Live data from Hacker News

Facebook Portal – Privacy review

foundation.mozilla.org

81–90 of 113 posts

Re: Facebook Portal – Privacy review

#81
post #31
post #20

This title is somewhat problematic. It makes it sound like the portal has "privacy not included" and yet that is the name of the blog. In fact, the Portal meets the Mozilla Foundation's "Minimum Security Standards". It gets a yes for encryption, security updates, strong password, manages vulnerabilities and a privacy policy! This is honestly kind of cruddy. You can feel however you want to feel about Facebook, but th…

Security and privacy are two different but related things. Security can help some privacy issues such as encryption stopping others from snooping. It does not include first party privacy issues though. Facebook has a history of privacy issues (hence the comment on the fine). File under things that are always left unanswered... what about the content the device picks up when it's not in a call? Like a TV show in the b…

Right below "Minimum Security Standards" is "Can it snoop on me?"

Camera: Yes

Microphone: Yes

Tracks location: Yes

Further down it ends with "Facebook has a history of betraying users' privacy and trust. [..] The question comes down to, does Facebook have your best interests at heart when it collects all the data this device is capabal [sic] of collecting on you. In the past--from Cambridge Analytic and beyond--the answer to that question has way too often been, NO"

Re: Facebook Portal – Privacy review

#83
post #74

Earlier quoted context omitted.

> This anti-Facebook stuff is mostly just politics Some of it is politics, but some of it is Mark Zuckerberg repeatedly lying through his teeth about failing to protect users' privacy. At a certain point, it stops sounding accidental. At worst, it was malicious enough that they were fined $5B for it (and should have been fined more). If you're going to make the claim that Facebook is not as malicious as everyone says…

I have to prove a negative? Whenever there is a big FB story I try and figure out what actually happened. This is often difficult because 95% of the media reporting on it is either entirely wrong, intentionally misleading, or both. For the recent Cambridge Analytica thing my take away was that a shady third party (CA) violated FB’s TOS by exploiting a vulnerability in their API that FB had sinced locked down. Cambrid…

The locking down of the API is done to prevent competition, while being publicly framed as a privacy enhancing scheme.

> The Switcharoo Plan turned out to be an idea whereby Facebook executives would deprecate various APIs that its developer partners depended on for fear that those developers would one day compete with Facebook directly, while publicly announcing that the changes were intended to promote privacy.

https://www.theverge.com/interface/2019/11/8/20953623/facebo...

Nothing Facebook says publicly should be trusted.

Re: Facebook Portal – Privacy review

#84
post #20

This title is somewhat problematic. It makes it sound like the portal has "privacy not included" and yet that is the name of the blog. In fact, the Portal meets the Mozilla Foundation's "Minimum Security Standards". It gets a yes for encryption, security updates, strong password, manages vulnerabilities and a privacy policy! This is honestly kind of cruddy. You can feel however you want to feel about Facebook, but th…

You've looked at the security features (which, as sibling comment points out, is related to, but not the same as privacy), and stopped short of reading the full privacy review.

A lot of commenters have made the same mistake, so perhaps this is useful UX feedback for Mozilla.

The title however, is NOT misleading. To copypaste the parts nobody seems to be reading:

  Can it snoop on me?

  Camera: Yes
  Microphone: Yes
  Tracks Location: Yes


  How does it handle privacy

  How does it share data?
  data about your Portal usage –
  how often you do video calls, what
  apps you open, what features you
  use – can be used to target you with
  advertisements across Facebook. The
  company may also share specific
  demographic and audience engagement
  data with advertisers and analytics
  partners.

  Collects biometrics data? Yes

  User friendly privacy info? No

Re: Facebook Portal – Privacy review

#85
post #20

This title is somewhat problematic. It makes it sound like the portal has "privacy not included" and yet that is the name of the blog. In fact, the Portal meets the Mozilla Foundation's "Minimum Security Standards". It gets a yes for encryption, security updates, strong password, manages vulnerabilities and a privacy policy! This is honestly kind of cruddy. You can feel however you want to feel about Facebook, but th…

We've changed the title to take out the name of the blog and say what's in the post.

Re: Facebook Portal – Privacy review

#86
post #20

This title is somewhat problematic. It makes it sound like the portal has "privacy not included" and yet that is the name of the blog. In fact, the Portal meets the Mozilla Foundation's "Minimum Security Standards". It gets a yes for encryption, security updates, strong password, manages vulnerabilities and a privacy policy! This is honestly kind of cruddy. You can feel however you want to feel about Facebook, but th…

I find Mozilla's editorializing in the little blurbs at the top of each page to be kind of problematic as well. It seems like they came up with an objective set of standards, but it turns out those standards didn't quite fit the narrative they wanted to put forth.

