Live data from Hacker News

Facebook crawls links in PDFs you send in Messenger

twitter.com

41–50 of 165 posts

Re: Facebook crawls links in PDFs you send in Messenger

#41
post #4

Microsoft does this with Skype too. They say it's for detecting malicious links.

And I do appreciate that they're doing that even. I want that, just like I want spam filtering on my email.

It's what else might be going on with the link analysis that's worrisome.

Re: Facebook crawls links in PDFs you send in Messenger

#42
post #10

Huh, but why? I can totally understand scanning a PDF for links to look for malicious links to protect users. But that wouldn't involve actual HTTP requests to them. I'm struggling to imagine what purpose this could have.

How do you know if they're malicious if you don't make HTTP requests to them? One of the things that phishers and others do is use link wrapping and other services to hide malicious links. So, I get something.wordpress.com/something-clean. I then put in an HTML or JS redirect on that page to something malicious. Given that browsers don't warn about HTTP, HTML, or JS redirects, it's an easy way for scammers to get aro…

>How do you know if they're malicious if you don't make HTTP requests to them?

look-alike domains are phishing vector that don't require you to make an http request.

Re: Facebook crawls links in PDFs you send in Messenger

#46

This will keep happening until they enable e2e. I’ve had Facebook block several links sent in private message groups, to completely legal and safe sites (Messenger prints out an obscure API error and refuses to send the content). They have done this for a long time.

I have had similar experiences, numerous to be more exact. The latest was 10 yrs old WordPress blog living on WordPress.com subdomain, definitely not hacked. It was about science, to be more exact, about neurology.

Re: Facebook crawls links in PDFs you send in Messenger

#47

Are there any comparable hosted messaging services that don't do this?

signal/telegram

Signal actually does optionally offer previews for a handful of services, and they really jump through some hoops to make that safer:

https://support.signal.org/hc/en-us/articles/360022474332-Li...

The service being previewed doesn't know who you are because Signal acts as a proxy, Signal doesn't know what you previewed on that service because their client deliberately sends overlapping Range requests so that the preview size is rounded.

Re: Facebook crawls links in PDFs you send in Messenger

#48

This will keep happening until they enable e2e. I’ve had Facebook block several links sent in private message groups, to completely legal and safe sites (Messenger prints out an obscure API error and refuses to send the content). They have done this for a long time.

You can choose to enable e2e on Messenger

Re: Facebook crawls links in PDFs you send in Messenger

#49
post #43

This should not be news to anyone. Facebook scans all links posted in Messenger.

This is links INSIDE a pdf. Thats one step further than most people assumed.

Mostly to scan the PDF and ensure it's safe I believe, or atleast that's would be the stated reason.

Re: Facebook crawls links in PDFs you send in Messenger

#50
post #48

This will keep happening until they enable e2e. I’ve had Facebook block several links sent in private message groups, to completely legal and safe sites (Messenger prints out an obscure API error and refuses to send the content). They have done this for a long time.

You can choose to enable e2e on Messenger

[deleted]
Post reply on HN