10 ms·
WhatsApp is broken, really broken
- aw3c2 14y agoSadly, normal free Jabber/XMPP does not seem to be a viable alternative. On Android, sure (though the clients are not too great at reconnecting/noticing-connection-loss/reporting-message-reception) but on iOS apparently you cannot run such things in the background. At least the situation was dire when I tried to convince some iOS friends to use XMPP instead of SMS last winter. http://monal.im/ http://monal.im/ looked most promising but turned out to crash or only work when active, I don't fully remember. Maybe it got better.
- morsch 14y agoYou could run the real XMPP client on a server and use the native push messaging system to wake up the mobile client. This would also enable receiving "offline" messages while the mobile device is not on a network or turned off. Of course, this would let the person operating the "real" XMPP client read your messages; but the person operating the XMPP server can do that already, so there isn't any real change -- either way you should be using OTR messaging at all times. In the peer to peer spirit of XMPP, such a project should make it really easy to run this virtual client yourself locally or on a cheap cloud server. Maybe something like that exists already? Anybody wanna build it?
- guruz 14y agoWe've been trying to build something supporting that, but so far with far less than full steam. Too busy with client projects right now :) http://woboq.im/ http://woboq.im/
- vvhn 14y agoimo.im on iOS works perfectly fine with google talk and i receive messages when it's not running as well.
- TazeTSchnitzel 14y agoimo.im is a web service, not a raw XMPP client.
- anonymoushn 14y agoWhile this is true, using imo.im is probably significantly easier than setting up your own XMPP client on your own box that will send push notifications to your phone and achieves the same thing.
- anurodhp 14y agoHi, I am the developer of monal. It is a real, direct xmpp client and remains open in the background as long as you have an internet connection. It even has preliminary support for Jingle voip.
- grk 14y agoSo, what's the best alternative?
- paulgb 14y agoKik uses XMPP over SSL and has user-defined passwords https://getsatisfaction.com/kik/topics/how_secure_is_kik https://getsatisfaction.com/kik/topics/how_secure_is_kik
- HarshaThota 14y agoGroupMe does the same, I believe. https://twitter.com/GroupMe/status/208200154484981761 https://twitter.com/GroupMe/status/208200154484981761
- spdy 14y agoNone with enough traction so i guess this has to go mainstream. Interesting though that i have not gotten any spam messages so far.
- rwmj 14y agoEmail?
- Splines 14y agoIt depends on what you want to do. If you want to make sure your little brother isn't spying on what you're saying, any of the IM platforms from established players is likely "good enough" (gtalk, skype, facebook chat, etc). If you're a dissident in the middle-east, your requirements may be difficult to meet.
- denzil_correa 14y agoViber [1] may be a good alternative. It s free on all ecosystems - iOS, Android, WP, Blackberry, Nokia and Bada. [1] http://www.viber.com/ http://www.viber.com/
- satjot 14y agoI sometimes use Gryphn to send super secure messages like giving a client my bank account #.
- gsibble 14y agoI've been seriously considering creating a highly secure text messaging replacement. I'm aware of TextSecure but find it lacking (and only available on Android). I'd love to hear if you guys think it would be a worthwhile project.
- niggler 14y agoWhat is the target market? I mentally treat all messages as insecure, and no self-proclaimed secure system would change my thoughts.
- ge0rg 14y agoYou can set up your own private XMPP server and use gibberbot, beem or yaxim on android (or any other XMPP client on the platform of your choice). This is the only way to ensure that your communication is really private.
- gsibble 14y agoThat's actually why I haven't built it yet. I think it should be done, but I'm not sure who would actually care enough to use it. What would change your thoughts regarding a secure messaging system? Open source?
- sachingulaya 14y agoIf it works on android/ios I'm a customer. I'm using textsecure right now.
- msh 14y agoSkype would be a decent bet.
- X-Istence 14y agoI wouldn't consider Skype secure when all traffic for Skype goes through private servers run by Microsoft and there is as far as I am aware no end to end encryption between end users. Also, Skype's protocol and entire stack is entirely opaque and thus hasn't been nearly as checked for security issues as something like XMPP with SSL for example.
- andrewljohnson 14y agoDid the author email the WhatsApp team to give them any chance to fix this before they splashed it across the internet for anyone to abuse? The article makes no mention of it, so I assume not. In my opinion, the obscurity peeled off by this expose did more to endanger WhatsApp users than the bad programming. So, I can only conclude this post's main goal is page views. OP could easily warn them, and at least wait until they didn't do anything before publishing.
- paulgb 14y agoThe disclosure was previously published on Sept 5 (OP links to it) http://samgranger.com/whatsapp-is-using-imei-numbers-as-passwords/ http://samgranger.com/whatsapp-is-using-imei-numbers-as-pass...
