16 ms·
Facebook Scans What You Send Other People on Messenger App
- p49k 9y agoThis actually sounds reasonable; most other messaging programs do the same in order to provide previews, thumbnail images, scan for malicious links or spam, etc.
- DRAGONERO 9y agoDoes Apple do this with iMessage? I don't think they can, even.
- criddell 9y agoThey could. Correct me if I'm wrong but users don't see which public keys have been used to encrypt the message's symmetric key. Theoretically Apple could easily and invisibly include themselves as a recipient.
- nstj 9y agoYou're exactly right and I'm not sure why this is being downvoted. Apple can add additional keys to iMessage messages and thus view them in transit - they say this themselves in their own security white paper[0]. [0]: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- oarsinsync 9y ago> Apple can add additional keys to iMessage messages and thus view them in transit - they say this themselves in their own security white paper I just read the section on iMessage (from around page 49) and I can’t see where this is written. Can you point to the part where they say this?
- nstj 8y agoPage 51: > The private keys for both key pairs are saved in the device’s Keychain and the public keys are sent to Apple’s directory service (IDS), where they are associated with the user’s phone number or email address, along with the device’s APNs address.
- mrep 8y agoI'm no security engineer but wouldn't that require Apple to have access to the private key, whereas the whitepaper says they only have access to the public key?
- ryanlol 8y agoApple can associate their own public key with the users phone number, then they will be able to read messages sent to that user.
- dvfjsdhgfv 8y agoThey can't mess up with the private key (at least this is what they say, and we can't verify that as their software is closed source). But they're free to manipulate the public key which is used during the encryption phase. For Apple as a company, not having access to iMessages is the safest thing to do, and I believe them when they say they can't access them in the current setup and are not willing to change that. It's because this would change their status from hardware/software vendor to telecommunications provider, with all related problems and costs - and they don't need any of these, so the best option is just to shield themselves from any user-to-user communication.
- criddell 8y agoI don't think so but I'm not a security expert either so I might have this wrong. If you send a group message, Apple provides your messaging client with all of the recipients' public keys that are used to encrypt the symmetric key that actually protects the message. They could slip their key into that list and I don't think you would be able to easily tell if they did that. If you send a message to a single person, then that's just a group of one. The interesting question to me is if Apple can be compelled to write code to do this if they haven't already done so (and I don't think they have). I wouldn't think they could be forced, but like Microsoft did with Skype, they might do it anyway.
- pmlnr 9y agoThis is not the provider's jurisdiction to do; let local security suits deal with it.
- Spivak 9y agoThis just in: Gmail scans every user's incoming emails in a controversial project they're calling a 'spam filter'.
- tristanj 9y agoOld news. Facebook has been doing this since at least 2009, I recall seeing an article where Facebook censored all links (including those in private messaegs) to thepiratebay.org [0] They also crawl links you share in private messages to grab the title, intro, and favicon to generate that clickable widget link thing. [0] https://torrentfreak.com/facebook-blocks-all-pirate-bay-links-090408/ https://torrentfreak.com/facebook-blocks-all-pirate-bay-link...
- djsumdog 9y agoYep, very old news. They also blocked URLs to competitors claiming the links were spam. Even if you legit posted the link, Facebook didn't notify you the message didn't send. It just failed silently.
- mehrdadn 9y ago> They also blocked URLs to competitors claiming the links were spam. Even if you legit posted the link, Facebook didn't notify you the message didn't send. It just failed silently. Any links to more reading on this?
- baq 9y agoAnecdata - I remember that.
- mehrdadn 9y agoThanks! I wasn't trying to question its validity, was just curious how bad/blatant it was, how often it happened, what kinds of links it happened to, etc.
- drusepth 9y agoHere's one from back when Google+ launched and they blocked G+ invite links for about a week.[1] If I recall correctly, there was something similar that happened about a year later where Messenger messages with a G+ profile URL would silently fail to send. I can't remember the details on that though. [1] https://www.zdnet.com/article/google-facebook-is-blocking-google-invite-links/ https://www.zdnet.com/article/google-facebook-is-blocking-go...
