[HN Gopher] Clubhouse user IDs, Chatroom IDs are transmitted in ...
       ___________________________________________________________________
        
       Clubhouse user IDs, Chatroom IDs are transmitted in plaintext over
       the internet
        
       Author : amrrs
       Score  : 84 points
       Date   : 2021-02-13 19:09 UTC (3 hours ago)
        
 (HTM) web link (twitter.com)
 (TXT) w3m dump (twitter.com)
        
       | offtop5 wrote:
       | Same reason Tinder ( Match Group who owns all the apps) sent user
       | location data all over the place.
       | 
       | Normal people will never learn about this , and doing it right
       | would take too much effort. While I would love new better social
       | media to take over, I don't think social media which serves it's
       | users is possible.
       | 
       | Hell, I self sensor more here than I do in real life. In real
       | life if I say something odd it's forgotten within minutes.
        
       | arkadiyt wrote:
       | Only peripherally related but after the recent Robinhood fiasco I
       | downloaded the Interactive Brokers mobile app, and they send your
       | login user/password in plaintext:
       | 
       | https://twitter.com/arkadiyt/status/1356054340008460293
        
         | bluesign wrote:
         | I don't think this is true (plaintext part), maybe they are
         | doing some custom encryption for snoopy corporate firewalls.
        
         | nickysielicki wrote:
         | This is pretty bizarre. I imagine it's due to user complaints
         | about not being able to make trades while behind very strict
         | corporate firewalls? Weird.
        
       | brobinson wrote:
       | So the PRC now has a list of PRC nationals, based on their phone
       | hardware IDs, who discussed "sensitive topics" (phrase used by
       | PRC state media about Clubhouse) on the app? Yikes.
        
       | vmception wrote:
       | I kind of like that Facebook is considering to compete with
       | Clubhouse.
       | 
       | There are a lot of software features that Clubhouse can add, but
       | they have to or choose to focus on many other things instead.
       | Something simple like a "shut up" button "we got your point two
       | minutes ago".
       | 
       | Competition will force them to re-prioritize just to keep the
       | users.
        
       | ketamine__ wrote:
       | What language are they using for the backend?
        
       | unicornporn wrote:
       | Who could've guessed? It would be interesting to see a "move slow
       | and fix things" approach for once. But I guess it isn't
       | compatible with ruthless expansion.
        
         | sofixa wrote:
         | Clubhouse is a startup, what ruthless expansion? A lot of
         | startups cut corners to get to market faster, but this is just
         | inexcusable.
        
           | etaioinshrdlu wrote:
           | Haha, this is one of the tamest instances of cutting corners
           | in the news lately. It's not like this is super-secret
           | information either. It's not health, finance, or legal data.
           | 
           | Some people on HN seem to take security much more seriously
           | than necessary, as if security is the most important feature.
           | But in business, it usually isn't.
        
       | nikolay wrote:
       | Why I can't register for an account even if the app is not
       | available? Why, again, Android users get discriminated against
       | and iPhone users get a leverage again and again?! How hard is to
       | create a signup form and give everybody an equal chance to
       | reserve their username?
        
       | Kiro wrote:
       | Maybe I'm stupid but how are user IDs and chatroom IDs sensitive
       | information? How can I join a room or interact with a user if I
       | don't know the ID?
       | 
       | Just trying to understand the severity here and if I'm doing
       | something wrong in my apps.
        
         | saladgnu054 wrote:
         | You can tell who is talking with whom.
        
         | CydeWeys wrote:
         | Why is your app sending _anything_ over the network
         | unencrypted? You 're making HTTP requests (not HTTPS)??
        
           | np_tedious wrote:
           | I think it's UDP. Probably for the audio
        
             | CydeWeys wrote:
             | That may be true of Clubhouse but not necessarily for the
             | person I responded to. Anyway, there's plenty of ways to
             | encrypt UDP, such as DTLS; see this RFC:
             | https://tools.ietf.org/html/rfc6347
        
           | YarickR2 wrote:
           | and why not ? Why do you insist everything should be
           | encrypted ?
        
         | tchalla wrote:
         | Everything can be sensitive if you don't get informed consent.
        
