Live data from Hacker News

Facebook pauses app reviews, disables new user authorizations

developers.facebook.com

51–60 of 157 posts

Re: Facebook pauses app reviews, disables new user authorizations

#51
post #44
post #42

Earlier quoted context omitted.

> Bitcoin is extremely secure, and also open to all. And it has zero privacy: everybody can see everybody's transactions.

That's because privacy was not a goal of that particular system. Pseudo-anonymity was the goal. (That's unrelated to my point about security and openness though.)

It seems pretty related in this case, since the kind of security that is being discussed here is around access to private data (and I'd note that it was you that used the word security here, not the OP who made the more correct contrast between openness and powerfulness).

One could equally make the point that Facebook is secure because no one has hacked their servers, and that it is open because it is free to join. That's a pointless thing to say though.

But in any case: yes, there is an inherent tension between privacy and openness.

Re: Facebook pauses app reviews, disables new user authorizations

#52
post #33

Earlier quoted context omitted.

>He hasn't. He has pledged to donate 99% of his wealth to a private, for-profit organization that he owns. I initially thought you were being overly critical here. It looks like you're right, the "Initiative" he created is an LLC and not a non-profit. https://en.wikipedia.org/wiki/Chan_Zuckerberg_Initiative#Com...

If you read higher up in that wiki it lists all of the money the initiative has given away so far. I'm not sure why people think that the LLC doesn't give away money.

The issue isn't that the LLC doesn't give away money. The issue is that it is a LLC.

Re: Facebook pauses app reviews, disables new user authorizations

#53
post #49

The so-called "data breach" was always in reality a by-product of an open platform that hundreds of thousands of developers could easily build apps on top. You may err on the side of "more reviews" or "less powerful API", but in the end, those ideals are in tension. The more open the platform, the more open to this kind of "breach". People who believe in the idea in this kind of platform having an API should have lon…

Apple got this right from the beginning despite years of criticism about the "walled garden". They took arrows for years: all the "open always wins" from the FOSS types, all the press coverage of some app developer crying about App Store rejections or onerous rules. They didn't get it wrong because they know who butters their bread: customers. Developers are rightly prioritized last. Fun to give this Paul Graham essa…

You're comparing Apples to oranges (I'm sorry)

Apple doesn't have a social network. They also don't rely on advertising and 3rd party data brokering.

It's easy for Apple to be the 'good guys' here when they have physical products as their profit generators.

FOSS would have worked better in the Facebook case too as people and developers would know/discover a) where their data is and b) what risks it faces

Re: Facebook pauses app reviews, disables new user authorizations

#54
post #51
post #44

Earlier quoted context omitted.

That's because privacy was not a goal of that particular system. Pseudo-anonymity was the goal. (That's unrelated to my point about security and openness though.)

It seems pretty related in this case, since the kind of security that is being discussed here is around access to private data (and I'd note that it was you that used the word security here, not the OP who made the more correct contrast between openness and powerfulness). One could equally make the point that Facebook is secure because no one has hacked their servers, and that it is open because it is free to join. T…

I should have used Monero as an example instead of Bitcoin, but I thought less people would have heard of it. Privacy can also be achieved with these primitives.

Re: Facebook pauses app reviews, disables new user authorizations

#55
post #38

The so-called "data breach" was always in reality a by-product of an open platform that hundreds of thousands of developers could easily build apps on top. You may err on the side of "more reviews" or "less powerful API", but in the end, those ideals are in tension. The more open the platform, the more open to this kind of "breach". People who believe in the idea in this kind of platform having an API should have lon…

This is buying into the idea that security and openness are at odds. Bitcoin is extremely secure, and also open to all. The way forward is people owning all their data encrypted, and revealing zero knowledge proofs about that data to services that want access.

> The way forward is people owning all their data encrypted, and revealing zero knowledge proofs about that data to services that want access.

Who has a financial incentive to build and maintain that system?

