Live data from Hacker News

Links sent privately through Facebook Messenger can be read by anyone

medium.com

11–20 of 70 posts

Re: Links sent privately through Facebook Messenger can be read by anyone

#11
post #7
post #5

Earlier quoted context omitted.

Not sure I'm comfortable with full disclosure as I still consider it potentially harmful (phishing mostly, or sending unsolicited emails without knowing the fb login email of a user) Maybe I should try to report it again on Hackerone, as this was reported through the old whitehat program and the guy who answered never fully addressed the issue or replied to my follow up

Sunlight it, if they won't change it. Bad publicity and bad behavior from other actors will only increase the likelihood that the bug gets fixed. If a company won't listen you've done your moral duty. The last step of responsible disclosure is publication. As a bonus, you'll probably even frontpage HN.

Agree.

Plus he has given lot of pointers so it's a matter of time someone find the comment and start trial-and-error to discover how to exploit the bug.

Re: Links sent privately through Facebook Messenger can be read by anyone

#12
post #2

FB also considers "won't fix" a bug I found a while ago that allows anyone to send anyone else on FB a spoofed email that comes from @facebook.com, without knowing their email address ¯\_(ツ)_/¯.

I'm not following how that's different than any other platform that receives email, From: addresses aren't verified. I can send you a message From: lpage@google.com to your gmail address, what difference does it make if I can send a message from any @facebook.com address, real or imagined, to you at your @facebook.com address?

Re: Links sent privately through Facebook Messenger can be read by anyone

#13
post #8

After hearing about people arrested for the content of their private chats on Facebook I basically act under the assumption that everything I do on Facebook is public.

Source? I'd really like to know more about this.

https://www.cnet.com/news/facebook-scans-chats-and-posts-for...

Re: Links sent privately through Facebook Messenger can be read by anyone

#16
This is one of the reasons many corporations have rules about only using internal messaging applications. Or, block external messaging apps. In environments I've managed, I've always enforced the rule: Anything confidential sent via a messaging app is no longer confidential.

Skype, Facebook & G+/GTalk have all "followed" URLs sent via their applications for at least a few years (that I have noticed). Anti-virus applications installed on computers have done it with URLs in email applications and such too.

One of the large A/V vendors (Trend or McAfee, I don't recall which) had a browser plugin that would follow all of your browsing activity. I used to be amused tailing logfiles to see a hit from a browser, then one of their corporate IPs with a "crawler"-like UA come along a few seconds later.

EDIT last line for clarity.

Re: Links sent privately through Facebook Messenger can be read by anyone

#19
post #17

How would you know the Graph ID number if someone doesn't explicitly tell it to you?

> I wrote a quick script that would take any identification number and increment it gradually to discover other links. It worked

Apparently the numbers, while non-sequential, are not sufficiently large and random to be 'unguessable'. Take a known point and look around it, see if you get something good.

Re: Links sent privately through Facebook Messenger can be read by anyone

#20
post #2

FB also considers "won't fix" a bug I found a while ago that allows anyone to send anyone else on FB a spoofed email that comes from @facebook.com, without knowing their email address ¯\_(ツ)_/¯.

Can't you just send someone an email to their facebookid@facebook.com since most people have a facebook email address and don't know about it? And then just use a fake from address of whatever@facebook.com?

This sends the email to the login email address, not to the @facebook.com address, you could fake the email headers but that'd get caught by most webmail filters as a spoof.

I think theoretically the @facebook.com email address is now supposed to redirect to primary email too, even though that doesn't really work for me (bounces back)

Post reply on HN