WhatsApp is broken, really broken
fileperms.org
fileperms.org
I don't know the history, but currently, the Android app is free, and it says the use of the service is free for the first year, then will be $0.99 per year after that.
Meanwhile, the iOS app is $0.99 straight up.
Thoughts:
(a) "Free for a year, $1/year after that" seems like an awful long time to wait for a payday, but if it works, and you get lots of free users, I bet you get more conversions in the long run than with a normal free/pro app business model.
(b) "Free in one store, paid in the other" is an interesting idea. If you can build up a large userbase of free Android users, and it's an inherently social app, your free Android users will tell their friends on iOS devices to get the app so they can communicate. They probably don't even know it's not free. It's like unintentional affiliate marketing.
(c) I realize (b) might not be an intentional choice by the developers, but a necessity due to the App Store perhaps not supporting pricing schemes like the one in (a).
On Android, sideloading of apps from unauthorized sources (not the store), and frail DRM makes piracy really easy. The US government has been targeting these sources[1], but as you can imagine, there are many. Some have said that Android app piracy may be up to 60%[2], but I think there's some sample bias in these figures and suspect it's a fair bit lower.
On iOS, piracy is a bit more difficult, requiring a jailbreak and then a hack that allows cracked apps. From there, cracked apps can be downloaded from various sources. There are fewer solutions to crack in-app purchases, but recently a few have come into the mainstream[3]. On the whole, Apple's DRM helps, but pirates have found ways around it.
[1] http://www.theverge.com/2012/8/22/3259808/android-app-pirate... [2] http://www.theverge.com/2012/8/7/3225154/dead-trigger-dev-in... [3] http://www.theverge.com/2012/7/13/3156875/ios-free-in-app-pu...
I'm not a gamer, but I've heard that many gamers have a large, ongoing appetite for new games, and perhaps this makes them more sensitive to price. Even a $0.99 price tag can seem high if you want to play a half dozen new games every month. Meanwhile, a non-gamer who downloads that many apps in a whole year might not mind paying as much.
Also, gamers seem to often be power users, so it doesn't surprise me if many of them are technically savvy enough to know how to pirate. I would imagine that apps meant for garden variety Android users might be less widely pirated.
I mean, FWIW, of the friends of mine who I know use Android phones, I estimate 80 percent would have no clue how to download a pirated app if the thought even were to occur to them. And most of the other 20 percent who are tech savvy enough to do it are probably unlikely to find it worth the hassle.
There's an interesting subtext here about demographics:
As mentioned above, it would seem that games are more vulnerable to piracy due to the broad audience (lowest common denominator) and lack of "necessity" (games may appear trivial and thus not worth paying for to some). Productivity-linked apps such as Instapaper, Omnifocus, and Day One seem to grab paying users with less difficulty.
Additionally, there's been some commentary around Android vs. iOS users being willing to pay for apps. The argument is that Apple was rather successful in targeting an audience who tend to be more willing to pay for applications. As a contrast, it's argued that Android users tend to prefer free software.
I guess it varies by region- I've seen lots of phone shops in Taiwan offering "JB" as their main service. In Germany, I've only ever heard of commercial jailbreaking services for the Xbox and Wii (which used to involve soldering).
Also, my $2 hobby iPhone game has hundreds of Chinese players after only selling one copy in China, according to iTunes Connect. In other regions it's a non-issue.
I don't want to generalize and it's certainly not a good idea to put everyone into categories, but in my opinion piracy is heavily tied to psychological characteristics and the personality of users - in addition to a user's financial limits of course.
This comment touches an aspect that is hard to sum up in a few sentences as it doesn't come down to one single reason, but generally speaking I guess Android users are more likely to engage in piracy.
I'm not sure how that works with their "login" stuff, though, since I'd get a new IMEI with each new phone, but it just seems to work and the contact list is still there...
Personally, I'd always assumed there was no security at all and it just worked off your phone number. Certainly, I never treated any of it as in any way secure.
Just the nature of the different app ecosystems, really.
You used to be able to create an account without it, but not it seems impossible (or if it is, you have to do some devious thing 99% of the population could not figure out, even after solid googling).
That "devious thing" is "attempt to download a free app without an account". Then it will present you with the credit card-free option.
Sure they solved a pain that's very common, replacing expensive text messaging, but part of their success is how easy it is for users without annoying username/password hoops to step through. They should fix the security, although I don't do anything important over it anyway, but I can't say they went wrong by avoiding a classic username/password setup that might have been more secure from the start.
If you also want to instant message on your laptop: The latest Thunderbird comes with XMPP support! Or give Jitsi, which supports end2end encryption, or one of the many alternatives a try! Enjoy!
What would change your thoughts regarding a secure messaging system? Open source?
Also, Skype's protocol and entire stack is entirely opaque and thus hasn't been nearly as checked for security issues as something like XMPP with SSL for example.
I imagine a messaging app which works like TextSecure (as far as encryption goes), but integrates with Orbot (Tor for Android). Both phones would set up a Hidden Service so they can communicate directly, over the Tor network, over the Internet without an intermediate server.
That would be the perfect messaging system IMO. Not only would the message content be hidden, but who is talking to who, and when, would also be hidden. And it wouldn't require anyone to run a server to handle the messages either.
Please, somebody make this app.
Your app would have a nice geeky audience of tech nerds who would drool over how secure it is and how smart they are.
WhatsApp on the other hand "just works." It requires zero setup, zero technical understanding, and is available on almost every platform (at least the "biggies" anyway).