Re: Facebook pauses app reviews, disables new user authorizations

#56
This is a bit out of left field, but since the height of Farmville I've argued that Facebook should offer cloud services. I know these days everyone wants you to build on their cloud and it's a bit oversaturated, but a very easy way for Facebook to make data available to developers while maintaining security is to run the code that operates on that data on their servers. Seems like such a no-brainer I'm surprised they haven't done it.

But maybe I'm missing something obvious.

Re: Facebook pauses app reviews, disables new user authorizations

#58
The Facebook API has been useless since 2014 when most access to friend data was cutoff. Since then, if your objective was data collection, that could be easily achieved by scraping publicly available information (many friends lists are public, there are many public posts, etc. - certainly enough to use in aggregate to formulate campaign strategies etc.). I suspect that will be the next “scandal,” since in 2018, people can’t possibly take personal responsibility for the things they post and allow to be public.

Ironically, the “scandal” that caused this whole thing is a non-issue. Pre-2014 Facebook apps could collect a lot of information about you and your friends, along with their Facebook user IDs, and that was scary because there was a time when you could simply submit a list of user ID’s that you wanted to show a specific ad to. But since Facebook advertising cannot be targeted by user ID anymore, and this policy was in place well before the 2016 election, all of that data was essentially useless to any participant in the 2016 election other than for aggregate things like general campaign strategies. I am intimately familiar with the advertise by ID issue - I was awarded a $2k Facebook bug bounty for spotting an exploit in the Custom Audiences feature that allowed an equivalent version of targeting by ID after they disallowed it.

So while it’s possible that Obama used his special access to the entire US social graph to successfully influence his elections, it is impossible for Trump or Hillary to have done it even if they had the data because of the changes in the FB ad platform in between 2012 and 2016. This entire “scandal” was created and promoted by people that don’t understand, or actively ignored, this concept. If you ask everyone that has read the recent headlines, including reporters that wrote the stories, I’ll bet 99%+ will tell you that they believe they could be specifically targeted with ads.

It would be interesting to see if the executives at any of the media companies that have managed to sell this scandal to the public took unusually large short positions in Facebook stock before releasing the story. Since the story is effectively fraudulent (it was not possible for the election to have been influenced in the way that the stories imply), I assume that would be securities fraud.

Re: Facebook pauses app reviews, disables new user authorizations

#59
post #23
post #8

facebook privacy through restricting the api is an illusion, a lot of content can be extracted with scrappers

You have to be someone's friend to extract that same info with scraper though, no?

It depends on their privacy settings. Some people expose a lot of information, and you can (if you're pateitnt) put together a great deal of information about a person with their privacy settings locked down if you study enough of their friends.

Of course, FB could just resort to making everyone's info private. But then it would suffer a serious loss of utility, as many friendships and social connections are validated by the existence of mutual acquaintances. Most of the time this is completely innocent and desirable for all parties, which is what allowed FB to become so popular in the first place.

Re: Facebook pauses app reviews, disables new user authorizations

#60
post #49

The so-called "data breach" was always in reality a by-product of an open platform that hundreds of thousands of developers could easily build apps on top. You may err on the side of "more reviews" or "less powerful API", but in the end, those ideals are in tension. The more open the platform, the more open to this kind of "breach". People who believe in the idea in this kind of platform having an API should have lon…

Apple got this right from the beginning despite years of criticism about the "walled garden". They took arrows for years: all the "open always wins" from the FOSS types, all the press coverage of some app developer crying about App Store rejections or onerous rules. They didn't get it wrong because they know who butters their bread: customers. Developers are rightly prioritized last. Fun to give this Paul Graham essa…

An API into a closed service is no more FOSSy than a graphical user interface into a closed desktop app. I don't really understand the comparison, what do you think motivates it?

Facebook has open-sourced a few internal projects, but none of them had much to do with our personal data.

In fact, it's difficult to blame the API when the problem was that the data was collected in the first place. Surely Zuckerberg has some political opinions of his own, if CA hadn't triggered this media storm what would have stopped him from supporting his own favorite candidate internally? In fact, what's stopping him from doing that right now? Would it even be illegal?

Post reply on HN