Why has WhatsApp accessed my contacts 23,709 times?
thenextweb.com
thenextweb.com
The author's validity comes into question with how alarming the tone of this post is, and how he gave the company a week to respond to a non-important question then flamed them for not responding. His article on the Priv titled "BlackBerry Priv review: One of the best Android handsets I’ve ever used" vs Ars's post[0] on the same model from one of the more respected Android writers which is titled "BlackBerry Priv review: Android fixes the OS, but the hardware can’t compete" tells me all I need to know about this.
[0] http://arstechnica.com/gadgets/2015/11/blackberry-priv-revie...
What, exactly, is so alarming about the tone? I'd also be curious as to why an app is accessing my contacts so often. There might even be valid battery-life concerns.
>and how he gave the company a week to respond to a non-important question
It's important to the customer. I guess this is lost on the SV people who no longer believe that people from the company selling you a service should actually be accessible. But there was a time when if you had a question, like "why is your product using so many of my phone's resources?" you could have it answered. A week certainly isn't unreasonable, especially for a journalist.
>tells me all I need to know about this.
Disagree with review; dismiss article? Do you think there's some kind of agenda?
The author's argument certainly doesn't present a clear path from the inciting incident to any of the conclusions, so I also feel comfortable dismissing it. There isn't much use for emotional persuasive writing about technological issues outside of handwringing, and handwringing is boring to many of us.
I mentioned the Blackberry article not because I think it's shady advertising, but just to point that out from my perspective anyone who thinks the Blackberry Priv is a great "one of the best Android handsets" simply does either not have enough exposure to the Android ecosystem or is just someone whose opinion I don't hold highly.
I'm not saying this confrontationally. Now that you have pointed it, I actually think you have a point.
I started becoming disengaged with them when they started repeating the Apple line of "Jaibreaking is bad, mm'key?" even though they continued to post tutorials about it, because that's what drove the visits (I wanted to jailbreak my device because I can't stand the standard iOS app menu interface. Besides, my device, my rules). The "f*ck it" moment came when they did a "report" of the latest apple iPhone charger, praising it's construction, it's electrical insulation, and whatnot. I'm an EE, and could easily tell that it was all BS and they had absolutely no idea what they were talking about.
I find that this happens regularly in the apple ecosystem, people follow the Apple talk too eagerly for my taste, and don't usually have a technical clue about what are they talking about. All the retina display marketing thing is a good example. Anyway, this applies to the second tier bloggers and commenters (huge majority), first tier, even if they follow the apple line to the letter, usually know what are they talking about.
As for their opinion of the Priv, it's an opinion, and there have been varying opinions about it in the tech press. The way your comment was phrased, it sounded like your disagreement with their Priv review was a factor in your evaluation of their Whatsapp article.
As mentioned by jc4p, that tiny bit of information has provided the author with just enough rope with which to hang himself.
Technical people know first-hand that the wrong information can easily lead you away from the source of a problem. Some (many?) slightly-technical people don't understand that screen-on time and cpu-awake time [0] are the major contributors to battery drain. If you provide a raw number for $ACTIONS_TAKEN [1] without establishing whether that number is in the normal range for that app and without tying that number to actual battery drain by correlating it to actual CPU or backlight usage, you're very likely to waste people's time on a wild goose chase.
When making reports for non- or slightly-technical people, you usually have to be careful to filter out irrelevant information.
[0] IIRC, both of which are stats that have been provided in Android for at least the past several major versions, and probably back to -at least- Gingerbread.
[1] In this case, number of times contacts have been accessed by a particular app.
It could probably access it less often by only sending deltas, but that would mean their servers would have to store your whole phone book. I don't think that's any better from a privacy perspective.
Of course Facebook Messenger doesn't do the same, it has its own contact list coming from Facebook.
Another app might access your contacts rarely but store them on their server (Facebook!?). I definitely prefer the previous scenario.
Your reasoning is spot on.
