• apps
  • games
  • desktop

Don’t rush generative AI apps to market without tackling privacy risks, warns UK watchdog

September 9, 2023

Now creators can promote their music with the Audiomack Creator App

September 9, 2023

NC State researcher says fitness app loophole may reveal users address

September 9, 2023

Hindi translation at the Bushplane? There’s an app for that

September 9, 2023
Facebook Twitter Instagram
  • Terms of Use
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • California Consumer Privacy Act (CCPA)
  • contact-us
Facebook Twitter Instagram
watshappwebwatshappweb
Demo
  • apps
  • games
  • desktop
watshappwebwatshappweb
Home » What is Secure? An Analysis of Popular Messaging Apps
apps

What is Secure? An Analysis of Popular Messaging Apps

watshappwebBy watshappwebSeptember 9, 2023Updated:September 19, 2023No Comments8 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit Email
Share
Facebook Twitter LinkedIn Pinterest Email

Justin Hendrix, Cooper Quintin, Caroline Sinders, Leila Wylie Wagner, Tim Bernard, and Ami Mehta.

In a world where privacy and security are increasingly under threat, particularly in countries swept up in a global wave of autocratization and erosion of rights, encrypted messaging apps are an increasingly popular—and necessary—way to share information, organize and engage with one another, and do business. But while the promise of secure messaging is private communications and user control over the spread of personal or group information, the reality is often more complicated, particularly in the age of surveillance capitalism. An overlapping, interconnected set of engineering, design, and system factors, coupled with varied user behaviors and shifting policy environments, have created conditions in which individuals may subvert their own interests or those of their communities while using encrypted messaging apps.

From September 2022 through May 2023, we analyzed popular messaging apps–including Signal, WhatsApp, Telegram, Messages by Google, Apple Messages and Meta’s Messenger–across a range of dimensions, including technical security, user experience, how the apps engage with users and developers, and their policies, terms and conditions. We sought to understand how people form mental models of their own individual or group digital security and corresponding threats, ways in which the technical and design decisions that the developers of encrypted messaging apps make can leave users vulnerable, and potential solutions that encompass technical, design, and policy adjustments.

To answer these questions, we adopted principles from frameworks such as Privacy by Design and Design from the Margins. We completed a technical review of selected apps; a detailed user experience and user interaction design analysis; and a comprehensive policy review. We interviewed a range of experts, and conducted field work with at-risk users including abortion rights activists in New Orleans, Louisiana and journalists in Delhi, India. 

The full 86-page report PDF is available for download here.

Key findings and recommendations include:

1. Users are too often flying blind. Even those most concerned about privacy rarely have sufficient information to make decisions that are in their own best interest. There is a substantial gap between the promise of encryption and the reality of threats to secure messaging in practice. We encountered various forms of “security folklore” that inform user decisions in place of information grounded in fact, as well as “security nihilism,” a debilitating sense among some that there is no way to communicate securely.

2. An app’s cryptographic security doesn’t mean it is secure. Implementation is everything. The failure to implement end-to-end encryption by default, such as on Telegram and Meta’s Messenger, illustrate this point. Users may not understand the distinction when presented with confusing options like “secret chat” and “private chat.” And few users understand design distinctions, such as different colors for messages in Apple’s iMessage and Google Messages, that are intended to communicate different types of messages (SMS or encrypted,) and thus different levels of security.

3. Follow Signal’s lead and encrypt or don’t store metadata. Signal is the only app that has taken steps to hide users’ profiles, contacts, group metadata, and even message sender information. Other developers need to follow Signal’s example and hide user metadata by keeping it encrypted with the user’s account key and only handling unencrypted versions in secure enclaves.

4. Let users decide which features should be on or off. Companies need to allow for any feature that impacts privacy and security to be turned on and off, and to explore and implement more granular settings that allow for users, especially high-risk users, to tailor the service to their needs, including when it comes to disappearing messages, link previews, storing and deleting call logs, and interaction history.

5. Close technical and design ‘loopholes’ that betray privacy. From unencrypted backups of messages and the use of phone numbers as identifiers to flaws in how deleted messages are handled, confusing naming conventions for certain features, and bad user design on some options, there are a range of technical and design issues that the makers of messaging apps need to address urgently.

6. Beware the bloat. Especially when it comes to apps that are connected to or are trying to emulate some aspects of social media platforms, including Meta’s Messenger, Telegram and increasingly WhatsApp, there is evidence of feature bloat and connections to other apps and services that may create new privacy concerns. The incentives of surveillance capitalism are privacy and safety’s worst enemy, particularly when developers deploy deceptive design patterns.

7. Encryption must be defended. Governments around the world–including in democracies–are threatening encryption with a range of new regulations and laws that will effectively break the model of apps like Signal and WhatsApp. It is crucial that policymakers, industry voices, and activists that understand the value of encryption speak up in its defense. 

This research, conducted by Convocation Research & Design and Tech Policy Press, was supported with funding from a program at Omidyar Network focused on private and trustworthy messaging.

The full 86-page report is available here.

