REVIEW 3 major objections 5 minor 42 references
An Exploratory Study of Malicious Link Posting on Social Media Applications
T0 review · 3 major / 5 minor · reviewed 2026-07-11 · grok-4.5
Pith's one-line read Most top Android social apps let verified phishing links be posted with little or no blocking.
desk verdict Clean, small-N pilot that shows four of five popular Android social apps block almost no verified phishing URLs at post time; useful snapshot, not a new attack or defense. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
A controlled posting pipeline: sample five PhishTank URLs every two weeks for three months, re-verify each with Safe Browsing and VirusTotal, attempt to post the original URL from a private test account, and, only if blocked, re-post a TinyURL redirect of the same destination. Success or failure of each post is the measured outcome.
What would settle it
Re-run the identical sampling and posting protocol on the same five apps today (or on a larger set of URLs) and record whether the block rates for original and redirected links remain as low as the 2022 figures; any large rise in blocking would falsify the claim of systemic weakness.
Extended reading notes
Core claim
When verified phishing URLs drawn from PhishTank are posted on the five highest-ranked Android social apps, the large majority are accepted: only Twitter performs meaningful blocking, and the aggregate block rate across all apps and both original and redirected forms is just 23.8 percent. The study therefore concludes that most of these platforms lack an effective defense against the posting and spreading of malicious links.
Load-bearing premise
A single post-time check of 35 already-flagged phishing URLs is treated as a fair proxy for each platform's real filtering behavior, including any later removal or differences between profile posts and private messages.
Editorial extensions
If this is right
- Attackers can currently seed phishing or malware links on TikTok, Instagram and Mastodon with near-certainty of successful posting.
- Even the modest blocking present on Facebook is defeated by ordinary URL shorteners, so redirect chains remain an open bypass.
- Google Play Store malware-policy language is not strong enough to force apps to stop the spread of known-bad URLs.
- Usable-security redesigns that preserve link-sharing while still intercepting known-malicious destinations are still needed.
Reading between the lines
- The same low post-time filtering likely extends to other high-traffic platforms not in the top-five list, widening the practical attack surface.
- Retroactive deletion of already-posted links, if it occurs at all, arrives after the window of highest engagement and therefore does little to reduce initial harm.
- A public, continuous monitoring dashboard that re-tests the same pipeline weekly could pressure platforms to close the gap without waiting for new regulation.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper reports an exploratory measurement of post-time filtering of known malicious URLs on five Android social apps (TikTok, Instagram, Twitter, Facebook, Mastodon). Over seven dates spanning three months the authors sample 35 PhishTank URLs, dual-validate them with Google Safe Browsing and VirusTotal, create isolated test accounts, and attempt to post each original URL (plus a TinyURL redirection if the original is blocked). Tables II–IV and the appendix show that TikTok, Instagram and Mastodon blocked none of the 35 originals, Facebook blocked four (~10 %), and Twitter blocked the large majority of both originals and redirections (~69 %), yielding an overall block rate of 23.8 % driven almost entirely by Twitter. The authors conclude that most of the examined platforms lack effective defenses against malicious-link posting, discuss security–usability trade-offs, and list several limitations as future work.
Significance. If the modest claim holds, the work supplies concrete, previously sparse evidence that several high-install social platforms perform little or no real-time filtering of known phishing URLs at the moment of posting. That observation is directly relevant to usable-security design, platform policy, and the residual attack surface for link-based social-engineering. Credit is due for the transparent pipeline (Fig. 1), dual external black-list validation, ethical isolation of test accounts, and the fully tabulated per-app/per-date outcomes that let a reader verify the headline numbers. As explicitly labeled pilot work the study usefully surfaces a measurement gap rather than claiming a definitive audit.
major comments (3)
- [§III-C, §IV, Tables II–III] §III-C, §IV and Tables II–III: the central claim that most apps ‘did not have an effective defense against the posting and spreading’ of malicious URLs rests solely on one-time post-time checks of 35 URLs. The authors themselves flag in §VI that retroactive removal and profile-versus-DM differences were never measured. Without those data the stronger language of ‘spreading’ and of ‘non-existent’ defenses for three apps is not fully supported; either the experiment must be extended or the conclusions must be substantially qualified to the post-time window actually observed.
