Live data from Hacker News

Facebook denies it collects call and SMS data from phones without permission

techcrunch.com

111–120 of 370 posts

Re: Facebook denies it collects call and SMS data from phones without permission

#111
post #37
post #5

The Facebook blog post includes this screenshot [0]. That's definitely an opt-in, although I could imagine a non-technical person clicking through it without reading the grey text. Better than nothing. [0]: https://fbnewsroomus.files.wordpress.com/2018/03/opt-in_scre...

dark pattern like this one needs to be hammered down by law. We should consider the most prominent button as "default" and such a form as an "opt-out".

I hate to play devil's advocate against something i agree with here, but there's a lot of subjective ideas here, most obviously determining which button is "most prominent."

Re: Facebook denies it collects call and SMS data from phones without permission

#112

I suspected this many years ago when familiar faces from our customers started to appear in the friend suggestion box. I've never installed the FB app on my phone, but our less privacy oriented customers probably have. What pisses me off is that while I can choose what information I share, I haven't given other people nor Facebook permission to read phone call logs that involve me.

The worst part is that they probably suggested these various customers to befriend themselves, just because they all had you in their contact list. Scenarios like these have been reported with unrelated patients of medical professionals.

Re: Facebook denies it collects call and SMS data from phones without permission

#113
post #42

Earlier quoted context omitted.

> People don't read the pages. People don't read the user agreements. Then maybe "people" shouldn't act completely outraged when they find out that their call history was uploaded?

No one chose anything. The best description I recently heard of these types push questions is "exploiting a bug in human behavior. And when the bug is in the brain, there is no patch."

So how do we solve this? What is the general framework we use to agree to transactions of this kind where users allow access for some data in return for something?

Re: Facebook denies it collects call and SMS data from phones without permission

#115
post #42

Earlier quoted context omitted.

It is not "better than nothing," it is the minimum that is technically and legally required. The UI is intentionally deceptive. The text is deceptive. The big text says "Text anyone in your phone," which sounds great, but doesn't actually say anything about data sharing. The small low contrast text, describes what they're doing. They know that by putting it small and grey, most people wont read it. The buttons are de…

> People don't read the pages. People don't read the user agreements. Then maybe "people" shouldn't act completely outraged when they find out that their call history was uploaded?

The ToS and other conditions attached to various services and relationships are literally far too long and complex for anyone to read, understand, and recall in full detail.

This point has been the subject of numerour articles and documentaries.

Hoback states that if one was to read everything in these user/service agreements, it would take one full month, that’s 180 hours every year” and that according to The Wall Street Journal “consumers lose over $250 million dollars due to what’s hidden in these agreements.”

https://en.m.wikipedia.org/wiki/Terms_and_Conditions_May_App...

Re: Facebook denies it collects call and SMS data from phones without permission

#116

Earlier quoted context omitted.

Apple had zero permission management on the contact book, it was wide open. Especially FB and LinkedIn exploited that heavily and partly do to this day.

not so true. "Users can grant or deny access to contact data on a per-app basis. Any call to CNContactStore will block the app while the user is being asked to grant or deny access. Note that the user is prompted only the first time access is requested; any subsequent CNContactStore calls use the existing permissions." https://developer.apple.com/documentation/contacts#1773385

They do today, back up to 2012-2013 they did not. Apps were also overly abusing it back then such as Path [1] and many others.

> The operator of the Path social networking app has agreed to settle Federal Trade Commission charges that it deceived users by collecting personal information from their mobile device address books without their knowledge and consent.

Android didn't really close/tighten permissions until 2014 with Android 4 Ice Cream.

[1] https://www.ftc.gov/news-events/press-releases/2013/02/path-...

Re: Facebook denies it collects call and SMS data from phones without permission

#118
post #113

Earlier quoted context omitted.

No one chose anything. The best description I recently heard of these types push questions is "exploiting a bug in human behavior. And when the bug is in the brain, there is no patch."

So how do we solve this? What is the general framework we use to agree to transactions of this kind where users allow access for some data in return for something?

Effectively, what GDPR requires. You must inform users what the data will be used for when asking for opt-in permission to use it, as well as offering opt-out and right-to-deletion.

Re: Facebook denies it collects call and SMS data from phones without permission

#119

Ok, well this is just great. So Facebook has all my contacts from their aquisition of WhatsApp and even though I've never used any of their Apps or had an account with them, I'm pretty sure everyone I typically communicate with has the App and did not opt-out of this collection. So they get data on me for free that the police would need a court order to get. This kind of data retention has been highly controversial i…

> I should have a way of asking them to delete all data they have on me including meta data from sms/phone calls they might have collected.

With GDPR they will have a legal requirement that "delete your account" deletes all of your data if you're in the EU. Currently they don't delete conversations with other people, and don't delete any ML data which was based on your data, but hopefully that will be ruled illegal under the GDPR requirements.

Re: Facebook denies it collects call and SMS data from phones without permission

#120
Could anyone here imagine if an application we installed on our computers did this? What if the twitter app went around my computer after asking for admin permissions to find all my contacts and messages from different programs just to beam up to facebook.

Such a thing was considered a virus in my time.

Post reply on HN