17 ms·
Any Android app can read your WhatsApp database
- deleted 13y ago[deleted]
- izacus 13y agoNo it cannot. Internal storage is protected and cannot be access (unless the device is rooted and has root privileges).
- kzahel 13y agoI thought the way android apps can lock down information away from other apps is they are able to set permission bits to be for their own unix "user" (e.g. each app gets their own userid). It's conceivable that WhatsApp simply set the permissions to be too open.
- izacus 13y agoEm, no - that can only be done in internal store "data" directories which are usually formatted with UNIX filesystems and are by default secure (and cannot be accessed by other apps at all). WhatsApp is storing to external (on most devices FAT) storage (which was SD card on older devices, it's usually a separate directory/partition on newer ones) which does not have any ACL-like system due to FAT backwards compatibility.
- Pxtl 13y agoHonestly, the more I tinker with Android, the more I'm terribly disappointed in Google. I mean, around Android 2 we were all excited by the potential of a first-class big-money supported open-source OS to really shake up the industry. It had so much potential. Now? Well, it still has a lot of potential. Even Google seems kind of embarrassed by it, compared to the Chrome brand.
- css771 13y agoI've never seen Google put out that vibe. If anything they're proud of it. I'm not sure what you mean. Can you elaborate?
- Pxtl 13y agoI just mean how they use the "Chrome" branding on everything, even Android-based devices like the Chromecast.
- yeukhon 13y agoIt does seem bizarre they don't make any ACL on external storage. I am sure this is not a strange isolated report. This problem must have been known for years both externally and internally. On the side note, from old news I remember Google is indeed pushing forward with Chrome-brand, specifically Chrome OS.
- lmz 13y agoBecause people want to take their SD card, plug it in somewhere else, and have access to their photos / videos / songs. This necessitates using FAT. That is the case for most removable media.
- izacus 13y agoStoring critical data to external storage (which is clearly explained as unsecure in http://developer.android.com/guide/topics/data/data-storage.html#filesExternal http://developer.android.com/guide/topics/data/data-storage....) is a huge security hole. This kind of basic oversight makes me wonder about base competence of WhatsApp developers - anyone with basic understanding of the OS would get that anyone can read external storage.
- DCKing 13y agoYou are absolutely right. Still, I think Google is taking the wrong approach: the insecure /sdcard partition is the place where most of the storage is in nearly all Android phones. If your app needs to store larger amounts of data, that is the place to do it. Now, there are methods to use that storage a lot more securely than this, but the way Android works really leaves developers no other option than storing this stuff on the SD card. Google should lock down access to the SD card even more, but they'll probably cause an uproar and break many apps.
- izacus 13y agoYeah I agree - increasing the size of internal storage was a blessing for my/our apps in terms of security (no more storing of secure data on shared storage due to lack of space). Google should probabl MTP from the start and just formatted SD cards with one of the ACL supporting filesystems to get security right. But as the saying goes... it's easy to be a general after battle :)
- deleted 13y ago[deleted]
- matt_heimer 13y agoGoogle did, almost everybody on HN whined like a baby. https://news.ycombinator.com/item?id=7255579 https://news.ycombinator.com/item?id=7255579
- deleted 13y ago[deleted]
- 13y ago
- anoncow 13y agoDoes this happen on Windows Phone devices as well? While WP allows reading and writing to the SD card, it provides isolated storage for apps(which is a source of much pain). While I am not sure about how android handles storage for apps, there should be a middle ground where users can explicitly permit apps to read protected storage data of other apps. WP disallows storage data sharing between apps leading to limited functionality.(this is not related to the article, just a wp rant)
- adwilson 13y ago>Does this happen Windows Phone devices as well? If they put the database in their isolated storage then no. Apps are sandboxed to their own isolated storage folder and cannot get access to the other apps folder (the source of your pain) Edit: Spelling is hard
- matt_heimer 13y agoGoogle switched to the isolated storage model (on the sd card) for KitKat - http://source.android.com/devices/tech/storage/ http://source.android.com/devices/tech/storage/. Google has content providers so if an app wants to share data it can do so https://developer.android.com/guide/topics/providers/content-provider-basics.html https://developer.android.com/guide/topics/providers/content.... If you really want to do something unsafe like allow direct file access to any folder then that is a reason to root your Android phone. Then using an app like SuperSU your can grant root permission to an application.
- deleted 13y ago[deleted]
- kllrnohj 13y agoHoly shit, the SAME AES key is used for everyone? Good god WhatsApp, what the fuck are you doing?
- sentenza 13y agoWhat's troubling is, that their security track record has been abysmal from the start. In that regard, the acquisition sends entirely the wrong message.
- stingraycharles 13y agoWhat message does it send, other than valuation not being based on the reputation of technical superiority?
- eropple 13y agoIt sends a message that caring about your users' trust, that doing what's right for them, is for suckers. This is not a test of "technical superiority". This is working against your users' best interests. One mistake is understandable, and sometimes forgivable, but you don't bilge it twice so cavalierly if you rank on the give-a-damn scale. (I say "cavalierly" because, as I noted elsewhere in this thread, I can't shake the feeling that this is the result of a design decision, not a technical failure.)
