Deactivate Message previews at all (Leak of message contents to smartphone OS logs)
- Edited
User Story
As a WIRE user
i want to keep my WIRE conversation confidental
so that nobody can access it without my consent.
Rationale
Good: The WIRE mobile apps (iOS/Android) already offer an option to disable the preview of "sender name" and "message content" in the push notifications.
>> Use case 1 - other person watching:
I suggest that most people think this function is only useful to prevent other people from having a look at your phone screen when you are inattentive.
But there is a second and much more relevant use case:
>> User Case 2: Operating System log Push notification contents // Data extractions
Any OS (iOS / Android) is keeping a storage of all push notification messages. That storage is maintained inside the OS and not directly accessible. One you get an push notification all information will be permanently stored there and is therefore extractable with specialty software.
Conclusion
If WIRE is meant for high-stake communications and sensitive content - you should reduce the ways user can misconfigure the app or take a bad decision by configuring the app.
I recommend removing the option to activate "previews with content" entirely.
If the feature is retained, I kindly request an additional pop-up warning that explains the risk of full data exposure (use case 2) to the operating system.
Comments
0 comments
Please sign in to leave a comment.