In the modern-day, where we have luxuries such as the internet, it also brings many vulnerabilities. People in large numbers use social apps to communicate for personal, business, and other matters.
To much extent, we have compromised our privacy for the sake of using online services to benefit us. Well, itâs not even balanced at all; privacy matters much more than anything else. The online mafia is everywhere, and you canât hide from the prying eyes. But, by taking sensible measures and being precautious, you can avoid being played at the hands of attackers.
Recently, a group of two researchers revealed another rising privacy concern. Talal Haj Bakry and Tommy Mysk explained how link previews on messaging apps could leak your data.
Those who use chat apps must have gone through the link previews. When you send someone a link via a chat app, the app shows you a preview of what that link contains. Whether itâs a picture, document, or video, youâll see a brief description along with the image previewâwhich summarizes whatâs inside the link. This happens without tapping on the link.
SEE ALSO: Best secure messaging apps
Link Previews with threats
Now, this isnât that simple. Things gamble in-between this process, and there are different ways how an application shows you a link preview. There is a mechanism for how a link converts into a preview. This means that the app automatically tracks the link or uses a third party for âlink previewâ conversion.
The primary mechanism is HTML programming language tags or ad hoc meta tags, through which the app collects the information. If anything goes wrong, or the link is malware, your personal data and IP address would be in the wrong hands.
There are three ways through which an automated link preview is created. The researchers elaborated that how each way is used and can be harmful.
In the first method, the sender itself generates the preview. Next, the app downloads the link data and turns it into a preview. This means that the sender directly converts the URL into link preview, so potentially there is not much risk at all as the link preview would brief you on whatâs inside.
The second method is creating link preview via a third-party server. The app forwards the link data to an external server asking to convert it into a preview. After completion, the server sends back the link preview to both sender and receiver.
Whereas, in the third method, the receiving app creates the preview. This is quite harmful. Whenever the receiving app gets the link, it would automatically create the preview. For this, the app connects to the server that the link guides to. This means that your app forwards your IP address as part of the GET request. This happens without the user opening the link.
For instance, Facebook Messenger uses server-side link previewsâthe second method. The researcher told Forbesâ cybersecurity expert that Messengerâs way to link preview could be a security ordeal. Facebookâs messenger doesnât provide link previews in secret conversations, which are end-to-end encryptedâinstead of in regular chats, where all the risk lies.
In this method, we do not know how much information the third-party server collects or for how long that data stays on the external server, said the researchers.
The researchers also highlighted that chatsâ links might contain intense private data only meant for the recipients. This could be anything such as medical records, contracts, official documents, research papers, or any confidential information, which leaves a severe security threat.
While in the third method, if you were to open the link, itâs okay. But, if in case you were not to open the link, it would still have your information leaked. This could leave you vulnerable in case of a malware link.
How to stay safe from link preview threats?
You can stay safe from link preview threats by using a tool like a virtual private network (VPN), that would hide your IP address and location online. Using VPNs is the best quick privacy safety measure to take today, whether itâs the link preview threat or any other.
Another recommendation to strengthen your security against such threats is to use a quality antivirus.
You might also want to compare VPN with antivirus to see how they both boast distinctive functions that can help you stay secure. Keep in mind that a little ignorance can make you fall victim to link preview threats.
For now, there is nothing more you can do unless the developers work on this and provide a much more secure network. The security threats are thereâin one way or another. So, the possible way to prevent yourself from harmâs way is to practice the best security measure.