- nathancahill 13y agoSure, the message was sent. But does it have a read receipt?
- roc 13y agoThe market's been sending that same message for years. Security is a cost center and potential source of user-friction. User Data Integrity is a "nice to have". Privacy is considered only from the angle of "what can other users see through normal operation". And that market is driven by the consumers themselves.
- higherpurpose 13y ago
- nchlswu 13y agoI thought WhatsApp had a history of horrendous security?
- LaSombra 13y agoI am flabbergasted they still didn't improve it properly... Let's hope Facebook helps their development team.
- balladeer 13y agoAs long as Facebook gets to read all those billions of "personal" communications - messages, videos, audio, images - they are fine with anything.
- pritambaral 13y agoOT, but AES write(decrypt(open())) in python as done on the post seems to be padding the decrypted data with extra bits to match up in size with the source. OpenSSL's aes-192-ebc gives me a slightly shorter, but well-formed db.
- pinaceae 13y ago19bn $. No way anyone else at FB could have built this app and given it away for free for years for that price. No way. Totally worth it. 19bn $. Sequoia's deck on the amazing sclaing of 32 devs supporting that many users? well, guess what, they did it through taking shortcuts. Who would have guessed. Totally flabbergasted.
- acchow 13y agoIt's also a highly-simplified backend. No multisession (synchronization is hard), no back-end message history searching (search and graphs are hard). They took a lot of shortcuts, which turned out really well for them. Simplification made for a very fast client and a low-latency, low-bandwidth protocol.
- sentenza 13y agoBeing slim to deliver only essential functionality is one thing, but playing fast and loose with user data is not a shortcut that should be rewarded so lavishly.
- 1337biz 13y agoSo they have no ability to sniff through my messages on the server? That's not a bug that's a feature for me!
- yid 13y agoNot exposing a client-facing search service has no bearing on their ability to search through your messages on the server; they most assuredly can search through your messages.
- Nux 13y agoWhatsapp's security is "legendary": http://tinyurl.com/nenaht8 http://tinyurl.com/nenaht8
- devcpp 13y agoNineteen billion dollars for that. What an amazing piece of software. Worth every penny. Each of the 1,900,000,000,000 of them.
- frik 13y agoAs you pointed to h-online.com, sadly "heise.de" english language branch is dead: http://www.h-online.com/news/item/The-H-is-closing-down-1920027.html http://www.h-online.com/news/item/The-H-is-closing-down-1920...
- biot 13y agoPlease don't post mystery URLs. The above goes to this search: https://www.google.com/search?q=whatsapp+site:h-online.com https://www.google.com/search?q=whatsapp+site:h-online.com
- mncolinlee 13y agoAs an Android developer, the real hole here is being able to read the encryption key. Jelly Bean 4.3 adds the potential for "secure key storage" which only works if the user is not smart or persistent enough to break the obfuscation through using the application itself with a debugger and a rooted phone. There is no fully safe method to store keys on a device if the attacker can gain access to the same device.
- giovannibajo1 13y agoDepends on the definition of "fully safe", or maybe "device". Extracting keychain secrets from a iOS device requires brute-forcing the lock screen password. Bruteforcing the 4-pin digit is easy "math-wise", but complicated in practice because you can't really access the data on the flash (not even dumping it, as it's fully encrypted with a hardware key), and the device will not pair to a new PC/Mac without first unlocking; so you would also need physical access to a paired PC/Mac. For the newest devices, fingerprints can't really be bruteforced (not because of complexity, but the because the hardware locks down burning its secret after a few attempts) and Apple advises using a complex password as a fallback for the fingerprint; basically the password is the real secret for encryption, while the fingerprint hw just holds a temporary unlock secret which selfdestroys if bruteforced; this is why the user is always required to enter the password after a reboot. Of course you might still have a 0-day root exploit to use if you're NSA (or somebody with $300K to invest), and that's where I concede the "not fully safe".
- jug6ernaut 13y agoSure. Why not then store on there servers, and have the phones only keep an in memory copy?
- gress 13y agoOne of the great advantages of android is that it permits developers to do things like this. Let's not get upset about it when mistakes happen. Users can always choose a different app if they dislike the behavior.
- danielweber 13y agoThis is actually good news . . .?
- gress 13y agoSure - consumers get to decide what tradeoffs they want, and the media assists by exposing information that might not be otherwise available, as is happening here.
- deleted 13y ago[deleted]
- lbebber 13y agoOf course, it's not so simple - for messaging, you have to use apps that other people use.
- happyscrappy 13y agoThe NSA agrees.
- baby 13y ago> if the user allows it to access the SD card. And since majority of the people allows everything on their Android device 1. So basically, if you're installing an app AND you're allowing the app to access all of your phone (and its dirty secrets) 2. I don't see why whatsapp would encrypt the chats (I might be very wrong on this one), isn't it better if we can access them offline through a computer if the phone crashes? 3. Bigger picture: at first, dividing permissions and asking for the user to accept them was a good idea, but now we tend to accept anything because in the end, we want to use the app. Same problem with facebook login, google login, where we tend to accept whatever info websites request just to get to the app.
