Live data from Hacker News

Links sent privately through Facebook Messenger can be read by anyone

medium.com

1–10 of 70 posts

Re: Links sent privately through Facebook Messenger can be read by anyone

#3
post #2

FB also considers "won't fix" a bug I found a while ago that allows anyone to send anyone else on FB a spoofed email that comes from @facebook.com, without knowing their email address ¯\_(ツ)_/¯.

That's pretty severe surely. Any more information?

Re: Links sent privately through Facebook Messenger can be read by anyone

#4
Facebook's response seems inadequate. Because let's be frank here:

1) There are obvious security concerns thinkable. For example, plenty of websites (google docs, dropbox etc) offer an 'anyone with this link can view document' option. Which is generally safe, given these randomly generated links usually contain > 100 bits of entropy. Access to the link is access to the document, and so the link is a PW.

2) This link can be publicly accessed, despite having only been published in an ostensibly private FB conversation. Facebook has now admitted that the contents of a private conversation can partially be public. That's ridiculous. Not just because it's not safe, there are more things that aren't safe (e.g. sending risque images on Snapchat). But mainly because it's against expectations. Snapchat told me on my first day of usage, in the app, that my friends can save my snaps and that I should keep this in mind, and while many users of Snapchat use it recklessly, I would guess that most are aware of the risks. Users carry much of the burden of responsibility now. But there's no such awareness of the risks of partial contents of a private facebook conversation not being publicly accessible, nobody is aware of this.

3) The response seems wholly unnecessary. It seems to me relatively trivial to require a security token to see this data, much like the rest of the chat itself.

Now I'm not particularly alarmed by the issue itself, it's one of those 'safety in numbers' kinds of things. A hacker would likely be more effective setting up a phishing website and buying an email database, than to collect links and then review them for sensitive data. But the response of FB feels inadequate and unnecessary to me.

Re: Links sent privately through Facebook Messenger can be read by anyone

#5
post #2

FB also considers "won't fix" a bug I found a while ago that allows anyone to send anyone else on FB a spoofed email that comes from @facebook.com, without knowing their email address ¯\_(ツ)_/¯.

That's pretty severe surely. Any more information?

Not sure I'm comfortable with full disclosure as I still consider it potentially harmful (phishing mostly, or sending unsolicited emails without knowing the fb login email of a user)

Maybe I should try to report it again on Hackerone, as this was reported through the old whitehat program and the guy who answered never fully addressed the issue or replied to my follow up

Re: Links sent privately through Facebook Messenger can be read by anyone

#7
post #5

Earlier quoted context omitted.

That's pretty severe surely. Any more information?

Not sure I'm comfortable with full disclosure as I still consider it potentially harmful (phishing mostly, or sending unsolicited emails without knowing the fb login email of a user) Maybe I should try to report it again on Hackerone, as this was reported through the old whitehat program and the guy who answered never fully addressed the issue or replied to my follow up

Sunlight it, if they won't change it. Bad publicity and bad behavior from other actors will only increase the likelihood that the bug gets fixed.

If a company won't listen you've done your moral duty. The last step of responsible disclosure is publication. As a bonus, you'll probably even frontpage HN.

Re: Links sent privately through Facebook Messenger can be read by anyone

#10
post #2

FB also considers "won't fix" a bug I found a while ago that allows anyone to send anyone else on FB a spoofed email that comes from @facebook.com, without knowing their email address ¯\_(ツ)_/¯.

Can't you just send someone an email to their facebookid@facebook.com since most people have a facebook email address and don't know about it? And then just use a fake from address of whatever@facebook.com?
Post reply on HN