- [§III-B] §III-B: the two-week sampling gap is presented as sufficient for platforms to have ingested the latest blacklist entries, yet no evidence is offered that the five apps consult PhishTank, Safe Browsing or VirusTotal, nor that they update on that cadence. This untested assumption underpins the inference that non-blocking equals inadequate defense rather than delayed or alternative detection; it should be either validated or removed as a load-bearing premise.
- [Table III, §IV-A] Table III and §IV-A: the headline 23.8 % block rate is almost entirely Twitter’s contribution (46 of the blocked instances). Aggregating without stronger per-app emphasis or simple statistical context risks overstating uniformity of the vulnerability across ‘most’ platforms; the discussion should more carefully separate Twitter’s relatively robust behavior from the near-zero rates of the other four apps.
minor comments (5)
- [Abstract] Title and abstract: ‘that usability into account’ is missing a verb; several other sentences in the abstract and introduction contain missing articles or run-on constructions.
- [§III, Table III] Section heading ‘METHODOLGY’ is misspelled; Table III header ‘EVLUATIONMATRIX’ is likewise misspelled and inconsistently capitalized.
- [Tables II–IV] Inconsistent orthography of ‘Redirectional’ / ‘redirectional’ / ‘transformed’ throughout Tables II–IV and the text; pick one term and use it uniformly.
- [Fig. 1] Fig. 1 caption and body text contain several typographic glitches (‘InProcess1&2we’, ‘createtransformedversion’, missing spaces). Clean for camera-ready.
- [§I] Introduction: ‘for personally identifiable informationPIIssuch’ lacks spaces and punctuation; similar concatenation errors appear elsewhere.
Circularity Check
No circularity: purely observational measurement of external blacklists against five apps; no fitted parameters, self-definitions, or load-bearing self-citations.
full rationale
The paper is an exploratory empirical study. Its central claim (most of the five Android social apps lack effective post-time defenses against verified phishing URLs; only 23.8 % of the tested links were blocked, almost all by Twitter) is obtained by (1) sampling 35 URLs from the external PhishTank database at two-week intervals, (2) re-validating them with Google Safe Browsing and VirusTotal, (3) posting the original and (when blocked) TinyURL-shortened versions from test accounts, and (4) counting successes/failures in Tables II–IV and the appendix. None of these steps defines a quantity in terms of itself, fits a free parameter that is later re-labeled a prediction, or rests on a uniqueness theorem or ansatz imported from the authors’ prior work. The few self-citations that appear (e.g., [32], [34], [40]) are background or related-work references and are not load-bearing for the numerical result. The authors themselves label the work “exploratory/pilot” and list the obvious sampling limitations (post-time only, profile vs. DM, no retroactive checks) as future work; those limitations affect external validity, not circularity. Consequently the derivation chain is self-contained against external benchmarks and scores 0.
Assumptions & free parameters
assumptions (3)
- domain assumption URLs flagged by PhishTank and confirmed by Google Safe Browsing plus VirusTotal are treated as ground-truth malicious for the purpose of the experiment.
- ad hoc to paper A two-week sampling gap is long enough for platforms to have ingested the latest blacklist entries.
- domain assumption Test-account posting behavior is representative of ordinary user posting for the purpose of measuring filter presence.
