Checking Links Before Opening
Phishing links are the most common way messaging accounts are stolen and devices are infected. With Check links before opening turned on in Settings → Privacy, Vavo Chat checks each link in a message you receive against known lists of dangerous sites before you can tap it. This page explains how that works and what it costs in privacy, so you can decide whether to keep it on.
What You'll See
- A link in a message you receive can't be tapped until it has been checked. Usually that takes a moment.
- If the link is on a list of known phishing, malware or unwanted-software sites, it stays disabled and you are told why.
- If the check couldn't be done, for example because you are offline, the link stays disabled until it can be. It is not treated as safe.
- Links you send are never checked, and are always tappable for you.
What Leaves Your Device
Your messages are end-to-end encrypted, so to check a link the app has to take it out of the message and send it for checking. We want to be clear about this, because it is a real trade-off:
- Only the link is sent. The rest of the message, and who sent it to you, never leave your device.
- The link goes to Vavo's servers over an encrypted connection, anonymously. Vavo's servers do not log or store who asked about which link.
- Vavo's servers check the link with Google's Web Risk service, the list of dangerous sites behind Google Safe Browsing. Google receives the link from Vavo. It does not receive your IP address, your account or anything else about you.
What Stays on Your Device
Your device remembers each result so the same link isn't checked every time you scroll past it. The results are stored under a scrambled fingerprint of the link (a SHA-256 hash), never the link itself. Anything that can read the app's settings, such as a backup, therefore can't list the links you received. A "safe" result expires and is checked again later. A "dangerous" result stays until a newer check replaces it.
Deep Analysis
If you want a closer look at a link, you can choose Run Deep Analysis from its safety sheet. This only happens when you ask for it, one link at a time:
- Vavo's servers submit the link to urlscan.io, a security service that opens the page in its own isolated browser and reports what it finds, such as impersonated brands, redirects or known threats.
- The scan is submitted as unlisted. It does not appear in urlscan.io's public search, but urlscan.io and the security researchers it works with can see it. Don't run a deep analysis on a link that contains private information, such as a password-reset or document-sharing link.
- urlscan.io receives the link from Vavo, never from your device, and nothing that identifies you.
- A deep analysis can take up to a minute or so, and the number you can run each hour is limited.
When You Turn It Off
- Links in messages you receive are tappable straight away, and no link is sent to Vavo's servers or anyone else for checking.
- You lose the warning before opening a known phishing or malware link, so take extra care with links from people you don't know.
- The setting applies to this device only and is not synced to your account.
What a Check Cannot Tell You
A check compares the link against sites already known to be dangerous. A brand-new phishing page may not be on any list yet. So a link that passes the check isn't guaranteed safe: be wary of any message that pressures you to sign in, pay or install something.
Related
Questions
If anything here is unclear, contact us at [email protected] or visit our Support page.