Live data from Hacker News

Facebook denies it collects call and SMS data from phones without permission

techcrunch.com

61–70 of 370 posts

Re: Facebook denies it collects call and SMS data from phones without permission

#61
So, this happened and we have confirmed about the dark patterns whether consented or not. What are good alternatives in this "Network effect" age? Facebook - I hardly use anymore. It exists undeleted because it serves as a kind of Social ID. I don't have the App installed anywhere, neither do I access it from my regular browser.

The thing I'm struggling to get alternative for is WhatsApp. How could I talk to all my contacts in a cross platform way without annoying them about installing yet another app?

Text/SMS - costs money because of shitty carriers.

IMessages - Works great but only on iPhones. :-(

Signal - good on paper - still have to trust Moxie not selling out, and needs people to install to be any useful.

Re: Facebook denies it collects call and SMS data from phones without permission

#62
post #5

The Facebook blog post includes this screenshot [0]. That's definitely an opt-in, although I could imagine a non-technical person clicking through it without reading the grey text. Better than nothing. [0]: https://fbnewsroomus.files.wordpress.com/2018/03/opt-in_scre...

This is exactly why I do not have any call/sms info in my FB data downloads. I read such stuff and deny the app these things. Btw. something I am required by law here in Germany. I would need written permission of every contact in my phonebook for this upload, before uploading. Same goes for WhatApp.

You are wrong about Germany. Only if you are a company you need permission.

Re: Facebook denies it collects call and SMS data from phones without permission

#63

Earlier quoted context omitted.

I got my contacts uploaded at some point despite always making sure to reject their prompt. I'm sure people will claim it was just a "bug" or I must have just mistapped (which I have no reason to believe was the case, but how would I prove this), but either way, it's oddly convenient how it works out for them.

That is worrying. The iOS security model would have served you better; Facebook could never accidentally forget you’d said no.

Facebook probably knows if the user is drunk.

Ask for permission at 3am on Sunday. People will press Allow just to get done whatever they thought they were doing, and forget they ever pressed it.

Re: Facebook denies it collects call and SMS data from phones without permission

#64
post #5

The Facebook blog post includes this screenshot [0]. That's definitely an opt-in, although I could imagine a non-technical person clicking through it without reading the grey text. Better than nothing. [0]: https://fbnewsroomus.files.wordpress.com/2018/03/opt-in_scre...

That should be considered an opt-out. It's barely noticable that it's an opt-anything when the prominent option is the creepy option.

Re: Facebook denies it collects call and SMS data from phones without permission

#65
post #56

So I downloaded my facebook data a few days ago and there were no phone nrs in there, no call history, actually much less of everything than I thought they'd have. Are they lying to me or does this depend on other factors?

The reports going around mostly stem from people who used the Facebook app on older versions of Android. A combination of people not understanding what Facebook would do with their data, and poor design in the Android permission system, granted access to call and message logs, which is how Facebook got them.

Re: Facebook denies it collects call and SMS data from phones without permission

#66
I think we are talking differently about this permission concept. Legally yes, they had permission. But the fact that they used those dark ux patterns to request that permission should not be forgotten.

Even though legally they are in the right, we as users should make this fact irrelevant and just abandon the platform. Let them be right, let them win the argument but lose the battle with the general public.

Re: Facebook denies it collects call and SMS data from phones without permission

#67
post #41

Of course it does and can deny it - isn't a user forced to grant the permission when installing the app? IMHO Google is to stop abuses like this on the Android OS level by means of allowing users to deny any particular permission an app demands and still install the app, encouraging users to grant/deny every particular permission consciously and forcing the app authors to handle denial of any particular permission gr…

Both Google and Apple should provide "middle" controls. Even if I grant the app "access" to my contacts, I want to be able to select "which" contacts and which fields. E.g. if I use whatsapp for 3 people out of my 100 contacts saved in my phone, I want to be able to give to whatsapp only the access to the phones of these 3 contacts. Others should be invisible for whatsapp, if I want so. And they should not get the ad…

There are rooted utilities that do this, or allow you to spew fake data at those apps. That is, if you could unlock your bootloader and install the software you want.