Cite this review
Pith. "Pith review of An Exploratory Study of Malicious Link Posting on Social Media Applications." pith.science (2026). https://pith.science/paper/H2ZNWKBV
@misc{pith2026260704042,
author = {Pith},
title = {Pith review of: An Exploratory Study of Malicious Link Posting on Social Media Applications},
year = {2026},
howpublished = {\url{https://pith.science/paper/H2ZNWKBV}},
note = {Machine review of arXiv:2607.04042}
}
read the original abstract
Social network platforms are now widely used as a mode of communication globally due to their popularity and their ease of use. Among the various content-sharing capabilities made available via these applications, link-sharing is a common activity among social media users. While this feature provides a desired functionality for the platform users, link sharing enables attackers to exploit vulnerabilities and compromise users' devices. Attackers can exploit this content-sharing feature by posting malicious/harmful URLs or deceptive posts and messages which are intended to hide a dangerous link. However, it is not clear how the most common social media applications monitor and/or filter when their users share malicious URLs or links through their platforms. To investigate this security vulnerability, we designed an exploratory study to examine the top five android social media applications' performance when it comes to malicious link sharing. The aim was to determine if the selected applications had any filtering or defenses against malicious URL sharing. Our results show that most of the selected social media applications did not have an effective defense against the posting and spreading of malicious URLs. While our results are exploratory, we believe our study demonstrates the presence of a vital security vulnerability that malicious attackers or unaware users can use to spread harmful links. In addition, our findings can be used to improve our understanding of link-based attacks as well as the design of security measures that usability into account.
Figures
Reference graph
Works this paper leans on
-
[1]
https://www.phishing.org/phishing-examples
Phishing examples. https://www.phishing.org/phishing-examples
-
[2]
https://www.bbc.com/news/technology-53607374
Twitter hack: Staff tricked by phone spear-phishing scam. https://www.bbc.com/news/technology-53607374
-
[3]
Cyber security in mobile social networks
Fadi Al-Turjman and Ramiz Salama. Cyber security in mobile social networks. InSecurity in IoT Social Networks, pages 55–81. Elsevier, 2021
2021
-
[4]
Security in social-media: Awareness of phishing attacks techniques and countermeasures
Amera Alharbi, Afnan Alotaibi, Lujain Alghofaili, Mona Alsalamah, Nora Alwasil, and Salim Elkhediri. Security in social-media: Awareness of phishing attacks techniques and countermeasures. In2022 2nd International Conference on Computing and Information Technology (ICCIT), pages 10–16. IEEE, 2022
2022
-
[5]
Civility and trust in social media.Journal of Economic Behavior & Organization, 160:83–99, 2019
Angelo Antoci, Laura Bonelli, Fabio Paglieri, Tommaso Reggiani, and Fabio Sabatini. Civility and trust in social media.Journal of Economic Behavior & Organization, 160:83–99, 2019
2019
-
[6]
Phishing activity trends report 2nd quarter 2022
APWG. Phishing activity trends report 2nd quarter 2022. url- https://apwg.org/trendsreports/, 2022
2022
-
[7]
Less is more: quantifying the security benefits of debloating web applications
Babak Amin Azad, Pierre Laperdrix, and Nick Nikiforakis. Less is more: quantifying the security benefits of debloating web applications. In28th USENIX Security Symposium (USENIX Security 19), pages 1697–1714, 2019
2019
-
[8]
Social engineering: revisiting end-user awareness and susceptibility to classic attack vectors
Taimur Bakhshi. Social engineering: revisiting end-user awareness and susceptibility to classic attack vectors. In2017 13th International Conference on Emerging Technologies (ICET), pages 1–6. IEEE, 2017
2017
Show all 42 references
-
[9]
Susanne Barth, Menno DT de Jong, Marianne Junger, Pieter H Hartel, and Janina C Roppelt. Putting the privacy paradox to the test: Online privacy and security behaviors among users with technical knowledge, privacy awareness, and financial resources.Telematics and informatics, ...
