Facebook Scans What You Send Other People on Messenger App(bloomberg.com)
bloomberg.com
Facebook Scans What You Send Other People on Messenger App
https://www.bloomberg.com/news/articles/2018-04-04/facebook-scans-what-you-send-to-other-people-on-messenger-app
188 comments
I have the same initial reaction. However, even though we 1% of tech geeks that are paying attention and are aware of these things, how many of us have had people slightly tilt their head sideways in confusion when we try to inform them of this stuff. I'm sure we've all been labeled kooks, conspiracy nut, tin foil hat wearers, etc in the past.
This is one of those situations where the mass populace just didn't want to understand, couldn't understand or combination of both, but the mass populace is finally starting to see just how much of this tracking stuff has been going on. I still think it's not enough, though.
This is one of those situations where the mass populace just didn't want to understand, couldn't understand or combination of both, but the mass populace is finally starting to see just how much of this tracking stuff has been going on. I still think it's not enough, though.
It's similar to the activities of most anti-virus/malware agents on computers. Of course, one could argue those cases are focused much more on the security aspects, rather than Facebook's revenue-generating motives to see what you do for advertising purposes.
Yep, very old news. They also blocked URLs to competitors claiming the links were spam. Even if you legit posted the link, Facebook didn't notify you the message didn't send. It just failed silently.
> They also blocked URLs to competitors claiming the links were spam. Even if you legit posted the link, Facebook didn't notify you the message didn't send. It just failed silently.
Any links to more reading on this?
Any links to more reading on this?
Here's one from back when Google+ launched and they blocked G+ invite links for about a week.[1] If I recall correctly, there was something similar that happened about a year later where Messenger messages with a G+ profile URL would silently fail to send. I can't remember the details on that though.
[1] https://www.zdnet.com/article/google-facebook-is-blocking-go...
[1] https://www.zdnet.com/article/google-facebook-is-blocking-go...
Interesting, thanks. Also interesting last paragraph:
> Some speculate this could be a Google plot to spur distrust for Facebook while bringing more attention to Google+. I'm not sure the search giant would go that far, but I think it's telling the company's employees chose to post about the issue on their own social network rather than contacting Facebook directly and asking for an explanation.
> Some speculate this could be a Google plot to spur distrust for Facebook while bringing more attention to Google+. I'm not sure the search giant would go that far, but I think it's telling the company's employees chose to post about the issue on their own social network rather than contacting Facebook directly and asking for an explanation.
WhatsApp used to do this [1], and WhatsApp is owned by Facebook. They've since stopped.
[1] https://www.androidpolice.com/2016/09/09/whatsapp-is-blockin...
[1] https://www.androidpolice.com/2016/09/09/whatsapp-is-blockin...
They are blocking links to FBPurity.com right now.
Yes the mechanics of handling a message or posting or whatever is understood at some level by everyone and perfectly acceptable. What's troubling is that they associate all of it and more with a cumulative collection of information about a "persona" that is essentially permanent, and in the majority of cases they know who that persona belongs to. The individual concerned has no control over it. Further even FB et al do not have complete control how that persona is used or abused.
This is not old news and the examples you provided are not proof that they were doing it prior.
It is perfectly possible to crawl pages to get titles and FavIcons client side or using a web service that don't necessarily keep a log of these requests.
Same thing for censoring links. You can have a static list of disallowed domains and do all the filtering client side or have a web service that given a link returns true or false if it should be censored. It doesn't necessarily means it needs to be logged, kept, associated with a user or manually analyzed.
What we're seeing now is that facebook is actively looking at whole messages, that's a step up from the previous instances. It's still unclear if this is all automated or if some are manually reviewed. It's also unclear if these are associated with a user, or anonymized when analyzing them. Are these logged? How long are they kept for? Facebook should be more clear on how this all works. Otherwise we're just left guessing.
It is perfectly possible to crawl pages to get titles and FavIcons client side or using a web service that don't necessarily keep a log of these requests.
Same thing for censoring links. You can have a static list of disallowed domains and do all the filtering client side or have a web service that given a link returns true or false if it should be censored. It doesn't necessarily means it needs to be logged, kept, associated with a user or manually analyzed.
What we're seeing now is that facebook is actively looking at whole messages, that's a step up from the previous instances. It's still unclear if this is all automated or if some are manually reviewed. It's also unclear if these are associated with a user, or anonymized when analyzing them. Are these logged? How long are they kept for? Facebook should be more clear on how this all works. Otherwise we're just left guessing.
I have much better links. Here's one from 2012: Facebook scans chats and posts for criminal activity https://www.cnet.com/news/facebook-scans-chats-and-posts-for...
The program probably started a year earlier than that, since in 2011, Facebook announced they were using a tool called PhotoDNA to scan every image shared for underage content. https://www.facebook.com/notes/facebook-safety/meet-the-safe...
