Security News Reading Time: 3 minutes

Threads, just another social media platform or a hacker’s dream? 

Social media platforms have completely changed how we communicate, share experiences, and maintain relationships in the age of digital connection. Recently Meta, the parent company behind social media platforms like Facebook and Instagram, launched a text-based app called threads, which has drawn attention because of its place in the social media ecosystem and the security issues it could present.

Since its launch on July 6, 2023, this app has amassed over 100 million users. It only took an hour to surpass a million users. Threads is a microblogging platform meant to be a direct competitor of the popular social media, Twitter. According to a Meta blog post, Threads is meant for “sharing text updates and joining public conversations.” It enables users to post text, links, images or videos and to like, comment, repost, or share content. 

How did Threads gain Popularity?

Threads gained popularity in a very short period since it was linked with another very popular social media platform. Creating Threads account is no hassle since it is integrated with Instagram, which has over 500 million daily active users globally. Instagram is mostly a photo/video sharing app, microblogging app Thread grabbed users’ attention very quickly, because it was something different. It also allows users to seamlessly share content between two apps, making it easy for Instagram users to translate to thread. The curiosity of trying something other than Instagram helped Threads gain its audience. 

Privacy Concerns regarding Threads

This new app of Meta has raised privacy concerns about the information it stores. According to its data privacy disclosure listed in AppStore, Threads could collect a wide range of Personal Information including health, financial, contacts, browsing and search history, location data, purchases, and “sensitive information”. The specificity and quantity of data and information that Threads can access provide a risk to the vast majority of users if it is misused by specifically targeting them. 

Threads App Privacy Policy

Threads is covered by Meta’s broader privacy policy, which also applies to Facebook and Instagram, two of its other social media sites. This policy explains how Meta collects information on everything you do, from creating accounts to clicking on or like things to making online friends to what device you use to access its products. It also monitors your activity on your device, including whether an app is running in the foreground or whether your mouse is moving, messages you send and receive, and information about purchases you make, including credit card details. 

How is Meta collecting data and its Privacy Policy

  • The launch of Threads in the European Union is on hold because it’s unclear how the company Meta handles user data and shares it across different platforms.
  • Many of the privacy issues with Threads stem from Meta’s past questionable privacy practices. There is no proof that Meta is being forthcoming about what it will do with sensitive private data or has explained its intentions clearly other than “because we want to.” Despite being a newcomer to the realm of social networking platforms, there is already a lot of information available on how Threads collects, saves, and shares user data.
  • The platform gives the company information regarding the posts users interact with and the people they follow. Threads privacy policy includes “the types of content you view or interact with and how you interact with it” as well as how frequently and for how long you use Threads.
  • The company’s privacy policy states that in addition to users’ Threads activity, it has access to GPS position, cameras, photographs, IP information, the type of device being used, and device signals such as “Bluetooth signals, nearby Wi-Fi access points, beacons, and cell towers.” When combined, this data may create an intricate and detailed map of people’s lives, especially when combined with all the data Meta already collects from Facebook, Instagram, and other social media.
  • The mass collection of data by Meta is for one goal – selling ads. Although Threads doesn’t run any ads in the meantime, it’s going to leverage ads in the coming future.
  • As of now, the information collected through this app can be used as a part of a larger collection of data which Meta uses to create ads on its other platforms.
  • The sensitive data this app collects includes, race, ethnicity, sexual orientation, biometric data, pregnancy status, politics, religious beliefs and all these data can potentially be sent to third parties, which can include marketers and law enforcement agencies. Such data if it lands on the wrong hands, can also lead to hate crimes and violence. The amount of data the app accesses, it can make any hacker excited about getting access to it and being very creative about it.

How is it affecting individuals?

Many individuals question the need to be concerned about the social media companies accessing their data as they’re not high-profile and do not engage with such media for controversial activities. They should realize that just because they’re safe today doesn’t mean that they’re safe tomorrow. We can see situations in countries like the US where certain marginalized people are often under attack. The value data holds are so much more; people become the product. So many things that an individual cannot even envision are being monetized; people think that they’re making certain decisions and formulating opinions, but in reality, those are being formed and decided for them. It’s necessary to consider a company’s history of how they tackle sensitive information. 

Mitigating the Risks

Users can take several steps to protect themselves from potential security threats while enjoying the benefits of Threads: 

  • Secure Account Practices

    For additional protection, create a strong, one-of-a-kind password for your Threads account and activate two-factor authentication.

  • Regular Updates

    Keep the app and the device’s operating system up-to-date to promptly address any security vulnerabilities.

  • Mindful Sharing

    Be cautious about sharing sensitive or private information, especially in photos or messages.

  • Limited Audience

    Regularly review and manage the close friends list to ensure only trusted individuals can access your shared content.

  • Educate Yourself

    To improve your online safety, keep up with the newest security best practices and potential dangers.

Conclusion

Threads stands out as a dynamic text-based communication and content-sharing platform, but it also brings forth heightened concerns about data privacy and security. While users can modify settings and limit access to personal information, the extensive data storage capabilities of Meta raise significant worries, given its history of data breaches.

To ensure a valuable and secure addition to the social media landscape, users must adopt proactive security measures and exercise caution when sharing personal data. By striking a balance between enjoying Threads’ features and safeguarding their online privacy, users can maximize their experience on the platform while minimizing potential risks to their sensitive information.

Encryption Consulting provides services related to data protection across the enterprise. Our services include CodeSign Secure: CodeSigning Solution, CertSecure Manager: Certificate Management Solution, PKI-as-a-ServiceHSM-as-a-Service. Please contact us at [email protected] for any queries regarding security solutions provided by us.

Free Downloads

Datasheet of Encryption Consulting Services

Encryption Consulting is a customer focused cybersecurity firm that provides a multitude of services in all aspects of encryption for our clients.

Download

About the Author

Surabhi Dahal's profile picture

Surabhi is consultant at Encryption consulting, working with Code Signing and development. She leverages her adept knowledge of HSMs and PKIs to implement robust security measures within software applications. Her understanding of cryptographic protocols and key management practices enables her to architect secure code signing solutions tailored to meet the requirements of enterprise environments. Her interests include exploring the realm of cybersecurity through the lens of digital forensics. She enjoys learning about threat intelligence, understanding how adversaries operate, and comprehend strategies to defend against potential attacks.

Explore the full range of services offered by Encryption Consulting.

Feel free to schedule a demo to gain a comprehensive understanding of all the services Encryption Consulting provides.

Request a demo