Live data from Hacker News

Facebook Data Collected by Quiz App Included Private Messages

mobile.nytimes.com

91–100 of 142 posts

Re: Facebook Data Collected by Quiz App Included Private Messages

#91
post #37

Earlier quoted context omitted.

Cambridge Analytica didn't pay to access this data. They got users to give it to them for free though Facebook's developer platform.

Thanks for the correction, I thought CA paid for access to the data the test collected.

As mwarkentin included, CA _did_ pay users via mechanical turk to install the quiz app. So they did pay the users directly for their data, but not facebook. It seems there is no way to completely stop this without facebook blocking people from exporting their own data. Since CA could just pay people to send them their exported facebook data.

Re: Facebook Data Collected by Quiz App Included Private Messages

#92

Why is it surprising or even remotely controversial that an app that people explicitly authorized to access their messages (informed consent) then proceeded to access their messages? The app didn't have access to friends' messages, so I don't see what the issue is here, other than yet another clickbait headline.

Context and intent matter.

If someone at a gas station asks me "hey could you give me $5 so I can buy some gas. I'm out of cash." and I give them the money. Then they proceed to fill up a can and go burn down a house. Should I be arrested as an accomplice?

There was no indication that they would do that and if I knew there's no chance I would agree to give them anything.

You'd have to find additional evidence that I consented to that action. In this case, I really doubt anyone knew that their data would be used in this way when all they wanted to do is take a quiz.

Re: Facebook Data Collected by Quiz App Included Private Messages

#93
post #70

Earlier quoted context omitted.

On one hand it's actually a fairly reasonable API. Imagine using third-party AIM clients a decade or more ago. Same kind of thing.

They never provided ability to send messages. This is a useless thing for AIM clients.

You used to be able to connect to facebook messenger via XMPP. Combined with this permission, it would have let you retrieve historical messages and add persistence among alternative clients.

https://news.ycombinator.com/item?id=9266769

Re: Facebook Data Collected by Quiz App Included Private Messages

#94
post #24
post #21

Earlier quoted context omitted.

Apparently, v1.0 of the Facebook Graph API could access users' private messages via the 'read_mailbox' API request [1]. This was deprecated when v2.0 launched. " Version 1.0 of the Graph API launched on April 21, 2010. It was deprecated in April 2014 and closed completely to legacy apps (ie, existing apps that used the API before April 2014) on April 30, 2015. " [1] https://medium.com/tow-center/the-graph-api-key-poi…

But why? Why would anyone set up an API access to PRIVATE messages. That's crazy :o

Facebook's agenda at that point was get as many developers onto their platform by enticing them with all this access to "data people gave away".

Re: Facebook Data Collected by Quiz App Included Private Messages

#95

Earlier quoted context omitted.

If a friend of yours authorized access to their messages, then the app would have access to your private messages with that friend.

Only in the same way that apps that you authorize to work through Gmail also have access to your emails with other people. I just don’t see an issue here. The messages permission required explicit, separate consent from other permissions. There is not a single user that could argue that they didn’t understand that specific aspect of this app. This story is just a grab at clicks.

> Only in the same way that apps that you authorize to work through Gmail also have access to your emails with other people.

"only"? What does that even mean in this context?

> I just don’t see an issue here.

Maybe write out your thought process instead of just a conclusion with no path from here to there.

Re: Facebook Data Collected by Quiz App Included Private Messages

#96
post #61

Earlier quoted context omitted.

There are a lot of valid uses. Why would it be better for your data to be locked up and unexportable?

False equivalence. Exportable doesn't mean acessible to the world.

But someone could pay you for your exported Facebook data (which can include data from friends such as your message history, etc). From my understanding, this is essentially what CA did. CA just obfuscated they were doing this by using the Facebook developer program to automate this process and Mechanical Turk to pay users to give them their data. I agree the Facebook developer program made it really easy to phish for this data.

Re: Facebook Data Collected by Quiz App Included Private Messages

#97
Around 2011+ we saw not only quiz apps but also offerings such as "See who views your profile" that would result in an OAuth authorisation. How long were those authorisations active before being revoked? How much data was exfiltrated, then and since, and to whom?

If it wasn't for recent changes to authorisations being suspended after a period of time these tokens could be seemingly worth something to the right person.

The root problem being, average users don't know what they're giving access to and know why its important to be critical of such access.

Re: Facebook Data Collected by Quiz App Included Private Messages

#98

Earlier quoted context omitted.

Your moral compass need to be checked.

And when I’m done doing that, I should probably check my sanity, because I have to be imagining this thread. It’s absurd that someone thinks that they have an expectation of privacy when they voluntarily choose to send a message to someone else. I know you can’t satisfy everyone all the people all the time, but this idea is just bonkers.

> It’s absurd that someone thinks that they have an expectation of privacy when they voluntarily choose to send a message to someone else.

How does this world view reconcile with the fact that many different states have 2 party consent? Or the fact that considerable money and effort have been spent on concepts like OTR?

People expect others to have some discretion in what private information they pass on to others. Most applications have this assumptions built in mind.

You can easily forward a single email to someone in gmail, but there is not 1-click solution to send all of your emails to someone else.

Re: Facebook Data Collected by Quiz App Included Private Messages

#99
post #62

Earlier quoted context omitted.

For people I've discussed with, the surprising part is that they can do anything with it. You and I know that (currently) if someone has the data, they'll scrape/manipulate it at will. I believe, a reasonable person, would expect the limits of the access grant to end with the purpose of the app (a quiz) and not extend any further. Most contracts/agreements have limits and this one is implicit in the working of the ap…

>Yes the user agreed to grant some permissions so a quiz could be taken. You had to authorize the messages permission separately from all other permissions. If you didn't want your messages accessed, you simply declined that permission. This one's on the user, not on anybody else.

You are willfully ignoring the strongest point in my statement.

Re: Facebook Data Collected by Quiz App Included Private Messages

#100
post #49
post #45

Earlier quoted context omitted.

>what more is there to ask? (1) Make an ernest attempt to use ML, algorithms to identify their customers who are using those leaked datasets Facebook negligently exposed and help devalue the data, instead of eagerly selling them targeted advertising services? I don't know if they did this, but it sure seems doubtful. (2) Quickly and openly disclose the extent of the leaked data (3) Stop using manipulative and deliber…

> (1) Make an ernest attempt to use ML, algorithms to identify their customers who are using those leaked datasets Facebook negligently exposed and help devalue the data, instead of eagerly selling them targeted advertising services? I don't know if they did this, but it sure seems doubtful. How could they do that? The cat is out of the bag and FB aren't going to have any knowledge about where that data is now. Have…

True, it's not easy to do, and maybe it's not feasable to determine who is using the data. I don't know, maybe someone from Facebook will chime in on the issue, or leak some more info about company behavior.

>I think some caution is a good idea, they don't want to get the numbers wrong - although they are making steps in the right direction with the message to 87 million on their news feeds.

Totally agree with the second part, but ~4 years (only divulging the info when forced to during PR damage control mode) is well past being cautious. It's being cautious with the amount of damage the disclosure does to your profits, Equifax doesn't even wait that long.

Post reply on HN