Facebook and Instagram Link Previews Would Break EU Privacy Law, Say Security Researchers

A follow-up report by security researchers Talal Haj Bakry and Tommy Mysk has alleged that Facebook Messenger and Instagram are collecting and using data from link previews in a way that would breach European privacy law.

facebook messenger icon new

In October last year, Bakry and Mysk revealed that link previews in popular messaging apps can lead to security and privacy issues on iOS and Android. It was discovered that apps could leak IP addresses, expose links sent in end-to-end encrypted chats, download large files without users' consent, and copy private data through link previews.

In that report, Bakry and Mysk found that Facebook Messenger and Instagram behaved unlike other messaging apps in that they downloaded the entire contents of any link to its servers, regardless of size. When questioned about this unusual behavior, Facebook reportedly said that it considers this to be "working as intended."

Copies of link preview data kept on external servers could be subject to breaches or misuse, which may be particularly concerning for users who send links to sensitive or confidential private data such as business documents, bills, contracts, or medical records.

Now, Bakry and Mysk have found that Facebook has recently stopped generating link previews in Messenger and Instagram for users in Europe to comply with the European Union's ePrivacy Directive. The change also applies to users outside Europe if they communicate with someone in the region.

messenger link previewsLinks sent in Facebook Messenger as seen in Europe and other regions

The researchers suggest that since Europe has "some of the most robust privacy laws" and Facebook has now removed link previews seemingly to comply with the legislation, the company must have been using the data from link previews in a way that would breach the ePrivacy Directive.

It is an implicit confirmation that Facebook's handling of link previews in Messenger and Instagram did not conform to privacy regulations in Europe, otherwise they wouldn't have disabled the feature... Stopping this service in Europe strongly hints that Facebook may be using this content for purposes other than generating previews.

Bakry and Mysk believe that Facebook's link previews may have infringed on articles 4:1a, 4:2, and 5:3 of the ePrivacy Directive. These articles include the requirement that personal data can only be accessed by authorized personnel for legal purposes, the need to inform users of the risks of a data breach, and the need to gain user consent having been provided with "clear and comprehensive information" about how data is collected.

As links may relate to personal data, the ePrivacy Directive prevents Facebook from storing, processing, or using this information without explicit consent from users in the EU. Facebook would also have to make it clear to users why it is downloading the contents of link previews prior to requesting consent.

Bakry and Mysk have demonstrated that Facebook servers download and store the content of links sent through its apps, and if the same link is sent a second time, Facebook generates a link preview without downloading the contents of the link. This purportedly indicates that the content is stored or cached by Facebook and is proven by the amount of data that is uploaded from a user's device.

Link previews continue to be available in Messenger and Instagram for users outside Europe. Facebook's current Terms of Service state that any content users share through any of Facebook's services will be used for various purposes such as personalizing content, ads, making suggestions, and learning about users, both on and off Facebook's products. In Europe, this use of personal data now requires explicit consent from users even if it is approved by Facebook's Terms of Service.

Facebook disabled link previews for users in Europe to comply with new privacy regulations. This confirms our privacy concerns that sending links to private files in Messenger and Instagram is unsafe. While Facebook did disable link previews in Europe, users in other regions should refrain from sending links through either of these apps. The better option would be to switch to other messaging apps which respect user privacy in all parts of the world alike.

Bakry and Mysk are now actively recommending that users outside Europe do not send links in Messenger or Instagram due to privacy concerns, and have even suggested that users move to other messaging apps entirely.

Beyond link previews, the researchers have previously investigated popular iPhone and iPad apps "snooping" on iOS pasteboard data and HTTP security vulnerabilities in TikTok.

Top Rated Comments

Matthew.H Avatar
42 months ago
Why does this not surprise me.
Score: 9 Votes (Like | Disagree)
and 1989 others Avatar
42 months ago
What is more curious, is that day by day we have story after story of the FB group misusing data, mining data, selling personal data, building profiles of individual for nefarious means, manipulating the political sphere etc etc...

