3 ms·
I'll see if I can put it briefly. Maybe Chad will show up, he's much better at this than me. The problem basically comes down to the fact that Snapchat needs t
by antics 13y ago
I'll see if I can put it briefly. Maybe Chad will show up, he's much better at this than me.
The problem basically comes down to the fact that Snapchat needs to be able to discriminate between clients that are legit, and clients that are not legit. In other words, at some point Snapchat has to trust that it's distributing the server key (or cookie or whatever it uses in the future to allow clients to say "hey, it's me, you can trust me") to a legit client and NOT to a badguy client. This is not possible. Consider this issue taken to the extreme: even if you built Snapchat directly into the OS, and then signed, you could still root the phone and spoof the relevant parts of the OS to make it seem like you're a legit client when really you're not. Note that even pinning the cert doesn't work. You can still get around it by sniffing around the relevant buffers.
Spoofing the client basically guarantees that the API can be tricked into providing services that it was designed to avoid providing. For example, you can save all Snaps upon receipt. This is a trivial abuse. There are much graver implications that lead to much graver privacy concerns, but I hope you'll understand when I don't publicly announce them. :) Though perhaps Chris will tell you about them if you ask nicely.
- jrockway 13y agoEven simpler. Point a camera at your screen and snap a photo.
- antics 13y agoYeah, I mean, my major point is that Snapchat cannot deliver the services without trusting the client at some level, but that trust cannot be guaranteed.
- sbov 13y agoI guess I don't understand the revelation here. Isn't this true of any client? Video game companies have been fighting this battle for over a decade. Maybe the problem is that I don't use snapchat so I don't understand why it's such a problem for them.
- jrockway 13y agoI think the problem is that Snapchat is significantly less complex than a video game. With a video game, a cheater might benefit from something like removing the fog of war. So the server can just calculate that itself, and not tell you about things your client can't see. This makes cheating more difficult. (But of course, the game needs to be fast, so sometimes you have to give the client more information than it should display. In this space, room for undetectable exploits exist, and so there is a lot of complexity like spyware that reads /proc/mem to check if you're cheating. Or so they say, I've never read the source code...) I've never used Snapchat, but from what I understand Snapchat basically sends people pictures with a time limit for looking at them. At that point, the client has perfect information, and it's up to the client to stop displaying the picture and remove it from system RAM, swap, CPU cache, GPU memory, and so on with 100% reliability after that timer expires, or the whole app is pointless. Since that's impossible unless you control every aspect of the system and encase it in self-destructing epoxy, the system is mostly pointless. (In that sense, it's like DRM. If you can view it, you can copy it.) My understanding is that this is mostly used for sexting, which begs for me to ask this question: why are you sending naked pictures of yourself to someone you don't trust with naked pictures of yourself? Maybe work on those human relationships rather than outsourcing trust to some random company? Get off my lawn. Wheeze.
- aidanlister 13y agoSnapchat let's you sext people you trust right now, without having to worry about trusting them until the end of time.
- schrodinger 13y agoIt's not meant to be secure, it's meant to be delete by default. Even without an exploit you can take a screenshot of the picture you receive. However, defaults matter. Even if you're sending a private picture to someone you completely trust, if you do it by email or mms, they'll likely leave that picture lying around inadvertently for someone borrowing their phone to accidentally and embarrassingly stumble upon. With snapchat, the picture will be automatically deleted unless the recipient takes explicit measures to save it. THAT is the feature, not security.
- plausibility 13y agoWell find_friends exploit is one of them - my favorite was one found by clever/you [1] which leaked _any_ user's phone number because they weren't validating auth tokens correctly. That's long since been patched, and rightly so - definitely more dire a situation than war dialing. [1]: http://cleveryou.net/post/40537133131/oops-snapchat-flaw-leaks-personal-data http://cleveryou.net/post/40537133131/oops-snapchat-flaw-lea...
- pencilo 13y agoChad here. First off I'd like to give props to the gibsonsec.org guys, that is a really high quality protocol breakdown and the attack is neat. I see nothing wrong with going full disclosure after being ignored this long. The key point is to understand that I, as a protocol reverse engineer/attacker/professional bad dude have access to _everything_ the Snapchat app has. I own the network and the device the app is running on. I can look at every bit of Snapchat's memory space if I want. I can view all network traffic between the app and the servers. Either by MITMing the app or if the app has cert pinning nothing stops me from peaking at buffers(I did this with Square, it was actually not that painful). With just that you can see it is not possible to stop me from saving a Snap. I don't even need to make my own API calls, I can simply intercept the traffic of the actual Snapchat client and pull the image out of there. Even if you had a magical way to make sure only the actual app was requesting the Snap it wont help, it is the legit client. The more important take away though isn't that Snapchat is broken, because that's not super interesting. What you should take away from Snapchat is that you cannot stop people from calling your remote APIs that your apps are using. All it takes is someone sufficiently bored to go dig through pcaps and decompiled code to map out the API. So what do you do? Don't trust the damn client. Your service shouldn't be broken just because I am calling your API outside of the bounds of how your application will call them. This isn't a new idea, but it seems like a lot of people never learned this lesson.
- antics 13y agoAs I said before: Chad is way better at this than me! :)