Live data from Hacker News

Why We Disagree with The New York Times

newsroom.fb.com

161–170 of 325 posts

Re: Why We Disagree with The New York Times

#161

I'm no huge Facebook fan - hardly use it these days, but... These apps are just alternative Facebook clients. Don't we _want_ a system where you can use different clients to access your own data? If the problem is not trusting the client, well, that'll be a problem for any such system, even some utopian fully open, distributed and federated social network - until you build an open source client yourself.

I think the problem is Facebook's lack of transparency here. As a user, suppose I have some information that I've marked as "not available to third-party apps". Then I might be surprised to find out that Blackberry's servers have access to that data via a secret API, even if it is to implement a "Facebook experience".

Re: Why We Disagree with The New York Times

#162
post #43

Earlier quoted context omitted.

Surely it is only giving blackberry the information if you type in your login credentials on a blackberry right? I don't see how the situation is actually different now: if you run the official Facebook app on your Galaxh phone then Samsung could scrape and exfiltrate the data anytime it wants. It is Samsung's fault if they do it not Facebook's.

If Samsung secretly runs a keylogger on all their phones and then steals your data that way, that's a Samsung problem and you should be angry. That is not what happened here. Facebook officially blessed other platforms, allowed them to say you were signing into Facebook, and then allowed those platforms to have access not only to your data, but your friends exhaustive data. Facebook was aware of this, explicitly allo…

“and then allowed those platforms to have access not only to your data, but your friends exhaustive data.”

Only for purposes of allowing the user to interact with Facebook. The platforms themselves couldn’t use the data for anything other than supporting user actions.

This is perfectly reasonable and is why APIs exist.

The issue, which has not been repeated, would be if those platforms retained data without user consent and used the data for other purposes. That would violate the contract they signed with Facebook and be bad for use privacy.

To a non technology person, these two very different things sound similar (Facebook let Microsoft access use data). But this is meaningless without more context.

Re: Why We Disagree with The New York Times

#163

Earlier quoted context omitted.

Sure, but do we just absolve people of all individual responsibility to think even a little bit and make educated choices? I think there is more evidence that people just don't really care about this issue. After all of this came out, FB use didn't really go down.

I think it's absurdly unrealistic to expect people to do in-depth due diligence on all of the services they use. Modern society requires us to trust innumerable service providers and their dependencies to enable so much of the convenience we take for granted. What little knowledge we do have about abuse comes from the accountability of these companies to regulators like the FTC and FCC. Realistically, I think we have…

I disagree completely, honestly. If you are signing up for a service like Facebook and they are asking you to click a bunch of boxes, it's not unrealistic to expect you to

a) either understand what you are clicking on or b) just refuse to click on it

what is unrealistic is to expect society to babysit you every single time a moderately complex choice is presented to you.

Re: Why We Disagree with The New York Times

#165

Earlier quoted context omitted.

> You broke your promise. Then you face the legal consequences for doing so. Thats what prevents people from breaking them in first place. Unless you are arguing that all legal contracts are useless because they can be broken. I am not asking about the logistics of leaking. Yes ofcourse its physically possible, I am asking why the consequences of breaking a contract don't matter in this specific case.

How do you prove that Bob leaked the information? How do you prove that Abe told Bob? How do you prove that FB was the source of information to Abe? How do you demonstrate that FB, Abe, and Bob did not take all good faith efforts to keep the information secure? How do you show any actual damages?

>How do you prove that Bob leaked the information? How do you prove that Abe told Bob?

Data watermarks, small changes (little tiny bits) that allows to track the leaks.

Also audit logs, you know who has what, etc. The topic has been hotly discussed with GDPR as the leaks have rather harsh consequences (beside being dragged through the mud, erm newspapers).

Re: Why We Disagree with The New York Times

#166

Earlier quoted context omitted.

Likely referring to this article [1]. However, the claim that they made "hundreds of thousands of people fall into a depression" is pretty exaggerated - FB demonstrated it could influence the mood of users via changes to the algorithm, but the overall effect size was small (Cohen's d = 0.001). I am very critical of FB and this type of research, but don't know if anyone became depressed over the experiment. It's possi…

Staging an experiment of this nature without informed consent of the participants is unethical, irrespective of whether the technique proved to be effective.

[deleted]

Re: Why We Disagree with The New York Times

#167

Earlier quoted context omitted.

Likely referring to this article [1]. However, the claim that they made "hundreds of thousands of people fall into a depression" is pretty exaggerated - FB demonstrated it could influence the mood of users via changes to the algorithm, but the overall effect size was small (Cohen's d = 0.001). I am very critical of FB and this type of research, but don't know if anyone became depressed over the experiment. It's possi…

Staging an experiment of this nature without informed consent of the participants is unethical, irrespective of whether the technique proved to be effective.

"It's easier to ask for forgiveness than permission" is a very popular mantra among the boy wonders of Silicon Valley.

Re: Why We Disagree with The New York Times

#168

Crazy that everyone in here is defending Facebook. - How on earth does Facebook justify giving direct API access to information that users have, in every setting possible, marked as private? - How on earth does Facebook justify offering deep API access on users who have literally disabled API access to their data? It's ridiculous, and it's more ridiculous that users here are conflating "basic API access with a sane p…

“How on earth does Facebook justify offering deep API access on users who have literally disabled API access to their data?”

Here how it seems really non-crazy to me as a programmer. Let’s say I make phone with a Linux OS. I want to make an app to let users check Facebook on my weird OS. I ask Facebook, they say no. I then build an app to call their API and let users do stuff.

All my app does is call the API and show it to the user. In order for the app to function it has to use private data. But the data are not retained or analyzed, just used to operate the app.

This is how all 3rd party apps work. The APIs were not for the general public, but only to trusted third parties. The alternative is that only Facebook can build and show apps.

So this is pretty much how APIs have worked forever and why you only install apps and log into apps you trust.

It would be like complaining that Adobe Reader can read private files from your laptop via Windows/Mac APIs. Of course it can, this is good. It’s bad of Adobe were to misuse the data.

Re: Why We Disagree with The New York Times

#169

Earlier quoted context omitted.

> Signed agreements do not prevent your information from being used in other ways. That's insane, literally. Yes but just two sentences later in the post... > And our partnership and engineering teams approved the Facebook experiences these companies built. They're saying they inspected these apps. You jumped to "literally insane" so fast there.

Nope, you know that once the data leaves your server it is out of your control. These companies could have fooled fb representatives quite easily if they wanted.

If you're not as up in arms about the access that web browsers have to user's facebook data, then I'll assume your response to this issue is just another instance of hn's fb derangement syndrome.
Post reply on HN