5 ms·
I'm one of the authors of Snapchat FS [1]. In order to build this, my coauthor Chad and I had to reverse engineer their API, which included decompiling the Andr
by antics 13y ago
I'm one of the authors of Snapchat FS [1]. In order to build this, my coauthor Chad and I had to reverse engineer their API, which included decompiling the Android APK and snooping around for the call site of util encrypt.
While a lot of the security problems they have could indeed be fixed, I think it's worth noting a couple things.
* The Snapchat API is fundamentally insecurable as it exists today. The problem is not that Snapchat could have secured their API against unauthorized access and simply failed to do so, it's that their API cannot possibly be secured, AND they happened to make some bad mistakes along the way. Even a serious security team would have been unable to lock everything down. They might have locked some of these issues down, but they would not have gotten all of them.
* So, while I sympathize with the feeling that Snapchat is anti-OSS and anti-hacker, realistically, I also sympathize with Snapchat's position. They don't have that many options. What are they going to do? Their public position -- i.e., that you should not break their TOS -- does not strike me as especially unreasonable considering that investing millions into security will still not give them a bulletproof solution.
* Also worth noting is that Snapchat does not unilaterally ignore security inquiries, or at least, they did not ignore me. I emailed them personally and the response I got (from a high-level employee) was warm and encouraging. I did not get the cold shoulder. In fact, I found our interactions quite pleasant, and it made me want to help them lock things down.
Ultimately I think it's easy to write off the team as just a bunch of incompetent fools, but let's be realistic here: it's easier to break things than make them provably unbreakable.
Again, yes they've made some bad mistakes, but posturing about breaking a system that cannot be secured is perhaps not the best use of Gibson's obvious talent. The same also goes for the many other security researchers who've audited the API.
[1] https://github.com/hausdorff/snapchat-fs https://github.com/hausdorff/snapchat-fs
- plausibility 13y agoYou got a reply from Snapchat? Are you some form of warlock, because I've yet to see them reply to many people.
- antics 13y agoHey Chris, how's it going? Yeah, I just dropped Bobby a note. I was like: "here's what I did", and he was like, that's pretty cool, how did you get in. And then I described the exploit. And then we had a short conversation about things they might have fixed that are easy to fix.
- andrewfong 13y agoCan you elaborate on why the API is "fundamentally insecurable as it exists today"?
- antics 13y agoI'll see if I can put it briefly. Maybe Chad will show up, he's much better at this than me. The problem basically comes down to the fact that Snapchat needs to be able to discriminate between clients that are legit, and clients that are not legit. In other words, at some point Snapchat has to trust that it's distributing the server key (or cookie or whatever it uses in the future to allow clients to say "hey, it's me, you can trust me") to a legit client and NOT to a badguy client. This is not possible. Consider this issue taken to the extreme: even if you built Snapchat directly into the OS, and then signed, you could still root the phone and spoof the relevant parts of the OS to make it seem like you're a legit client when really you're not. Note that even pinning the cert doesn't work. You can still get around it by sniffing around the relevant buffers. Spoofing the client basically guarantees that the API can be tricked into providing services that it was designed to avoid providing. For example, you can save all Snaps upon receipt. This is a trivial abuse. There are much graver implications that lead to much graver privacy concerns, but I hope you'll understand when I don't publicly announce them. :) Though perhaps Chris will tell you about them if you ask nicely.
- jrockway 13y agoEven simpler. Point a camera at your screen and snap a photo.
- antics 13y agoYeah, I mean, my major point is that Snapchat cannot deliver the services without trusting the client at some level, but that trust cannot be guaranteed.
- sbov 13y agoI guess I don't understand the revelation here. Isn't this true of any client? Video game companies have been fighting this battle for over a decade. Maybe the problem is that I don't use snapchat so I don't understand why it's such a problem for them.
- gibsonsecurity 13y agoHi, I'm one of the authors of the above release [1], and the exploit we primarily talked about (find_friends) isn't really an issue with the protocol as a whole. We understand the need to support legacy clients, but Snapchat could easily limit the damage this exploit could do. It wouldn't be that hard for them to make the best of what they have, by auditing all the code that typically has these exploits, and from that point onwards, also auditing riskier areas in the code base periodically. But yeah, we have seen an improvement in some of the Snapchat client code, which indicates there are probably some bright new developers that have just joined the team. We just find it pretty bad that in this time, we haven't seen attempts (on our end, server side may be different) to secure the protocol. Also regarding communication, we haven't heard a word from Snapchat in 4 months, neither has the reporter of this story, Violet Blue. If any of the guys from Snapchat are reading this (or you can pass on a message), tell them they're free to message us at security@gibsonsec.org. We're pretty easy to contact. [1]: http://gibsonsec.org/snapchat/fulldisclosure/ http://gibsonsec.org/snapchat/fulldisclosure/ * Just saw your edit, the purpose of this release wasn't to tell everyone we're the nth person to reverse engineer Snapchats protocol, but rather to bring attention to the particular vulnerabilities. I can speak for the rest of our team, and we're pretty sick of Snapchats protocol, and this will most likely be our last release regarding it. (Also I noticed newlines broke, kinda fixed that)
- antics 13y agoYeah, I agree with pretty much everything you said. I too think they could do a lot of things better. Yes, they've been really really slow to fix known issues. I did not mean to denigrate your work, which seems solid. :) I'm just saying, 9 months down the road, if they had the optimal version of their security protocol, someone could still break in and write a post that "audits" it, just like we get every couple of months on the HN frontpage. Everyone would laugh, again. Some people would know that it's as good as it gets, but most people would just be in it for the circle jerk. There's no win for them here. That's all I'm saying. * Also, seeing your edit responding to my edit, sorry, I sometimes post before I work everything out perfectly. This isn't really an indictment of you guys specifically. I think your work is great.
- 13y ago
- X4 13y agoTeenagers and Kids use Snapchat mostly to share pictures, or did the target user base change, since I last heard about Snapchat? I recognize that this is a sensible topic, so it's really up on Snapchat to really do something now, for PR reasons, or to protect their users from potential damage.