- giovannibajo1 13y agoThere are endless good reasons for an app to request access to the SD card, so I would say it's still very reasonable to trick anybody into accepting it. The idea of handling the SD card has a global shared filesystem that totally bypasses the application sandbox is a security disaster from the get go. Fortunately, SD cards are on the way out, and Google doesn't even bother to fix it at the system level since they're dropping it anyway at some point.
- userbinator 13y ago> Fortunately, SD cards are on the way out, I don't know about you, but I'd rather not sacrifice my freedom to manage storage for a little temporary security...
- deleted 13y ago[deleted]
- delecti 13y agoUnless I'm mistaken, any application can read the device's SMS database if given the appropriate permission (and few users are very discerning with regards to permissions). To an end-user, WhatsApp is essentially an SMS application, except it doesn't use SMSs. Given that, this doesn't seem like the end of the world.
- sp332 13y agoWhatsApp claims to keep your texts secret, and this is a big selling point. They make privacy claims that go beyond normal SMS messages, and that's why this is a big deal.
- weixiyen 13y agoI've been using WhatsApp for years and seen many selling points, but security has never been one. A link would help because I've never gotten the impression that they were trying to sell security.
- bennyg 13y agohttp://www.whatsapp.com/faq/en/general/21864047 http://www.whatsapp.com/faq/en/general/21864047 - from their FAQ
- aryastark 13y agohuh? Stop making shit up. None of what you said is true. They were sending messages in plaintext not that long ago. Their switch to encrypted communication was merely a footnote.
- hagope 13y agowait a second...my SD card folder contains a folder called DCIM which includes all my camera photos... are you suggesting that all my images are available to any app that includes SD card permissions?
- jnbiche 13y agoYes. There is no way on Android to give fine-grained directory-based access permissions (unfortunately). So all SD card permitted apps can read the SD card globally.
- hagope 13y agoSo why isn't HN up-in-arms about Google allowing Android apps access to all your phone's un-encrypted images?!? That seems like a much bigger issue!
- kingnight 13y agoPerhaps it's inaccurate? It has to be right? I would have to think this would be something EVERYONE would be upset by.
- jnbiche 13y agoNo, it's quite true. If you're running Android prior to 4.1, any app can read anything from your SD card. Starting in 4.1, apps require READ_EXTERNAL_STORAGE to be able to read from the card (so user has to grant app this permission upon installation)[1]. Have you never noticed this when you grant apps permissions? All of this is clearly written on the permissions list -- READ_EXTERNAL_STORAGE is explained there in layman's terms (as in, "this app will be able to read and write files on your SD card" or something similar). And now, in KitKat, there have been some major changes in how the SD card can be accessed by apps, which I don't fully understand (never had to develop for KitKat only). But only a small percentage of users have KitKat installed. If you're really storing sensitive things on your SD card, you should probably look into using some type of app for encrypted file storage (there are many on the market). 1. http://source.android.com/devices/tech/storage/index.html http://source.android.com/devices/tech/storage/index.html
- JelteF 13y agoFrom the title I thought the current database. But it's just the by default daily created backup. I remember writing a rooted script for Tasker to get the actual messages to my pebble, since WhatsApp still doesn't expose them through their notifications. I fired an SQL query to their sqlite database everytime a notification from WhatsApp came in to see what the new message actually contained.
- barbs 13y ago> I used this webserver with a simple php script. "webserver" is a hyperlink, but it just links back to the blog. Anyone know what he's referring to here?
- userbinator 13y agoWhat's his blog hosted on...?
- bobbles 13y agoConsidering apps like this exist: https://play.google.com/store/apps/details?id=com.androidappetizers.whatstat https://play.google.com/store/apps/details?id=com.androidapp... it seems pretty obvious that this was the case
- rahij 13y agoCan't any app access all SMSs too in an easier manner? Whatsapp is a similar app, so why hold it to different standards?
- EvilBanshee 13y agoThis is nothing new - I've been using this app (https://play.google.com/store/apps/details?id=com.zegoggles.smssync https://play.google.com/store/apps/details?id=com.zegoggles....) for ages to sync my SMS and call log to Gmail, and for the past year or so, it's also been able to sync Whatsapp messages.
- arsupertec 13y agoThis is actually ridiculous because having this much largest app in android market and this type of bug can kill all of their audience.... must have to aware from now..
- sidmkp96 13y agoThis is where something like https://github.com/facebook/conceal https://github.com/facebook/conceal will help.
- sebastianavina 13y agoWhat is a AES Key?
- skeg 13y agoIf you think of encrypted data as being locked in a box, then the AES key is the key that unlocks that box. http://en.wikipedia.org/wiki/Advanced_Encryption_Standard http://en.wikipedia.org/wiki/Advanced_Encryption_Standard
- tbaba18 13y agoAre you in search a legitimate hacker? Do you wish to hack someone else facebook, gmail, hotmail, yahoomail, bank account without trace? Do you wish to upgrade your university score or college score without fear of been caught? Do you wish to delete some information from a website database, do you need a website? Search no more as hack word is here to give you a new lease of life. Interested persons should contact us now on this mail. dgf090293@gmail.com