- username223 9y ago> "For example, on Messenger, when you send a photo, our automated systems scan it using photo matching technology to detect known child exploitation imagery or when you send a link, we scan it for malware or viruses," a Facebook Messenger spokeswoman said in a statement. "A Facebook Messenger spokeswoman" who wouldn't put her name to the statement? Ugh. Child porn is terrible, but very few people produce it or want to look at it. On the other hand, opaque and unaccountable algorithmic censorship hurts everyone.
- barryduffman 9y agoIf they didn't scan and detect child porn, there would be articles about how they're letting people get away with sharing child porn on Messenger. It seems there's no way for Facebook to win here, given that people want both complete privacy and also no illicit activity on the platform.
- lostlogin 9y ago> If they didn't scan and detect child porn, there would be articles about how they're letting people get away with sharing child porn on Messenger. No there wouldn’t be. Do you hear that about iMessage, SMS, email or the numerous other services?
- barryduffman 9y agoGoogle does scan for child pornography in Gmail: https://www.pcworld.com/article/2461400/how-google-handles-child-pornography-in-gmail-search.html https://www.pcworld.com/article/2461400/how-google-handles-c.... This is done with PhotoDNA, a system used by many large tech companies for child pornography detection: https://en.wikipedia.org/wiki/PhotoDNA https://en.wikipedia.org/wiki/PhotoDNA.
- lostlogin 9y agoThanks for that link - I can’t edit my above comment now to note that some scanning does happen. I wonder how well it works, as the false positive rates must be huge? The idea of someone looking at my account and playing abuse/not abuse roulette is disturbing.
- monochromatic 9y agoI would be shocked if they didn’t.
- hmate9 9y agoOfcourse they do. On one hand it’s absolutely surprising that such a piece is considered “news” but on the other hand at least the general public (not just people in CS) are paying more attention to their privacy. But in this case I think it’s 100% fine, even expected in order to stop bad content (porn, abuse etc) from going through
- pmlnr 9y agostopping "Bad content" is a slippery slope, especially on a network, where most only talk to people they actually know and who are usually using real identities. Keep in mind it's private messaging we're talking about.
- criddell 9y agoTransparency would help. If they told you what was being blocked and why and also gave the recipient the option to override the block, then I think the slippery slope problem is minimized.
- drngdds 9y agoIt's really not a dangerous slippery slope. If Facebook starts moderating messages too harshly, people will just move to another platform.
- 908087 8y agoI heard the same thing about Facebook and Google invading privacy "people will just move to another platform if they start getting too creepy!". Still waiting on that...
- StanislavPetrov 8y agoExcept of course that Google and Facebook manipulate the data you see so that it becomes much, much harder (if not impossible) for any competitor to gain traction because they are blocked or buried on page 50 of search results.
- StanislavPetrov 8y ago
- Kuraj 9y agoOf course they do.
- dominotw 9y agoduh..
- koko775 9y agoCoin sorting machines scan money you put in coin tubes, too.
- teaneedz 9y agoJust another reason to avoid Facebook products : Facebook, Messenger, Instagram, WhatsApp ... I think E2E encrypted messaging is the only social solution that makes sense in today's ad tech pervasive tracking world.
- deleted 9y ago[deleted]
- nbvt45 9y agoWhatsApp is E2E encrypted
- pmlnr 9y agoAnd also closed source, so no real way of auditing this promise.
- sp332 9y agoYou can audit the binary. It's not a magic black box.
- pmlnr 9y agoThe server part as well?
- sp332 9y agoIf you can be sure that the part running on your phone encrypts the message, then it doesn't matter as much what's running on the server. Anyway being open source wouldn't improve the auditability of the server.
- cesarb 9y agoThe whole point of it being E2E encrypted is that you don't need to audit the server. As long as it's implemented correctly on the client, both users verified the shared key out-of-band, and both users have enabled the option to warn when the shared key changes, the most the server can do is traffic analysis or denial of service.
