Latest News

While Facebook faces the music, maybe it is time to #DeleteWhatsApp | Opinion
Wednesday, April 4, 2018 IST
While Facebook faces the music, maybe it is time to #DeleteWhatsApp | Opinion

WhatsApp differentiates itself from Facebook by touting its end-to-end encryption. “Some of your most personal moments are shared with WhatsApp”, it says, so “your messages, photos, videos, voice messages, documents, and calls are secured from falling into the wrong hands”. A WhatsApp founder recently expressed outrage at Facebook’s privacy policies by tweeting “It is time. #deletefacebook”.

 
 

But WhatsApp may need to look in the mirror. Its members may not be aware that when using WhatsApp’s “group chat” feature, they are susceptible to the same type of data harvesting and profiling that Cambridge Analytica employed on Facebook. WhatsApp goes further, making available mobile phone numbers, which can be used to accurately identify and locate group members.
 
WhatsApp groups are designed to enable discussions between family and friends. Businesses also use them to provide information and support. The originators of groups can add contacts from their phones or create links enabling anyone to opt in. These groups, which can be found through web searches, discuss topics as diverse as agriculture, politics, pornography, sports, and technology.
 
Researchers in Europe demonstrated that any tech-savvy person can obtain treasure troves of data from WhatsApp groups by using nothing more than an old Samsung smartphone running scripts and off-the-shelf applications.
 
Kiran Garimella, of École Polytechnique Fédérale de Lausanne, in Switzerland sent me a draft of a paper he co-authored with Gareth Tyson, of Queen Mary University, UK, titled “WhatsApp, doc? A first look at WhatsApp public group data”. It details how they were able to obtain data from nearly half a million messages exchanged between 45,754 WhatsApp users in 178 public groups over a six-month period, including their mobile numbers and the images, videos, and web links that they had shared. The groups had titles such as “funny”, “love vs. life”, “XXX”, “nude”, and “box office movies”, as well as the names of political parties and sports teams.
 
The researchers obtained lists of public WhatsApp groups through web searches and used a browser automation tool to join a few of the roughly 2,000 groups they found—a process requiring little human intervention and easily applicable to a larger set of groups. Their smartphones began to receive large streams of messages, which WhatsApp stored in a local database. The data is encrypted, but the cipher key is stored inside the RAM of the mobile device itself. This allowed the researchers to decrypt the data using a technique developed by Indian researchers, LP Gudipaty and KY Jhala. It was no harder than using a key hidden atop a door to enter a home.
 
The researchers’ goal was to determine how WhatsApp could be used for social science research. They plan to make their dataset and tools publicly available after they anonymise the data. Their intentions are good, but their paper has exposed the flaws of the application, and how easily marketers, hackers, and governments can take advantage of the WhatsApp platform.
 
Indeed, The New York Times recently published a story on the Chinese government’s detention of human rights activist, Zhang Guanghong, after monitoring a WhatsApp group of Guanghong’s friends, with whom he had shared an article that criticised China’s president. The Times speculated that the government had hacked his phone or had a spy in his group chat; but gathering such information is easy for anyone with a group hyperlink.
 
This is not the only fly in the WhatsApp ointment that this year has revealed. Wired reported that researchers from Ruhr-University Bochum, in Germany, found a series of flaws in encrypted messaging applications that enable anyone who controls a WhatsApp server to “effortlessly insert new people into an otherwise private group, even without the permission of the administrator who ostensibly controls access to that conversation”. Gaining access to a computer server requires sophisticated hacking skills or the type of access that only governments can gain. But as Wired wrote, “the premise of so-called end-to-end encryption has always been that even a compromised server shouldn’t expose secrets”.
 
Researcher Paul Rösler has said: “The confidentiality of the group is broken as soon as the uninvited member can obtain all the new messages and read them… If I hear there’s end-to-end encryption for both groups and two-party communications, that means adding of new members should be protected against. And if not, the value of encryption is very little”.
 
WhatsApp also announced in 2016 that it would be sharing user data, including phone numbers, with Facebook. In an exchange of emails, the company told me that it does not track location within a country and does not share contacts or messages, which are encrypted, with Facebook. But it did confirm that it shares phone numbers, device identifiers, operating system information, control choices, and usage information with the “Facebook family of companies”. That leaves open the question as to whether Facebook could then track those users in greater detail even if WhatsApp doesn’t.
 
Facebook and its “family of companies” are being much too casual about privacy, as we have seen from the Cambridge Analytica revelations, harming freedom and democracy. It is time to hold them all accountable for their massive breaches of our privacy.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

Tata Harrier’s three-row seat version in works, details out  

Recently posted . 2K views . 0 min read
 

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 2K views . 2 min read
 

 Article
India's Top 5 Mobile Charger manufacturer Brand 2019

The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

Recently posted . 2K views . 0 min read
 

 Article
Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

XUV300 is the latest entrant in the compact SUV segment.

Recently posted . 2K views . 0 min read
 

 
 

More in Electronics & Gadgets

 Article
Meet Waqar Ali’s electric motorcycle ‘MODI’: 150 kmph and dedicated to PM Modi

Waqar Ali has made an electric bike MODI that offers a range of 100 km while achieving a top speed of 150 kmph. It took Waqar two months to make the said electric b...

Recently posted. 1K views . 2 min read
 

 Article
Shuttl raises $11 million funding from Amazon India, others

Shuttl will use the funding from Amazon India, Amazon Alexa Fund, Dentsu Ventures to expand into two new cities by the end of 2018-19 and grow in existing cities ...

Recently posted. 856 views . 1 min read
 

 Article
This robot taught itself to walk entirely on its own

Google is creating AI-powered robots that navigate without human intervention—a prerequisite to being useful in the real world.

Recently posted. 584 views . 0 min read
 

 Reviews
2019 Renault Triber review, test drive



Recently posted . 926 views . 70 min read
 

 Article
Top 7 Best Air Fryers in India | TodayIndya

Love fried foods? Who doesn’t, everyone loves to enjoy the delicious taste of fried dishes, but the consciousness about health sometimes become a barrier. How...

Recently posted. 1K views . 2 min read
 

 Article
LG 88Z9, the World’s First Commercially Available 8K OLED TV, Goes Up for Pre-Order

This one is for early adopters and those who want to be future ready.

Recently posted. 636 views . 0 min read
 

 
 
 

   Prashnavali

  Thought of the Day

Happy are those who dream dreams and are ready to pay the price to make them come true
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top