Live data from Hacker News

Meta has banned the personal Facebook accounts for everyone on our team

twitter.com

231–240 of 442 posts

Re: Meta has banned the personal Facebook accounts for everyone on our team

#231

Earlier quoted context omitted.

Let me offer you a question then: Do you know how much data the OG App is taking from you while you authorize it to work on your behalf? How do you know it's not reading through your entire message history? Or building its own network graph of your friends to sell? How about security? How do you know it's securely storing your credentials? Or that it's not selling said credentials as well? Like in this scenario to Fa…

Yes, people can and will write malicious programs. Those will sometimes take the form of third party clients for a service. That is not and will never be a valid argument against them being allowed to exist. Monopolies are not ok. Abusive behavior by the dominant market players isn't ok.

Yes, but my point is that said clients should have to talk through properly secured APIs and required by law. Until then, an app like this is a massive, MASSIVE security risk and I would question the sanity of any team that saw something like this and ignored it.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#232
post #29

If it was a really good app you made, why not also make your own backend and completely decouple from meta? If you build an app using the meta platform in a way that is a clear violation of their tos, the app will obviously be killed the second it gets popular. If I was running a service and another company attempted to do this to my service (violated my TOS, built on top of my private API in a way that striped all m…

It's not just the app that was killed (which would be understandable), it was their personal facebook accounts that were in no way linked to the app.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#233
post #207

Earlier quoted context omitted.

I haven't read it thoroughly, but given the App Attest service runs on the OS, why can't someone just find the certificate for it hidden somewhere and use that to sign fake attests in userland? This is just an extra layer of obfuscation. It doesn't prevent someone from faking api calls with no app (or phone) involved.

Given that this only runs on certain Apple hardware, I wouldn’t be surprised if the Secure Enclave holds that certificate and can confirm at an extremely low level that it is being used only to sign a hash of of the app code itself and a shared secret with the app developer. Brilliant, in a scary way. In a way it makes data portability regulations all the more important.

From my quick reading of the docs:

It generates a public-private key pair that is stored in the secure enclave, then it sends that public key (or the hash maybe) to Apple for them to sign. The rest of the stuff is as you expect.

One could simply figure out how the request to apple is made to get them to sign a key, and that's that. Get them to sign a key and pretend to be the app from now on.

I guess this prevents spam from someone signing thousands of keys using a specific phone's serial number, though. Assuming there's an unique public-private key for each phone apple makes, one can't simply get them to sign keys with random serial numbers.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#234

Earlier quoted context omitted.

To be clear, I'm not saying that there should be no consequences if you distribute a message that I didn't want you to. I'm just saying that I shouldn't be able to stop you from doing so. If you signed a contract saying you wouldn't, and then you do, I should still be able to sue for that, but the existence of such a contract shouldn't let me control your technology to prevent you from breaking it in the first place.

I'm confused, what's the point of the contract that says "you can't do this" if not to legally enforce that you can't do that?

I'm distinguishing between two different meanings of "can't": not allowed vs. not capable. You should be capable of violating NDA/ToS's, but possibly suffer legal consequences if you choose to do so.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#235
post #222

Earlier quoted context omitted.

Meta isn't some utility people can't live without. It's optional. If you're worried about abuse, then don't use it.

> Meta isn't some utility people can't live without. This is not true for large parts of society. There are many institutions which force you to communicate via facebook, so not having access to it means you're locked out of parts of your real life. This is horribly wrong by those institutions, of course, but here we are. It should be illegal, but isn't yet.

Which institutions? if it affected “a large part of society”, I would imagine that I would be aware of it.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#236

Earlier quoted context omitted.

That’s a pretty hot take, can you elaborate? I’m not sure I understand.

Your argument is basically "what Meta did is okay since you agreed to it in the terms of service that you accepted", right? I'm saying that like selling yourself into indentured servitude, accepting Meta's TOS is not always a completely free choice.

Luckily we have laws in place in many countries that invalidate contracts that are clearly disadvantaged to one party.

