Links sent privately through Facebook Messenger can be read by anyone
medium.com
medium.com
1) There are obvious security concerns thinkable. For example, plenty of websites (google docs, dropbox etc) offer an 'anyone with this link can view document' option. Which is generally safe, given these randomly generated links usually contain > 100 bits of entropy. Access to the link is access to the document, and so the link is a PW.
2) This link can be publicly accessed, despite having only been published in an ostensibly private FB conversation. Facebook has now admitted that the contents of a private conversation can partially be public. That's ridiculous. Not just because it's not safe, there are more things that aren't safe (e.g. sending risque images on Snapchat). But mainly because it's against expectations. Snapchat told me on my first day of usage, in the app, that my friends can save my snaps and that I should keep this in mind, and while many users of Snapchat use it recklessly, I would guess that most are aware of the risks. Users carry much of the burden of responsibility now. But there's no such awareness of the risks of partial contents of a private facebook conversation not being publicly accessible, nobody is aware of this.
3) The response seems wholly unnecessary. It seems to me relatively trivial to require a security token to see this data, much like the rest of the chat itself.
Now I'm not particularly alarmed by the issue itself, it's one of those 'safety in numbers' kinds of things. A hacker would likely be more effective setting up a phishing website and buying an email database, than to collect links and then review them for sensitive data. But the response of FB feels inadequate and unnecessary to me.
This isn't really particular safe even if its unguessable, its more the internet equivalent of a casual privacy lock.
Skype, Facebook & G+/GTalk have all "followed" URLs sent via their applications for at least a few years (that I have noticed). Anti-virus applications installed on computers have done it with URLs in email applications and such too.
One of the large A/V vendors (Trend or McAfee, I don't recall which) had a browser plugin that would follow all of your browsing activity. I used to be amused tailing logfiles to see a hit from a browser, then one of their corporate IPs with a "crawler"-like UA come along a few seconds later.
EDIT last line for clarity.
From a legal and HR standpoint, those types of policies need to be documented for all employees. Senior managers may also have fiduciary responsibility and the reminder is generally a good idea.
Eg: they're scanning chats for discussions about criminal activities, and reporting what they find to the police. If some people plan a murder in Facebook chat, it goes unnoticed, and they commit the murder, the victim's family could potentially sue Facebook for providing a forum for the planning to take place. Facebook can no longer claim that they're not responsible for the actions of their users, because they're actively monitoring those actions and reporting to the police.
Just because Facebook is monitoring chat sessions, I don't think it's been established that that makes them liable for any activities which are planned over those chat sessions. They're augmenting the police, not replacing them.
The FCC classified Internet Service Providers as common carriers, effective June 12, 2015, for the purpose of enforcing net neutrality. Before that time, the Good Samaritan provision of the Communications Decency Act established immunity from liability for third party content on grounds of libel or slander, and the DMCA established that ISPs that comply with the DMCA would not be liable for the copyright violations of third parties on their network.
My understanding (which may be flawed) is that "ISP" covers things like discussion forums, public chatrooms, and private(ish) chat like Skype and Facebook Messenger, and that the liability immunity goes beyond libel and slander. But, ISPs that filter third-party content are not protected because they're exerting control over the content, and implicitly approve of anything that is not filtered.
[0] https://en.wikipedia.org/wiki/Common_carrier#Telecommunicati...
If I try to spoof my email to make it look like I'm sending it from @facebook.com, your webmail provider will tell you this email might be fraudulent (and likely place it straight in the spam folder)
With this method, you get a legit email from @facebook.com, but I can edit the content of the email to point to a url under my control
I'm looking at the headers of an automated message sent by Facebook (so-and-so shared a post), received by Gmail:
Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) XXX@facebookmail.com; spf=fail (google.com: domain of XXX@facebookmail.com does not designate ### as permitted sender)
This suggests to me DKIM and SPF are not weighted heavily to determine the legitimacy of a message from Facebook (or "Facebook") and filtering would be based more on the body of the message, as it often is, including the URL you specify. I don't see how Facebook email is less secure than email in general, email in general is not secure.
Maybe I should try to report it again on Hackerone, as this was reported through the old whitehat program and the guy who answered never fully addressed the issue or replied to my follow up
If a company won't listen you've done your moral duty. The last step of responsible disclosure is publication. As a bonus, you'll probably even frontpage HN.
Plus he has given lot of pointers so it's a matter of time someone find the comment and start trial-and-error to discover how to exploit the bug.
I think theoretically the @facebook.com email address is now supposed to redirect to primary email too, even though that doesn't really work for me (bounces back)
The Google Docs URL is public whether or not you send it through Facebook. It's only secret until someone guesses the link (Edit: maybe not mathematically in the case of Google Docs, but many other services use 'unlisted' URLs without having a long token to guess) - something they can do without the URL even going through Messenger.
If you're sharing passwords or confidential information via a public URL with no authentication and hoping nobody finds the address, you're asking for trouble. I don't blame Facebook for not doing anything about it.
Not really - a sufficiently large random number is effectively unguessable in your lifetime. This is no different than sharing a password with your partner in a private Facebook chat and discovering that outsiders can stumble on it.
Does anyone know what will happen when Facebook Messenger is encrypted end to end?
Title rating: unreasonably alarmist
Which is perfectly reasonable to do: a URL containing a cryptographically-secure identifier is itself a cryptographically-secure identifier. An example would be http://foo.invalid/ed2e898ff0b132202cb0bd0dea0d389a7b6439160....
Another example would be OAuth2 bearer tokens, which may be encoded in the URL as a parameter.
> It is only actionable if you can MITM or otherwise easedrop and find the graph ID.
It looks like the graph IDs are enumerable, rather than being high-entropy, so it looks like you can trawl through the graph looking for interesting objects.
I would much, much, much rather not have link previews than be open to this sort of simple exploit.
Seems like someone could just write a script to pull down a few thousand links, and then search for links from specific sites, private Google Docs documents, etc.
Having predictable, incrementing integers as IDs for public resources isn't a problem. The problem is most people perceive Messenger as a private chat, and don't expect their privately-shared links to be catalogued in a publically accessible, trivially crawlable object store.
https://freedom-to-tinker.com/blog/vitaly/gone-in-six-charac...
Precisely because of what the article says.
Apparently the numbers, while non-sequential, are not sufficiently large and random to be 'unguessable'. Take a known point and look around it, see if you get something good.