Private Links Shared on Facebook Messenger Aren't So Private: Report

Advertisement
By Ketan Pratap | Updated: 13 June 2016 18:02 IST
Highlights
  • The security researcher informed Facebook about the issue.
  • Facebook responded stating that the process was intended.
  • Facebook is not likely to fix the issue as per researcher.
Private Links Shared on Facebook Messenger Aren't So Private: Report

Privacy and security has been a contentious issue with all social networks, and Facebook is no exception. We've suggested to our readers to perform a digital clean-up to ensure their account is safe. However, a recent report suggested that a new vulnerability related to Facebook's Messenger app as well as online chat could allow an attacker to change or modify a conversation in the thread. The company however patched the bug fixing the issue.

Now, security researcher Inti De Ceukelaire in a Medium post has claimed that links shared privately on Messenger can be read by Facebook and developers with access to its API. Ceukelaire informed the company about the issue and was shocked to learn that "Facebook had no problems with privately shared links being accessible."

Ceukelaire was able to access the links using Facebook's crawler tool. The social giant describes the tool as, "Content is most often shared to Facebook in the form of a webpage. The first time someone shares a link, the Facebook crawler will scrape the HTML at that URL to gather, cache and display info about the content on Facebook like a title, description, and thumbnail image."

During his testing, Ceukelaire discovered that all the objects saved on Facebook such as images, status, or even a link was given a "unique, non-chronological identification number". He noticed Mark Zuckerberg was object number four on Facebook.

Advertisement

He noted that developers can request an object via Facebook API (an interface for developers) by its number which will return with the details "only" if they had permission to access. After some more searching, he decided to request a URL for the queried object and was given the link address. He then "wrote a quick script that would take any identification number and increment it gradually to discover other links," and discovered he was returned a list of URLs shared by users.

"[While] it's not possible to get links for a specific user, you could easily run through results all day* until you find something interesting. *Yes, Facebook does block excessive requests but there are ways to bypass that, e.g., using multiple access tokens and if needed, VPN's. Rate limiting won't stop someone who is determined," he added.

Advertisement

He pointed out that the results didn't confirm the user who shared the link but it was not hard considering the user ID was linked to the results shown. The researcher points out the shared links can sometimes carry personal details which the user doesn't intend to share with others.

"While you may only share links to funny cat videos with your friends, you should still be worried about this exploit. Sometimes, sensitive information (personal data, secret keys, ...) are included in links without you even noticing," adds Ceukelaire.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Apps, Facebook, Messenger, Social
Advertisement

Related Stories

Popular Mobile Brands
  1. Dell Launches Alienware 16 Aurora in India; Sale Begins on Prime Day 2025
  2. Vivo T4R 5G Tipped to Launch in India Soon With This Chipset
  3. iPhone 17 Pro Alleged Hands-on Images Leak Online
  4. Acer Iconia Tab iM11 With 11.45-Inch Screen, 7,400mAh Battery Debuts in India
  5. Lenovo Yoga Tab Plus With 12.7-Inch Screen, AI Features Launched in India
  6. Amazon Prime Day 2025 Sale: Check Early Deals on Smartphones
  7. Ray-Ban Meta Glasses Successor's Design Leaked via Alleged Renders
  8. Google Pixel 10 Pro Fold Spotted on Geekbench With 16GB RAM, Android 16
  1. iPhone 17 Pro Alleged Hands-on Images Offer Closer Look at the New Rear Camera Design
  2. Google Pixel 10 Pro Fold Listed on Geekbench With 16GB RAM, Octa-Core SoC and Android 16
  3. Ray-Ban Meta Glasses Successor’s Design Leaked via Alleged Renders; Launch Slated for This Year
  4. Apple Reportedly Plans to Launch iPhone 17e, M5 MacBook Pro, and More Devices in 2026
  5. Indian Startup QWR Unveils AI-Powered Smart Glasses Humbl, to Be Shipped Later This Year
  6. Elon Musk Says Grok Chatbot Is Coming to Tesla Vehicles by Next Week
  7. Amazon Introduces Rewards Gold Cashback Program Ahead of Prime Day 2025 Sale
  8. Vivo T4R 5G Tipped to Launch in India Soon; May Get MediaTek Dimensity 7400 SoC
  9. Musk's Starlink Receives India's Final Regulatory Nod for Launch
  10. Google Announces Rollout of Ads in AI Overviews in India, AI-Powered Ad Solutions
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.