Thursday, January 28, 2021

WhatsApp's New Privacy Policy: Collecting Metadata and Its Implications

This article is by

Share this article

Article Contributor(s)

Vaishnavi Krishna Mohan

Article Title

WhatsApp's New Privacy Policy: Collecting Metadata and Its Implications

Publisher

Global Views 360

Publication Date

January 28, 2021

URL

Representative Image WhatsApp

Representative Image WhatsApp | Source: Rachit Tank via Unsplash

According to WhatsApp’s new privacy policy, the app is set to collect “only” user’s Metadata. Metadata can reveal a lot more than merely the app usage of a person. Former NSA General Counsel Stewart Baker stated, “Metadata absolutely tells you everything about somebody’s life. If you have enough metadata you don’t really need content.”

This article explores the ways in which WhatsApp is underselling the true estimation of the significance of Metadata.

Facebook owned WhatsApp recently announced the update of its privacy policy terms. 8th of February, 2021 was initially set as the deadline for users to either accept the new privacy policy or delete their account. By this time, most of us have already witnessed or been a part of the backlash that WhatsApp is experiencing. LocalCircles conducted a survey and the results indicated that 15% of India’s users are likely to move away entirely from the app while 36% will drastically reduce the usage and 67% of users are likely to discontinue chats with WhatsApp business accounts.

To reinstall trust in its users, WhatsApp released a clarification stating that the new policy update doesn’t compromise privacy of messages with friends and family. Furthermore, it explains that the update includes changes related to WhatsApp business accounts are optional too.

However, owing to severe backlash, WhatsApp has pushed the deadline to May 15 while they further clarify their policy updates.

It is true that WhatsApp cannot read our messages as it is end-to-end encrypted which implies that only a message’s sender and receiver can read it. The updated privacy policy intends to alert users that some businesses would soon be using Facebook-servers to store messages with their customers. By accepting the new privacy policy, users will be allowing WhatsApp to reserve all rights to collect your data and share it with the expansive Facebook and Instagram networks ‘regardless of whether you have profiles on those apps.’

A person using WhatsApp | Source: Andrés Rodríguez via Pixabay

By using WhatsApp, you may now be sharing your usage data, your phone’s unique identifier, your location when the location service is enabled, among several other types of metadata. A culmination of all your metadata is linked to your identity.

The value of metadata has been underestimated since the term isn’t clearly understood. Metadata is data about our data. For instance, in a cell phone conversation, the conversation itself isn’t metadata but everything except that is metadata. Data regarding who you called, how long you spoke for, where you were when you placed the call, where the other person on the line was and the time you placed the call. Consider a situation when every time you made a call to someone, you had to inform a particular person about who you called, how long you spoke for, when and where and all other details except the content spoken. This applies for every single call and everyone else’s metadata is also being recorded. The person owning the metadata can analyze and tell a lot about your personal life. Who you work with, who you spend time with, who you are close to, where you are at particular times and so on…

Kurt Opsahl, in his post in the Electronic Frontier Foundation, gives an example of how companies and governments collect intimate details about your life with the disguised use of the word called metadata. The following examples are an excerpt of his article:

“They know you rang a phone sex service at 2:24 am and spoke for 18 minutes. They know that you called suicide prevention hotline from the Golden Gate Bridge.

They know you spoke with an HIV testing service, then your doctor, then your health insurance company in the same hour.

They know you called a gynaecologist, spoke for a half hour, and then called the local Planned Parenthood's number later that day. But nobody knows what you spoke about.”

Metadata provides more than required context to know some of the most intimate and personal details of your lives.  When this data is correlated with the records of other phone calls, one can easily obtain a lot more data and track our daily routines. This is merely about phone calls. WhatsApp includes a lot more features and will collect metadata of chats, businesses and money transactions.

In WhatsApp’s words:

“We collect service-related, diagnostic, and performance information. This includes information about your activity (such as how you use our Services, how you interact with others using our Services, and the like), log files, and diagnostic, crash, website, and performance logs and reports.”

In addition to this, WhatsApp also collects information about IP address, OS, browser information and phone number.

Stanford’s computer scientists conducted an analysis to understand the extent of intrusion of privacy using metadata. The scientists built an app for smartphones. The app was developed to retrieve metadata of calls and text messages from more than 800 volunteers’ phone logs. The researchers received records of more than 250,000 calls and 1.2 million texts. Their inexpensive analysis revealed personal details of several people like their health records. Researchers were also able to learn that one of their participants owned an AR semi-automatic rifle with only metadata.

Gen. Michael Hayden | Source: Wikimedia

Gen. Michael Hayden, the former head of the National Security Agency once stated that “the U.S. government kill[s] people based on metadata.”

