Earlier quoted context omitted.
> That would imply they are incompetent and negligent. Not really. Product Manager: I want to be able to support Facebook login for our app. Developer: OK... [googles for how to do that] ... We can use the FB SDK for that. PM: Cool, let's do that. Dev: [implements it] Nobody really does much more due diligence than that most of the time. I suppose you could argue that's negligent, but if that's the case, then pretty…
> I suppose you could argue that's negligent, but if that's the case, then pretty much every company that has an app with login functionality is probably in that boat. I think every company that does this is negligent. Audit your dependencies, people!
Zoom’s Use of Facebook’s SDK in iOS Client
121–130 of 272 posts
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#122Earlier quoted context omitted.
My point is that you've removed one instance of the Facebook SDK from your phone, but you still have 50 others. Plus probably hundreds of other analytics frameworks that you've never even heard of that are just as bad or worse.
A journey begins with a single step. As a community, we suss our and shame the rest into removal. If shame doesn’t work, those in California try using the CCPA. We’re all stuck inside for a while, this is the perfect time to act. One app and SDK at a time.
During covid nobody is paying attention and we have the additional problem that they're trying to use cellphone location data to enforce social distancing! Once this is in effect it will be difficult to undo because the next epidemic will be "just around the corner" ...
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#123Earlier quoted context omitted.
No, you attack the systematic problem and don't become happy by fixing one of them, since it is a hollow victory, and public outrage has limited capacity for repeated posts of "app x is sending to Facebook".
honest question: _how_ do we attack the underlying systematic problem to solve it once and for all? write a blog post? take it twitter/HN/reddit? hold a rally/demonstration outside Apple/Google? call our MP? bombard their employees with phone calls or knock on their front door where they live? write malware? ... really I got nothing that sounds like it would work. In retrospect all of Tim Cook's privacy / security gr…
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#124Earlier quoted context omitted.
> I suppose you could argue that's negligent, but if that's the case, then pretty much every company that has an app with login functionality is probably in that boat. I think every company that does this is negligent. Audit your dependencies, people!
As nice as it would be, auditing everything you use is almost impossible, especially for smaller teams.
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#125What if mobile platforms (iOS, Android... ) changed the security/privacy policy so that apps had to request the “network access” permission, either whitelisting domains they want to talk to, or askingfor wildcard access? Most apps shouldn’t need wildcard access, and the mobile device could include a warning when an app does this teaching users that they should be careful with the app. This way at least when you insta…
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#126Earlier quoted context omitted.
I don't want to live in a world where my parents and grandparents are expected to pull up Wireshark to figure out if the app they're using will record their front camera without consent. Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private. Blaming Apple? Why, when Zoom is on the Play Store as well? https://play.google.com/store/apps/details?id=us.zoom.videom... >As long…
> Blaming Apple? Why, when Zoom is on the Play Store as well? Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. pu…
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#127It's good that they removed it, but it's also dissapointing that they had no idea that it was happening until someone made a blog post about it. Do their employees not vet any of the code they use, and just slap things together off the internet and hope it's not doing anything their users don't like?
Re: Zoom’s Use of Facebook’s SDK in iOS Client
#128Re: Zoom’s Use of Facebook’s SDK in iOS Client
#129I contacted LG last month regarding their use of the Facebook SDK's automatic event collection in their ThinQ Android app. They responded and told me that they're disabling it in an upcoming release (incidentally, today's). If a single email is all it took to get a company with over $50 billion in revenue to disable Facebook's tracking in one of their apps, I really don't think that these companies are sharing data i…
> I don't think these companies are sharing data with Facebook intentionally. That would imply they are incompetent and negligent. Would one not expect large companies like LG to have internal security and privacy reviews of the software they publish, and know very well what they are doing? > What justification Their core business.
> Would one not expect large companies like LG to have internal security and privacy
can't tell if this is sarcasm because this is exactly what they are. an OEM is just packaging stuff and always bigger than it's parts (in this case meaning the knowhow of their otherwise bright and knowledgeable engineers is lost in the organization as a whole). the biggest companies are always the dumbest places where no matter how bright you may be the management layers above make sure that this gets cancelled out (I've worked at Samsung, Nokia and Ericsson and it was the case in all these places). Doubt LG would be any different.