with-matrix-2-0-and-the-eu-digital-markets-act/ https://fosdem.org/2024/schedule/event/fosdem-2024-3345-open...
- Razengan 3y agoThere's something really appalling that I discovered lately and I can't believe there isn't enough uproar about it. Every attempt to talk about this gets ignored or buried (maybe by people who want this ""feature"" to be kept quiet) so I will take every opportunity on existing discussions about Facebook to bring it up: Facebook (and TikTok) store tracking data on iOS that the user CANNOT SEE and CANNOT DELETE: • It shows my previous account even after I delete the app. • Clearing Safari's cache does not work. • Disabling iCloud Drive and iCloud Keychain does not work. • Even completely signing out of iCloud does not work! • On a Mac in the Terminal, you can go to ~/Library/Mobile Documents and "ls -al" to see hidden folders like "iCloud~com~Facebook~Messenger" that you cannot otherwise view or delete. • Someone mentioned that even RESTORING an iCloud BACKUP will resurrect these "eternal cookies"!! ---- WHERE do they store this data? WHY can't the user see this data? WHY can't the user delete this data without going through the app? WHAT ELSE do apps store on our devices that we aren't even aware of? (This is just what we can see: The list of saved accounts for "quick login") HOW MANY other apps are secretly doing this? WHY does Apple, parading around as a pompous paragon of privacy, even allow this in the first place??
- HumblyTossed 3y agoThis is nuts. There should be a grand total of zero files on my personal computing device that I cannot remove (no matter the consequences).
- redeeman 3y agothen you have chosen the wrong platform. Just be grateful that the mighty apple even deems you worthy of having files
- Razengan 3y agoAndroid's security was way worse for years. How long did they even take before having granular permissions or a Privacy Report, if they do now at all?
- 3y ago
- irusensei 3y agoSignal or matrix interop would be great. I use WhatsApp as the logistical tool of choice to communicate with my coworkers when away from the company but I wish I could uninstall it. Not my tribe.
- ydnaclementine 3y agoNot sure if signal should interopt with data mining software. Keep that stuff isolated
- Krasnol 3y agoThey have usernames now. Using it with a dedicated username for whatsapp contacts could be a way.
- crtasm 3y agoSignal would have to change how they work for that, at present it shares your profile name after you've initiated a chat using the "username" - very confusing choice of wording.
- nottorp 3y agoWhat do you mean? You can set a nickname but they'll send your phone number to everyone you chat with? What's the point of nicknames then?
- nonillion 3y agoCurrently everyone who chats with me cannot see my phone number — even people who have my phone number saved in their phone (I was surprised as I thought it would still show this if they had it saved). There is a setting to entirely hide your phone number from everyone.
- madeofpalk 3y agohttps://signal.org/blog/phone-number-privacy-usernames/ https://signal.org/blog/phone-number-privacy-usernames/ > Usernames simply allow you to initiate a connection on Signal without sharing your phone number > Starting soon, your phone number will no longer be visible to people you chat with on Signal, unless they have it in their phone’s contacts. You will also be able to configure a new privacy setting to limit who can find you by your phone number on Signal. And, you’ll now be able to create an optional username that you can share with the people you want to connect with on Signal.
- Pannoniae 3y agoThe most hilarious part: "Partner represents and warrants that it shall not introduce into WhatsApp’s Systems or Infrastructure, the Sublicensed Encryption Software, or otherwise make accessible to WhatsApp any viruses or any software licensed under the General Public Licence or any similar licence (e.g. GNU Affero General Public License (AGPL), GNU General Public License (GPL), GNU Lesser General Public License (LGPL)) containing a "copyleft" requirement during performance of the Services"
- majke 3y agoCan a binary even be gpl?
- looofooo0 3y agoA binary can be under gpl sure. Type gcc in bash for example
- quadhome 3y ago“Any viruses” huh? The semantic gap between engineering and legal is real.
- diego_sandoval 3y agoViruses licensed under the MIT or BSD licenses are OK, though.
- organsnyder 3y agoThe lack of punctuation makes that a totally viable interpretation.
- NekkoDroid 3y agoWould be a shame if someone where to use the EUPL-1.2 just to fuck with them :)
- arp242 3y agoThat entire section 6 is weird; because 6.1 talks about gaining access to WhatsApp's "systems, networks, databases, computers, or other information systems owned", and then 6.2 is the bit you quoted that talks about copyleft. But ... it's not like WhatsApp is hiring me as a sysadmin for their servers, are they? Why would they give me access to their systems? They won't. This seems copy/paste legalese.
