Protocol | China

WeChat promises to stop accessing users’ photo albums amid public outcry

A tech blogger claimed that popular Chinese apps snoop around users' photo libraries, provoking heightened public concerns over privacy.

A hand holding a smartphone.

A survey launched by Sina Tech shows 94% of the some 30,000 responding users said they are not comfortable with apps reading their photo libraries just to allow them to share images faster in chats.

Photo: S3studio via Getty Images

A Chinese tech blogger dropped a bombshell last Friday, claiming on Chinese media that he found that several popular Chinese apps, including the Tencent-owned chat apps WeChat and QQ, as well as the Alibaba-owned ecommerce app Taobao, frequently access iPhone users' photo albums in the background even when those apps are not in use.

The original Weibo post from the tech blogger, using the handle of @Hackl0us, provoked intense debates about user privacy on the Chinese internet and consequently prompted WeChat to announce that it would stop fetching users' photo album data in the background.

@Hackl0us said he tracked the apps' activities for seven days using a new iOS 15 feature called Record App Activity, along with a third-party app called App Privacy Insights. Screenshots of activity logs provided by @Hackl0us show that the three Chinese apps read his photos multiple times throughout the day with each read lasting up to 60 seconds.

"This is disgusting," @Hackl0us wrote. "Photos are a user's private [possession]. They have no idea when the apps fetch their private data. Judging from the log, the apps read the photo library even while the user is asleep."

Chinese web users reacted strongly to @Hackl0us' findings. His original Weibo post trended on the platform's hot search chart last Friday. By the time of this writing, his post has been shared over 50,000 times, and nearly 220,000 people have liked it. A related hashtag has received 200 million reads. In a survey launched by Sina Tech on Weibo, 94% of some 30,000 respondents said they are not comfortable with apps reading their photo libraries.

WeChat, one of the most frequently used apps in China with over 1.2 billion users, immediately responded through Chinese media. The company explained that an Apple protocol, which web users identified as the PHPhotoLibraryChangeObserver, notifies app developers of changes that occur in their user' photos libraries. The protocol allows an app to track changes within and outside the app. When an app receives those change messages, the iOS 15 system records the activity as if it were photos being read on a user's phone.

WeChat explained this protocol allows users to share photos faster in chats, causing a preview of the last photo in a user's album to pop up. WeChat stressed in its statement that the processing is on-device, and that app was able to do this because users gave their consent by authorizing WeChat to access their albums.

"We do not collect, save, or upload any images from a user's album without the user's authorization," a Tencent spokesperson wrote in a statement shared with Protocol.

WeChat promised that it would withdraw the background fetching protocol in its next update, and it is finding an alternative to "optimize the quick picture sending function.

But WeChat's statement didn't fully address privacy concerns. In a Zhihu article where @Hackl0us documented his complaint, he wrote that WeChat's technical teams had reached out to him and explained why WeChat decided to enable the image posting feature through background data fetching. But @Hackl0us believes WeChat is breaking a butterfly on a wheel. He argued that WeChat could achieve the same feature in alternative ways without systematically reading photo libraries in the background. Not only does invoking this protocol intrude on user privacy, @Hackl0us said, it consumes unnecessary memory and battery at the expense of user experience.

"I really don't understand why WeChat needs to use Apple's PHPhotoLibraryChangeObserver protocol to implement such a simple feature," he wrote. "It's probably fine for one app to do this, but if many Chinese apps act like this, and they do, it will have a big impact on our phone's battery life."

Legitimate privacy concerns

Digital privacy experts told Protocol that app developers seeing a list of photo changes by itself offers very limited utility, but if the apps can access the photos themselves, they could exploit Apple's PHPhotoLibraryChangeObserver protocol to analyze user behavior or sentiment, which is of great commercial value. Apps could also run facial recognition algorithms to facilitate social mapping.

"WeChat is closed-source software, so it is impossible to know how the protocol is implemented, what it does, and whether it is commercialized by generating a library of fingerprints from user albums until we see the source code," @Hackl0us wrote in his Zhihu article.

The controversy over privacy occurred less than one month before China's privacy law, the Personal Information Protection Law (PIPL), becomes effective. This law will shield Chinese internet users from excessive data collection and misuse of personal data by tech companies. One big theme running throughout the law is ensuring the consumer's right to consent and the right to know how their information is being used. Data handlers are required to collect data only when necessary to provide certain services, and must secure user consent for the collection.

Without knowing more details of app developers' processes on the device and regulations, it's hard to know whether the action of frequently reading photo albums would violate the forthcoming Personal Information Protection Law, according to Graham Webster, a research scholar at the Stanford University Cyber Policy Center and the editor in chief of the center's DigiChina Project.

"One real question is whether on-device processes limited to functional needs for the app even constitute 'personal information handling' under the law," Webster told Protocol. "Meanwhile, it seems it would be impossible to know ahead of time whether a given photo qualifies as 'sensitive personal information.'"

Under PIPL, data handlers are required to obtain "separate consent" from users while dealing with "sensitive personal information" and inform them of the necessity of collecting such data as well as the impact on their rights.

The law is new. Companies and consumers should expect more detailed regulations to clarify questions like this. "Depending on the details, [the background fetching of albums data] could well be a legitimate privacy concern, even if it isn't one that's covered in the new law," Webster said.

Protocol | Fintech

Crypto wallet maker Ledger gears up for battle with Dorsey’s Block

CEO Pascal Gauthier wishes Block’s CEO were still distracted with Twitter, but he’s still gunning for the big opportunity in securely stashing customers’ coins.

Ledger CEO Pascal Gauthier talked about Ledger’s strategy in an interview with Protocol.

Photo: Ledger

Ledger CEO Pascal Gauthier reacted with an odd mix of excitement and fear to news that Jack Dorsey was leaving Twitter to focus full-time on Square.

“Oh, shit,” was his immediate thought, he told Protocol. “I would have preferred him to stay with more companies and not focus on anything.”

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at bpimentel@protocol.com or via Signal at (510)731-8429.

In a tight labor market, businesses are competing for top talent, even as employees leave in droves. A record 4.4 million Americans resigned in September 2021 — the highest on record for nearly 20 years — ushering in what some call the Great Resignation. That same month, 65% of U.S. workers said they were looking for a new job.

Business leaders have to respond to mitigate the negative impacts of this disruptive churn, with 36% of CFOs saying they're very concerned about turnover remaining high indefinitely and weighing on revenue growth. The answers to this challenge should be informed by the root causes of employee dissatisfaction as well as retention drivers.

Keep Reading Show less
Suneet Dua, PwC
As PwC’s US Products & Technology Chief Revenue and Growth Officer, Suneet Dua is responsible for driving more than $1 billion in product revenue and executing PwC’s product revenue strategy. He’s focused on driving innovation, delivering world-class, forward-thinking products and digitally upskilling the workforce and society at large. With 20+ years of technology, media and entertainment industry experience, he’s positioned as a catalyst for organizational transformation and delivers on the firm’s promise to solve the world’s most important problems. Additionally, he launched Salesforce and client-focused centers of excellence, such as our Cybersecurity centers in Israel, Singapore and India––all to improve the way PwC serves its clients. During his tenure as US Chief Product Leader, Suneet, and his team, played a critical role in designing and implementing digital tools that upskilled more than 55,000 of its US employees, which led to the development of PwC’s digital learning platform, ProEdge, that addresses the digital skills gap crisis facing today’s workforce. He also serves as a board member of PwC’s Trifecta Consulting (US, China, Japan and Mexico). Previously, Suneet served on PwC’s US leadership team and was Global Client Market Leader for PwC’s Global Network.
Protocol | Fintech

A legal brawl failed to uncover bitcoin’s fabled creator

Is Craig Wright Satoshi Nakamoto? A trial didn’t lead to an answer.

Craig Wright has claimed to be the creator of bitcoin.

Photo: Eugene Gologursky/Getty Images for CoinGeek

A legal battle was supposed to answer the biggest question in crypto: Who is Satoshi Nakamoto?

Well, that didn’t exactly happen. The identity of bitcoin’s fabled creator remains a mystery, despite high hopes that an unusual civil suit would lead to Nakamoto’s unmasking.

Keep Reading Show less
Benjamin Pimentel

Benjamin Pimentel ( @benpimentel) covers fintech from San Francisco. He has reported on many of the biggest tech stories over the past 20 years for the San Francisco Chronicle, Dow Jones MarketWatch and Business Insider, from the dot-com crash, the rise of cloud computing, social networking and AI to the impact of the Great Recession and the COVID crisis on Silicon Valley and beyond. He can be reached at bpimentel@protocol.com or via Signal at (510)731-8429.

Snap CTO Bobby Murphy on embracing Apple’s AR glasses

Snap is building its own AR Spectacles, but the company also wants to embrace third-party devices.

Bobby Murphy wants Snap’s AR lenses to run everywhere — even on hardware made by competitors.

Photo: Getty Images for Snap Inc

Snap is all in on AR: The Snapchat maker has been building its own AR glasses, and is currently testing an early version with a small group of creators. Snap has also signed up 250,000 creators to build mobile-centric AR experiences through its Lens Studio platform, whose lenses have collectively been viewed over 3.5 trillion times.

Snap celebrated those milestones at its Lens Fest Tuesday, which the company also used to release a number of updates for both mobile and headworn AR. Snap CTO Bobby Murphy recently put that work in context in an interview with Protocol, in which he talked about the company’s progress in building AR Spectacles, why it isn’t focused on non-AR wearables anymore and why it ultimately also wants to build apps and experiences for AR devices made by its competitors.

Keep Reading Show less
Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Discord launches paid channel memberships

The company’s new subscription tiers effectively broaden the creator economy to include people managing communities.

Select Discord server creators can start charging membership fees as part of a new pilot program.

Image: Discord

Creating and managing successful communities can be a lot of work. Now, Discord wants to make sure that the people doing this on its platform can also reap some rewards: The company launched a pilot program for premium memberships Tuesday that allows community creators to put parts or all of their servers behind a paywall.

“We want to make sure that running communities on Discord is more sustainable,” said Discord Engineering Director Sumeet Vaidya in an interview with Protocol.

Keep Reading Show less
Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Latest Stories
Bulletins