3 ms·
Yeah, but this is nothing new. I run several sites whose (non-public) links are regularly scanned by Facebook after someone types them in a chat. Presumably the
by whitehat2k9 11y ago
Yeah, but this is nothing new. I run several sites whose (non-public) links are regularly scanned by Facebook after someone types them in a chat. Presumably they're doing this to scan and flag malicious websites/pages.
- guava 11y agoThe key point here is that the links are scanned by a 3rd party who are not related to Facebook (as far as we know).
- onion2k 11y agoThey could be intercepting the traffic anywhere between the author's network and Facebook though, not necessarily with any complicity on the part Facebook.
- psykovsky 11y agoWhat about SSL? Doesn't facebook use it?
- jcrawfordor 11y agoThe third-party does threat intelligence... I don't see how it's unreasonable to think that Facebook has hired them to perform malware/scam detection on links sent through chat. Given Facebook's policy, someone has to do it.
- rmxt 11y agoThat seems like quite a generous interpretation. Yes, that is an ostensible reason for the scanning [1], but to imagine that that is all they are doing with the information gleaned from the scans seems a bit naive. I would posit that sender, recipient, link, time, the page's content, and the conversation's context are forever stored in a database somewhere, waiting to be fed into the data analysis/advertising program du jour at some point in the future. Who owns that database or where the information ends up is probably a trip down the rabbit hole, and the posted article is a first step into it. [1] Facebook policy on interstitials for malware/malicious links https://www.facebook.com/notes/facebook-security/link-shim-protecting-the-people-who-use-facebook-from-malicious-urls/10150492832835766 https://www.facebook.com/notes/facebook-security/link-shim-p...