- ChrisArchitect 3y agoRelated: Making messaging interoperability with third parties safe for users in Europe https://engineering.fb.com/2024/03/06/security/whatsapp-messenger-messaging-interoperability-eu/ https://engineering.fb.com/2024/03/06/security/whatsapp-mess... (https://news.ycombinator.com/item?id=39614085 https://news.ycombinator.com/item?id=39614085)
- PandaBear123 3y ago> 7.5.1. Partner User Location. Any Partner Users that Partner Enlists or provides access to the Interoperable Messaging Services must be located and remain in the EEA. Without limiting Section 11 (Warranties), Partner represents and warrants that it will only (i) Enlist and (ii) enable access to the Interoperable Messaging Services by Partner Users that Partner independently validates are located in the European Economic Area, (i.e., a Partner User must be present within the European Economic Area within any consecutive sixty (60) calendar day period). If WhatsApp detects or otherwise has reasonable grounds to suspect a Partner User Enlisted to receive the Interoperable Messaging Services is not located in the European Economic Area or is no longer located in the EEA, WhatsApp reserves the right to immediately suspend such Partner User(s) from accessing the Interoperable Messaging Services, and if multiple violations are detected, Partner shall remedy Partner's location validation procedures to ensure compliance with the terms of this Agreement. Looks like interoperability is geo-fenced to Europe only.
- pmontra 3y agoSo what happens when a EU citizens go on vacation in the US? No more sharing messages between platforms until they go back home?
- kolmogorov 3y agothis reads as if they can for 60 consecutive days and on day 61 they'd be disconnected from interoperable messaging
- jraph 3y agoAnd that they are reluctantly complying in bad faith in the most hostile way they found. Is this going to fly? Where do these 60 days come from for instance? How is it any useful and who is going to want to implement such interoperability under such terms? This reads like a lot of words to say Fuck You Europe to me. Well, feelings are mutual, at least we are on the same page, them and me.
- concinds 3y ago
- 2Gkashmiri 3y agoIf I a EU citizen (wink wink) and want to communicate with my family member living in usa, will this let me or not let me?
- mdasen 3y agoIf you reside within the EEA, yes. However, given the "wink wink", the answer might be no. Meta is requiring that people reside within the EEA, not just are someone who is an EU citizen. They're requiring integrating services to give them the IP addresses of users and for the integrating service to confirm that you're within the EEA at least once in any 60 day period. If Meta thinks you're violating that as a user, they'll cut you off from the integration. If they think the integrating service is just violating it, they'll cut off the integrating service. It looks like Meta might be requiring as much identifying information about you as they can get so it will probably be relatively easy for Meta to figure out who is cheating. But if you're not trying to cheat, then yes you'd be able to message US WhatsApp users from a non-WhatsApp account in the EU.
- deleted 3y ago[deleted]
- advisedwang 3y agoWow this shows the DMA might really do some good. I'm impressed with EU regulation. Standardized chargers, ending roaming charges, GDPR, DMA. Definitly worth the side effects overall.
- mbertschler 3y agoSide effects like horrendous cookie banners everywhere. I really like the DMA too
- albert180 3y agoJust use an Add-On like Consent-O-Matic that declines/accept (based on your preferences) automatically for you. This way you also don't have to deal with the illegal shady dark patterns, many companies use
- advisedwang 3y agoAfter gdpr you can pretty consistently get companies to delete their data about you, and often get a data export. Those alone seem worth the consent pop ups.
- nottorp 3y agoIs there some loophole to just do custom WhatsApp clients without running your own network? One that never loads images would be lovely.
- pillusmany 3y agoYou literally have an option in WhatsApp do disable loading of audio/image/video.
- nottorp 3y agoOh yes, it's there, thanks. I wonder when they added it... Edit: Waaait a bit. I have it on iOS and I have it on some laptop where whatsapp desktop is an old version. I can't find it on my desktop where their desktop app is the latest and greatest... They probably "improved my whatsapp experience". Edit 2: besides, that just doesn't download the photos, I think? They still take half the screen that could be used for displaying more text...
- adhvaryu 3y agoThe option to disable auto download has been there since day 1.
- abdullahkhalids 3y ago> I wonder when they added it... At least 7-8 years. Probably from whenever it became possible to send media messages.
- nottorp 3y agoDoes not work on any version of whatsapp desktop, even the ones that have the option present. I still get all the crappy gifs in my chats.
- cprecioso 3y agoI'm using Beeper with its Matrix bridges just fine
- sebtron 3y agoSo any messaging app that wants to implement Whatsapp interoperability has to apply for it, pray to get their blessing and then sign an NDA. It is probably a positive change for end users, but far far away from the "open up your protocol" I was hoping for.
- shafyy 3y agoI was also hoping to just be able to build my own messaging app and use it to chat with people who have WhatsApp. I guess this is a first step, and better than nothing. Let's hope the DMA keeps evolving and also closing loop holes.
- idle_zealot 3y agoSo the same loophole Apple us using to render the app distribution part of the DMA moot. I look forward to seeing whether the EU considers this an acceptable interpretation.
