Live data from Hacker News

Facebook Gave Device Makers Deep Access to Data on Users and Friends

nytimes.com

221–230 of 233 posts

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#221
post #5

What is this describing? First-party apps with Facebook integration and/or OS features connecting to Facebook? The leakage of Facebook information onto MS/Apple/Blackberry servers would be concerning, but having Microsoft software connect to Facebook on a user's device sounds harmless (to the extent we trust MS/Apple/Blackberry software to not leak information so accessed). Right now I'm giving Apple similar access t…

The distinction wasn't made clear because we're talking about some 60 different agreements with various companies, with each company acting differently.

As stated in the article: Facebook acknowledged that some partners did store users’ data — including friends’ data — on their own servers. .. which meets your definition of concerning.

It will likely be some time before we learn the extent of all of these agreements and how the data was used.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#222

Earlier quoted context omitted.

Google, Firefox, and Edge are not Facebook so yes they are third party.

And does it upset you that when a user signs into facebook in one of these browsers, facebook allows the browser access to that user's data and even data of that user's friends? Even when those friends have explicitly disabled sharing of facebook data with third parties?

HN has reached a level of popularity where its attracted too many non-engineers that love jumping into these threads with ignorant, reactionary, hyperbolic responses. every post on uber/tesla autopilot has at least a few people calling for elon to be tried for manslaughter for car accidents. really shows the stupidity of the mob. this thread is another great example. if only it were benign and didn't have real, foolish policy implications like the GDPR

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#223
post #153

Earlier quoted context omitted.

Google, Firefox, and Edge are not Facebook so yes they are third party.

That’s not what the term means. User agents which render Facebook UI components are not “third parties” to my Facebook data anymore than my monitor manufacturer is a third party to my Facebook data while I am viewing the pixels in the screen.

> my monitor manufacturer is a third party to my Facebook data

It actually is. Your monitor, on the other hand, can be considered a part of yourself for the purposes of viewing the data.

If it somehow sends sensitive information back to its manufacturer, thought, that would be a new, different can of worms.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#224
post #94

Earlier quoted context omitted.

I generally agree with you that this piece is a bit sensationalistic but... > [...] they’re just engineers trying their best to do the right thing. What makes you say that? Beyond potential abuses of data by third parties (or whatever), I would expect that most FB employees are trying their best to get paid . Whether or not all or any single one of them cares about “the right thing” is mostly unknown to outsiders. I…

I worked there in the past. Everyone I met was earnestly trying to do good work and afraid of getting fired or sued for doing something that would impact privacy and thereby FB’s bottom line. Facebook is strongly incentivised to protect user data because that is their primary market advantage—having ad targeting data that other ad networks don’t. Leaks and breaches of trust are bad for business and bad for the RSUs t…

There is a huge distance between "Doing the right thing" and "doing one's best to avoid getting sued". There are lots of things that are legal but frowned upon in a decent society.

And no, Facebook is not "just engineers ". There are lots of other positions who make high-level decisions, e.g. decide how the company is going to make money.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#225

Earlier quoted context omitted.

Once an app has particular data, there is nothing FB can do to prevent it from uploading that data wherever. It would be difficult for Google or Apple to prevent that, and they control the platform. With enough apps, it is a certainty that this happened.

Have you heard of the power of legally enforceable contracts? Lots of things aren't technically impossible but are forbidden by the law or by a contract. It's one of the ways modern societies function, check it out!

How many firms have FB sued for breach of this hypothetical contract? Other than "Cambridge Analytica", can you think of one they might sue?

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#226

Earlier quoted context omitted.

> This disregard for ethics has allowed Facebook to “grow at all costs." There's a great phrase for this: "move fast and break things". When you believe it is ok to break small rules and norms, it becomes easier to break larger norms and ethics and rules. This philosophy took SV by storm, but at its core it's always been about disregarding things like laws and ethics, and now we are seeing the world that created.

