Earlier quoted context omitted.
Are they closed source? I.e. does facebook not have a license to make copies of them?
source avail != anyone can make copies of the binary
Facebook scans system libraries on Android and uploads them to their server
101–110 of 188 posts
Re: Facebook scans system libraries on Android and uploads them to their server
#102Re: Facebook scans system libraries on Android and uploads them to their server
#103I was going to say this isn’t a big deal but copying and uploading the libraries is actually illegal (copyright violation) and users likely can’t even consent to this even if it is in the Facebook ToS as many android phones contain proprietary libraries not licensed for redistribution. The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt an…
--------------------
> copying and uploading the libraries is actually illegal (copyright violation)
That isn't what is happening here - the headline is misleading.
Further into the tweet (FFS, it is a tweet and people aren't reading it all before reacting!) it clearly says "It periodically uploads metadata of system libraries to the server".
Basically that means they are sending and storing what versions of what things you have, not the code or other data in the libraries themselves. I'm pretty sure there is no reasonably copyright on the name and version number of a library in this context.
If it is being done for fingerprinting purposes then there might be an unreasonable tracking claim by the users, but not the library copyright holders.
The less worrying explanation is that it is being used for problem analysis: if a new version crashes a lot but only on devices with a specific version of a specific library, that makes tracking down the bug and implementing a workaround or fix much quicker. Of course this is facebook so if it is for the issue analysis (which it almost certainly is) but can also be used for fingerprinting as well, you can bet your bottom dollar that it will be used for fingerprinting as well.
Re: Facebook scans system libraries on Android and uploads them to their server
#104Earlier quoted context omitted.
I wonder how many users would understand what these files are, why Facebook might want them, and what the risks are associated with sending these.
That's why telemetry uploads metadata, not actual binaries. If you don't upload other's files, you don't need to ask permission to do so.
Re: Facebook scans system libraries on Android and uploads them to their server
#105Earlier quoted context omitted.
> If you have read access, then yes. Conventional desktop and server linux distributions would allow this behavior. The difference is in people's expectations of mobile vs. desktop apps. You'd never install untrusted software on your desktop, but mobile OSes provide the sense that software is isolated. In Android, that's mostly an illusion.
I feel like users install untrusted software on the desktop all the time and it's called closed source software. It's not like Facebook is some small, unknown malware peddler so that its software should be considered "untrusted". If anything, it's untrusted because it's coming from a scummy company and opaque (due to being closed source).
Re: Facebook scans system libraries on Android and uploads them to their server
#106Re: Facebook scans system libraries on Android and uploads them to their server
#107I was going to say this isn’t a big deal but copying and uploading the libraries is actually illegal (copyright violation) and users likely can’t even consent to this even if it is in the Facebook ToS as many android phones contain proprietary libraries not licensed for redistribution. The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt an…
Edit: CANCEL MY KNEE-JERK REACTION TO A KNEE-JERK REACTION! A few tweets down (good [deity] twitter is a terrible way to transmit information, this is why I don't generally bother with it) she does say the full library is sent. -------------------- > copying and uploading the libraries is actually illegal (copyright violation) That isn't what is happening here - the headline is misleading. Further into the tweet (FFS…
"Facebook can upload the entire files of all system libraries to their server through their Android apps"
and
"I found they have already collected metadata of 2233 system libraries from my phone, in which 1162 system libraries are pending to be uploaded"
So they've already uploaded the metadata and are in process of uploading the whole files.
Re: Facebook scans system libraries on Android and uploads them to their server
#108How does the internal culture at FB come to grips with the world's vision of them as creepy and amoral and still do stuff like this anyway?
Re: Facebook scans system libraries on Android and uploads them to their server
#109Re: Facebook scans system libraries on Android and uploads them to their server
#110I was going to say this isn’t a big deal but copying and uploading the libraries is actually illegal (copyright violation) and users likely can’t even consent to this even if it is in the Facebook ToS as many android phones contain proprietary libraries not licensed for redistribution. The creators of those various libraries should have a valid legal case against Facebook here, if they want to exercise it. I doubt an…
Edit: CANCEL MY KNEE-JERK REACTION TO A KNEE-JERK REACTION! A few tweets down (good [deity] twitter is a terrible way to transmit information, this is why I don't generally bother with it) she does say the full library is sent. -------------------- > copying and uploading the libraries is actually illegal (copyright violation) That isn't what is happening here - the headline is misleading. Further into the tweet (FFS…