Regarding how Facebook crawls links shared in Messenger, there's this medium story I saw on HN a while back https://news.ycombinator.com/item?id=11875419
In that medium story, the Facebook devs claim accessing privately shared messenger links is a publicly documented behavior, citing the Facebook Crawler Docs. They quote: "The first time someone shares a link, the Facebook crawler will scrape the HTML at that URL to gather, cache and display info about the content on Facebook like a title, description, and thumbnail image." https://developers.facebook.com/docs/sharing/webmasters/craw...
I would update my original comment if I could, however the edit period has passed.
The program probably started a year earlier than that, since in 2011, Facebook announced they were using a tool called PhotoDNA to scan every image shared for underage content. https://www.facebook.com/notes/facebook-safety/meet-the-safe...
Regarding how Facebook crawls links shared in Messenger, there's this medium story I saw on HN a while back https://news.ycombinator.com/item?id=11875419
In that medium story, the Facebook devs claim accessing privately shared messenger links is a publicly documented behavior, citing the Facebook Crawler Docs. They quote: "The first time someone shares a link, the Facebook crawler will scrape the HTML at that URL to gather, cache and display info about the content on Facebook like a title, description, and thumbnail image." https://developers.facebook.com/docs/sharing/webmasters/craw...
I would update my original comment if I could, however the edit period has passed.
FTA:
“For example, on Messenger, when you send a photo, our automated systems scan it using photo matching technology to detect known child exploitation imagery
Ah yes, the "Think of the children" [1] argument. This is the favorite argument of censorship [2] lawmakers, dictators and everyone who wants to destroy personal liberties and privacy. They always invoke "think of the children" arguments because you look like a monster if you oppose it.
[1]: https://en.wikipedia.org/wiki/Think_of_the_children
[2]: http://www.abc.net.au/news/2014-01-31/wolf-internet-censorsh...
Ah yes, the "Think of the children" [1] argument. This is the favorite argument of censorship [2] lawmakers, dictators and everyone who wants to destroy personal liberties and privacy. They always invoke "think of the children" arguments because you look like a monster if you oppose it.
[1]: https://en.wikipedia.org/wiki/Think_of_the_children
[2]: http://www.abc.net.au/news/2014-01-31/wolf-internet-censorsh...
What do you propose as an alternative? This isn't govt mandated censorship, it's a private company not wanting to become a CP sharing portal.
I think the parent's (unstated) implication is that a system that can detect and block from a list of CP hashes could also be used to block any other content.
For example, let's say I create an eye catching flyer image detailing locations for a peaceful protest against the firing of a Mueller. Such a system could be used to block it.
Right now no one opposes building it, but the capacity once created can be easily abused.
For example, let's say I create an eye catching flyer image detailing locations for a peaceful protest against the firing of a Mueller. Such a system could be used to block it.
Right now no one opposes building it, but the capacity once created can be easily abused.
Don't fool yourself. There's nothing stopping any pedophiles from sending links to private websites where their content is hosted. Saying that they are scanning anything to "think of the children" is simply being naive.
As if pedophiles would send their stuff in the clear...
Based on the perp walks I've seen on TV they don't look exceptionally intelligent.
Some (off the top of my head, Taleb) advance the argument of survival bias:
Smarter criminals are less likely to get caught and so, are less likely to be offered a seat by Chris Hansen.
There seems to be a cottage industry around making words more palatable when it comes to tech privacy.
"Scans" should be "reads and stores"
"What you send to other people" should be "private messages, images, and videos"
"What you send to other people" implies that there was no expectation of privacy in the first place, which (while true) I think does not match the 'normal' person's expectations or understanding.
News organizations need to be more candid with the public about how their information is being inspected and stored instead of using slick language to downplay the distasteful practices of many organizations.
"Scans" should be "reads and stores"
"What you send to other people" should be "private messages, images, and videos"
"What you send to other people" implies that there was no expectation of privacy in the first place, which (while true) I think does not match the 'normal' person's expectations or understanding.
News organizations need to be more candid with the public about how their information is being inspected and stored instead of using slick language to downplay the distasteful practices of many organizations.
Another example of charitable sanitisation: referring to personal data being 'monetized' rather than 'sold'. Information is sold when advertisers can target sets of users based on their personal data.
But, if I sell you an ebook, you would expect a copy to read, right?
Accusing Facebook of selling data makes it easy for them to rebut: no data changed hands.
Similar to accusing copy
Accusing Facebook of selling data makes it easy for them to rebut: no data changed hands.
Similar to accusing copy
They also crawl links you share in private messages to grab the title, intro, and favicon to generate that clickable widget link thing.
[0] https://torrentfreak.com/facebook-blocks-all-pirate-bay-link...