Follow Us

New AIM instant messaging client poses privacy risks, says EFF

The Electronic Frontier Foundation warns, don't upgrade

Digital rights watchdog Electronic Frontier Foundation (EFF) is advising users of AOL Instant Messenger (AIM) not to upgrade to the next version of the instant messaging application because its features expose them to privacy risks.

Back in November, AOL revamped AIM with a new look and new functionality such as cross-device log syncing and on-the-fly media embedding in chat messages. The final version has not been released yet, but a preview one is available for users who wish to test it.

"The new preview version of AOL Instant Messenger raised privacy concerns for us when it was first introduced, first because it started storing more logs of communications and second, because it apparently scanned all private IMs for URLs and pre-fetched any URLs found in them," EFF said in a blog post on Tuesday.

The upcoming AIM client stores all chat logs on AOL's servers by default so that they can be accessed from multiple devices. However, despite the obvious usability benefits, this behavior poses privacy risks to users.

"AOL's intent is to make it easy to see the same messaging history even if you sign in from a different device, but the danger is that your private conversations are now available to, for instance, law enforcement agents with a warrant or a national security letter, or to criminals in the event of a data breach," EFF said.

The new AIM provides an off-the-record option which disables logging, but this can only be enabled on a per-contact basis and doesn't work for group chats. In addition, users of third-party clients like Pidgin or iChat, which are compatible with the AIM protocol, won't be able to use the option.

Another privacy-unfriendly feature implemented in the new AIM client is the automatic embedding of pictures and videos into messages. This works by crawling URLs pasted by users into their chat windows and rendering the media files they point to.

The preview version parses all URLs, regardless of their type and purpose. This includes links that lead to internal network resources, links that contain authentication data and links that trigger one-time actions.

EFF contacted AOL about its concerns and the company agreed to make some changes until the final release. These include providing better notice to users about how links are used and limiting the automatic crawling only to certain types of URLs.

"We appreciate AOL's willingness to discuss this with us and their openness to changing course in response to our concerns and will continue to watch to see how they implement what they've promised," EFF said.

However, the non-profit organisation is not satisfied with the progress made so far. For one, there is no option to disable link crawling, and for another, the update is not compatible with OTR (Off-The-Record) Messaging, an end-to-end encryption plug-in for Pidgin, Adium and other IM clients that support the AIM protocol.

"Bottom line: Because signing onto the new version of AIM permanently changes your account settings to log all conversations to AOL's servers by default, we recommend that existing AIM users do not upgrade," EFF said. "As always, we recommend users stay safer online by using chat clients that are compatible with OTR." AOL did not immediately return a request for comment.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Be the IT Superhero - Try Remote Supprot for Free

LogMeIn support can help you resolve PC, Mac and smartphone issues via the internet.

Find out more...

Site Map

* *