WeChat promises to stop accessing users’ photo albums amid public outcry

A tech blogger claimed that popular Chinese apps snoop around users' photo libraries, provoking heightened public concerns over privacy.

A hand holding a smartphone.

A survey launched by Sina Tech shows 94% of the some 30,000 responding users said they are not comfortable with apps reading their photo libraries just to allow them to share images faster in chats.

Photo: S3studio via Getty Images

A Chinese tech blogger dropped a bombshell last Friday, claiming on Chinese media that he found that several popular Chinese apps, including the Tencent-owned chat apps WeChat and QQ, as well as the Alibaba-owned ecommerce app Taobao, frequently access iPhone users' photo albums in the background even when those apps are not in use.

The original Weibo post from the tech blogger, using the handle of @Hackl0us, provoked intense debates about user privacy on the Chinese internet and consequently prompted WeChat to announce that it would stop fetching users' photo album data in the background.

@Hackl0us said he tracked the apps' activities for seven days using a new iOS 15 feature called Record App Activity, along with a third-party app called App Privacy Insights. Screenshots of activity logs provided by @Hackl0us show that the three Chinese apps read his photos multiple times throughout the day with each read lasting up to 60 seconds.

"This is disgusting," @Hackl0us wrote. "Photos are a user's private [possession]. They have no idea when the apps fetch their private data. Judging from the log, the apps read the photo library even while the user is asleep."

Chinese web users reacted strongly to @Hackl0us' findings. His original Weibo post trended on the platform's hot search chart last Friday. By the time of this writing, his post has been shared over 50,000 times, and nearly 220,000 people have liked it. A related hashtag has received 200 million reads. In a survey launched by Sina Tech on Weibo, 94% of some 30,000 respondents said they are not comfortable with apps reading their photo libraries.

WeChat, one of the most frequently used apps in China with over 1.2 billion users, immediately responded through Chinese media. The company explained that an Apple protocol, which web users identified as the PHPhotoLibraryChangeObserver, notifies app developers of changes that occur in their user' photos libraries. The protocol allows an app to track changes within and outside the app. When an app receives those change messages, the iOS 15 system records the activity as if it were photos being read on a user's phone.

WeChat explained this protocol allows users to share photos faster in chats, causing a preview of the last photo in a user's album to pop up. WeChat stressed in its statement that the processing is on-device, and that app was able to do this because users gave their consent by authorizing WeChat to access their albums.

"We do not collect, save, or upload any images from a user's album without the user's authorization," a Tencent spokesperson wrote in a statement shared with Protocol.

WeChat promised that it would withdraw the background fetching protocol in its next update, and it is finding an alternative to "optimize the quick picture sending function.

But WeChat's statement didn't fully address privacy concerns. In a Zhihu article where @Hackl0us documented his complaint, he wrote that WeChat's technical teams had reached out to him and explained why WeChat decided to enable the image posting feature through background data fetching. But @Hackl0us believes WeChat is breaking a butterfly on a wheel. He argued that WeChat could achieve the same feature in alternative ways without systematically reading photo libraries in the background. Not only does invoking this protocol intrude on user privacy, @Hackl0us said, it consumes unnecessary memory and battery at the expense of user experience.

"I really don't understand why WeChat needs to use Apple's PHPhotoLibraryChangeObserver protocol to implement such a simple feature," he wrote. "It's probably fine for one app to do this, but if many Chinese apps act like this, and they do, it will have a big impact on our phone's battery life."

Legitimate privacy concerns

Digital privacy experts told Protocol that app developers seeing a list of photo changes by itself offers very limited utility, but if the apps can access the photos themselves, they could exploit Apple's PHPhotoLibraryChangeObserver protocol to analyze user behavior or sentiment, which is of great commercial value. Apps could also run facial recognition algorithms to facilitate social mapping.

"WeChat is closed-source software, so it is impossible to know how the protocol is implemented, what it does, and whether it is commercialized by generating a library of fingerprints from user albums until we see the source code," @Hackl0us wrote in his Zhihu article.

The controversy over privacy occurred less than one month before China's privacy law, the Personal Information Protection Law (PIPL), becomes effective. This law will shield Chinese internet users from excessive data collection and misuse of personal data by tech companies. One big theme running throughout the law is ensuring the consumer's right to consent and the right to know how their information is being used. Data handlers are required to collect data only when necessary to provide certain services, and must secure user consent for the collection.

Without knowing more details of app developers' processes on the device and regulations, it's hard to know whether the action of frequently reading photo albums would violate the forthcoming Personal Information Protection Law, according to Graham Webster, a research scholar at the Stanford University Cyber Policy Center and the editor in chief of the center's DigiChina Project.

"One real question is whether on-device processes limited to functional needs for the app even constitute 'personal information handling' under the law," Webster told Protocol. "Meanwhile, it seems it would be impossible to know ahead of time whether a given photo qualifies as 'sensitive personal information.'"

Under PIPL, data handlers are required to obtain "separate consent" from users while dealing with "sensitive personal information" and inform them of the necessity of collecting such data as well as the impact on their rights.

The law is new. Companies and consumers should expect more detailed regulations to clarify questions like this. "Depending on the details, [the background fetching of albums data] could well be a legitimate privacy concern, even if it isn't one that's covered in the new law," Webster said.


