Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hi everyone. I work on the security team at Facebook. While investigating the claims of this post, we've confirmed that Facebook doesn't use Recorded Future -- an open source aggregator of public data -- to scan any private content. That means we haven't partnered with or directed Recorded Future to scan anyone's message links.

It's hard to tell precisely what's going on based on the amount of information in the post. It's possible that another interaction, including one that could be occurring on the client machine, is consuming the URL and generating this behavior.

We'll update if any new information is discovered.



Thank you for contributing to the thread.

I have had a lot of difficulty in the past discussing security and privacy concerns with your team - in particular a complain about the censorship of my linking leaked Snowden and Wikileaks documents and PDF scans of Islamic Extremist magazines (non-violent/gross content).

Do you have a transparency document anywhere that you can link, so that we can understand what you as a representative can and will contribute to the conversation? Could you also provide some proof that you are a representative of Facebook security?

Thank you again for your time.


Hi. You can easily find corroboration that I work at Facebook and my contact information. Please feel free to contact me with details of your issues.

If you have specific security vulnerabilities to report, here's a link to our Whitehat program: https://www.facebook.com/whitehat/report/


Thank you for replying with some more information regarding steps to verify your employment with Facebook.

Is there a legal or transparency document that you can link so that we can understand what information you are able to share?


While I think you are just baiting in an attempt to air your personal grievances, here you go...

Facebook Transparency Reports https://www.facebook.com/about/government_requests

Facebook Terms (legal documents) https://www.facebook.com/policies/


Nope. :)

Thank you for the links.


It is known that you guys do regularly use Webroot to scan links in messages, so it's not a stretch that Recorded Future can be setup on a similar type program. http://www.eweek.com/security/facebook-webroot-expand-securi...


That was the Facebook AV Marketplace, which to my knowledge does not exist anymore. Here's the old post about it from 2012: https://www.facebook.com/notes/facebook-security/the-faceboo...


Do you guys dump anonymized link data into https://threatexchange.fb.com/ ?


Why should we believe you?


Thank




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: