Live data from Hacker News

Facebook Gave Device Makers Deep Access to Data on Users and Friends

nytimes.com

81–90 of 233 posts

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#82

At which point can facebook start suing around for [slander/damages]? It's not like they did all this in secrecy , they were quite open about their platform with developers (which has helped developers warm up to a company that basically sells gossip). They never will of course, because they 'd be retroactively judged with today's standards. E.g. I find their unfair advantaging of the Obama campaigns a lot more troub…

You can't sue for libel over accurately reported news? The bar for successful libel actions is extremely high in the US, as well.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#83
post #5

What is this describing? First-party apps with Facebook integration and/or OS features connecting to Facebook? The leakage of Facebook information onto MS/Apple/Blackberry servers would be concerning, but having Microsoft software connect to Facebook on a user's device sounds harmless (to the extent we trust MS/Apple/Blackberry software to not leak information so accessed). Right now I'm giving Apple similar access t…

> Facebook allowed the device companies access to the data of users’ friends without their explicit consent, even after declaring that it would no longer share such information with outsiders. Some device makers could retrieve personal information even from users’ friends who believed they had barred any sharing, The New York Times found.

There's a dangling "their" in there which is causing trouble. What I think this means:

- Alice adds their email or phone number to their Facebook account. Alice sets this to "private".

- Bob is friends with Alice

- Bob's phone has access to Alice's phone/email, even though this wouldn't be normally visible to him.

(The Windows Phone social media integration in the contact maanger was absolutely excellent at presenting everything about your friends on every platform in one convenient place)

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#84
post #44
post #42

Response from FB: "Why We Disagree with the NYT" https://newsroom.fb.com/news/2018/06/why-we-disagree-with-th...

"We are not aware of any abuse by these companies." - seems to be carefully worded. They do not make claims that there are no abuses, nor do they elaborate what checks/audits they have in place to detect abuse.

> They do not make claims that there are no abuses

How can any honest people make such claim? It is the same as proving the non-existence of abuses.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#85
post #67

Earlier quoted context omitted.

I wish I could agree with you're more nuanced viewpoint, but seeing a whole industry making insane amounts of money based on abusive and deceptive business models suggests that there truely is a broader issue. Whether the underlying attitude is best describe by "move fast, break things" is debatable but we can't easily dismiss the idea.

I think the point is that that quip usually refers to technical breakage, i.e. "it's better to ship more often and potentially break something that you then fix equally quickly, than spending thrice as much time analysing the problem to ensure there's no breakage in the first place". In other words, an entirely different meaning that what the grandparent meant when they said it was a great phrase for it.

The point that the poster was making was that while the phrase normally refers to its technical development philosophy, it seems that it also seems to reflect Facebook's attitude to other issues, such as regulation and privacy.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#86
post #83
post #5

What is this describing? First-party apps with Facebook integration and/or OS features connecting to Facebook? The leakage of Facebook information onto MS/Apple/Blackberry servers would be concerning, but having Microsoft software connect to Facebook on a user's device sounds harmless (to the extent we trust MS/Apple/Blackberry software to not leak information so accessed). Right now I'm giving Apple similar access t…

> Facebook allowed the device companies access to the data of users’ friends without their explicit consent, even after declaring that it would no longer share such information with outsiders. Some device makers could retrieve personal information even from users’ friends who believed they had barred any sharing, The New York Times found. There's a dangling "their" in there which is causing trouble. What I think this…

I don't think that's right. They clarify this somewhat further into the article. "Facebook’s view that the device makers are not outsiders lets the partners go even further, The Times found: They can obtain data about a user’s Facebook friends, even those who have denied Facebook permission to share information with any third parties." I'm pretty sure this is a reference to the setting which disabled sharing information with Facebook apps used by friends. If I'm understanding correctly, it's more like this:

- Alice adds their email or phone number to their Facebook account. Alice sets this to be visible to friends, but not to third-party apps they use.

- Bob is friends with Alice.

- Bob's phone has access to Alice's phone/email, even though this wouldn't normally be available to third-party Facebook apps like games.

Edit: Facebook's response at https://newsroom.fb.com/news/2018/06/why-we-disagree-with-th... also clarifies this. "Contrary to claims by the New York Times, friends’ information, like photos, was only accessible on devices when people made a decision to share their information with those friends."

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#87
post #42

Response from FB: "Why We Disagree with the NYT" https://newsroom.fb.com/news/2018/06/why-we-disagree-with-th...

What I apprehended from the article is that those API's still exist, and even still work in full.

Meaning that today it is still possible to generate an access_token using a client_id extracted from an old blackberry device with a valid facebook account and extract much more data (using the private device API's) than what that user should be allowed to see.

Do I understand that correctly? Because that seems like an enormous security breach.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#88

Most notable pieces I took from the article: 1) Facebook does not see third parties (such as BlackBerry) as “third parties.” 2) Facebook told Congress that it disabled third party access to user data, but in actuality did not. My own strong interjection: Facebook’s competitive advantage is its disregard for ethics. Somehow, Zuckerberg has been able to convince a lot of smart people to do unethical things and build un…

And they got the FTC to not really interfere with their practices, even after they were found out.

Good luck on net neutrality with the FTC...

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#89
post #43
post #42

Response from FB: "Why We Disagree with the NYT" https://newsroom.fb.com/news/2018/06/why-we-disagree-with-th...

Agree with FB on this one. The privacy issue with 3rd party developers was that friend data was sent to the 3rd party developer databases. Here, the data just stays on the device. The way the article is titled can make it look like the device makers actually got to make their own database of Facebook users. Edit: I read it again, the article does say "Facebook acknowledged that some partners did store users’ data — i…

Once an app has particular data, there is nothing FB can do to prevent it from uploading that data wherever. It would be difficult for Google or Apple to prevent that, and they control the platform. With enough apps, it is a certainty that this happened.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#90
Facebook's old policy: Move fast and break things.

Facebook's new policy: Move fast and deny everything.

I'm only half-joking as I was surprised to see a Facebook rebuttal so quickly after an article like this. It seems a new strategy is in place, to not let these article fester. The problem is their response is devoid of actual content, or even actual rebuttals to the main points of the NYT article. Mainly that FB does not consider these vendors as "third-parties", and that friends data is accessed even when sharing is explicitly disabled.

Post reply on HN