I'm no fan of Facebook, but if you want to point out their privacy shortcomings, come up with a stronger set of standards and apply them to all the products. Don't take cheap shots at them at the top of a page that gives them 5 stars.

Re: Facebook Portal – Privacy review

#87

Earlier quoted context omitted.

I have to prove a negative? Whenever there is a big FB story I try and figure out what actually happened. This is often difficult because 95% of the media reporting on it is either entirely wrong, intentionally misleading, or both. For the recent Cambridge Analytica thing my take away was that a shady third party (CA) violated FB’s TOS by exploiting a vulnerability in their API that FB had sinced locked down. Cambrid…

The locking down of the API is done to prevent competition, while being publicly framed as a privacy enhancing scheme. > The Switcharoo Plan turned out to be an idea whereby Facebook executives would deprecate various APIs that its developer partners depended on for fear that those developers would one day compete with Facebook directly, while publicly announcing that the changes were intended to promote privacy. htt…

It can be both - the Reuters link in that verge article is a little better: https://www.reuters.com/article/us-facebook-antitrust/facebo...

FB can be concerned about apps like Pikini that damage their brand and concerned about other companies trying to leverage their data in order to build a competitor.

This is a little hard to reason about fairly given the context that the document leak was targeted to make FB look bad by lawyers that had an agenda around a current anti-trust lawsuit from a client that used FB user data to make a bikini photo finding app (not the most ethical bunch).

That said, I'd argue there's no reason FB should have to allow API access to a company that directly conflicts with FB's interests, particularly when they're trying to take FB's data to build a replacement (and it looks like it would trigger some sort of contract discussion initially anyway). A lot of companies remove third party API access for a number of reasons and this ability is typically explicitly specified in the terms of the API access agreement.

Framing it around a privacy narrative to avoid media backlash around API deprecation is trying to get a handle on PR - I prefer when companies are just direct, but given the risk around bad media coverage I can see why they did it.

This entire issue is somewhat distinct from what I was talking about in the Cambridge Analytica case which I think was a bug in the social graph (they were not supposed to be able to crawl as much of it as they could) and this bug was fixed prior (I think years prior?) to the whistleblower from CA releasing details. My understanding was that accessing the data, while technically possible due to the bug, was still in violation of TOS.

Re: Facebook Portal – Privacy review

#88
post #81
post #31

Earlier quoted context omitted.

Security and privacy are two different but related things. Security can help some privacy issues such as encryption stopping others from snooping. It does not include first party privacy issues though. Facebook has a history of privacy issues (hence the comment on the fine). File under things that are always left unanswered... what about the content the device picks up when it's not in a call? Like a TV show in the b…

Right below "Minimum Security Standards" is "Can it snoop on me?" Camera: Yes Microphone: Yes Tracks location: Yes Further down it ends with "Facebook has a history of betraying users' privacy and trust. [..] The question comes down to, does Facebook have your best interests at heart when it collects all the data this device is capabal [sic] of collecting on you. In the past--from Cambridge Analytic and beyond--the a…

I fully understand the scepticism around this product. That said, this section feels incomplete. It would be valuable to assess if there are physical controls to turn off both the camera and microphone or a physical camera cover. I think Facebook wisely chose to include that while similar products like the Nest Hub Max didn't. Even if I distrust Facebook more than Google, the Portal seems to have a clear privacy advantage on the Camera front.

Re: Facebook Portal – Privacy review

#90
post #86
post #20

This title is somewhat problematic. It makes it sound like the portal has "privacy not included" and yet that is the name of the blog. In fact, the Portal meets the Mozilla Foundation's "Minimum Security Standards". It gets a yes for encryption, security updates, strong password, manages vulnerabilities and a privacy policy! This is honestly kind of cruddy. You can feel however you want to feel about Facebook, but th…

I find Mozilla's editorializing in the little blurbs at the top of each page to be kind of problematic as well. It seems like they came up with an objective set of standards, but it turns out those standards didn't quite fit the narrative they wanted to put forth. I'm no fan of Facebook, but if you want to point out their privacy shortcomings, come up with a stronger set of standards and apply them to all the product…

I agree that the privacynotincluded site should have a broader set of standards but I really commend them for investing resources into tackling the truth of the huge amount of surveillance built in to a lot of these products these days. Hopefully they can improve the UI in future as it is a bit confusing. However the main takeaway at the bottom should be understood:

"Facebook has a history of betraying users' privacy and trust. They've faced record fines for this and have been caught hiding privacy breaches from their users. This is the starting point for bringing a device with an AI-powered smart camera and always listening microphone that is sending data back to Facebook regularly. They also say they do human review of audio snippets unless you chose (and take the time to figure out how) to opt out. The question comes down to, does Facebook have your best interests at heart when it collects all the data this device is capable (*fixed typo) of collecting on you. In the past--from Cambridge Analytic and beyond--the answer to that question has way too often been, NO."

Post reply on HN