- dllthomas 14y agoIn this case, I think I disagree. A lot of this not just easy for an attacker to find - it is trivially easy for an attacker to find. Letting people know their communications are vulnerable is important, and it's not like they don't have plenty of alternatives.
- dromidas 14y agoJust because a skilled attacker can trivially find the information, doesn't mean that the 15 year old kid living next door to you can find it. Now they can. The problem doesn't stem from giving information to "l33t hax0rz" but rather providing the key information that can be abused by anyone with a computer and half a brain. They are the ones more likely to make use of it in a widespread and destructive manner. But with that said, most developers don't care if you tell them this stuff directly since it's simply information and not a proof of concept. Until someone starts using it and shows them that its actually a problem that is affecting their product they usually write it off as paranoia.
- dllthomas 14y agoMy point is that most of the threats exposed don't take elite hacker, or even "l33t hax0rz", skills to discover. A hugely greater percentage of people are going to hear about this and say, "oh, I should switch to something else" or "oh, I shouldn't say sensitive things" than are going to fail to hear about this and be snooped on by someone who did and wouldn't have figured it out anyway.
- ollysb 14y agoI'd have thought a large majority of what's app users use it for chatting. I can't imagine they're particularly fussed about people sniffing their plans for meeting up that night. There are varying requirements for security...
- zachalexander 14y agoSo just because 99 percent of SMSs don't contain sensitive information, it's OK to leave the remaining 1 percent insecure?
- jdost 14y agoIt isn't the information they can view, it is the things they can do impersonating you. Any application installed on your phone can probably access the two authenticating pieces of information. Then they can impersonate you in messages to, say, your parents and say something like "Hey mom, I need to order something, can you send me your credit card?" and then your mom, under the illusion that WhatsApp is secure, will send it right over.
- mikeash 14y agoI suggest you go find some nearby open wifi in use, spy on some people, then tell them what you've found and see how they react to it. Report back when you're done... If you can....
- ollysb 14y agoIf the table next door was having an obviously private discussion they'd probably be a bit put out if you started offering your opinion. People know their conversations often aren't secure, but then there are certain social expectations. Sometimes it's just expected that other people will politely ignore their conversation. If you told people that you had been spying on them I guarantee you that they would not blame their tech. They would place the blame squarely at your door for having listened in on something you shouldn't have.
- yen223 14y agoA large majority of whatsapp users use it as a straight-up replacement for normal SMS. It's easy to impersonate someone's account and pull off the whole "I am stuck please wire me money" scam.
- d0k4 14y agohttp://www.kakao.com/talk/en http://www.kakao.com/talk/en ^^
- zachalexander 14y agoOT, but I'm intrigued by their business model. I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that. Meanwhile, the iOS app is $0.99 straight up. Thoughts: (a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet you get more conversions in the long run than with a normal free/pro app business model. (b) "Free in one store, paid in the other" is an interesting idea. If you can build up a large userbase of free Android users, and it's an inherently social app, your free Android users will tell their friends on iOS devices to get the app so they can communicate. They probably don't even know it's not free. It's like unintentional affiliate marketing. (c) I realize (b) might not be an intentional choice by the developers, but a necessity due to the App Store perhaps not supporting pricing schemes like the one in (a).
- mahyarm 14y agoI think it comes down to it being harder to make money on the android store and ease of piracy vs ios store. The market share / profit tradeoff ratio on android makes it worth more to be free. On iOS they sometimes make the app free too.
- zachalexander 14y agoTell me more. I wasn't aware app piracy was a major problem in either store.
- executive 14y agoNot in store - Android allows app installs from outside of the store.
- spartango 14y agoApp piracy is actually a substantial issue on both stores: On Android, sideloading of apps from unauthorized sources (not the store), and frail DRM makes piracy really easy. The US government has been targeting these sources[1], but as you can imagine, there are many. Some have said that Android app piracy may be up to 60%[2], but I think there's some sample bias in these figures and suspect it's a fair bit lower. On iOS, piracy is a bit more difficult, requiring a jailbreak and then a hack that allows cracked apps. From there, cracked apps can be downloaded from various sources. There are fewer solutions to crack in-app purchases, but recently a few have come into the mainstream[3]. On the whole, Apple's DRM helps, but pirates have found ways around it. [1] http://www.theverge.com/2012/8/22/3259808/android-app-pirate-department-of-justice-seizure http://www.theverge.com/2012/8/22/3259808/android-app-pirate... [2] http://www.theverge.com/2012/8/7/3225154/dead-trigger-dev-interview-piracy-android-ios http://www.theverge.com/2012/8/7/3225154/dead-trigger-dev-in... [3] http://www.theverge.com/2012/7/13/3156875/ios-free-in-app-purchase-hack http://www.theverge.com/2012/7/13/3156875/ios-free-in-app-pu...