2019
-
[10]
An analysis of phishing blacklists: Google safe browsing, openphish, and phishtank
Simon Bell and Peter Komisarczuk. An analysis of phishing blacklists: Google safe browsing, openphish, and phishtank. InProceedings of the Australasian Computer Science Week Multiconference, pages 1–11, 2020
2020
-
[11]
L. Ceci. Whatsapp global unique users 2022. https://www.statista.com/statistics/1306022/whatsapp-global-unique- users/
2022
-
[12]
Mobile fact sheet
Pew Research Center. Mobile fact sheet. url=https://www.pewresearch.org/internet/fact-sheet/social-media/, 2021
2021
-
[13]
Usability, security and trust in password managers: A quest for user-centric properties and features.Computer Science Review, 33:69– 90, 2019
Sunil Chaudhary, Tiina Schafeitel-T ¨ahtinen, Marko Helenius, and Eleni Berki. Usability, security and trust in password managers: A quest for user-centric properties and features.Computer Science Review, 33:69– 90, 2019
2019
-
[14]
A sur- vey of phishing attacks: Their types, vectors and technical approaches
Kang Leng Chiew, Kelvin Sheng Chek Yong, and Choon Lin Tan. A sur- vey of phishing attacks: Their types, vectors and technical approaches. Expert Systems with Applications, 106:1–20, 2018
2018
-
[15]
J. Clement. Facebook mau worldwide 2020. https://www.statista.com/statistics/264810/number-of-monthly-active- facebook-users-worldwide/
2020
-
[16]
S. Dixon. Social sharing - statistics & facts. https://www.statista.com/topics/2539/social-sharing/
-
[17]
Twitter mdau in the united states 2022
S Dixon. Twitter mdau in the united states 2022. https://www.statista.com/statistics/970911/monetizable-daily-active- twitter-users-in-the-united-states/
2022
-
[18]
friends:
Nicole B Ellison, Charles Steinfield, and Cliff Lampe. The benefits of facebook “friends:” social capital and college students’ use of online social network sites.Journal of computer-mediated communication, 12(4):1143–1168, 2007
2007
-
[19]
Android permissions: User attention, com- prehension, and behavior
Adrienne Porter Felt, Elizabeth Ha, Serge Egelman, Ariel Haney, Erika Chin, and David Wagner. Android permissions: User attention, com- prehension, and behavior. InProceedings of the eighth symposium on usable privacy and security, pages 1–14, 2012
2012
-
[20]
Fake person generator- faq
Fake Person Generator. Fake person generator- faq. https://www.fakepersongenerator.com/Site/faq
-
[21]
Coordi- nated link sharing behavior as a signal to surface sources of problematic information on facebook
Fabio Giglietto, Nicola Righetti, Luca Rossi, and Giada Marino. Coordi- nated link sharing behavior as a signal to surface sources of problematic information on facebook. InInternational Conference on Social Media and Society, pages 85–91, 2020
2020
-
[22]
Phishing url detection with lexical features and blacklisted domains
Jiwon Hong, Taeri Kim, Jing Liu, Noseong Park, and Sang-Wook Kim. Phishing url detection with lexical features and blacklisted domains. In Adaptive autonomous secure cyber systems, pages 253–267. Springer, 2020. 6
2020
-
[23]
No}one can hack my {Mind
Iulia Ion, Rob Reeder, and Sunny Consolvo.{“... No}one can hack my {Mind”}: Comparing expert and{Non-Expert}security practices. In Eleventh Symposium On Usable Privacy and Security (SOUPS 2015), pages 327–346, 2015
2015
-
[24]
Advertising content and consumer engagement on social media: Evidence from facebook.Management Science, 64(11):5105–5131, 2018
Dokyun Lee, Kartik Hosanagar, and Harikesh S Nair. Advertising content and consumer engagement on social media: Evidence from facebook.Management Science, 64(11):5105–5131, 2018
2018
-
[25]
A critical genre analysis of covert advertising through short-videos in douyin: The chinese version of tik-tok.SAGE Open, 12(4), 2022
Dongmei Li, Ung T’chiang Chow, and Cecilia Yin Mei Cheong. A critical genre analysis of covert advertising through short-videos in douyin: The chinese version of tik-tok.SAGE Open, 12(4), 2022
2022
-
[26]
Google safe browsing