And YET people still use the services every single day.
Score: 8 Votes (Like | Disagree)
Mike_Trivisonno Avatar
42 months ago
Honestly, what the heck is wrong with these companies? They are so weird and creepy. Can't they just stop stalking their users? Just quit it. People want advanced technology, not cyber-stalking freaks.
Score: 6 Votes (Like | Disagree)
luvbug Avatar
42 months ago
Evil, just simply evil. Scumbags extraordinaire.
.
Score: 6 Votes (Like | Disagree)
Pangalactic Avatar
42 months ago
Waiting for the Facebook reply "But tracking and data mining is good for you! It is privacy that violates your...ehmm...advertising potential!"
Score: 6 Votes (Like | Disagree)
infinitejest Avatar
42 months ago
They only do that to save small businesses, guys!
Score: 6 Votes (Like | Disagree)

Popular Stories

5

Apple Event Live Blog: New iPad Pro, iPad Air, and More

Tuesday May 7, 2024 6:33 am PDT by
Apple's "Let Loose" event kicks off today at the unusual time of 7:00 a.m. Pacific Time, and we're expecting to see an iPad-focused event with new iPad Pro and iPad Air models, updated Apple Pencil and Magic Keyboard accessories, and perhaps some other announcements. Apple is providing a live video stream on its website, on YouTube, and in the company's TV app across various platforms. We...
f 7ba5b5b668dd68b7179a599305cff6b117ef35d1

Apple Announces New iPad Pro With M4 Chip, OLED Display, and More

Tuesday May 7, 2024 7:15 am PDT by
Apple today unveiled redesigned iPad Pro models featuring the M4 chip, Ultra Retina XDR OLED displays, a nano-texture display option, and more. The new iPad Pro offers a considerably thinner design and slightly larger 11- and 13-inch display size options. The 11-inch model is 5.3mm thick and weighs less than a pound, while the 13-inch model is just 5.1mm thick and weighs a quarter pound less ...
iOS 17 All New Features Thumb

Apple Says iOS 17.5 Coming 'Soon' With These New Features for iPhones

Monday May 6, 2024 7:33 am PDT by
Apple today announced that iOS 17.5 will be released to the public "soon," following over a month of beta testing. While the software update is relatively minor, it does have a few new features and changes, as outlined in the list below. "The new Pride Radiance watch face and iPhone and iPad wallpapers will be available soon with watchOS 10.5, iOS 17.5, and iPadOS 17.5," said Apple, in its...
5

Apple Event This Week Expected to Last 'About 35 Minutes'

Sunday May 5, 2024 3:13 pm PDT by
Apple will be holding its first event of the year this Tuesday, May 7 at 7 a.m. Pacific Time, with a live stream to be available on Apple.com and on YouTube. How long will the event be? In his newsletter today, Bloomberg's Mark Gurman said the video will have a runtime of "around 35 minutes." Apple is expected to announce new iPad Pro and iPad Air models, along with updated Apple Pencil...
iPhone 15 Colors yellow

'iPhone 17 Slim' With Smaller Display Rumored to Launch Next Year

Monday May 6, 2024 9:14 am PDT by
While the iPhone 16 series is still months away from launching, an early rumor about an all-new iPhone 17 model has now surfaced. In a research note with investment firm Haitong this week, analyst Jeff Pu said Apple is planning a so-called "iPhone 17 Slim" model that would replace the Plus model in the lineup. Pu said this model will feature around a 6.6-inch display, a slimmer design, an...
f 157980180c661f30ff9611287c90241baf30faff

Apple Announces Redesigned Magic Keyboard for New iPad Pro Starting at $299

Tuesday May 7, 2024 7:39 am PDT by
Apple at its "Let Loose" event today announced a new Magic Keyboard for the latest iPad Pro models, with a thinner, lighter design. Apple says the Magic Keyboard has been redesigned to be thinner and lighter, while maintaing the same floating design. Two colors are available that match the new iPad Pro. New features include a function row with screen brightness controls, an aluminum...
iOS 18 Apple Music Messages and Notes Feature 1

iOS 18 Rumored to Add New Features to These 16 Apps on Your iPhone

Tuesday April 30, 2024 10:44 am PDT by
Apple is expected to announce iOS 18 during its WWDC keynote on June 10, and new features have already been rumored for many apps, including Apple Music, Apple Maps, Calculator, Messages, Notes, Safari, and others. Below, we recap iOS 18 rumors on a per-app basis, based on reports from MacRumors, Bloomberg's Mark Gurman, and others: Apple Maps: At least two new Apple Maps features are...