- morsch 14y agoNo mention of this on their blog (in fact, no new posts since July). And no quick patch that pops up a box asking the user to assign a password. Since it's tied to a phone number/SIM card anyway, you could easily offer a password retrieval option via SMS. I wonder what happens if a phone number (the login) is tied to a different IMEI (the password). This can happen when you transfer a phone number from one provider to another.
- truncate 14y ago> I wonder what happens if a phone number (the login) is tied to a different IMEI I think they send verification code to the phone via SMS or ask your permission to make a call and speak the verification code.
- hwatson 14y agoYep. You'll normally see this happen if you restore an iPhone backup onto another iPhone then try to launch WhatsApp. Login will fail and you'll be asked to type in the SMS received.
- ZoFreX 14y agoYes, it's insecure by the standards we would normally apply to software. But let's be honest - this is competing against SMS, not XMPP, Skype, et al. How hard do you think it is for someone to sniff an SMS?
- msh 14y agoCompared to sniffing data over public wifi, pretty hard.
- blakecaldwell 14y agoI'm no SMS engineer, but I'm pretty sure SMS is stuffed in one of the ping packets used to keep the phone connected to the cell towers.
- mseebach 14y agoIt's sent on the control channel, not the payload channel. But that's not the important bit - This is: to sniff wifi you need a computer with wifi and a freely available, easy to use program. To sniff GSM you need a rather elaborate setup. It's not that it's "hard" to sniff SMS in a crypto-sense, it's just that that bar is a lot higher that sniffing unencrypted wifi traffic.
- revelation 14y agoCompared to this? Ridiculously hard. A5/1, while severely compromised, still requires heavy IOPS and computing power to break quickly with rainbow tables (see Kraken). Even worse: this allows for trivial spoofing. You're far, far away from doing that with SMS.
- ZoFreX 14y agoActually, SMS spoofing is arguably easier than WhatsApp spoofing.
- mikeash 14y agoArmed with this blog post and a laptop, you could start spying on IM traffic in your local coffee shop in five minutes. I don't know where you'd even begin with spying on SMS, but I bet that in the least it requires substantially more specialized equipment.
- fruscando 14y agoWe should all start using our regular XMPP accounts now! Most of us already have one. If you have a Gmail, Fastmail, Lavabit, GMX, Ovi.com, Yandex email address, you are ready to go. All that's left to do: Install Xabber or IM+ on your smartphone! Btw, both support OTR end2end encryption! If you also want to instant message on your laptop: The latest Thunderbird comes with XMPP support! Or give Jitsi, which supports end2end encryption, or one of the many alternatives a try! Enjoy!
- alpeb 14y agoLike Oscar Wilde once said, everything popular is wrong. Quality is well down in the list of things that matter to have a successful product.
- lnanek2 14y agoThis app has ridiculously penetration, however. I've met people who use this and no other app not out of the box before. In foreign countries it is easier to get someone to WhatsApp me than it is to get them to text my strange US number. Sure they solved a pain that's very common, replacing expensive text messaging, but part of their success is how easy it is for users without annoying username/password hoops to step through. They should fix the security, although I don't do anything important over it anyway, but I can't say they went wrong by avoiding a classic username/password setup that might have been more secure from the start.
- rjzzleep 14y agoseriously though, why does it have to send the whole contact list EVERY time? you close whatsapp remove the contact list permission, open it again, surprise, it won't work. -_-
- UnoriginalGuy 14y agoI presume because the list of potential people who you could connect to might change. I guess they could re-scan it on a schedule but that wouldn't solve your issue and might annoy their user base who are using it because it "just works." Plus removing a permission isn't something any app supports that I am aware of. It isn't even something you're meant to be able to do on Android.
- rjzzleep 14y agopoint being, it's a stupid idea. every half decent programmer would just update the diff.
- UnoriginalGuy 14y agoNope, I wouldn't even consider that. Firstly because K.I.S.S. and secondly because you've exchanged a relatively small data "cost" with a much larger storage and processing "cost." You've had to have a database of everyone's contacts and then be comparing X with Y every few connections...
- FuzzyDunlop 14y ago> "On iOS devices the password is generated from the devices WLAN MAC address" On what planet is using this data a valid form of security? Anyone can get hold of a MAC address.
- norrs 14y agoAnyone know if deleting message history is enough to kill the history on their servers?
- willrax 14y agoOn their website it says that they don't store messages on the server. Once yet are delivered, they get removed.
- bvdbijl 14y agoI was working on a better whatsapp api than the mess that is whatsapi, do not have enough time though. It's based in wazapp which has an actual implementation of the binary packed xmpp transfer mechanism they use. Might upload it if someone's interested, it seems broken right now though
- HarshaThota 14y agoDo it. It may be possible for someone to create a third-party client for WhatsApp instead of relying on the official version.