- tensor 3y agoIf only the DMA also required that users that are not E2E encrypted be displayed as such. As a user, it's important to know when your chat is actually secure. Competition should not be at the expense of security.
- ajayyy 3y agoDMA requires that the interoperability be at the same level of encryption than normal chats. In whatsapp's case, that means all interoperability must be E2E
- arp242 3y agoGosh, all of this is so locked down. I've been waiting for this, and hoping I could "just" cook up some of my own code to use with WhatsApp, and/or integrate it with Pidgin or bridge to email or whatever. But the entire process is about as hostile as possible. For example "Partner shall have in place a dedicated security team" basically excludes most startups, or most smaller companies. It's not clear to me if this is really complying with the DMA – it's certainly not in the spirit of it, but less sure about the letter of it.
- Calvin02 3y agoYou seem to be confusing interoperability with WA’s desires to make sure that e2e encryption isn’t broken. What’s the point of thinking that WhatsApp is e2ee if anyone can write their own end point? my friends and I use WhatsApp because we know the messages are secure. Imagine if every other group message had the “green bubble” equivalent experience if someone was using a custom client.
- arp242 3y agoYou can do E2E encryption without all of these requirements. It's basically just TOFU some key when someone messages you. You can do 3rd-party implementation for other E2E messengers: Telegram, Signal (even though they don't like it), and of course XMPP (with extension). I need to read a bit more carefully through the (limited) technical documentation they have; but all of this seems highly excessive. I'm not a distrustful or cynical person by nature, but I find it hard to avoid the impression that they intentionally made it as hard as possible. I don't know what "the green bubble experience" means(?)
- lxgr 3y agoTo be fair, there is one aspect where the platform is trusted with services like Signal and WhatsApp: Identity to phone number binding. Many people don't actually ever verify their contacts' keys, but rather just rely on the platform provider to have done phone number verification correctly. In that sense, the security model is bit better than TOFU in practice. > I'm not a distrustful or cynical person by nature, but I find it hard to avoid the impression that they intentionally made it as hard as possible. There I fully agree. If anyone could find a way, it's the company running the largest messaging infrastructure in the world.
- Sytten 3y agoI am wondering if DMA forces Signal to also be less hostile to third party clients. It's not like they have been open to it up to now.
- 3np 3y agoSignal is not classified as a gate-keeper and therefore no.
- lannisterstark 3y agoSigh Just...use Matrix or XMPP or something ffs. The open protocols _already exist_.
- jeroenhd 3y agoThey don't provide the same level of privacy that the Signal protocol does, though. Plus, I'm not sure why WhatsApp would implement a whole second protocol in the first place, they're doing this out of legal obligation, of out of free will. I have some minor hope that WhatsApp will eventually switch to MLS+MIMI, as someone from Facebook does take part in the design process, but that could also be because of Facebook Messenger really.
- lannisterstark 3y ago>They don't provide the same level of privacy that the Signal protocol does, though Can you elaborate on this please?
- jeroenhd 3y agoSignal is built around metadata minimisation. Messages contain the absolute bare minimum information to get delivered. Because there is only one server everyone is connected to, there is almost no routing metadata attached to the encrypted binary blob. You get a key and ciphertext and that's about it. Not even Signal knows the sender metadata that's part of the message, by encrypting it. Basically all Signal knows about you is your phone number, IP address, and the last time you checked the server. It also doesn't store messages for longer than it absolutely needs to (which leads to the desktop client needing to connect to your phone or vice versa for multi device chats). XMPP needs to have a username and server name at the very least. This is because it needs to work in a federated context, and it doesn't use things like DHTs to decentralise messages in a way that allows hiding the routing data. The message body is encrypted, of course, and headers can be minimised, but there will always be unencrypted metadata. To quote the spec: > The OMEMO protocol does not protect against attackers who rely on metadata and traffic analysis. As for Matrix: the message body is usually mostly encrypted, but it's leaking a lot of metadata. Message IDs sometimes fine themselves outside of the encrypted envelope as well as timestamps and other information I don't think should need to be outside the encrypted envelope. Neither XMPP nor Matrix were designed with encryption as a first priority and that led to protocol design choices regarding metadata that cannot be altered without breaking most clients. They also tend to store messages grouped by chat group/conversation, though multi device support is technically optional for XMPP. From a server dump of either XMPP or Matrix, someone can deduce what users are chatting to what users when. In Matrix, you could deduce what messages are responses, updates, or deletions of what other messages, as well as reactions. For Signal, you'd need wiretaps on both sides to deduce that level of information. A protocol like Signal would be near impossible to federate. That said, if federation is your goal, MIMI+MLS seems to be the future. Matrix is moving towards MLS, Google's RCS encryption already uses MLS, and MIMI and MLS are often tied together in spec definitions. I believe the XMPP people are also working on (have finished work on?) embedding MLS in XMPP as an alternative to existing encryption methods.