Preliminary Findings on Whisper
zdziarski.com
zdziarski.com
The core platform this application appears to be designed on is Fiksu (http://www.fiksu.com). Fiksu’s describes themselves as a “user acquisition” company, focused on analytics, social tracking, advertising, incent, and interest mining. ... Unlike most applications that incorporate analytics packages as a secondary module, it appears that Whisper is built on top of the Fiksu platform, where Fiksu acts as the primary application delegate, and the social networking element of Whisper acts as secondary to the application’s subject tracking and analytics core.
Putting the users unique Whisper ID into the EXIF data of uploaded pictures - now that was sneaky.
Is there any legitimate need for Whisper to have serial numbers and the phone numbers that users call?
Can any lawyers versed in this area of the law comment on whether something like a phone can ever be "plausibly deniable" absent obvious evidence of theft?
Or comment on the concept of "plausible deniability" as a useful legal defense in general? I'm dubious that it offers any meaningful protection,
But it's ludicrous for Whisper to deny that an IP address and timestamp isn't personally identifying information. To law enforcement or anyone else you have to worry about, it's close enough.
Also all the analytics stuff is troubling, in an app that supposedly focuses on privacy.
[0] https://stackoverflow.com/questions/3411629/decoding-the-cll...
What the hell? I just want to read a random page.
> DDoS protection by CloudFlare
No other content on the page.
Anyone have the article in a readable form?
"The application incorporates pieces of various analytics packages, including those from Fiksu, Facebook, and some proprietary logging. As a result, it is likely possible that all activity within the application can be collected, including user taps, application activity time, hours of use, and even potentially unsent content typed in by the user. I have not made any attempt to specifically identify what analytics are active in the app; I am speaking of the capabilities of most analytics packages in general."
This app includes third party libraries. Therefore it could do anything. I didn't check.
Shameful.
In the context of an app which is "committed to being a safe place for our users to anonymously share their innermost thoughts" (http://whisper.sh/privacy) that is interesting, if not conclusive.
I don't see anything disgraceful about publishing that information. A full security investigation of an app from a security firm costs $'000s - you can't expect a definitive rundown for free.