Hacker News new | ask | show | jobs
by gridder 1887 days ago
When you are online anyone can check it. There is no option to hide the online status. Using an easy script anyone can then spy and understand pretty much everything of a person, or a group. This is easy cyber stalking and dangerous. Especially because normal people do not understand this and think that hiding last seen is useful to avoid being stalked…
3 comments

Do you mean any one of your contacts? or anyone who has your phone number? And I'm still confused about the definition of "online" and how that can give anyone an understanding of you.
Anyone with your number, and it reports when you have the application open. Assuming WhatsApp is the first and last app you open in the day (good morning and good night messages) you know how long a person sleeps, and this is only a very easy analysis you can do. I am sure you can find something more interesting recording when people open an app.
OK, yeah I agree that should be configurable, or at least limited to contacts. Maybe it should only count as online if you're actively using the app instead of having it open in the background. I'm sure many people just have it open 24/7. If I still used it, I would want an option to only receive messages when I'm online.
>Maybe it should only count as online if you're actively using the app instead of having it open in the background

Not sure about desktop clients and not sure about what you mean by "open in the background" in this specific case, but I can answer this for mobile WhatsApp apps specifically. For those, it only tracks when you actually have the app open in your main view.

More specifically, if you just have the app in the background while using some other app, it doesn't count as online. If someone sends you a WhatsApp message and you receive a notification but don't open the app itself, it doesn't count. Only when you actually open the app is when it shows you as being online.

Personally, I agree with you that the simplest solution that would already resolve a ton of those issues is to simply only display your "online" status to those who you have added to your contact list (instead of to literally the entire world).

" understand pretty much everything of a person, or a group."

How does this work - does it leak status or location, messages, contact lists etc? We have a number of folks who are absolutely freaking out over how folks are being killed because of this - can someone walk us through how it leaks all this info?

A quick note that I make my entire calendar public in terms of available times so that folks can schedule their time with me.

> We have a number of folks who are absolutely freaking out over how folks are being killed because of this

I can totally see that happening:

Person X suspects their partner is cheating on them with Person Y. So they start logging every time their partner is online and every time Person Y is online. Person X becomes obsessed with this theory of cheating and discovers a correlation between their online times, concluding that they're being cheated on, so they explode in rage and go kill their partner.

Um, my wife and I use the same code for all our devices - if your partner is developing this level of paranoia aren't there easier approaches to this question? Or maybe setup a separate whatsapp account to use for cheating if you are big into that so folks can't track you while you cheat?
You can absolutely hide it - it's in the settings, as mentioned in the article. The tradeoff is you won't be able to see anyone else's status.

I do agree I don't particularly like that it's on by default.

The parent commenter is talking about the "currently online" indicator, which can't be disabled. From a (strangely worded) WhatsApp doc:

> Please note you can't hide your online.

https://faq.whatsapp.com/general/chats/about-last-seen-and-o...

That’s one of the reasons I jailbreaked my phone, to be able to control which app can access which data and when.
your answer doesn’t make any sense in this context. this is a standard whatsapp feature that can not be turned off. you can disable networking and open whatsapp and that flag will not be sent, but also your conversations won’t get updated. jailbreaking doesn’t change any of this.
If you have root you could decrypt the traffic on the fly, and block any data that is not necessary for basic functionality. Maybe even run squid locally, and configure it there. I doubt that's what they meant, and it would take a bit of reverse engineering, but would be kind of fun.
https://watusi.fouadraheb.com/ Check the privacy features.