Live data from Hacker News

Links sent privately through Facebook Messenger can be read by anyone

medium.com

21–30 of 70 posts

Re: Links sent privately through Facebook Messenger can be read by anyone

#21
post #12
post #2

FB also considers "won't fix" a bug I found a while ago that allows anyone to send anyone else on FB a spoofed email that comes from @facebook.com, without knowing their email address ¯\_(ツ)_/¯.

I'm not following how that's different than any other platform that receives email, From: addresses aren't verified. I can send you a message From: lpage@google.com to your gmail address, what difference does it make if I can send a message from any @facebook.com address, real or imagined, to you at your @facebook.com address?

Ok, if I send you an email from facebookadminforsure@gmail.com with a link saying "Your Facebook account has been compromised" that takes to a phising page, you probably won't click.

If I try to spoof my email to make it look like I'm sending it from @facebook.com, your webmail provider will tell you this email might be fraudulent (and likely place it straight in the spam folder)

With this method, you get a legit email from @facebook.com, but I can edit the content of the email to point to a url under my control

Re: Links sent privately through Facebook Messenger can be read by anyone

#22
This probably isn't a popular opinion, but I fail to see how this is a problem with Facebook.

The Google Docs URL is public whether or not you send it through Facebook. It's only secret until someone guesses the link (Edit: maybe not mathematically in the case of Google Docs, but many other services use 'unlisted' URLs without having a long token to guess) - something they can do without the URL even going through Messenger.

If you're sharing passwords or confidential information via a public URL with no authentication and hoping nobody finds the address, you're asking for trouble. I don't blame Facebook for not doing anything about it.

Re: Links sent privately through Facebook Messenger can be read by anyone

#24
post #21
post #12

Earlier quoted context omitted.

I'm not following how that's different than any other platform that receives email, From: addresses aren't verified. I can send you a message From: lpage@google.com to your gmail address, what difference does it make if I can send a message from any @facebook.com address, real or imagined, to you at your @facebook.com address?

Ok, if I send you an email from facebookadminforsure@gmail.com with a link saying "Your Facebook account has been compromised" that takes to a phising page, you probably won't click. If I try to spoof my email to make it look like I'm sending it from @facebook.com, your webmail provider will tell you this email might be fraudulent (and likely place it straight in the spam folder) With this method, you get a legit ema…

> If I try to spoof my email to make it look like I'm sending it from @facebook.com, your webmail provider will tell you this email might be fraudulent (and likely place it straight in the spam folder)

I'm looking at the headers of an automated message sent by Facebook (so-and-so shared a post), received by Gmail:

Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) XXX@facebookmail.com; spf=fail (google.com: domain of XXX@facebookmail.com does not designate ### as permitted sender)

This suggests to me DKIM and SPF are not weighted heavily to determine the legitimacy of a message from Facebook (or "Facebook") and filtering would be based more on the body of the message, as it often is, including the URL you specify. I don't see how Facebook email is less secure than email in general, email in general is not secure.

Re: Links sent privately through Facebook Messenger can be read by anyone

#25

This probably isn't a popular opinion, but I fail to see how this is a problem with Facebook. The Google Docs URL is public whether or not you send it through Facebook. It's only secret until someone guesses the link (Edit: maybe not mathematically in the case of Google Docs, but many other services use 'unlisted' URLs without having a long token to guess) - something they can do without the URL even going through Me…

It's pretty much mathematically impossible to "guess a link" for a google docs or dropbox URL.

Re: Links sent privately through Facebook Messenger can be read by anyone

#26

This probably isn't a popular opinion, but I fail to see how this is a problem with Facebook. The Google Docs URL is public whether or not you send it through Facebook. It's only secret until someone guesses the link (Edit: maybe not mathematically in the case of Google Docs, but many other services use 'unlisted' URLs without having a long token to guess) - something they can do without the URL even going through Me…

A URL with a long random token is unguessable, same as your login token/session token is unguessable.

Re: Links sent privately through Facebook Messenger can be read by anyone

#27

This probably isn't a popular opinion, but I fail to see how this is a problem with Facebook. The Google Docs URL is public whether or not you send it through Facebook. It's only secret until someone guesses the link (Edit: maybe not mathematically in the case of Google Docs, but many other services use 'unlisted' URLs without having a long token to guess) - something they can do without the URL even going through Me…

> It's only secret until someone guesses the link - something they can do without the URL even going through Messenger.

Not really - a sufficiently large random number is effectively unguessable in your lifetime. This is no different than sharing a password with your partner in a private Facebook chat and discovering that outsiders can stumble on it.

Re: Links sent privately through Facebook Messenger can be read by anyone

#28

This probably isn't a popular opinion, but I fail to see how this is a problem with Facebook. The Google Docs URL is public whether or not you send it through Facebook. It's only secret until someone guesses the link (Edit: maybe not mathematically in the case of Google Docs, but many other services use 'unlisted' URLs without having a long token to guess) - something they can do without the URL even going through Me…

It's pretty much mathematically impossible to "guess a link" for a google docs or dropbox URL.

Google Docs maybe - but not every service that uses a similar mechanism.
Post reply on HN