In 2016, Facebook was involved in the infamous data privacy scandal which centered around collection of personal data of over 87 million people by Cambridge Analytica, a political consulting and strategic analyst firm. The organization harvested user data for targeted advertising, particularly political advertising during the 2016 U.S. election. While the central offender was Cambridge Analytica, the apparent indifference for data privacy to Facebook facilitated Cambridge Analytical and several other organizations.

In June 2018, Facebook confirmed that it was sharing data with at least 4 Chinese companies, Huawei, Oppo, Lenovo and TCL. Facebook was under scrutiny from the U.S. intelligence agencies on security issues as they claimed that the data with the Chinese telecommunication companies would provide an opportunity for a foreign espionage.

In September 2019, there were reports that the Indian government contemplated making it mandatory for companies like Google, Facebook, and Amazon, to share the public data of users.

The Ministry of Electronics and IT (MeitY) was planning on issuing new guidelines under the Information Technology Act which according to which tech giants would have been required to share freely available data or the public information that they collate in the course of their operations, including traffic, buying and illness patterns.

Europe is exempted from WhatsApp’s new privacy policy as EU antitrust authorities fined Facebook 110 million euros for misleading the regulators during the takeover of WhatsApp in 2014. EU’s strict privacy laws empowers regulators to fine up to 4% of global annual revenue of the companies that breach the bloc’s rules.

Your Metadata is extremely personal. By giving WhatsApp the authority to access it, you are giving access to several other organizations, businesses and it also makes you more vulnerable to third-party hackers and trackers. WhatsApp has given multiple assurances about its updated privacy policy being noninvasive. However, most of these assurances are cleverly worded and misleading statements. It is important to read through the fine print of the new policy before accepting it.

Support us to bring the world closer

To keep our content accessible we don't charge anything from our readers and rely on donations to continue working. Your support is critical in keeping Global Views 360 independent and helps us to present a well-rounded world view on different international issues for you. Every contribution, however big or small, is valuable for us to keep on delivering in future as well.

Support Us

Share this article

Read More

February 4, 2021 4:39 PM

US Sanctions versus Iran’s fight against COVID-19 pandemic

Iran is the hardest-hit country by the coronavirus pandemic in the middle east. The contagion was first detected on 19 February 2020 in the holy city of Qom, and thereafter spread quickly across the country. As of 18th June 2020, it had over 9000 coronavirus related fatalities. The virus attacked all the 31 provinces of the country not discriminating between the common man and the people at high places including the members of the Parliament, religious leaders and senior ministers. The crisis touched most parts of the country, but it most severely impacted working and the poor class. 

The Iranian government has been criticized for its response towards the pandemic. The health care policy, which has been politicized, has preferred denial and misinformation as a response to the crisis the pandemic brought with it. Questions have also been raised about the role of US sanctions in crippling Iran’s economy, public health facilities and public health facilities. All these factors, when combined, have disabled Tehran (the capital of Iran) from providing the best response to the pandemic. 

What do the sanction laws say?

According to the Office of Foreign Assets Control, the US has “consistently maintained broad exceptions and authorizations to support humanitarian transactions with Iran.” The first significant sanctions were imposed in 1995 by Bill Clinton, and in 2001 exemptions for medical goods and medicine first came into effect. These sanctions have periodically widened the scope of products for exemption, and by 2012, the exclusions included agricultural products and most foods. After the world powers, including the US, reached a deal with Iran on its nuclear programme in 2015, the sanctions were lowered against Iran. This approach was abandoned after Trump withdrew the US from the deal and sought to force Iran’s leaders to change their anti-US policy. .

The US sanctions are enforced through a wide array of instruments. Financial sanctions prohibit US banks from transacting with Iran, which limits Iran’s access to dollar-denominated transactions. Secondary sanctions measures also target non-US entities that have dealings with Iran, thus at a risk of facing prosecution in the US. These sanctions make transactions with Iran lengthy and complicated, and even impossible in some cases

There are some exemptions from sanctions for humanitarian assistance (sale of agricultural commodities, food, medicine and agricultural services). Despite these exemptions, sanctions have severely impaired Iran’s ability to be able to finance humanitarian imports. Given the volume of complexity and due diligence involved, most banks are reluctant to deal with Iran. This makes it difficult to find a way to pay for purchases difficult for Iran. Also many items require additional authorization because the US considers them as “dual-use” (the things might also be used for defence- for example, the sort of oxygen generators that are needed in life support machines used to treat coronavirus cases). Lastly, the sanctions on Iran’s oil exports led to a decline in revenue, further weakening Iran’s currency, which has left the country vulnerable and with fewer resources to pay for non-sanctioned items as well. 

All these put together have directly caused shortages of medical equipment and impacted Iran’s health sector negatively. This has also impacted the capability of Iranian healthcare sector to effectively manage the COVID-19 situation.

Read More