Wire-ios: Restricted context menu on timed messages – cannot copy

Created on 27 Apr 2020  Â·  3Comments  Â·  Source: wireapp/wire-ios

Checklist (please check before submitting)

  • [x] I checked the existing issues, and the issue was not reported before.

The problem

When sending towards desktop/browser, disappearing messages in a note-to-self group are a great way to transfer one-time passwords, long numbers, etc. – just select the thing on the receiving end and copy it, no need to worry about deleting the message.

When sending to iOS, this doesn't work as the context menu for disappearing messages was lobotomized. You can't copy the text (even though this feature was specifically advertised for this: "It’s also perfect for sending sensitive data like credit card details, login information, and other private matters. The messages will automatically disappear from the conversation once the timer runs out.") and so you have to do the super annoying dance of app switching and manually typing, or use a different program, or don't use disappearing messages.

Environment

  • Wire version that exhibits the issue: 3.56 (4057)
  • Last Wire version that did not exhibit the issue (if applicable): none known
  • iOS version used to run Wire: tested on multiple, including current 13.4
  • iOS device type: tested on multiple iPhones

Details

  1. Send a disappearing message containing e.g. bank transfer details to an iOS device.
  2. try to copy the information.

Expected behavior

It is possible to copy the message. (Ideally, select parts of it to copy, but that doesn't even work with normal messages.)

Screenshots

DFEABF23-5FC6-4DF8-97D3-B546665FD96D

1D6DBFA7-E8E9-40FE-9970-42C2A9D59BCD

Feature request Question

Most helpful comment

To approach this from a different direction: You say that this is "by design", therefore I assume that you have a threat model against which you have evaluated the costs and benefits of not allowing copying. You seem to have concluded that it is more helpful than harmful to prevent copying.

Even without knowing the details of your threat model, I think that your analysis is flawed and the costs outweigh the benefits. Here is why:

  1. As evidenced by the screenshot above, it is possible to make a screenshot of a timed message. This screenshot is roughly functionally equivalent to the message in Wire with the current behavior (you can manually transcribe it and you can delete it, but you cannot directly copy the text), but unlike the timed message it will not self-destruct. Disallowing copying from the app therefore does not prevent the preservation of the information beyond the intended time limit.

  2. More strongly: When using Wire in the browser via app.wire.com, it is possible to select and copy text. (It is also possible to right click and 'view image' to extract/save images.) As messages are not bound to a single device, I can easily log in to the browser on a real computer, using the same account, and copy/save the message text over there.

Whatever your threat model is, whatever the thing that is presumably being mitigated by disallowing copying, anyone who is not limited to just an iOS device can use the web version, which cannot prevent copying. So for this to be a sound design decision, there had to be a threat that existed only when extracting the text on an iOS device and not when saving a screenshot or when extracting the text elsewhere. I doubt such a threat exists, or at least not one that affects sufficiently many people that it's worth making everyone pay the price of this restriction. I therefore call this a design flaw – in other words, a bug.

This bug prevents Wire timed messages from being easily usable as a bidirectional transfer channel from your computer to your phone: While it is possible to send data via timed messages from iOS to your computer and copy it from there, it is not possible in the other direction. As phone keyboards are painful to type on, it would be great if that restriction could be lifted, i.e. copying of timed message text was enabled.

All 3 comments

Hi @229c9cf0, timed message is not allow to copy by our design. My own alternative would be sending a timed files contains the secret.

Then why does your own promotional blog post suggest using timed messages to send e.g. login information? (See quote & link in OP.)

If you cannot copy the info you are forced to manually type it again. For long strings of numbers/symbols where typos are potentially dangerous (e.g. fingerprints), this makes it entirely useless.

Also, this is not a question, it is a bug report.

To approach this from a different direction: You say that this is "by design", therefore I assume that you have a threat model against which you have evaluated the costs and benefits of not allowing copying. You seem to have concluded that it is more helpful than harmful to prevent copying.

Even without knowing the details of your threat model, I think that your analysis is flawed and the costs outweigh the benefits. Here is why:

  1. As evidenced by the screenshot above, it is possible to make a screenshot of a timed message. This screenshot is roughly functionally equivalent to the message in Wire with the current behavior (you can manually transcribe it and you can delete it, but you cannot directly copy the text), but unlike the timed message it will not self-destruct. Disallowing copying from the app therefore does not prevent the preservation of the information beyond the intended time limit.

  2. More strongly: When using Wire in the browser via app.wire.com, it is possible to select and copy text. (It is also possible to right click and 'view image' to extract/save images.) As messages are not bound to a single device, I can easily log in to the browser on a real computer, using the same account, and copy/save the message text over there.

Whatever your threat model is, whatever the thing that is presumably being mitigated by disallowing copying, anyone who is not limited to just an iOS device can use the web version, which cannot prevent copying. So for this to be a sound design decision, there had to be a threat that existed only when extracting the text on an iOS device and not when saving a screenshot or when extracting the text elsewhere. I doubt such a threat exists, or at least not one that affects sufficiently many people that it's worth making everyone pay the price of this restriction. I therefore call this a design flaw – in other words, a bug.

This bug prevents Wire timed messages from being easily usable as a bidirectional transfer channel from your computer to your phone: While it is possible to send data via timed messages from iOS to your computer and copy it from there, it is not possible in the other direction. As phone keyboards are painful to type on, it would be great if that restriction could be lifted, i.e. copying of timed message text was enabled.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

jensrossbach picture jensrossbach  Â·  4Comments

IpsmLorem picture IpsmLorem  Â·  3Comments

S2F0amEgS2xvdmVy picture S2F0amEgS2xvdmVy  Â·  3Comments

IpsmLorem picture IpsmLorem  Â·  3Comments

lucifer662607004 picture lucifer662607004  Â·  5Comments