Hacker News new | ask | show | jobs
by jsiepkes 1989 days ago
It matters because people don't always realize that it means making trade-off's. And people often don't know what the consequences can be of those trade-offs because they didn't realise it was a trade-off to begin with.

In case of whatsapp and keeping chat history it can mean years of chat history becoming public if for example your Apple / Google account (where whatsapp automatically stores your conversation backups) gets hacked.

Do you think the people on Parler would have used the DM function if they had realised all those DM's could become public one day? Of course not. But they simply didn't realize that the "handy" DM function meant those messages were stored somewhere and that in turns means it can all get public one day.

2 comments

> In case of whatsapp and keeping chat history it can mean years of chat history becoming public if for example your Apple / Google account (where whatsapp automatically stores your conversation backups) gets hacked.

This just isn't the threat model most people care about, nor do they have to. Given a choice between preserving their chat history with their loved ones and not having any of it in the off chance that it might be leaked somewhere, the vast majority of people will opt for the former. Once you value chat history and other media in this way, then the risk simply isn't relevant. Again, this is all irrelevant. You people keep thinking on this one track of "but it's not secure" when that isn't the overriding concern for these people. It needs to be secure enough while not completely disregarding one of their core needs (preserving history). It's non-negotiable and no amount of discussing of risk or privacy will change this. Again, I find it insufferable that tech people are so unwilling to take normal peoples' needs into account.

Signal has the opportunity to become the default secure messaging app while also providing "secure" backups. They don't even need to be cloud backups, though that would be preferred. Even local backups can be sufficient. But as long as they don't account for the needs of "normal" people, Signal isn't a real option.

If I go to my friend's girlfriend and say, here's this awesome secure messaging app that you need to switch to and she switches, then something happens to her phone and she loses all her precious chats, how do you think that's going to go over? I can blabber on about privacy and risks all I want, I'm still the asshole.

> In case of whatsapp and keeping chat history it can mean years of chat history becoming public if for example your Apple / Google account (where whatsapp automatically stores your conversation backups) gets hacked.

IIRC the backups aren't stored in plaintext. They are encrypted with a key known to the device and whatsapp. The key is restored to a new device by whatsapp after SMS authentication.

Hence only a Google Drive compromise will not lead to full chat history compromise. That also requires something like a Sim Swap attack.