I would say its audience is teenagers, and the less tech savvy consumer in general. I cannot see them wanting to switch to something else unless you make come up with a USP which appeals to them (i.e. security is not a USP that they're interested in).
That said, I think the number of people concerned with message privacy is on the rise around the world. Over a few years, the market may grow significantly as privacy receives more attention.
I encountered the same thing recently with Raidcall. It's a shitty voice service that's in every way inferior to Skype, but trying to position itself as a competitor to Teamspeak (Which itself has been eclipsed on features and price by Mumble). Yet, somehow people will argue with you about it and evangelize it, without any sort of benefit comparison.
iMessage doesn't work for non-iOS phones. Annoyingly, GTalk doesn't have an official client on iOS. SMSes can get expensive.
It's the quickest direct replacement for SMS.
I use the mentioned app with my Lady every day because it works so well on her iPhone too. The easy of sending photoes is just pure awesome. Never failed (during one year). It works so well I don't hesitate a second to pay a dollar of it when it asks for it.
Ps. Drunk in a bar and a regular guy next me agrees who did not agree on punch of other stuff.
How to explain to a "regular dude" anyone can listen your phone call if they want to?
In my world everyone "normal I know" loves the mentioned app. How do I explain them everyone can read their messages if they want to? They answer me, everyone can steal my "normal" mail too if "they want to".
Ppps. I modified the typo i think i created after 8 pints.
It's not that it's "hard" to sniff SMS in a crypto-sense, it's just that that bar is a lot higher that sniffing unencrypted wifi traffic.
Even worse: this allows for trivial spoofing. You're far, far away from doing that with SMS.
Of course, this would let the person operating the "real" XMPP client read your messages; but the person operating the XMPP server can do that already, so there isn't any real change -- either way you should be using OTR messaging at all times.
In the peer to peer spirit of XMPP, such a project should make it really easy to run this virtual client yourself locally or on a cheap cloud server. Maybe something like that exists already? Anybody wanna build it?
I wonder what happens if a phone number (the login) is tied to a different IMEI (the password). This can happen when you transfer a phone number from one provider to another.
I think they send verification code to the phone via SMS or ask your permission to make a call and speak the verification code.
I do not know how secure Viber is but they have been steadilu acquiring good user base. If I was Viber, I would cash on this opportunity to write a blog or advertise their security models.
Option1 - Use an insecure paid app Option2 - Use an insecure free app
I am not sure about you but I will choose Option2 gien the constraints and restrict my use to communications which have no privacy problems.
Example:
F0:AB:C7:11:xx:yy
So you can easily crack this by brute force without sniffing the device address at all.
[1]http://en.wikipedia.org/wiki/Organizationally_Unique_Identif...
Considering that each phone has at least two MACs (wifi and bluetooth), even the 16 millions that would be given by using the full 3 bytes look scarce.
I think that Apple has several OUIs. In fact, my iPhone's MAC doesn't have a single byte in common with the parent's.
Ok, there is a simple way, let's collectively compile a list of the HN users reading this thread having an iPhone. I'll start with:
4s - F0:CB:A1:xx:yy:zz (me)
4s - F0:CB:A1:xx:yy:zz (wife)
4s - F0:CB:A1:xx:yy:zz (friend)
Please reply with your first three bytes.4s - 0C:77:1A:xx:yy:zz
p.s. I've verified that other 4s have a different (but numerical very "near") fourth byte. It seems in the range 20-24 or alike.
On what planet is using this data a valid form of security? Anyone can get hold of a MAC address.
you close whatsapp remove the contact list permission, open it again, surprise, it won't work. -_-
I guess they could re-scan it on a schedule but that wouldn't solve your issue and might annoy their user base who are using it because it "just works."
Plus removing a permission isn't something any app supports that I am aware of. It isn't even something you're meant to be able to do on Android.
You've had to have a database of everyone's contacts and then be comparing X with Y every few connections...
In my opinion, the obscurity peeled off by this expose did more to endanger WhatsApp users than the bad programming. So, I can only conclude this post's main goal is page views. OP could easily warn them, and at least wait until they didn't do anything before publishing.
http://samgranger.com/whatsapp-is-using-imei-numbers-as-pass...
The problem doesn't stem from giving information to "l33t hax0rz" but rather providing the key information that can be abused by anyone with a computer and half a brain. They are the ones more likely to make use of it in a widespread and destructive manner.
But with that said, most developers don't care if you tell them this stuff directly since it's simply information and not a proof of concept. Until someone starts using it and shows them that its actually a problem that is affecting their product they usually write it off as paranoia.
But it does not take a skilled attacker to "hack" a system where messages are being sent in plain text.
On the other hand, this article does little to alert users, while blithely informing techies, some of whom are likely to be hackers of some order.
I agree about the need to disclose such security issues to the authors privately. While I understand the sentiment of others, that it's such an inherent issue in their design that it'll take time to fix, that's not really a reason to not give them a chance. If it had been 1-2 months after disclosure, and it still wasn't fix, then sure, grab your pitchforks. But the initial public disclosure was on Sept. 5. I don't know if there was any private disclosure, but 10 days is not a lot of time to fix these kinds of things.
Nevertheless, I've linked them to it, let's see what they do.
You else where claim the author doesn't do enough to get the attention of non techie users to justify publishing this? What else could he have done? Spelled it out simpler? he only has his tech blog unless you think maybe he has funds to take out adverts and wishes to spend a small fortune alerting everyone that way?