- fwdpropaganda 9y agoHold on. Wasn't Facebook Messenger supposed to be encrypted E2E? EDIT: Ok, from the responses I get I was confused. Maybe Allo? Skype? I'm sure someone else other than Signal and WhatsApp were using Signal's protocol. Just ignore this post.
- marksomnian 9y agoNope. Not unless you explicitly enable Secret Conversations.
- pmlnr 9y agoNo. What made you think it was?
- Spivak 9y agoYou're probably thinking of WhatsApp?
- nstj 9y agoYou are correct, Messenger "Secret Conversations" uses E2E with the Signal protocol[0] [0]: https://www.wired.com/2016/10/facebook-completely-encrypted-messenger-update-now/ https://www.wired.com/2016/10/facebook-completely-encrypted-...
- TYPE_FASTER 9y agoWhen our daughter was born, and I sent an announcement via GMail, I started seeing ads for diapers. After that, I assume anything I'm doing on the internet is being data mined for advertising or some other source of revenue.
- alex- 9y agoI think most people, at some level, know this and accept it. I think the shock comes when you think how long this information is kept for, and what that means. i.e. each year they can advertise age appropriate birthday presents, a few years from now they might get adverts for children party suppliers. As they grow up college saving funds, colleges, trips to Disney land, first cars can all be targeted to you at just the right time.
- rectang 9y agoThe shock is that it's exploitable by political actors who people are opposed to. That's what's getting attention these days.
- jerf 9y agoI just hope people, including a lot of people reading this, remember this for longer than two or three news cycles. Just because Not-Trump gets into power someday doesn't mean that he or she won't be followed by Not-Not-Trump. In fact, I guarantee the eventual rise to power of Not-Not-Trump, because the only thing that would stop it is if Not-Trump successfully institutes totalitarianism, hardly a win. Our vigilance on this matter can't depend on how much we collectively do or do not like the people currently in power. That was a big mistake Silicon Valley made over the past decade and the bill is coming due in a big way.
- IIAOPSW 8y ago>I just hope people, including a lot of people reading this, remember this for longer than two or three news cycles. Name one thing that people remember for more than 2 news cycles.
- ktta 9y agoObligatory: Use Secret Conversations[1] if you have to use Facebook's Messenger. [1]: https://www.facebook.com/help/messenger-app/1084673321594605/ https://www.facebook.com/help/messenger-app/1084673321594605...
- colanderman 9y agoSo does Google with GTalk. In fact links sent via GTalk are modified to redirect through Google's servers.
- DeepYogurt 9y agoSo they mention the encrypted mode, but they don't confirm that facebook doesn't read those (either can't or won't). Can anyone confirm one way or another?
- nstj 9y agoI'm not sure why this is being downvoted - it's IMO one of the most important questions about this post.
- feelin_googley 9y ago"You can't watch your kids 24/7," reads one poster, which has a picture of Schumer, Zuckerberg, and a shirtless Anthony Wiener outside Facebook's New York offices. "BUT WE CAN." ... Schumer - who in 2016 railed that "a person's cellphone should not become a James Bond-like personal tracking device for a corporation to gather information" - has stayed relatively silent since Facebook's user data scandal with Cambridge Analytica broke last month." Source: https://nypost.com/2018/04/03/street-artist-taunts-schumer-over-his-daughters-facebook-job/ https://nypost.com/2018/04/03/street-artist-taunts-schumer-o...
- 908087 8y agoI really wish I could find a source that has a picture of this one: > "You can't watch your kids 24/7," reads one poster, which has a picture of Schumer, Zuckerberg, and a shirtless Anthony Wiener outside Facebook's New York offices. "BUT WE CAN."
- fourthark 8y agohttp://www.dailymail.co.uk/news/article-5573875/Street-artist-Sabo-mocks-Mark-Zuckerberg-posters-New-York.html?ITO=1490&ns_mchannel=rss&ns_campaign=1490 http://www.dailymail.co.uk/news/article-5573875/Street-artis...
