All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...
> a service where millions of people are giving their banking credentials so some random startup can mine your transaction data
Wow, that's insane. I didn't think I'd ever be happy that all banks here in Brazil require you to install an invasive piece of software to validate your computer before allowing you to use online banking, which as far as I can see makes that sort of business model non-viable here.
All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...
Swedish payment processor Klarna does something similar to this as well. If bying something through the platform by direct bank transfer you are asked to sign to your bank to accept the payment using BankID [0], which is normal. What is not normal is that they grab your personal identification number and send a login request using BankID before you open your app. When authenticating the login you authorize one of Kla…
The way I saw this done is through an iframe, I suppose it's something similar to 3DS/VbV (while ridiculously misguided, this iframe thing was done correctly)
I think Facebook is very desperate and they don't seem to have a choice. You see, Facebook has Facebook.com, Instagram and Whatsapp. Facebook.com has already reached it's peak and is not going to grow. Instagram is likely to have the same trajectory as Facebook.com and Whatsapp is not making them money anyways. They failed to get into any new market or come up with any decent product. And they are supposed to compete…
> extremely competitive offerings Chrome OS Have you followed news recently? It's dead.
Why is this insane? It's just asking. If you don't want to, don't give your pw to facebook. You make a proposition to an entity, they evaluate the risk-benefit and respond. Unless of course, you think adults are actually childiren and should be protected from themselves by the technocrats.
The user that found this and is cited in OP's article mentions there was no alternative to giving Facebook your password: https://twitter.com/originalesushi/status/111249895877604966...
I think Facebook is very desperate and they don't seem to have a choice. You see, Facebook has Facebook.com, Instagram and Whatsapp. Facebook.com has already reached it's peak and is not going to grow. Instagram is likely to have the same trajectory as Facebook.com and Whatsapp is not making them money anyways. They failed to get into any new market or come up with any decent product. And they are supposed to compete…
You can't possibly be serious.
Google continues to make the majority of their money from advertising. And since those early days they have not released a single product which has helped to diversify their revenue stream. But they've had plenty of failures along the way.
Facebook is far more interesting in terms of diversification. Payments via Messenger/WhatsApp is going to be great for them and is already doing well. Spilling over into web services e.g. Dating is equally looking promising. And they've done okay in the enterprise space with Workspace.
Fact is that it's far harder to switch social graphs than it is to switch search engines.
Amateur photographer here, Instagram is invaluable. Post only what you want the world to see, and so on...
Are you an amateur photographer? Or are you someone who posts images to a social media website for a dopamine hit? Perhaps there’s a value to gatekeeping. It can make us actually put effort and consideration into things. Modern web services like Instagram have allowed human fantasies to run wild, completely detached from reality. If you truly cared about your art and wanted it to be seen, you would devote yourself to…
>If you truly cared about your art and wanted it to be seen, you would devote yourself to that and work on getting into a gallery
You've not understood what the word amateur means, at all. It's like suggesting an amateur tennis player doesn't care if he isn't trying to play Wimbledon. Or an amateur runner doesn't care if he isn't top 5% of marathon.
I find it fascinating how big tech companies are intent on spending enormous sums of money seeking out the top tech talent in the world. Then rather than listen to them when they voice concerns they try to beat them down into submission. I get that if you worked at a company whose core mission is evil that you just have to accept that when you sign up, but there's no reason facebook needs to be make these active mora…
That's exactly why they spend that much money. They know you can be submitted. They want tech talent. Not revolutionists. It's a rough world out there and it's better to get in line than lose your pot of gold. Doesn't make it right at all. But if you were that engineer, it's easier to say to yourself that you'll work your way up and change things the day you are in charge.
> Many professionals set out to make a contribution to society and add meaning to their lives. Yet our system of professional education and employment abusively inculcates an acceptance of politically subordinate roles in which professionals typically do not make a significant difference.
I just don't understand how this gets implemented without someone speaking up and saying "hey, wait, isn't this an insane thing to do?". I would guess it's some combination of the complainers being ignored, and people at a higher level thinking "well we're doing this in a secure way, as long as the user trusts us, and why wouldn't they trust us, we're Facebook!".
Easy. The engineers who built it care mostly about their total compensation and getting promoted. They therefore gleefully implement the product requirements. The PMs behind the idea also care about the above, except they are held to account by business objectives. By narrowly optimizing for a particular objective (reducing account fraud) in an unprincipled manner, they come up with an insane feature idea like this.…
I partially agree with you. When I used to work at one of the big five, PMs for my team would regularly disregard the engineers' output on most matters (apart from occasionally letting us make purely technical decisions). This, of course, ultimately led to almost the entire team leaving, including me, and the rest transferring internally.
It's not all the engineers' fault. One can push back as much as one wants, but it rarely changes anything at all. However the PMs' success is measured based on delivered features and projects. In most big enterprises the engineers are just worker bees, for the queen PM bee and if they don't perform or don't want to do something, they can be somewhat easily replaced with someone who will. And don't forget that a lot of the engineers might be on a working visa, for example. And why would they jeopardize their job and their way of life on moral grounds, instead of keeping their head down and just going through the motions. I'm not saying that I agree with them, but putting all engineers in the same basket seems unfair.
Now that's why realistically it is much rarer for a group of engineers to take a stance than you'd think. This is why cases like the Google engineers who refused to work on military contracts got so much attention. As inspiring and empowering as it might seem, in reality it (almost) never happens.
All of these types of "hey, give us your password to this other system" are just training users to get phished. IMO the worst offender in this is Plaid, which has created a service where millions of people are giving their banking credentials so some random startup can mine your transaction data. And people think FB has privacy implications...
They do this because banks refuse to implement a properly-secured read-only API for granting access to transaction data. (I think maybe Chase now finally has one)
Maybe if the banks realize their customers are handing over their credentials in large numbers, it will light a fire under them to build a real solution.