- bvdbijl 14y agoLook up wazapp, it's a third party client for Nokie N9
- koski 14y agoI'm a "open source guy". Very picky to pay of Anything. I use the mentioned app with my Lady every day because it works so well on her iPhone too. The easy of sending photoes is just pure awesome. Never failed (during one year). It works so well I don't hesitate a second to pay a dollar of it when it asks for it. Ps. Drunk in a bar and a regular guy next me agrees who did not agree on punch of other stuff.
- koski 14y agoPps. yes. Ofcourse the dude next to me did not know about the possible problems the auther mentions. Which ofcourse is an issue. How to explain to a "regular dude" anyone can listen your phone call if they want to? In my world everyone "normal I know" loves the mentioned app. How do I explain them everyone can read their messages if they want to? They answer me, everyone can steal my "normal" mail too if "they want to". Ppps. I modified the typo i think i created after 8 pints.
- GauntletWizard 14y agoHow do apps like WhatsApp get popular? They offer inferior service in every way to builtins, and require that both parties have installed something. SMS is in every way better unless you don't have a texting plan, in that case, GTalk and iMessage are in every way better (And GTalk is even cross platform with several fairly simple XMPP clients on IOS). Who uses this shit? I encountered the same thing recently with Raidcall. It's a shitty voice service that's in every way inferior to Skype, but trying to position itself as a competitor to Teamspeak (Which itself has been eclipsed on features and price by Mumble). Yet, somehow people will argue with you about it and evangelize it, without any sort of benefit comparison.
- yen223 14y agoWhatsApp was there first. Network effects cemented their position. iMessage doesn't work for non-iOS phones. Annoyingly, GTalk doesn't have an official client on iOS. SMSes can get expensive.
- hboon 14y agoNo, there was an app Ping, which was around earlier than WhatsApp. It was ugly and didn't work well. WhatsApp is easy to set up, easy to use, and have relatively good functionality.
- Achshar 14y agoI am not a fan of whatsapp either but its popularity may have somethig to do with zero setup and no username and password to remember. A neat idea but this could have certainly been done better. The app may have some basic infrastructure problems but average person unfortunately does not care.
- deleted 14y ago[deleted]
- matthijs 14y agoYou account is your phone number which is a really smart thing I think. Therefore you do not have to add each of your contacts one by one. And when someone in your contact list installs WhatsApp they automatically show up in your WhatsApp contacts. It's the quickest direct replacement for SMS.
- imkarthikk 14y agoTIme to move towards Viber or Kik? Never knew that my number was getting transferred in PlainText.
- denzil_correa 14y agoJust received an update on the iOS app stating "Full encryption for messages over mobile and WiFI".
- antirez 14y agoIt's worse than that, in iOS devices the mac address is easy to predict. For instance my phone and my wife phone have the first four bytes the same. Example: F0:AB:C7:11:xx:yy So you can easily crack this by brute force without sniffing the device address at all.
- mmcnickle 14y agoThis is by design[1]. The first 3 bytes are the same for the same manufacturer. The last 3 bytes can be assigned as they wish. Apple probably assign the 4th byte as a product identifier, so would be consistent across iPhones. I wonder what the 4th byte is for other iOS devices, or if it's the same? [1]http://en.wikipedia.org/wiki/Organizationally_Unique_Identifier http://en.wikipedia.org/wiki/Organizationally_Unique_Identif...
- ot 14y agoThat's very unlikely: an address space of just 65K numbers would be left, which is orders of magnitude less than the number of iPhones produced. Considering that each phone has at least two MACs (wifi and bluetooth), even the 16 millions that would be given by using the full 3 bytes look scarce. I think that Apple has several OUIs. In fact, my iPhone's MAC doesn't have a single byte in common with the parent's.
- mmcnickle 14y agoYou're right, I didn't do the maths. This list[1] from 2010 shows that Apple has dozens of OUIs and I imagine the list is much, much longer now. [1]http://www.scribd.com/doc/42074577/Apple-OUI-List http://www.scribd.com/doc/42074577/Apple-OUI-List
- antirez 14y agoBut maybe given products use a small subset of their available addresses... Ok, there is a simple way, let's collectively compile a list of the HN users reading this thread having an iPhone. I'll start with: 4s - F0:CB:A1:xx:yy:zz (me) 4s - F0:CB:A1:xx:yy:zz (wife) 4s - F0:CB:A1:xx:yy:zz (friend) Please reply with your first three bytes.
- pheraph 14y agoDoes anybody know if the latest update changed anything on the security side?
- irfan 14y agoNew version of whatsapp for iOS is there.
- brokenlogins 14y agoWell, the name is stupid. Let's just start there.