- IIAOPSW 8y agoThe post reports on generic graffiti now? Are they that desperate to find their daily DeBlasio/Schumer/Cumo 2 min hate? Can they not just call random Democrats Communist to satisfy their readership? Could Sabo possibly find a more tenuous link between Schumer and Facebook? The fact that Sabo admits to having an unnamed financial backer coupled with the fact that this non-news is reported on in the Murdoch press makes me think this is some sort of guerilla marketing by an underhanded conservative firm similar to Cambridge Analytica.
- StanislavPetrov 8y ago>Are they that desperate to find their daily DeBlasio/Schumer/Cumo 2 min hate? Anyone who lives in New York doesn't need the Post for that.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- rco8786 9y agoWhy is this newsworthy? Did people think Facebook somehow didn't have access to what was being sent across its own platform?
- Shank 9y agoYes, they have access. The point is more that they have an automated system scanning and flagging messages, specifically so that they're reviewed by humans, for content they don't want on their platform. My landlord has access to my apartment, and I certainly don't expect them to just pop in and take things out that they don't like -- I at least expect some kind of notice. You can apply this to basically anything in the physical world, like mail. Having the capability to access does not equate to having permission to access.
- konceptz 9y agoIn many states (all of them?) landlords are specifically not legally allowed to “just pop in” without reasonable cause or sufficient notice. So yes I agree with your statement but in this example it’s already a law.
- rco8786 9y ago> Having the capability to access does not equate to having permission to access. So it would be ok if there was a 30 day delay on the messages Facebook was accessing? I don't understand your analogy.
- fencepost 9y agoThe point is more that they have an automated system scanning and flagging messages, specifically so that they're reviewed by humans, for content they don't want on their platform. Expect more of that due to the recently passed sex trafficking legislation that got Craigslist personals, reddit escorts and all sorts of other places shut down.
- BeetleB 8y ago>My landlord has access to my apartment, and I certainly don't expect them to just pop in and take things out that they don't like -- I at least expect some kind of notice. That is because there are laws preventing them from doing it (both the theft and the entry without notice). And I did live in a state that allows them entry without prior notice. And they did do it. And it didn't bother me because they clearly have the right to do so. >You can apply this to basically anything in the physical world, like mail. Again, very clear legislation on this. I believe it is an explicit felony to open other people's (physical) mail. >Having the capability to access does not equate to having permission to access. Yes, but sans any legislation, doing stuff on their platform does equate to having permission to access - especially if there is no legal contract (e.g. terms of service, privacy policy, etc) stating otherwise. I honestly don't get this. In the old days people (including me) ran message boards on this web site. There was no shock when the owner of the message board deleted posts or put filters, etc.
- deleted 9y ago[deleted]
- bistro17 9y agoif you are in europe here is a template of an email you can send in post GDPR world - https://sixthvariable.com/?p=6 https://sixthvariable.com/?p=6
- kingosticks 9y agoI don't think you even had to actually send anything. Don't they grab everything you type, even if you delete it all before clicking enter (when you calm down quick enough)?
- langitbiru 9y agoYann LeCun (the famous Deep Learning researcher) gave the reason behind this: "WhatsApp uses end-to-end encryption. Facebook Messenger doesn't, which allows it to provide enhanced services using AI-based content understanding (the information is not shared with 3rd parties). Both are owned/run by Facebook. It gives you a choice." https://twitter.com/ylecun/status/977746081877512193 https://twitter.com/ylecun/status/977746081877512193
- balls187 9y agoThis should be a surprise to no one, and is not unique to Facebook. Gmail has been scanning the email it's servers receive since it's inception. Initially this was to show ad relevancy. Once your email content became more valuable than showing ads, Google removed ads.