         | josephg wrote:
         | User IDs are sensitive because they can be used by internet
         | service providers to track and identify users as they move
         | through various networks. And they can be associated to figure
         | out who your contacts are. As others have mentioned, the CCP
         | could use this information to punish users for joining rooms
         | they don't like.
         | 
         | The rule is, if ever in doubt, send all data through https.
         | There is just about no reason to use unencrypted http or tcp in
         | 2021.
        
       | polote wrote:
       | This is not the bug of the year. Ok, the id is not the encrypted.
       | So encrypt it and next. Nothing to see
        
         | noop2714 wrote:
         | > This is not the bug of the year. Ok, the id is not the
         | encrypted. So encrypt it and next. Nothing to see
         | 
         | The privacy implications of leaking user identifying
         | information are massive. Not something that should be dismissed
         | so quickly as "nothing to see".
         | 
         | Maybe not interesting for you, but many of us care about
         | holding companies accountable for bad practices. If you don't,
         | this will become more common as it's effectively being
         | tolerated.
        
           | polote wrote:
           | There is no evidence that they tried to hide that. The
           | company was created in 2020 and one of their API is not
           | encrypted, that kind of things has probably happened to most
           | of companies created less than a year ago
        
             | noop2714 wrote:
             | > that kind of things has probably happened to most of
             | companies created less than a year ago
             | 
             | No company gets a free pass on the implications of
             | sacrificing privacy or security. Even if "less than a year
             | old".
             | 
             | This is serious:
             | 
             | "Any observer of internet traffic could easily match IDs on
             | shared chatrooms to see who is talking to whom. For
             | mainland Chinese users, this is troubling"
        
               | YarickR2 wrote:
               | Like somehow you're the judge the jury and the
               | executioner of said conpanies. Don't use their product.
        
         | hellotomyrars wrote:
         | Right. Do the obvious and right thing after you're caught. No
         | big deal.
         | 
         | A dangerous and all too common pattern of negligence. Willful
         | or otherwise.
        
       | 188201 wrote:
       | For me, Clubhouse is a honey pot for CCP to arrest people for
       | expressing their opinion, otherwise why they are using a
       | Shanghai-based startup for their voice backend platform?
       | 
       | Not sure how many Xinjiang people and Chinese who are sympathetic
       | to Xinjiang people are arrested after CCR blocked Clubhouse.
       | 
       | Or prove me wrong, at least stop using Chinese SaaS service if
       | they really care about their user. Or better, use an open source
       | implementation to support their service.
        
         | vmception wrote:
         | > otherwise why they are using a Shanghai-based startup for
         | their voice backend platform?
         | 
         | Is there a term for this form of argument? Like where someone
         | makes a rhetorical question after seeding the answer? Its like
         | creating a false dilemma, where one intentionally removes non-
         | binary choices for their own agenda, but its not quite a false
         | dilemma yet, except after someone responds about how weak this
         | form of argument is by presenting second, third and fourth
         | reasons that were outside of the boundaries of the question but
         | inside the boundaries of reality.
        
           | acheron9383 wrote:
           | Seems like begging the question, they assume it is a CCP
           | honeypot and then push the false dichotomy with the voice
           | back end? *edit s/video/voice/
        
         | Barrin92 wrote:
         | >why they are using a Shanghai-based startup for their voice
         | backend platform
         | 
         | because a lot of Chinese companies are really good at voice
         | related services due to the ubiquitous use of it in China.
         | (typing Mandarin is annoying because you have to use pinyin).
        
           | onlyfortoday2 wrote:
           | yeah right lol
        
         | vmception wrote:
         | The CCP has all power over corporate trade in China, and can
         | obtain access to corporate data.
         | 
         | That fact of life is not guiding factor for why corporations
         | create technology, compete for contracts, and make revenue.
         | 
         | And there is a lot of technology there. It is an innovative,
         | high growth, competitive maybe overly competitive, and dense
         | part of the world. Most of which has nothing to do with what's
         | happening on the other side of the Gobi desert. If that is to
         | be your cause, great, because that's going to keep happening,
         | but its a large stretch to make that the sole guiding factor
         | for everyone else that creates or simply uses software from
         | China.
         | 
         | If you are subject to that system, then you should use
         | discretion on Clubhouse, that would really be the entirety of
         | your message.
        
       ___________________________________________________________________
       (page generated 2021-02-13 23:01 UTC)