Meta made a decision they were entitled to make, though I understand that this is a separate point of controversy wherein company’s are arbitrarily banning users across their platforms with no recourse.

Metas TOS holds no weight over you outside their platform. Indeed the only weight they try to hold over you outside their platform (mandatory binding arbitration) has been demonstrated to be unenforceable in the U.S. at the very least.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#237

Oh wow, this app got pulled from everything because it's an unofficial 3rd party client for Instagram? I'll say it again, companies should be legally forbidden from blocking 3rd party clients. They don't have to explicitly support them, but taking action to explicitly thwart them (and writing ToS that forbids them) should be outlawed. There's no reason I should have to be subjected to untold tracking, snooping and ad…

Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.

I think I should have the legal right to access private messages addressed to me by family members via the service explicitly designed to facilitate private communication between friends and family members. I don't think I should be forced to see advertisements and be subjected to historically-unprecedented surveillance to read those couple hundred bytes of text from a family member.

When a platform's primary purpose is communication, certain legal rights should be invoked immediately. In my opinion, one of those rights should be the ability to access those communications by any 3rd party client that doesn't intentionally function maliciously. How "proper 3rd-party client behaviour" is evaluated can be a problem for the industry to solve. They have the $trillions to figure something out. I think they'll survive.

The argument "don't like it, don't use it" isn't a very reasonable argument when, socially speaking, you "have" to use a given service (usually the regionally-omnipresent service) to be included in society. Communication is the foundation of society and of human existence. I miss out on a shocking and honestly depressing amount of social activity because of my boycotting of FB, IG, WhatsApp and other similar services.

I expect that our ability to communicate is carefully protected and treated as something crucially important. There's a reason there are SO MANY commercial services around communication and they are largely the most lucrative, because everyone NEEDS to communicate. People will subject themselves to extremely disadvantageous conditions to enable communication with others. Think about it. Facebook, Twitter, Instagram, TikTok, the internet, cellular phone service. These things are fundamental to communication in global society, and a TON of laws are written to govern their employment/usage. Internet communication just happens to still be pretty early in the stages of its effect on humanity, and as usual the legal world is well behind what those effects are. The effects are finally being felt. I believe my feelings on this subject will become more widespread as people realize how deeply they have been exploited by industry (once again).

Re: Meta has banned the personal Facebook accounts for everyone on our team

#238

Earlier quoted context omitted.

So I should be able to steal from my neighbor because that's true freedom? Because you're using their resources and servers in a way they didn't authorize.

It's not stealing if they gave you the data.

They gave you the data conditioned on an agreement not to use unauthorized clients, the same way any number of real-world businesses "give" you things subject to conditions, like the waffle maker in the hotel lobby which requires you to stay there overnight to use it.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#239

Earlier quoted context omitted.

Your argument is basically "what Meta did is okay since you agreed to it in the terms of service that you accepted", right? I'm saying that like selling yourself into indentured servitude, accepting Meta's TOS is not always a completely free choice.

If you don't like Meta's terms, don't use Meta products and services. It's that simple. There's no indentured servitude because you're not giving Meta free work. In this case, people don't want to pay for Meta services by viewing ads. If you don't want to pay, don't use the service.

> don't use Meta products and services. It's that simple.

Doesn't that basically completely cut you off from electronic communication with everyone else in most European countries, where WhatsApp has basically completely replaced SMS?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#240
post #215

Earlier quoted context omitted.

Meta isn't some utility people can't live without. It's optional. If you're worried about abuse, then don't use it.

Doesn't meta have an obligation to product users that do want to use their product? This is like saying people should be free to pee wherever they want, if you're worried about the smell, don't walk there.

Actually, the pee analogy fits better with your argument. You’re arguing that people can siphon electricity and use meta’s servers without paying (via ads).

As I’ve already mentioned, meta isn’t a utility that people can’t live without like a phone. If they don’t like it, they should use something else. There are many alternatives

Post reply on HN