WhatsApp privacy questioned dozens apps track online activity - WhatsApp is always proud to take care of the privacy of its customers, but this does not end up being entirely true.
User data poured into the IM application is tracked by dozens of external applications. They track users ' activity to determine who they are likely to be talking to, when they sleep, and when they are using their devices.
These applications and services use "online" signaling, which serves to identify connected users, to monitor without their consent all the digital habits of anyone who uses WhatsApp, according to Business Insider.
Despite the measures of the app owned by Facebook to protect user data such as encryption of messages, these intrusive applications are able to track user information.
The "online" function is the weak point
The vulnerability of WhatsApp comes from the function that publicly indicates whether a user is "online", that is, that they are using the application at any given time. In isolation, this is relatively irrelevant information, but when this data is collected for days and weeks, services can create detailed profiles of WhatsApp user activity and interactions.
Apps do not expose the content of WhatsApp users ' messages or reveal what users share or receive.
WhatsApp privacy questioned dozens apps track online activity
Its purpose is to advertise to potential customers to help them determine when people sleep, when they use WhatsApp and even who they are talking to in the app. The latter are found by comparing activity records of several people and detecting when they match.
Invasive applications resemble a less severe version of "stalkerware" - a covert software that people use to spy on other people's messages and devices that is sometimes used for control purposes in abusive relationships.
"You can imagine what an abuser could do with that information or, say, a boss who uses this to track whether his employees are speaking on WhatsApp during the working day, or someone in the police watching if people are speaking on WhatsApp during a protest," comments Cooper Quintin, senior security researcher at the Electronic Frontier Foundation (EFF). "I can't think of a single good legitimate use of this," he tells Business Insider.
Since WhatsApp have warned through a statement that their app provides privacy controls to users to protect their profile picture, the 'last seen' and on the connection status.
"We maintain automated anti-abuse systems that identify and prevent applications that attempt to detect information from WhatsApp users, and we constantly work to improve our systems over time. We also request that app stores remove apps that abuse our brand and violate our Terms of Service."
WhatsApp tracking apps have proliferated in Google and Apple's mobile app stores.
Dozens of them are available in the Google Play Store and Apple's iOS App Store, raising questions about what controls the two technology platforms are doing to monitor invasive apps.
From Google have not wanted to comment on it and have referred to the company's rules that prohibit "spyware". After the query, many of the tracking apps were removed from the Google Pay store.
For its part, Apple also did not want to talk to Business Insider and WhatsApp tracking applications are still available in its App Store.
The user of a tracking application enters the phone number of the person you want to track, and the application constantly checks whether the target is "online" or not, creating a record of its activity 24 hours a day 7 days a week.
Then, this data is displayed visually, allowing the user to monitor their target's online habits. With this you can find out how often you use the device, when you sleep and even if you are working or not.
Some of the apps allow users to enter multiple phone numbers and then compare their activity automatically to see if they are online at the same time and, therefore, are likely to be talking to each other.
In some cases, apps sell themselves as useful tools for parents to control children. Others are more explicit about their potential to spy on their spouses, colleagues, and others without their knowledge.
"Our online WhatsApp checker and tracker has many potential uses," says one website. "Think about tracking teens who stay up all night to chat before a big exam, co-workers who spend more time on WhatsApp than they should, or even family and friends who are plotting something suspicious. If you need to know desperately, I'm here to help, " reads the promotional text.
Another Google Play description :" you can guess if your lover is talking to someone else by looking if he is online. You can compare the online time of two people. With the timeline, you can see exactly when it comes in and out. You can receive notifications instantly when you're online or offline. You can analyze everything by looking at several graphs showing your connection activity."
Apps can usually be downloaded for free and some have millions of downloads from the Google Play Store. They usually offer only restricted functionality or limited time until the user spends money through in-app purchases, and it is unclear how many people have used the services.
There seems to be no way for normal WhatsApp users to avoid being tracked. An online tool was able to track my online activity on WhatsApp even after the account was blocked to prevent read receipts and disable the "last View" feature. A WhatsApp spokesman confirmed that there was no way to disable the "online" feature.
The provider consulted a dozen app developers to ask them if they believed the apps violated users ' privacy, if there was a way to opt out, and if they believed their tools violated WhatsApp rules. None responded.
All messages in the services are end-to-end encrypted, which means that no one can read them, apart from the sender and the recipient, including WhatsApp itself.
"Our mission is to connect the world privately by designing a product that is simple and private. So whether you send a message to your loved ones or make a video call to a friend, your communications remain secure and you always have control. Here, your conversations are held among you, " they explain on their website.
Its terms of Service stipulate that users should not " use (or assist others to use) our services in such a way ... violate, misappropriate or infringe WhatsAp's rights to our users or others, including privacy."
The WhatsApp spokesman confirmed that the apps violate its terms of Service and added that the company has anti-abuse systems to detect these apps and has blocked similar apps in the past.
However, it is unclear why the company did not do more to take strong action against these applications before they were detected by Business Insider.
Applications advertise their services openly in app stores and websites, without trying to hide their purpose. Similarly, Facebook's automated monitoring tools, which are designed to detect and prohibit bots and data scraping, apparently did not detect application activity.
Quintin de EFF asked WhatsApp to do more to correct the "flaw" that allows apps to collect user data. "Facebook and WhatsApp are taking a reactive approach, which failed to stop these applications until they were caught their attention," he says. "Clearly, this is not the best solution. What they need to do is take a proactive approach and make sure that no application can exploit this functionality."
WhatsApp privacy questioned dozens apps track online activity