Live data from Hacker News

Facebook crawls links in PDFs you send in Messenger

twitter.com

91–100 of 165 posts

Re: Facebook crawls links in PDFs you send in Messenger

#91
post #48

Earlier quoted context omitted.

You can choose to enable e2e on Messenger

Because the key, nonce, result, and keyshare or Diffie-Hellman exchange are all done inside of messenger... why would anyone believe this is legit? It might be, IDK, but if it’s all inside their system, how could you audit that?

This argument applies to any messenger app that claims e2e encryption. You could build signal from source. But how much do you trust your compiler?

Re: Facebook crawls links in PDFs you send in Messenger

#92
post #18
post #10

Earlier quoted context omitted.

How do you know if they're malicious if you don't make HTTP requests to them? One of the things that phishers and others do is use link wrapping and other services to hide malicious links. So, I get something.wordpress.com/something-clean. I then put in an HTML or JS redirect on that page to something malicious. Given that browsers don't warn about HTTP, HTML, or JS redirects, it's an easy way for scammers to get aro…

But in this case, that doesn't help at all because facebook's crawler uses a predictable user agent string. You give a clean result to the facebook crawler and a malicious result to everyone else.

Not always, it masks UA and IPs when checking for ads content to uncover cloakers, so its within theit codebase to do this. Not sure why they’re not using it here.

Re: Facebook crawls links in PDFs you send in Messenger

#93

Huh, but why? I can totally understand scanning a PDF for links to look for malicious links to protect users. But that wouldn't involve actual HTTP requests to them. I'm struggling to imagine what purpose this could have.

Could be collecting the links so if a user blocks the sender after opening the pdf, and this is done at scale, they can infer it was one of the links and starts blocking them?

Or link support requests to people who received a certain link via message.

So basically data mining to feed a model that takes future actions in consideration.

Re: Facebook crawls links in PDFs you send in Messenger

#94
post #59

Earlier quoted context omitted.

Couldn't you sort of test this by enabling E2E, sending a link that was previously blocked, and seeing if it is still blocked? That would at least show some sign if it's all a sham or not.

That would guarantee absolutely nothing.

Agreed. There is nothing stopping the sender's app from parsing and reporting URLs in any and all content before e2e occurs... Even to FB servers

Re: Facebook crawls links in PDFs you send in Messenger

#95
post #15

Earlier quoted context omitted.

I remember the sheer awe when I first learned there was a huge open web outside of AOL. I'm sure people nowadays are aware of the rest of the web, but if the draw is minimal, they will likely get stuck in the same loops of well-trodden space.

A lot of the same people who kept that AOL walled garden alive, just migrated to Facebook. To them Facebook is the web, the restaurants they like are there, the tired celebs they worship are there and whatever crazed conspiracy theories someone told them at work or at church are under Facebook News. It's comfortable and I agree with you and like how you phrased it as "the same loops of well-trodden space."

Sort of like how all of us check Hacker News daily? Don’t act like we’re any better

Re: Facebook crawls links in PDFs you send in Messenger

#96

Earlier quoted context omitted.

Because the key, nonce, result, and keyshare or Diffie-Hellman exchange are all done inside of messenger... why would anyone believe this is legit? It might be, IDK, but if it’s all inside their system, how could you audit that?

This argument applies to any messenger app that claims e2e encryption. You could build signal from source. But how much do you trust your compiler?

I trust my compiler more than Facebook

Re: Facebook crawls links in PDFs you send in Messenger

#97

And if they didn't the headline would read: "Facebook fails to stop malicious and illegal content from being shared on their Network! Should they be shut down?!"

this sounds like a strawman to be honest because I haven't heard anyone rant about illegal music since probably 15 years, and if anything ever only politicians and not ordinary people. If we'd be talking really malicious stuff like chid pornography then in the context of filesharing these companies already have systems in place to distinguish content, so blanket banning of torrent files seems blatantly unnecessary.

> this sounds like a strawman to be honest because I haven't heard anyone rant about illegal music since probably 15 years

This is the real strawman, as nobody on this entire thread is talking about illegal music. On the other hand, there's a strong and persistent thread of calls for tech platforms like Facebook to control "malicious or illegal" information being spread on their platforms: an obvious example is the NZ shooter's manifesto + video.

Re: Facebook crawls links in PDFs you send in Messenger

#98
post #30

Earlier quoted context omitted.

As always in big tech, you're damned if you do and damned if you don't.

So they might as well don’t; at least then we get some modicum of privacy.

This is certainly how I feel, but "damned if you do and damned if you don't" doesn't imply that the level of damnedness is equal. The balance between fettering "malicious" speech/activity and preserving privacy seems to be strongly tilting in the mainstream towards the former recently; "tech platforms have a responsibility to heavily police the content on their systems" is apparently a lot more resonant with most people than "tech platforms should preserve the privacy of their users".

Re: Facebook crawls links in PDFs you send in Messenger

#99
post #87

This will keep happening until they enable e2e. I’ve had Facebook block several links sent in private message groups, to completely legal and safe sites (Messenger prints out an obscure API error and refuses to send the content). They have done this for a long time.

Same can be done if e2e is enabled. Nothing prevents Facebook from sending links from client to a "validation" service. They do this already in WhatsApp for instance.

Maybe I'm being foolish, but isn't the point of e2e that Facebook wouldn't even know what you were sending (a link or otherwise), it being encrypted in flight?

Re: Facebook crawls links in PDFs you send in Messenger

#100

Earlier quoted context omitted.

this sounds like a strawman to be honest because I haven't heard anyone rant about illegal music since probably 15 years, and if anything ever only politicians and not ordinary people. If we'd be talking really malicious stuff like chid pornography then in the context of filesharing these companies already have systems in place to distinguish content, so blanket banning of torrent files seems blatantly unnecessary.

> this sounds like a strawman to be honest because I haven't heard anyone rant about illegal music since probably 15 years This is the real strawman, as nobody on this entire thread is talking about illegal music. On the other hand, there's a strong and persistent thread of calls for tech platforms like Facebook to control "malicious or illegal" information being spread on their platforms: an obvious example is the N…

Twitch didnt get deplatformed because a mentally ill person streamed murder on it, and you wont hear a peep about the other big chan. That had nothing to do with "protecting" (seriously? wtf) people from reading some mentally ill person's note, it was a problem-reaction-solution to axe an inconvienent site.
Post reply on HN