What-Is-Secure-An-Analysis-of-Popular-Messaging-Apps-20-June-2023

Justin Hendrix is CEO and Editor of Tech Policy Press, a new nonprofit media venture concerned with the intersection of technology and democracy. Previously, he was Executive Director of NYC Media Lab. He spent over a decade at The Economist in roles including Vice President, Business Development & Innovation. He is an associate research scientist and adjunct professor at NYU Tandon School of Engineering. Opinions expressed here are his own.

Cooper Quintin is a security researcher and senior public interest technologist with the EFF Threat Lab, and board member of Open Archive. He has worked on projects including Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. Cooper has given talks about security research at prestigious security conferences including Black Hat, DEFCON, Enigma Conference, and ReCon about issues ranging from IMSI Catcher detection to fem tech privacy issues to newly discovered APTs. He has also been published or quoted in publications including: The New York Times, Reuters, NPR, CNN, and Al Jazeera.  Cooper has given security trainings for activists, non profit workers, and vulnerable populations around the world. He previously worked building websites for nonprofits, including Greenpeace, Adbusters, and the Chelsea Manning Support Network. In his spare time he enjoys making music, visualizing a solar-punk communitarian future, and playing with his kids.

You do not have any posts.

Caroline Sinders is a critical designer and artist. For the past few years, she has been examining the intersections of artificial intelligence, abuse, and politics in digital conversational spaces. She has worked with the United Nations, Amnesty International, IBM Watson, the Wikimedia Foundation and others. Sinders has held fellowships with the Harvard Kennedy School, Google’s PAIR (People and Artificial Intelligence Research group), the Mozilla Foundation, the Weizenbaum Institute Pioneer Works, Eyebeam, Ars Electronica, the Yerba Buena Center for the Arts, the Sci Art Resonances program with the European Commission, and the International Center of Photography. Over the past four years, she’s been exploring dark patterns and how design affects policy and technology. Over the past six years, she’s been researching security and privacy within design, technology and through the lens of consumer safety and harm mitigation. Caroline is based in London and New Orleans.

Leila Wylie Wagner is a project manager and disaster response professional based in New Orleans, Louisiana. Her work for the past two years has focused on designing and managing programs to combat COVID-19 misinformation and disinformation and to decrease vaccine hesitancy in Southeast Louisiana. Her areas of interest include the role of social media in disaster management and the shift to mutual aid-based response and recovery. She holds a BA in Anthropology from Brooklyn College and is currently pursuing a Master’s of Public Administration at Tulane University. Leila is based in New Orleans.

You do not have any posts.

Tim Bernard recently completed an MBA at Cornell Tech, focusing on tech policy and trust & safety issues. He previously led the content moderation team at Seeking Alpha, and worked in various capacities in the education sector. His prior academic work includes an MA in Talmud and a BA in Philosophy.

Ami Mehta (she/her) is a creative technologist, researcher, and artist based in Brooklyn. As a Postdoc Fellow at NYU’s Interactive Telecommunications Program, Ami is exploring ethnographic approaches to XR design practices. Her research interests include issues related to safety, privacy, self-identity, and representation in online social spaces, virtual worlds, and video games. Ami is a member of the Extended Realities Track at NEW INC, an art, design, and technology incubator led by the New Museum. In the past, Ami has consulted on strategy, planning, and cultural policy for global non-profit arts and media organizations. She holds an M.P.S. in Interactive Telecommunications from NYU, an M.A. in Art History from The Courtauld, and a B.A. in History from NYU.

You do not have any posts.

Related



Source link
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
watshappweb
  • Website

Related Posts

Don’t rush generative AI apps to market without tackling privacy risks, warns UK watchdog

September 9, 2023

Now creators can promote their music with the Audiomack Creator App

September 9, 2023

NC State researcher says fitness app loophole may reveal users address

September 9, 2023

Hindi translation at the Bushplane? There’s an app for that

September 9, 2023

DLTPAY launches MiCA-compliant DeFi app for SME payments

September 9, 2023

You Can Get Luminar Neo for 80% Off Right Now

September 9, 2023

Leave A Reply Cancel Reply

apps

Don’t rush generative AI apps to market without tackling privacy risks, warns UK watchdog

By watshappwebSeptember 9, 2023

The UK’s data protection watchdog has fired its most explicit warning shot yet at generative…

apps

Now creators can promote their music with the Audiomack Creator App

By watshappwebSeptember 9, 2023

Learn how the creator app music sharing and discovery platform Audiomack can assist with many…

apps

NC State researcher says fitness app loophole may reveal users address

By watshappwebSeptember 9, 2023

A loophole in the popular fitness app Strava may be revealing your home address to…

apps

Hindi translation at the Bushplane? There’s an app for that

By watshappwebSeptember 9, 2023

Launched in April, new app for the Canadian Bushplane Heritage Centre delivers content in six…

Facebook Twitter Instagram Pinterest
  • Terms of Use
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • California Consumer Privacy Act (CCPA)
  • contact-us
© 2023 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.