- stvswn 9y agoGoogle shows ads on Gmail under the Promotions tab. It does not scan emails to target ads. https://support.google.com/mail/answer/6603 https://support.google.com/mail/answer/6603
- balls187 9y agoIt does not scan email for ad-targeting anymore https://www.nytimes.com/2017/06/23/technology/gmail-ads.html https://www.nytimes.com/2017/06/23/technology/gmail-ads.html Google has enough data on you that it no longer needs to scan email to show you relevant ads.
- Jerry2 9y agoFTA: “For example, on Messenger, when you send a photo, our automated systems scan it using photo matching technology to detect known child exploitation imagery Ah yes, the "Think of the children" [1] argument. This is the favorite argument of censorship [2] lawmakers, dictators and everyone who wants to destroy personal liberties and privacy. They always invoke "think of the children" arguments because you look like a monster if you oppose it. [1]: https://en.wikipedia.org/wiki/Think_of_the_children https://en.wikipedia.org/wiki/Think_of_the_children [2]: http://www.abc.net.au/news/2014-01-31/wolf-internet-censorship/5229690 http://www.abc.net.au/news/2014-01-31/wolf-internet-censorsh...
- saboot 9y agoWhat do you propose as an alternative? This isn't govt mandated censorship, it's a private company not wanting to become a CP sharing portal.
- greggarious 9y agoI think the parent's (unstated) implication is that a system that can detect and block from a list of CP hashes could also be used to block any other content. For example, let's say I create an eye catching flyer image detailing locations for a peaceful protest against the firing of a Mueller. Such a system could be used to block it. Right now no one opposes building it, but the capacity once created can be easily abused.
- Raphmedia 9y agoDon't fool yourself. There's nothing stopping any pedophiles from sending links to private websites where their content is hosted. Saying that they are scanning anything to "think of the children" is simply being naive.
- tzahola 9y agoAs if pedophiles would send their stuff in the clear...
- reaperducer 9y ago
- linuxftw 9y agoThere seems to be a cottage industry around making words more palatable when it comes to tech privacy. "Scans" should be "reads and stores" "What you send to other people" should be "private messages, images, and videos" "What you send to other people" implies that there was no expectation of privacy in the first place, which (while true) I think does not match the 'normal' person's expectations or understanding. News organizations need to be more candid with the public about how their information is being inspected and stored instead of using slick language to downplay the distasteful practices of many organizations.
- aserafini 9y agoAnother example of charitable sanitisation: referring to personal data being 'monetized' rather than 'sold'. Information is sold when advertisers can target sets of users based on their personal data.
- jpttsn 8y agoBut, if I sell you an ebook, you would expect a copy to read, right? Accusing Facebook of selling data makes it easy for them to rebut: no data changed hands. Similar to accusing copyright infringers of “stealing” movies. It muddies the waters.
- linuxftw 8y agoI disagree. If I can query some API and it gives me some output, the data has changed hands. I can't really imagine a system where one has 'access' to data and does not receive it, unless it's in some kind of "Data Library" and nothing is allowed to leave the premises.
- fouc 8y agoThat's true. Maybe it's better to accuse companies of "selling access to the person". Such as if you were eating at a restaurant and touts came directly in and started trying to sell you various things. Where the touts had paid off the business for access to your person.
- nstj 9y agoSo Facebook Messenger has the option of end-to-end encryption of chats when you use "Secret Conversations", which are encrypted using the Signal Protocol [0], [1] Is there any indication that FB doesn't scan the contents of these messages before encrypting them with your own key and sending them across the wire? [0]: https://www.facebook.com/help/messenger-app/1084673321594605?helpref=uf_permalink https://www.facebook.com/help/messenger-app/1084673321594605... [1]: https://www.wired.com/2016/10/facebook-completely-encrypted-messenger-update-now/ https://www.wired.com/2016/10/facebook-completely-encrypted-...
- Mandatum 8y agoHave tested this myself with known bad links (ie malware, spam and piracy websites). None were blocked. Steve Weis was involved in its development (previously PrivateCore, Google Security Engineer where he developed 2FA and the keyczar library) and jumped on the defense after it was initially announced. Earlier versions were reviewed externally by some pretty well-known cryptographers. That being said, meta-data around use of E2E encryption in Messenger is still an issue since it's not enabled by default.