Not to snark, but how do you know this? Do you know what actions increment the "This app accessed the contacts list" counter, and how many of those actions a comparable IM/telephony app executes? :)
Pure speculation. How do you know? It could be just as well that Whatsapp queries contacts one by one at the moment they are supposed to show up on the screen.
That way you could easily have 150 times (depending on the size of your contact list) your database accessed by scrolling once through your complete contact list.
Or the author is one of the few that has 1k contacts. In this case basically any operation that requires querying every single contact every now and then could cause this.
Also: the thumbnails you see of your contacts are accessed via URIs - could be that Android increases the counter every time you show a thumbnail of a contact. (it is part of your contacts information)
So if any app were to access my contacts 23k times, I'd say WhatsApp is the one app which could justify that.
But this article revolves around the trope of "if it's free you're the product", and altough it might be true, I don't think the 23k thing is a proof of it. That's what I meant with my comment.
If you do, you should probably cite it in your comment.
Sounds pretty straightforward to me, if that's the case.
or...
Is the app traversing the permissions boundary, and CACHING deltas on the device, for a deferred, less frequent upload of detected differences within a longer time period, perhaps phoning home once every 24 hours, to pass a message that indicates no changes, or only the current diff, OR the complete series of changes, even if there's no net difference, since the last upload?
Traversing the permissions boundary can trigger a counter, while traversing the network boundary might be an independent permissions request.
It's not clear if the author of the article has insight into these differences.
Both scenarios still have the same net effect on privacy, reducing the privacy of the user.
The difference here, being a tradeoff in possibly some low-watt brief increases in CPU load, and more expensive network/radio traffic, possibly also affecting mobile data/bandwidth caps.
And it's WhatsApp ffs, if you're concerned about it having your contacts what on Earth are you doing with it.
I would like to hear from other people about other methods or tools to answer your question.
Edit: Sorry, been awake for too long and misread your question. You could use this, but I am not endorsing this app: https://play.google.com/store/apps/details?id=com.gsamlabs.b...
https://github.com/M66B/XPrivacy#xprivacy
http://i.imgur.com/mZC4RjE.png (random picture of usage history, found on net)
edit: I don't really know a lot about this stuff, I was just trying to understand the comment I was responding to. I think I maybe misunderstand something fundamentally.
No, but Google has made sure that doing so is pretty trivial: https://wiki.cyanogenmod.org/w/Install_CM_for_hammerhead
If by "letting users root" you mean providing instructions on using ADB to unlock the bootloader, install a custom recovery, sideload SuperSU, and reboot into a fully rooted device, then no. Google doesn't provide these instructions, but they also don't lock the phone down to the point that you have to find an exploit and pray you don't brick the phone. No exploits necessary on a Nexus, just standard tools and instructions available on any reputable Android dev site.
The factory battery report isn't sophisticated enough to correctly attribute blame for more indirect battery usage patterns.
Turned out a newer update of Google Services just does something wrong on unofficial builds. You can see from the preferences which application is keepign the phone awake, but I think you might have to enable the developer options.
Solution was hacky, had to install a runtime script which was called on each boot, so that the particular service was blocked. Or maybe it was just looking at the battery stats, not sure anymore.
If there is no listener for of some kind in the api (android system telling all apps who want to know once there is an update), it will have to ask the system over and over again.
If Whatsapp was a bad citizen in respect to battery life I would at least understand why he is asking, but this is not the case.
What I am sure of: Whatsapp maps E.164 normalized telephone numbers from your contact list to every contact in the phones address book.
The app probably queries you phones contact database just like the standard phone or SMS app would do for every bit of information it shows.
Actually this is a hint that they actually might not store your contacts names, pictures, addresses etc in their own app, but only retrieve that information to display it.
The way their web client works (it communicates with the smartphone app, not with the whatsapp servers) is another hint that they might not even store your full contacts on their own servers.
It does seem excessive; perhaps sub-optimal or even an accidental bug. But certainly nothing for the media to freak out about..
Author's fear mongering is unwarranted.
They can also use it as a gauge to see how their advertising for whatsapp gets used.