Skip links

What is a Link Preview, and Why Should You Avoid Them?

Link Preview IT Security
Take a moment to pause before clicking a link that you’ve received via messenger app, even if you trust the sender. 

If you’ve ever been sent a link via a messenger app, you’ve probably seen a link preview before. Many messenger and social media platforms that we use every day use this feature, from popular social networking apps like Facebook Messenger and Instagram, to tools we use in the workplace, like Slack, Zoom, and LinkedIn. A link preview is an automatically generated preview of a web page, usually in the form of an image or a headline, pulled from a website address by the app itself. 

How do they work? The app will visit the link and survey what information is there. It then determines the most relevant information from the page and displays it to the recipient without them needing to click and open the link first. These visual previews can seem helpful—they provide you a quick snippet of what to expect in a news story, or display an image without needing to leave the app.

However, recent research has shown that these previews may actually expose your device to privacy concerns when they are not managed safely and securely. 

What are the risks associated with using link preview? 

In a recent research report by Talal Haj Bakry and Tommy Mysk, link previews were found to be a dangerous risk to cyber security. These previews can potentially leak sensitive data, expose devices to malware, and be a major drain on cellular data. 

To generate a preview, the app or proxy downloads and copies information off of the URL, saving the information on their servers. As such, if you share private documents via link on an unsecure messenger platform, you risk a copy of your document being accessible to hacks and leaks. Even a password-protected URL—for example, a Dropbox or Google Drive link to some important company files—can be copied and saved to an app’s database. It’s always safest to share private company documents via email or a secure messenger platform, even when they are password protected. 

Should you receive a malware link when a connection’s account is hacked, a link preview can begin downloading malware even if you are wise enough not to click the link. This can sadly negate all the careful training you’ve done with your employees to never click an unsafe link. 

On the somewhat-less-frightening end of the scale, link previews can also be a costly nuisance. They drain battery life and may run up unnecessary data charges on a cell phone or tablet. Because they automatically begin downloading a file without your permission, simply receiving the URL to a large file can quickly burn through precious cellular data. Imagine receiving a preview of a 2GB video file your colleague has shared with the team while you’re on your commute home… yikes.

Does this mean all messenger apps are unsafe? 

Well, yes and no. You don’t have to block all social media platforms at your business to keep your company and employees safe. However, it’s critical to be aware of the safest ways to send and receive links using company devices, and educate your employees to follow protocol. Social media platforms have proven to be the worst offenders for link security, with Facebook Messenger and Instagram topping the report on the least secure ways to send and receive URLs. 

This new research serves as a powerful reminder that private messages aren’t always completely private.

  • Whenever possible, use apps that don’t generate a link preview at all, especially in the workplace.
  • These apps will simply send the URL in text format, allowing you to read the full address.
  • This helps the recipient determine whether the address is safe or not and prevents an app from saving a copy of the link.

If you’re looking for further guidance on how to keep your organization safe, it’s time to consider hiring someone to help manage and monitor your IT infrastructure for you. As we enter an increasingly digital era of work, security is more important than ever. Stay on top of security threats with managed IT services. Contact us to find out more. 

FAQs

What exactly is a link preview and how does it function?

A link preview is a visual summary of a website—typically including a thumbnail image, headline, and brief description—that appears automatically when you paste a URL into a messaging app like Slack, WhatsApp, or Facebook Messenger. To create this, the app (or its server) “crawls” the destination website to scrape relevant data. While this helps you see what a link contains before clicking, it essentially means the app is visiting the website on your behalf without your explicit permission. 

The primary danger lies in how information is gathered and stored. When an app generates a preview, it often downloads content from the link onto the app’s own servers. This process introduces several critical risks: 

Data Leaks: If you share a private link (like a Dropbox file or a password-protected document), the app’s server may save a copy of that preview, potentially exposing sensitive data to the app’s developers or future breaches. 

Malware Execution: Some malicious links are designed to trigger code execution as soon as they are “crawled.” This means your device or the app server could be exposed to malware even if you never actually click the link. 

IP Tracking: Clicking a link isn’t the only way to be tracked; the act of generating a preview can reveal your IP address and geographic location to the sender or the destination website. 

Yes, link previews can be a “hidden” drain on your resources. Because the app automatically connects to the web and downloads images or metadata for every link you receive, it consumes cellular data in the background. If someone sends you a link to a high-resolution video or a large file, the preview generation might attempt to download parts of that file, leading to unexpected data charges and faster battery depletion. 

Most privacy-conscious apps allow you to turn off this feature in their settings. Taking this step ensures that links are sent and received as plain text. Common ways to manage this include: 

Slack: Go to Preferences > Messages & Media and uncheck “Show previews of websites.” 

WhatsApp: You can often prevent previews by deleting the preview box that appears above your message before hitting send. 

Discord: Navigate to User Settings > Text & Images and toggle off “Link Previews.” 

Signal: Known for its security, Signal allows you to disable link previews under Settings > Privacy to ensure no data is sent to their servers for crawling. 

Shortened URLs (like those from Bitly or TinyURL) are particularly risky because they hide the final destination of the link. Since you cannot see the actual web address, a link preview might inadvertently crawl into a malicious site without you realizing it. Additionally, links to “one-time-use” secrets or reset tokens should never be shared via apps that generate previews, as the preview crawler might “consume” the token, rendering it useless for the intended recipient.