Live data from Hacker News

Facebook Gave Device Makers Deep Access to Data on Users and Friends

nytimes.com

141–150 of 233 posts

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#141

This and the discussion here is obnoxiously bad. Facebook gave some device makers special APIs to access authorized data. This is literally no different than a web API or scraping facebook HTML, just more streamlined. What you guys seem to be objecting to is that non-facebook code was able to interact with authorized user data. But that is a necessary feature of displaying data of any kind (unless facebook owns the e…

> This is literally no different than a web API or scraping facebook HTML, just more streamlined. I see you're using the new definition of literally, the one that means figuratively. In the same sentence you have said it is no different and then said it is vastly different. Your post makes no sense. Even if you were right that the data is 100% hash-compatible, SHA-1 it and get the same data as the API (you're wrong),…

Did you actually write this many words based on your disagreement of my usage of "literally"?

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#142

Earlier quoted context omitted.

No, you are wrong, this is a pretty egregious mistake. They defined device makers as service providers, and then allowed them to do things that even third parties weren't allowed. Yet they claimed they shut that stuff off to third parties (so they lied by omission). "No, we don't allow third parties anymore to do that kind of stuff" (but there's this large group that can do it, but we aren't calling them third partie…

>They defined device makers as service providers, and then allowed them to do things that even third parties weren't allowed. Because they're not third parties. Third parties are anyone off the street that meets some minimal requirements. It's like the distinction between third party and second party releases on video game consoles. Second party releases are extensions of the first party publisher because of the spec…

The user is the second party dude.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#143
post #114

Earlier quoted context omitted.

> Editorial: It's startling to me how outfits as reputable as NYT can time and again parrot a narative (e.g., FB is better than sliced bread), and then after the fact report on something that was right under their nose all along. That is almost completely a problem of the format of news articles, and that journalists have to write for a lowest common denominator. Take as an example from the NYT article: > Details of…

> Note, in the first case FB did constrain the ability of the device makers to access data on the phone, by getting them to sign TOS of the api That's not a very good constraint.

My point is, that after reading the NYT article twice, I see several different interpretations, and the difference between the interpretations runs from FB is trying to do the right thing, to FB is outright lying. (And that it is pretty hard to write an article that nails down one of the interpretations without going into more technical detail than is possible in an article for a general audience.)

I agree that such a TOS is not a strong constrain, it is not technical and it is easily cirumvented, by just not using that specific api and instead getting the same data from the OS.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#144

Earlier quoted context omitted.

> This is literally no different than a web API or scraping facebook HTML, just more streamlined. I see you're using the new definition of literally, the one that means figuratively. In the same sentence you have said it is no different and then said it is vastly different. Your post makes no sense. Even if you were right that the data is 100% hash-compatible, SHA-1 it and get the same data as the API (you're wrong),…

Did you actually write this many words based on your disagreement of my usage of "literally"?

No, I wrote that comment because you are an abrasive member of the community who is writing direct insults to other members, calling them deranged, etc, and doing other things that are against the rules of the site. You are breaking the conversation here. You are distracting. You are lying. You are being abrasive and causing fights. You are calling people names and causing a big scene.

You ignored my entire post, and instead chose to post an off-topic question, further distracting and hurting the conversation. That is also against the rules. I'm responding to you so that others are more aware of the damage you are causing.

We are not "deranged" people for our thoughts on Facebook. Stop it.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#145

This and the discussion here is obnoxiously bad. Facebook gave some device makers special APIs to access authorized data. This is literally no different than a web API or scraping facebook HTML, just more streamlined. What you guys seem to be objecting to is that non-facebook code was able to interact with authorized user data. But that is a necessary feature of displaying data of any kind (unless facebook owns the e…

This is simply Facebook functionality being integrated into parts of the OS chrome.

We trust our devices not to exfiltrate our data every second we are typing on them. Tightly integrating social features into a mobile OS is not third party access unless the device maker in exfiltrating the data for any purpose other than encrypted cloud backup.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#146

Earlier quoted context omitted.

Yes, I didn't quite understand that. Apple had this to say: > An Apple spokesman said the company relied on private access to Facebook data for features that enabled users to post photos to the social network without opening the Facebook app, among other things. So is this like what connecting your Facebook account in Settings does? Allow you share pictures through the share sheet in Photos or whatever? What does App…

>is this like what connecting your Facebook account in Settings does? It depends on the platform. On iOS you could post various types of information to Facebook, and you could sync Facebook contact and calendar data to the local device. https://www.cnet.com/how-to/understanding-facebook-integrati... Aside from letting you share information and sync Facebook contacts and calendars, Windows Phone 7, for instance, pulle…

Apple told the Times that it wasn't involved with this since September of last year. I wonder if this is why it's no longer possible to update your Facebook status from the Notifications panel.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#147

This and the discussion here is obnoxiously bad. Facebook gave some device makers special APIs to access authorized data. This is literally no different than a web API or scraping facebook HTML, just more streamlined. What you guys seem to be objecting to is that non-facebook code was able to interact with authorized user data. But that is a necessary feature of displaying data of any kind (unless facebook owns the e…

No, you are wrong, this is a pretty egregious mistake. They defined device makers as service providers, and then allowed them to do things that even third parties weren't allowed. Yet they claimed they shut that stuff off to third parties (so they lied by omission). "No, we don't allow third parties anymore to do that kind of stuff" (but there's this large group that can do it, but we aren't calling them third partie…

This is like saying that Chrome, Edge or Firefox are “third parties”.

Embedding user agent functionality into the OS is not the same as third party access.

Talk to me when a device manufacturer is caught exfiltrating this user data off the phone and then aim your pitchforks at them.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#148

This and the discussion here is obnoxiously bad. Facebook gave some device makers special APIs to access authorized data. This is literally no different than a web API or scraping facebook HTML, just more streamlined. What you guys seem to be objecting to is that non-facebook code was able to interact with authorized user data. But that is a necessary feature of displaying data of any kind (unless facebook owns the e…

> Facebook gave some device makers special APIs to access authorized data. This is literally no different than a web API or scraping facebook HTML, just more streamlined. If I found out that Google was using Chrome during my authenticated Facebook web sessions to scrape my Facebook data, and my friends' Facebook data, I'd be pretty upset too.

But nothing like that happened here... in the slightest?

This was OS chrome integrating Facebook features. An API for Mobile OS UI to integrate Facebook features.

How else do you think the OS provides FB functionality... after you enter your credentials into the Settings screen?!

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#150
post #147

Earlier quoted context omitted.

No, you are wrong, this is a pretty egregious mistake. They defined device makers as service providers, and then allowed them to do things that even third parties weren't allowed. Yet they claimed they shut that stuff off to third parties (so they lied by omission). "No, we don't allow third parties anymore to do that kind of stuff" (but there's this large group that can do it, but we aren't calling them third partie…

This is like saying that Chrome, Edge or Firefox are “third parties”. Embedding user agent functionality into the OS is not the same as third party access. Talk to me when a device manufacturer is caught exfiltrating this user data off the phone and then aim your pitchforks at them .

Google, Firefox, and Edge are not Facebook so yes they are third party.
Post reply on HN