- nstj 8y agoOh nice one. Did the links get blocked when Messenger was in “non-Secret” mode?
- Mandatum 8y agoYep. Same with the Apple crash character bug from a few weeks ago. Also when linking .EXE's and .SCR's, I didn't see any hits on the server. Facebook blocks direct linking to executable files, and usually does a HEAD request against the web server - in this case I didn't see anything when sending via Secret.
- nstj 8y agoGreat catch - appreciate the follow up.
- mobilemidget 9y agoNot a FB user here, but with all this bad press going non stop, I start to wonder how can I figure out who makes money on FB stock going down?
- egze 9y agoPuts buyers, calls sellers. Look up options.
- arijun 9y agoI think they were trying to insinuate there is some big player with a short on FB manipulating the news.
- koko775 8y agoNot outlandish, but also not aware of any evidence: https://slate.com/technology/2018/02/facebooks-influence-has-long-drawn-underhanded-attacks-from-rupert-murdoch-wired-reports.html https://slate.com/technology/2018/02/facebooks-influence-has...
- crb002 9y agoHAXL has been known for years.
- paulie_a 9y agoMessenger is such low quality garbage. People might receive a message, you might get a notification 2 months later. But you will always get a notification about some phantom message. The dark patterns, ugly UI and unreliability, all with zero privacy.
- acchow 9y agoThese problems are why I left gchat. Very unreliable multi-client syncing. Messenger has been rock solid for me.
- TaylorGood 9y agoAt some point Facebook will disgust the majority of their users. Today, as well, it goes public that not just to Cambridge but all their user database was "leaked" to advertisers. 2 billion. There is far too great of smart people at FB to not know. Right now it's being spun publicly to offset responsibility, but their entire business model is about what happens once the lights turn off...
- nameisu 8y agoi gonna guess even in whatsapp
- Romanulus 8y ago... and why the hell wouldn't they?
- ggg9990 8y agoSpeaking from experience, when Facebook didn’t do anything message scanning with messenger (allowed any person to send any message to anyone else) it was a tool for massive amounts of extreme personal abuse, blackmail, etc.
- lz400 8y agoIs the recent attack on Facebook a coordinated effort to kill Zuck's office run? Don't get me wrong, I think all the flak Facebook is getting is deserved but there's little in the revelations coming lately after Cambridge Analytica that is really new. However the media backlash is a lot, a lot bigger and more sustained that I thought it'd be, even here in HN. I'm not one for conspiracy theories but could it be partially orchestrated by some political powers that be to kill his political aspirations? Or even if it didn't start that way, I guess it could have been helped by this.
- rock_hard 8y agoOn top of that news outlets essentially lost almost all their web traffic after FB started focusing on meaningful connections in January. They are probably beyond pissed because of the ad revenue loses...wonder how many of them will fold soon?
- tyingq 8y agoI think his sort of awkward introvert style already marked him as not much of a threat politically. How would he do in a debate? Thus, not buying a conspiracy to keep him out of politics. It shouldn't be this way, but charisma is a base requirement in politics.
- lz400 8y agoI don't disagree but listening to the absolute nonsensical, lie riddled incoherent rambling of the current POTUS makes me believe I don't really know what charisma is.
- dvtv75 8y agoI just showed this to a friend of mine, who turned very white. It seems that she's been sending some rather saucy texts, plus a topless photo or two and a few panty shots. She went straight back to Facebook, though, and really doesn't seem to care that she's feeding the beast..
- mikroskeem 8y agoYep that's quite old news. They scan messages for offensive content and block messaging for few days if they find something.. let's say "interesting". For example, kids at school sending these "dank memes" to eachother and Facebook slaying bans to them.
- narven 8y agofacebook like any other company with social products, scans anything and everything, since the beginning till the day they die. thats what social companies do. they cannot survive without it. PS: this does not only apply to companies with social products.