You might think that that's a great phrase for it, but many other people don't interpret "move fast and break things" to mean what you think it means. I'm all for criticizing things that have gone wrong, but you're using an overly-broad brush.

I think at first people thought it meant something less toxic, like "things" meaning "software" or "industry norms".

But then the likes of Uber came along and showed that it meant "laws".

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#227

Earlier quoted context omitted.

Move fast and break things means don't be afraid to try things that might fail, but it doesn't mean ethics don't matter. There has long been a concern about what facebook does with people's privacy, now there's no doubt they went way too far.

> Move fast and break things means don't be afraid to try things that might fail, but it doesn't mean ethics don't matter. Sure it does. Move fast and break things means don't be afraid to try new things, but the line isn't "ethical concerns" but rather "legality". There's a whole gray area between what is ethically acceptable and what is legally acceptable, and FB profits in that gray area that other companies are a…

I think Uber's strategy was to go illegal in a big way, presenting a city with a fait accompli of a large number of unlicensed Uber cabs on the street. And then Uber would resist any regulatory efforts through lobbying and in court.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#228

Earlier quoted context omitted.

Yes, I didn't quite understand that. Apple had this to say: > An Apple spokesman said the company relied on private access to Facebook data for features that enabled users to post photos to the social network without opening the Facebook app, among other things. So is this like what connecting your Facebook account in Settings does? Allow you share pictures through the share sheet in Photos or whatever? What does App…

Apple is basically outsourcing user data mining to Facebook so that they can take the high groud. Didn't Tim Cook just two months back bragged about how Apple doesn't do certain things? He was right. He asked Facebook to do that for him.

Apple dropped social media integration from their upcoming operating systems.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#229

Earlier quoted context omitted.

The NYT article is definitely overblown. It’s popular to hate on Facebook about privacy, and yeah, they’ve made mistakes in the past, but that’s largely because they’re just engineers trying their best to do the right thing. IMO they need more non-engineer types to inform them what “the right thing” actually is, when it doesn’t align with the typical attitude of “Oh, there’s a technical solution to this problem!” > t…

Also from the article: Some device partners can retrieve Facebook users’ relationship status, religion, political leaning and upcoming events, among other data. Are those public?

Also, is it the data belonging to the user of the device and the Facebook account the device is logged into?

"Facebook integration on device OS allows viewing user's own profile after logging in to account" doesn't seem that shocking.

Re: Facebook Gave Device Makers Deep Access to Data on Users and Friends

#230
post #102
post #100

Earlier quoted context omitted.

So basically, your argument is that it's a dangerous attack on users' privacy for Facebook to allow users to view it through any app but their own, no matter how strict their contracts with the app developers, even if those developers are big companies like Microsoft with a lot to lose if they get caught doing something malicious? That it's an attack on gay rights for the Facebook walled garden to not be maximally st…

So basically your argument is that corporations should be trusted to self-police, because they know that bad things would happen if they get caught misbehaving? Like, Microsoft would be destroyed if they were found to be sending users' information to their servers and the average user didn't realize it?

Quite the opposite.

The moment facebook provides a way for a person to use a device to view information, they've simultaneously produced something the device's OS could use to exfiltrate that information. There's nothing facebook can practically* implement to allow Windows Phone users to use Facebook while preventing Microsoft from exfiltrating data.

Drop the API, and they can scrape webpages; it doesn't remove any fundamental barrier to information. If Facebook wanted/needed to limit access to this information from untrusted device manufacturers, a website is out of the question, and you couldn't just release a windows/android/linux app — you'd need to go per-manufacturer.

This leaves pretty much everyone worse off. [though it'd be pretty great for Apple.]

Users need to trust the manufacturer of the devices they use. There's room for regulation/enforcement to ensure that they can.

But holding services responsible for vetting the platforms that can access their data makes open platforms like the web untenable, and doesn't fix anything.

* Impractically, facebook could send and show encrypted data which can be decrypted by the user via pen & paper.

Post reply on HN