You should really blame phone manufacturers/carriers and Congress for giving you the privilege of paying for a piece of locked hardware that you don't own. They're only loaning you a billboard, after all, so what do you expect? Personally I wouldn't put any important information on a locked device, nor do I ever acquire unlockable devices. People have lost their minds giving up all of the most important electronic freedoms that form the backbone of the future.

Re: Facebook denies it collects call and SMS data from phones without permission

#68

Earlier quoted context omitted.

CopperheadOS[1] has a good permission model (compared to stock Android). Notice that they had implemented a better permission model over Android's even in older Android versions which didn't have runtime granular permissions. It proves what the ad company Google itself could have implemented in stock Android had they not been an ad company. CyanogenMod's Privacy Guard[2] - basically a proxy that sits between the apps…

> It proves what the ad company Google itself could have done had they not been an ad company. I think you make fair points, but I think this does not prove anything. CopperheadOS has a different user base than Android. A permission model that CopperheadOS users understand (e.g., CopperheadOS users are likely to be more technical) may not work for Android user base.

Their existence proves what was possible in stock Android. Why it didn't happen that way is open to speculation.

Personally, I feel it was because Google's main business did not, and does not, provide any incentives to design stronger permission and privacy models because it itself depends on collecting information about users.

Was usability also a factor? It may very well have been.

However, I disagree with a thinking that uses usability as an excuse to treat a user base numbering in the hundreds of millions as a homogeneous set who don't know anything, and who can't learn anything new.

People fall in a spectrum of capabilities, and more importantly, every individual is capable of moving around in that spectrum with time.

For example, a non-technical user who started out giving one app all permissions may realize their mistake when their email or phone number turn up in google searches, and become more careful with other apps.

Stock Android could have catered to that and standardized on a very granular runtime permissions as the default model. They already had existing ACL models like iOS / Windows policies / SELinux to copy from. They could have left the simplification to the market - the equipment manufacturers and users - to decide. But stock Android made it a binary all or nothing choice for a long time, and left it to equipment manufacturers to provide any additional protection, who of course didn't implement anything either because they too had no incentives to protect user information or standardize the security APIs.

Even now, Android's runtime permissions, while comparatively more granular, are not granular enough, and in practice become a binary choice where some apps refuse to work if a particular permission is not granted.

I have also noticed how Google in their PlayStore keep the permission information hidden away in an obscure location at the bottom of the page, and don't provide any way to filter apps by permissions. How do I search an app that lets me draw on images without asking for contact book information? Not possible without opening every app's page and checking their permissions. I usually try a bit, give up, and head back to gimp on desktop. Is it for better usability? Does better usability mean keeping users ignorant and uneducated? I think it's not a good approach, and based on anecdotes from my personal network, I also think it's a mistaken assumption.

Re: Facebook denies it collects call and SMS data from phones without permission

#69
post #8

I'm sure they had their "permission" on page 27 of the terms of service. This isn't news... My opinion is still that those terms of services are silly. If I ever do start my own business, one of the things on the checklist is to have a minimal, if any, terms of service, because nobody wants to waste time reading them, and 99% of what is in ToSes is in the law anyway. Except, of course, data collection beyond function…

If you read the TechCrunch article you wouldn't have to guess where it was shown. There is a screenshot of the prompt that shows that the prompt and explanation "Continuously upload info about your contacts like phone numbers and nicknames, and your call and text history." Your solution of hiding this information in a minimal terms of service is strictly worse. My take away is that you can tell users exactly what you…

In the article is mentioned people that did not get that prompt and still have the contacts and calls uploaded, could this prompt been added later so people that used FB before it was added did not had the chance to opt out?

I did not see in the screenshot an OS permission prompt, so if the app had the access locally a bug in the settings could have reset/flip the options and upload the data anyway, like how Windows forgets about your privacy settings on updates.

Re: Facebook denies it collects call and SMS data from phones without permission

#70
post #59
post #6

I notice the Facebook response is all written in present tense - technically not specifying whether they were abusing the laxness of android v16 up until Oct 2017... And I trust everything Facebook say precisely as much a Zuckerberg told us all we should with his much-quoted quip "They trust me. Dumb fucks."

I feel like if you should quote a very inflammatory and controversial "quip" you should at least provide a source. Maybe I'm the only one on HN that hasn't heard about it, but even so, sources shouldn't be omitted.

https://en.wikiquote.org/wiki/Mark_Zuckerberg
Post reply on HN