4 ms·
They shouldn't store the images on the phone. You should be only able to view the image immediately after downloading it. After 10 seconds of viewing the image,
by readerrrr 12y ago
They shouldn't store the images on the phone. You should be only able to view the image immediately after downloading it. After 10 seconds of viewing the image, everything gets deleted from ram.
- johsoe 12y agoThen you have to wait for the download every time you open the app. This is an okay compromise tbh. (They could offer a super secure option or whatever, I guess)
- readerrrr 12y agoActually you could just download the encrypted images without the unique key( for every image ) and then get the key on demand. Load the image into ram, decrypt, show the image and then erase everything.
- JoachimSchipper 12y agoThat would be more secure, but you still need to wait for the key to be downloaded on-demand - you don't exactly get butter-smooth scrolling that way. (I like security.)
- fla 12y agoI wonder why they didn't choose this path. A trade off for better usability ? Why would an app break it's core promise to offer better usability ?
- MichaelGG 12y agoBecause it's still totally flawed? Nothing stops anyone from writing a program that pretends to be Snapchat and downloads the keys and images as it pleases.
- roywiggins 12y agoIf you hide a per-device API key inside the real Snapchat app, you might at least require that the user root the device before being able to grant an Evil App access to their photos.
- cortesoft 12y agoIf you look at the link, even the current method requires root on the device.
- roywiggins 12y agoI was thinking about Bad Apps that users voluntarily hand their login details to (so they can download snapchats they get sent). Those don't need root, since they're just mimicking the Snapchat app and receiving the photos directly. But it doesn't work, since you need some way to generate new API keys for your second device... which could be a Bad App. If you 1) enforce one key at at time (so one "device" at a time), 2) rate-limit key changes (if you switch to a new device, or Bad App, you can't switch back within a day or two) and 3) eliminate Bad Apps in the app stores- you effectively limit Bad Apps to being entirely web-based, and hopefully the restrictions on webapps will make the Bad App sufficiently a pain in the ass to use that people won't want to switch to it, even though it lets them save photos, since it locks them out of the real app.
- deleted 12y ago
- singron 12y agoIt's also not difficult to bypass the app completely and poll the service from another program (for instance, run by cron on a server). Like other people have said, the entire premise is flawed.
- meowface 12y agoI wouldn't say the premise of the app is flawed, rather it's just that people seem to misunderstand its technical capabilities. Snapchat was designed for ephemeral communication, not secure "send-and-destroy" messages. It would be very foolish of them to market it as something it cannot possibly be.
- deleted 12y ago[deleted]