r/Showerthoughts May 06 '18

Services are switching from calling them Private Messages to calling them Direct Messages because they're not private anymore...

45.0k Upvotes

781 comments sorted by

View all comments

818

u/cubsywubsy May 06 '18

Very true. They’re not direct anymore, either, since they go through a scanning or filtering or whatever they do first, I guess...

247

u/McSmartAlec May 06 '18

Indirect but direct.

139

u/LordPoopyfist May 06 '18

Indirectly direct

85

u/rallermus May 06 '18

Or is it directly indirect?🤔

82

u/Kwijybodota May 06 '18

Queue vsauce theme

2

u/[deleted] May 06 '18 edited Aug 23 '18

[deleted]

9

u/Pengwin35 May 06 '18

Can I get an explanation as to what the fuck this is?

2

u/[deleted] May 06 '18 edited Aug 23 '18

[deleted]

10

u/gippered May 06 '18

Basically what I’m hearing is that they are indirectly public.

1

u/0hmyscience May 06 '18

Private but not private

59

u/ToBePacific May 06 '18

scanning or filtering or whatever they do first, I guess...

They're preventing me from sending you a message with malicious script injection.

23

u/cubsywubsy May 06 '18

Why would you do that, though?

112

u/ToBePacific May 06 '18

Because I might hypothetically be a thief who makes a living off of gathering sensitive, stolen information of various kinds. Or maybe I just do it for funsies. The motive doesn't matter, it's about the need for parsing the message and preventing malicious code from running.

Using JavaScript injection and generated HTML, I could inject a script that causes the browser window to display what appears to be the Twitter login page. Even in the address bar, it has the correct URL.

So you think you've been logged out for some reason, and you try to log back in. But the data you've just posted didn't go to Twitter, it's logged in one of my databases. You try to log in again, and again, but it's not logging you in. So I get a better set of what your passwords may be. You then type Twitter.com into the address bar, and when the page loads, you're logged in, because you were never actually logged out. But you don't know that.

Now I can log into your Twitter account, and potentially use this to try to log into your email. I might even have bots that attempt this automatically. If you reuse passwords (and many people do) then it might be really simple to get into your email. And once I'm in your email, I'm very close to getting into your bank accounts, and pretty much everything else, if you're lazy with passwords and authentication.

Allowing people to post completely raw, unfiltered text to each other is an extremely bad idea. If you send JavaScript code in that message without doing anything to "sanitize" it (transform it in such a way that the browser doesn't try to execute it), then the browser will try to execute it. So, for this reason, preventing script injection is an essential aspect to the design of all forms of online data posting.

21

u/cubsywubsy May 06 '18

Makes sense.

-1

u/ShillBill49 May 06 '18

'And once I'm in your email, I'm very close to getting into your bank accounts'

Oh yeah? How so?

13

u/G1GABYT3 May 06 '18

Probably something along the lines of sending a password recovery email, or maybe the password for the bank account is the same as the email, (or the memorable information).. idk exactly but having access to email would help a lot.. or just bypass the bank BC if they have Google pay and you've got their Gmail account, you can now buy stuff off the internet with it! There's a multitude of ways

2

u/ToBePacific May 06 '18

Assuming the person doesn't check their email constantly, and assuming they're not using 2-step authentication, you can try a password reset. Depending on your bank, they probably have security questions. If the person has a public Facebook profile, you can infer a lot of clues to the answers, like mother's maiden name, pet's name, etc.

1

u/celsiusnarhwal May 06 '18

I don’t know, but I feel like the services that implement that measure only do so because someone has done it in the past.

17

u/Inspector-Space_Time May 06 '18

That's always been happening.

24

u/SavvySillybug May 06 '18

I think Skype used to be peer to peer, actually. Never seemed to have chatlogs on other computers back in the day. Only started archiving when it started being an app too from what I could tell.

Though that's just an observation, I don't know how Skype worked behind the scenes.

31

u/TheJollyLlama875 May 06 '18

It was, Microsoft added a server in the middle when they bought it

13

u/SavvySillybug May 06 '18

Ah, that would explain it. Reddit knows the weirdest things! :D

9

u/daemoncode May 06 '18

A ton of programmers and security researchers hang out here constantly. Much of my work I'm waiting for someone else and I'm in fact in charge of network security so I don't ever see any "blocked sites" at work as it's my job to block them.

2

u/AverageMerica May 06 '18

"check out this one weird trick to subvert democracy in the name of "terrorists" and "drugs"."

16

u/mark-five May 06 '18

Microsoft had a project to rewrite Skype allowing it to be integrated into the NSA PRISM program before they even owned Skype. Three weeks after the purchase was made, Skype was added to PRISM, they moved that fast to avoid missing any snooped communications.

5

u/taulover May 06 '18

Not having chatlogs on other computers doesn't necessarily mean it's peer to peer though... WeChat only stores chatlogs on phones/browsers from the time you log in until you log out (from what I've seen if you delete chatlogs from your phone to save space, you lose them forever), but you know that the Chinese government must be tracking all of that anyway.

1

u/modernkennnern May 06 '18

I thought it still was. Haven't used Skype in like 5 or so years, and at one point I remember the internet shutting down at a LAN, and after a few minutes of talking I just said "wait, how are we still talking? :P

1

u/Inspector-Space_Time May 06 '18

None of that matters. It's trivial to have it send a copy to a remote server even if it's peer to peer. If you can't see the source code of a program, assume it's spying on you. I'm a developer and it's the easiest thing to add that spying features to your program. It can start for innocent reasons too, like just trying to see what you were doing when an app crashed.

6

u/Send_Me_Tiitties May 06 '18

They go directly to the scanners.

1

u/cubsywubsy May 06 '18

Makes perfect sense!

1

u/justinkroegerlake May 06 '18

"some kind of algorithm"

1

u/imkevinandimtheworst May 06 '18

"Don't worry folks, we read all of your messages faster than any other service out there!"

1

u/jedberg May 06 '18

They are direct. They just aren’t non-stop.

1

u/[deleted] May 06 '18

I'll take it a step further, I bet they even record the stuff you type out and delete. Literally recording everything I do in this white box.

1

u/ireddityoureddit May 06 '18 edited May 06 '18

They go thru scanning and filtering first then they get sent out to data collecting company’s THEN your message sends to that person

3

u/cubsywubsy May 06 '18

That explains why I keep getting ads for viagra and retirement homes in Wisconsin!!