Judge Zia Faruqui is trying to teach you crypto, one ‘SNL’ reference at a time

His decisions on major cryptocurrency cases have quoted "The Big Lebowski," "SNL," and "Dr. Strangelove." That’s because he wants you — yes, you — to read them.

The ways Zia Faruqui (right) has weighed on cases that have come before him can give lawyers clues as to what legal frameworks will pass muster.

Photo: Carolyn Van Houten/The Washington Post via Getty Images

“Cryptocurrency and related software analytics tools are ‘The wave of the future, Dude. One hundred percent electronic.’”

That’s not a quote from "The Big Lebowski" — at least, not directly. It’s a quote from a Washington, D.C., district court memorandum opinion on the role cryptocurrency analytics tools can play in government investigations. The author is Magistrate Judge Zia Faruqui.

Keep ReadingShow less
Veronica Irwin

Veronica Irwin (@vronirwin) is a San Francisco-based reporter at Protocol covering fintech. Previously she was at the San Francisco Examiner, covering tech from a hyper-local angle. Before that, her byline was featured in SF Weekly, The Nation, Techworker, Ms. Magazine and The Frisc.

The financial technology transformation is driving competition, creating consumer choice, and shaping the future of finance. Hear from seven fintech leaders who are reshaping the future of finance, and join the inaugural Financial Technology Association Fintech Summit to learn more.

Keep ReadingShow less
The Financial Technology Association (FTA) represents industry leaders shaping the future of finance. We champion the power of technology-centered financial services and advocate for the modernization of financial regulation to support inclusion and responsible innovation.

AWS CEO: The cloud isn’t just about technology

As AWS preps for its annual re:Invent conference, Adam Selipsky talks product strategy, support for hybrid environments, and the value of the cloud in uncertain economic times.

Photo: Noah Berger/Getty Images for Amazon Web Services

AWS is gearing up for re:Invent, its annual cloud computing conference where announcements this year are expected to focus on its end-to-end data strategy and delivering new industry-specific services.

It will be the second re:Invent with CEO Adam Selipsky as leader of the industry’s largest cloud provider after his return last year to AWS from data visualization company Tableau Software.

Keep ReadingShow less
Donna Goodison

Donna Goodison (@dgoodison) is Protocol's senior reporter focusing on enterprise infrastructure technology, from the 'Big 3' cloud computing providers to data centers. She previously covered the public cloud at CRN after 15 years as a business reporter for the Boston Herald. Based in Massachusetts, she also has worked as a Boston Globe freelancer, business reporter at the Boston Business Journal and real estate reporter at Banker & Tradesman after toiling at weekly newspapers.

Image: Protocol

We launched Protocol in February 2020 to cover the evolving power center of tech. It is with deep sadness that just under three years later, we are winding down the publication.

As of today, we will not publish any more stories. All of our newsletters, apart from our flagship, Source Code, will no longer be sent. Source Code will be published and sent for the next few weeks, but it will also close down in December.

Keep ReadingShow less
Bennett Richardson

Bennett Richardson ( @bennettrich) is the president of Protocol. Prior to joining Protocol in 2019, Bennett was executive director of global strategic partnerships at POLITICO, where he led strategic growth efforts including POLITICO's European expansion in Brussels and POLITICO's creative agency POLITICO Focus during his six years with the company. Prior to POLITICO, Bennett was co-founder and CMO of Hinge, the mobile dating company recently acquired by Match Group. Bennett began his career in digital and social brand marketing working with major brands across tech, energy, and health care at leading marketing and communications agencies including Edelman and GMMB. Bennett is originally from Portland, Maine, and received his bachelor's degree from Colgate University.


Why large enterprises struggle to find suitable platforms for MLops

As companies expand their use of AI beyond running just a few machine learning models, and as larger enterprises go from deploying hundreds of models to thousands and even millions of models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

As companies expand their use of AI beyond running just a few machine learning models, ML practitioners say that they have yet to find what they need from prepackaged MLops systems.

Photo: artpartner-images via Getty Images

On any given day, Lily AI runs hundreds of machine learning models using computer vision and natural language processing that are customized for its retail and ecommerce clients to make website product recommendations, forecast demand, and plan merchandising. But this spring when the company was in the market for a machine learning operations platform to manage its expanding model roster, it wasn’t easy to find a suitable off-the-shelf system that could handle such a large number of models in deployment while also meeting other criteria.

Some MLops platforms are not well-suited for maintaining even more than 10 machine learning models when it comes to keeping track of data, navigating their user interfaces, or reporting capabilities, Matthew Nokleby, machine learning manager for Lily AI’s product intelligence team, told Protocol earlier this year. “The duct tape starts to show,” he said.

Keep ReadingShow less
Kate Kaye

Kate Kaye is an award-winning multimedia reporter digging deep and telling print, digital and audio stories. She covers AI and data for Protocol. Her reporting on AI and tech ethics issues has been published in OneZero, Fast Company, MIT Technology Review, CityLab, Ad Age and Digiday and heard on NPR. Kate is the creator of and is the author of "Campaign '08: A Turning Point for Digital Media," a book about how the 2008 presidential campaigns used digital media and data.

Latest Stories