Instagram DMs are no longer private — this common mistake could risk your security

Instagram DMs are no longer private — this common mistake could risk your security

Meta announced the change last week (Picture: Getty Images) After Meta announced it had removed end-to-end encryption (E2EE) on Instagram messaging last week, digital security experts are urging users to take extra precautions in the DMs. The social media giant — which also owns Facebook and WhatsApp — first introduced E2EE as an opt-in feature back in 2023, but has now decided to scrap it altogether due to low uptake. To many, this change may seem like little more than a technicality you can get away with ignoring; like a website ‘accept cookies’ box or app’s terms and conditions. However, according to Kamran Bahdur, technical director at FLR Spectron, the change means messages sent via the platform ‘are not fully as private as you may think’. ‘Without encryption, Meta can access, scan, store, and display message content,’ he tells Metro. ‘Messages can also be used for AI purposes [to train large language models].’ Users are advised to take sensitive conversations off Instagram (Picture: Getty Images) Javvad Malik, cybersecurity advisor at KnowBe4 compares it to missives becoming ‘more like postcards than locked boxes’, adding: ‘Most people aren’t sending state secrets, but privacy isn’t about guilt. It’s about boundaries. ‘You close your curtains at home not because you’re doing something illegal, but because you don’t want strangers looking in.’ Both experts advise people to take ‘sensitive conversations’ somewhere more secure from now on; Telegram, Signal and WhatsApp, for example, all have E2EE. What is end-to-end encryption? End-to-end encryption, often shortened to E2EE, is a security feature designed to keep messages completely private between the sender and the person receiving them. When it’s switched on, messages are scrambled into unreadable code as they’re sent, and can only be unlocked by the recipient’s device — meaning nobody in between, including the app itself, hackers or internet providers, can read them. Without end-to-end encryption, platforms may still protect messages while they travel across the internet, but the company running the service can potentially access, scan or store the contents of conversations. For the chats you do have on Insta though, it’s imperative you consider your privacy, because everyday information can be surprisingly valuable to the wrong people. Alongside the obvious – such as bank details – people should avoid sharing any personal data, such as dates of birth, home or work addresses, National Insurance numbers, medical information, private disputes, legal issues and security codes, as these could leave them vulnerable to identity theft and cyberattacks. This also includes things you may not normally think about, such as the answers to your password recovery questions (even when said in conversation), and screenshots or photos that may unintentionally reveal details, from a picture of your front door to a scan of your passport. How do you feel about Instagram DMs no longer having end-to-end encryption? This is concerning, I value my privacy.Check It doesn't bother me much, I don't use DMs for anything sensitive.Check I will switch to more secure platforms for private conversations.Check Kamran warns too much detail about your daily routines (when shared in real-time) should be avoided too, as it can ‘increase the risk of stalking’, while even biometric data in the form of clear facial images could be risky, since it ‘cannot be changed once out there’. Although the odd selfie is likely fine, modern facial recognition systems map unique physical features — such as the distance between your eyes, the shape of your jaw, nose structure and even skin contours — to create a digital ‘faceprint’. So, if a cybercriminal has a number of high quality images, as well as personal information, they can potentially use it to trick facial verification systems used by banks, payment apps and cryptocurrency platforms. WhatsApp, however, still has end-to-end encryption (Picture: Getty Images) Meta said in its statement that instructions will be provided for users who want to download and keep affected chats, but Javvad recommends deleting any sensitive conversations altogether to be on the safe side. Additionally, he highlights the importance of not linking too much personal context together in one place, and remembering that disappearing messages are not foolproof. ‘Privacy is not one setting; it is a habit,’ he says. ‘The danger is not just one message, but the pattern. A scammer, stalker, data broker or hostile partner does not need your whole life story in one go. They can build it from fragments. Instagram DMs often feel casual, but casual information can become very powerful in the wrong hands.’ Essentially, ‘anything that could help someone impersonate, manipulate, locate or profile’ you, puts you at risk. Chris Linnell, associate director of data privacy at Bridewell, echoes his concerns, telling Metro users should assume ‘anything shared in direct messages could potentially be accessed, reviewed or exposed’. ‘If privacy is a priority, people should familiarise themselves with the privacy and security features offered by different platforms and consider using services where end-to-end encryption is enabled by default,’ he says. ‘Even seemingly harmless details can be pieced together by criminals to target individuals or compromise accounts.’ Do you have a story to share? Get in touch by emailing MetroLifestyleTeam@Metro.co.uk. Arrow MORE: North Korean hackers are stealing passwords and data using fake Zoom calls Arrow MORE: Trump supporters who coughed up $100 for gold phone still waiting and may not get refund Arrow MORE: UK seaside town gets 2,000,000 tourists yearly – but it has one frustrating flaw

Original Source

Read the full article at Metro →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.