Latest News

  • Home
  • While Facebook faces the music, maybe it is time to #DeleteWhatsApp | Opinion
While Facebook faces the music, maybe it is time to #DeleteWhatsApp | Opinion
Wednesday, April 4, 2018 IST
While Facebook faces the music, maybe it is time to #DeleteWhatsApp | Opinion

WhatsApp differentiates itself from Facebook by touting its end-to-end encryption. “Some of your most personal moments are shared with WhatsApp”, it says, so “your messages, photos, videos, voice messages, documents, and calls are secured from falling into the wrong hands”. A WhatsApp founder recently expressed outrage at Facebook’s privacy policies by tweeting “It is time. #deletefacebook”.

 
 

But WhatsApp may need to look in the mirror. Its members may not be aware that when using WhatsApp’s “group chat” feature, they are susceptible to the same type of data harvesting and profiling that Cambridge Analytica employed on Facebook. WhatsApp goes further, making available mobile phone numbers, which can be used to accurately identify and locate group members.
 
WhatsApp groups are designed to enable discussions between family and friends. Businesses also use them to provide information and support. The originators of groups can add contacts from their phones or create links enabling anyone to opt in. These groups, which can be found through web searches, discuss topics as diverse as agriculture, politics, pornography, sports, and technology.
 
Researchers in Europe demonstrated that any tech-savvy person can obtain treasure troves of data from WhatsApp groups by using nothing more than an old Samsung smartphone running scripts and off-the-shelf applications.
 
Kiran Garimella, of École Polytechnique Fédérale de Lausanne, in Switzerland sent me a draft of a paper he co-authored with Gareth Tyson, of Queen Mary University, UK, titled “WhatsApp, doc? A first look at WhatsApp public group data”. It details how they were able to obtain data from nearly half a million messages exchanged between 45,754 WhatsApp users in 178 public groups over a six-month period, including their mobile numbers and the images, videos, and web links that they had shared. The groups had titles such as “funny”, “love vs. life”, “XXX”, “nude”, and “box office movies”, as well as the names of political parties and sports teams.
 
The researchers obtained lists of public WhatsApp groups through web searches and used a browser automation tool to join a few of the roughly 2,000 groups they found—a process requiring little human intervention and easily applicable to a larger set of groups. Their smartphones began to receive large streams of messages, which WhatsApp stored in a local database. The data is encrypted, but the cipher key is stored inside the RAM of the mobile device itself. This allowed the researchers to decrypt the data using a technique developed by Indian researchers, LP Gudipaty and KY Jhala. It was no harder than using a key hidden atop a door to enter a home.
 
The researchers’ goal was to determine how WhatsApp could be used for social science research. They plan to make their dataset and tools publicly available after they anonymise the data. Their intentions are good, but their paper has exposed the flaws of the application, and how easily marketers, hackers, and governments can take advantage of the WhatsApp platform.
 
Indeed, The New York Times recently published a story on the Chinese government’s detention of human rights activist, Zhang Guanghong, after monitoring a WhatsApp group of Guanghong’s friends, with whom he had shared an article that criticised China’s president. The Times speculated that the government had hacked his phone or had a spy in his group chat; but gathering such information is easy for anyone with a group hyperlink.
 
This is not the only fly in the WhatsApp ointment that this year has revealed. Wired reported that researchers from Ruhr-University Bochum, in Germany, found a series of flaws in encrypted messaging applications that enable anyone who controls a WhatsApp server to “effortlessly insert new people into an otherwise private group, even without the permission of the administrator who ostensibly controls access to that conversation”. Gaining access to a computer server requires sophisticated hacking skills or the type of access that only governments can gain. But as Wired wrote, “the premise of so-called end-to-end encryption has always been that even a compromised server shouldn’t expose secrets”.
 
Researcher Paul Rösler has said: “The confidentiality of the group is broken as soon as the uninvited member can obtain all the new messages and read them… If I hear there’s end-to-end encryption for both groups and two-party communications, that means adding of new members should be protected against. And if not, the value of encryption is very little”.
 
WhatsApp also announced in 2016 that it would be sharing user data, including phone numbers, with Facebook. In an exchange of emails, the company told me that it does not track location within a country and does not share contacts or messages, which are encrypted, with Facebook. But it did confirm that it shares phone numbers, device identifiers, operating system information, control choices, and usage information with the “Facebook family of companies”. That leaves open the question as to whether Facebook could then track those users in greater detail even if WhatsApp doesn’t.
 
Facebook and its “family of companies” are being much too casual about privacy, as we have seen from the Cambridge Analytica revelations, harming freedom and democracy. It is time to hold them all accountable for their massive breaches of our privacy.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 

More in

 Article
How to book train tickets in India straight from the Google Pay app

Google Pay (earlier named Tez) has recently rolled out the ability to book train tickets in India straight from the app – both on iOS and Android. The money w...

Recently posted. 1K views . 1 min read
 

 Article
Sony Xperia XA2 Plus announced with 6" screen, Snapdragon 630

Sony Xperia XA2 and Sony Xperia XA2 Ultra have been around since January, and now the Japanese manufacturer unveiled a middle-ground solution called Xperia XA2 Pl...

Recently posted. 913 views . 2 min read
 

 Article
Nokia to launch iPhone X-like smartphone under Rs 10,000 today: All you need to know

Nokia X5 is said to be a mid-range smartphone that will fill the void of a toned version for Nokia X6  

Recently posted. 982 views . 0 min read
 

 Video
26/11 - Never Forget, Never Forgive!



Recently posted . 1K views
 

 Video
Funeral at the airpot



Recently posted . 1K views
 

 Article
Love Facebook Messenger? Now, get used to autoplaying ads

Messenger service with ads will be an important part of Facebook’s long-term revenue growth. The rollout starts next week

Recently posted. 763 views . 0 min read
 

 Article
Redmi Note 7 Pro launched in India with 48MP camera, 128GB storage: Check price, specs and availability

Redmi Note 7 Pro made its global debut on Thursday afternoon. Check its price, specs and availability.

Recently posted. 774 views . 0 min read
 

 
 
 

   Prashnavali

  Thought of the Day

“It’s time to start making better choices.”
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top