That is a stellar decision. I wonder if there were application-specific constraints that prevented a more secure option.
That is a stellar decision. I wonder if there were application-specific constraints that prevented a more secure option.
I don't think the developers are to blame. They did what they could.
The real problem is that snapchat promises something it can not technically deliver. Once a photo leaves your phone and is delivered to somebody else, you lost control over that photo.
This is an okay compromise tbh.
(They could offer a super secure option or whatever, I guess)
(I like security.)
But it doesn't work, since you need some way to generate new API keys for your second device... which could be a Bad App.
If you 1) enforce one key at at time (so one "device" at a time), 2) rate-limit key changes (if you switch to a new device, or Bad App, you can't switch back within a day or two) and 3) eliminate Bad Apps in the app stores- you effectively limit Bad Apps to being entirely web-based, and hopefully the restrictions on webapps will make the Bad App sufficiently a pain in the ass to use that people won't want to switch to it, even though it lets them save photos, since it locks them out of the real app.
Snapchat was designed for ephemeral communication, not secure "send-and-destroy" messages. It would be very foolish of them to market it as something it cannot possibly be.
Only problem: Someone could still decompile your app, use your API and request the decryption keys.
The reason why Snapchat has screenshot notification is actually due to that API being absent from iOS for a long time.
It's precisely the same problem with DRM. You either lock down everyone's devices against their owners (a massive "do not want" situation) - and then you could still copy the data via the old-fashioned analogue hole (I'm not including the truly disturbing idea of adding implants to people's brains that force them to "delete" something they've seen) - or accept the inevitable fact that data that can be accessed is data that can be copied.
Quite frankly, Snapchat is a form of DRM, except it's marketed toward users in a way that makes it appear desirable.
I think this is something that is orders of magnitude easier for technophiles to accept than the average person.
Because to the average person it so so easy to delete data - they press the delete key and its gone! So they look at the problem and think the computer programmers just need to do a better job.
Whereas you or I realize that it virtually is impossible to prevent access of data - at least on a systemic level, and the problem (though in some cases it is the programmer's fault) isn't something that better programmers could fix.
Yes, this is all exactly as bad as you think it is. Yes, you did just read ECB. Snapchat clearly isn't even trying to be secure.