Google LLC. Google safe browsing. https://safebrowsing.google.com/
-
[27]
The future development of e-commerce in tiktok
Jianyu Ma and Siwei Yu. The future development of e-commerce in tiktok. In2021 International Conference on Public Relations and Social Sciences (ICPRSS 2021), pages 241–246. Atlantis Press, 2021
2021
-
[28]
With twitter in chaos, mastodon is on fire — cnn business, Nov 2022
Rachel Metz. With twitter in chaos, mastodon is on fire — cnn business, Nov 2022
2022
-
[29]
Framing and counter-framing a peace march in russia: the use of twitter during a hybrid war.Social Movement Studies, 18(5):602–621, 2019
Olena Nikolayenko. Framing and counter-framing a peace march in russia: the use of twitter during a hybrid war.Social Movement Studies, 18(5):602–621, 2019
2019
-
[30]
Us- ability analysis of shared device ecosystem security: informing support for survivors of iot-facilitated tech-abuse
Simon Parkin, Trupti Patel, Isabel Lopez-Neira, and Leonie Tanczer. Us- ability analysis of shared device ecosystem security: informing support for survivors of iot-facilitated tech-abuse. InProceedings of the new security paradigms workshop, pages 1–15, 2019
2019
-
[31]
Michael Rubin. Evolution of iranian surveillance strategies toward the internet and social media.The Digital Age, Cyber Space, and Social Media The Challenges of Security & Radicalization, page 191, 2020
2020
-
[32]
To- wards characterizing covid-19 awareness on twitter.arXiv preprint arXiv:2005.08379, 2020
Muhammad Saad, Muhammad Hassan, and Fareed Zaffar. To- wards characterizing covid-19 awareness on twitter.arXiv preprint arXiv:2005.08379, 2020
2005 arXiv
-
[33]
Shafahi, L
M. Shafahi, L. Kempers, and H. Afsarmanesh. Phishing through social bots on twitter. In2016 IEEE International Conference on Big Data (Big Data), 2016
2016
-
[34]
Phishing email detection method: Leveraging data across different organizations
Tanusree Sharma, Priscilla Ferronato, and Masooda Bashir. Phishing email detection method: Leveraging data across different organizations. 2021
2021
-
[35]
A survey of trust in social networks.ACM Computing Surveys (CSUR), 45(4):1–33, 2013
Wanita Sherchan, Surya Nepal, and Cecile Paris. A survey of trust in social networks.ACM Computing Surveys (CSUR), 45(4):1–33, 2013
2013
-
[36]
PhD thesis, 2020
Jason Sibrian.Sensitive Data? Now That’s a Catch! the Psychology of Phishing. PhD thesis, 2020
2020
-
[37]
Deceptive previews: A study of the link preview trustworthiness in social platforms
Giada Stivala and Giancarlo Pellegrino. Deceptive previews: A study of the link preview trustworthiness in social platforms. 2020
2020
-
[38]
Thispersondoesnotexist
ThisPersonDoesnotExist. Thispersondoesnotexist. https://thispersondoesnotexist.com/
-
[39]
Virustotal - how it works
VirusTotal. Virustotal - how it works. https://support.virustotal.com/hc/en-us/articles/115002126889-How- it-works
-
[40]
Gaming apps’ and social media partnership: A privacy perspective
Tian Wang and Masooda Bashir. Gaming apps’ and social media partnership: A privacy perspective. InHCI for Cybersecurity, Privacy and Trust: Third International Conference, HCI-CPT 2021, Held as Part of the 23rd HCI International Conference, HCII 2021, Virtual Event, July 24–29...
2021
-
[41]
Mobile banking: evolution and threats: malware threats and security solutions
Mohammad Wazid, Sherali Zeadally, and Ashok Kumar Das. Mobile banking: evolution and threats: malware threats and security solutions. IEEE Consumer Electronics Magazine, 8(2):56–60, 2019
2019
-
[42]
The importance of trending topics in the gatekeeping of social media news engagement: A natural experiment on weibo.Communication Research, 49(7):994–1015, 2022
Tian Yang and Yilang Peng. The importance of trending topics in the gatekeeping of social media news engagement: A natural experiment on weibo.Communication Research, 49(7):994–1015, 2022. VIII.APPENDIX 7 TABLE IV RESULTS OFORIGINAL ANDREDIRECTIONAL(Transformed) MALICIOUSURLS ...
2022
Reviewed July 11, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.