Hacker News new | past | comments | ask | show | jobs | submit login

I don't think I get your complaint

Without open-sourcing the crypto, they could be just doing rot16($message) for all we know. Open-source is a requirement for being considered secure. It doesn't mean they aren't secure if they aren't open-source, but that you shouldn't consider it so, because you don't know if it is or not.




> I don't think I get your complaint

> Without open-sourcing the crypto, they could be just doing rot16($message) for all we know.

There are two things you can do:

1. Watch the outbound traffic and attempt known-plaintext attacks

2. Reverse engineer the app

Neither is particularly difficult. Most Android apps are trivial to break apart using Lobotomy. A large swath of software security folks specialize in binary auditing.


Has anyone done that and produced a fully open source app to connect to whatsapp?


Lots of people.

https://github.com/tgalal/yowsup for example


Looks like WhatsApp isn't so happy about that ...

https://gigaom.com/2015/01/20/whatsapp-cracks-down-on-people...

Do you know if the clients work with the new encryption?


Yes, axolotl is open source. (However I can't comment on how much it's been modified for the official client)




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: