Why you shouldn't share links on Facebook
medium.com
medium.com
Really the problem is that several situations coincide which make the result surprising:
- It's not so bad that posting URLs to Facebook generates a link preview and saves that as a public resource in their Object Graph.
- It's not so bad that you can find the Object's object-instance-id by the URL.
- It's not so bad that Facebook correlates a bunch of information about that Object's relationship with other nodes in their graph.
- For data they believe is all-public, it's not so bad that object-instance-ids are not cryptographically secure and are trivially crawlable.
But when taken together, it -is- surprising that URLs shared through Messenger (a setting that most users would assume to be "private") can be trivially crawlable.
[1] https://developers.facebook.com/docs/sharing/opengraph/objec... [2] https://developers.facebook.com/docs/sharing/webmasters/faq
One would naturally assume private conversations are 100% private and not scrapable by some third party.
But I also think sites should never use personally identifiable information in the URL. There are much more sites that cause issues when sharing these kinds of URLs. To name a few: bit.ly, twitter, Comments in Hacker News.
Keeping information in URLs is fine as long as it has enough entropy to be unbruteforcable. Bit.ly and t.co don't, and so aren't secure.
I use HN comments as an example of an unsafe way to share URLs with personally identifiable information.