Hacker News new | ask | show | jobs
by pseudo0 1326 days ago
Is the Whatsapp client really a black box? APKs are fairly straightforward to decompile back to Smali or a reasonable approximation of Java, or people on rooted devices can hook it with Frida. Of course source code would be better, but it would be pretty brazen to stick a backdoor in an app store release. App versions for popular apps get archived by numerous third-party sites, so even a temporary backdoor in one specific version would be archived forever. That would be putting their reputation and billions of dollars on the line.

Non-E2E with black box server code like Telegram is far more concerning, in my opinion. With a system like that, it would be trivial to backdoor and leave behind no evidence after the fact.

3 comments

It is very difficult to find a backdoor even in the open source code, in megabytes of closed source code it is nearly impossible.

> That would be putting their reputation

Does Facebook have any reputation left?

> Does Facebook have any reputation left?

Most people still think of WhatsApp and Facebook as separate. For a while, WhatsApp displayed a Facebook logo for a second whenever it started (and given how Android works, opening WhatsApp does not necessarily mean starting it, most of the time it just switches to an already started process), but even that does not happen anymore, since it was replaced by a "Meta" logo (and most people do not associate "Meta" with Facebook).

Which reputation? The reputation of a company that doesn't care about privacy at all and we t through dozens of privacy scandals?
Seems like someone doesn't like the truth
Telegram has more reputation that Meta.