Live data from Hacker News

Meta has banned the personal Facebook accounts for everyone on our team

twitter.com

291–300 of 442 posts

Re: Meta has banned the personal Facebook accounts for everyone on our team

#291

Earlier quoted context omitted.

Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.

Why are first parties serving unauthorized API requests? If the API request is unauthorized, surely the proper response is "401 Unauthorized" and not "all the data you asked for, but then I'll find the people who helped you and get mad at them"? The problem here is that Meta wants to plug things into the internet and then control who gets to ask for those things. This is not how the internet works, at all. If you don…

This.

> unauthorized api requests

The word "unauthorized" has two meanings here:

One is authorized by the user, another is authorized by the vendor.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#292

Oh wow, this app got pulled from everything because it's an unofficial 3rd party client for Instagram? I'll say it again, companies should be legally forbidden from blocking 3rd party clients. They don't have to explicitly support them, but taking action to explicitly thwart them (and writing ToS that forbids them) should be outlawed. There's no reason I should have to be subjected to untold tracking, snooping and ad…

Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.

> Don't like it, don't use it

I don't like it and I don't use it, but unfortunately it's more complicated than that because of the network effect.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#293

Oh wow, this app got pulled from everything because it's an unofficial 3rd party client for Instagram? I'll say it again, companies should be legally forbidden from blocking 3rd party clients. They don't have to explicitly support them, but taking action to explicitly thwart them (and writing ToS that forbids them) should be outlawed. There's no reason I should have to be subjected to untold tracking, snooping and ad…

Of course they should be able to block 3d party clients. Just because it's technically possible to hijack an API, doesn't mean it's legal or ethical. If you don't want to be tracked, don't use Instagram. However, Meta blocking the developers fb accounts is basically harassment. Let the courts sort it out if their app is illegal. Meta shouldn't take things into their own hands.

>Of course they should be able to block 3d party clients. Just because it's technically possible to hijack an API, doesn't mean it's legal or ethical. If you don't want to be tracked, don't use Instagram.

This is the bit that's confusing to me.

If I want to access my FB/IG/whatever content, and present my credentials to the server along with a valid request for my data, why should Meta care how I do so?

I could be using nc[0] piped through openssl, rather than a web browser (do you believe Meta can mandate which browser you use and/or what add-ons/extensions it runs?). Is that "hijacking" the API?

If the answer to that question is "no," then shouldn't I be able to write my own client, to access my data, too? If you think I should, then how are either of those (nc, write my own client) really different from using software written by someone that's not me or Meta, as long as I (providing authentication/authorization for my own access) use it to access my own data?

[0] https://www.unix.com/man-page/Linux/1/nc/

Re: Meta has banned the personal Facebook accounts for everyone on our team

#294

Earlier quoted context omitted.

The issue isn't that I can't use SMS without paying. Even if I am willing to pay, it does me no good if none of my friends are using it because they're all only on WhatsApp themselves.

Everyone with a phone still has access to SMS. Your personal choice is not Meta’s problem, nor does meta have a monopoly on communication. No one, especially in developed countries, is forced to use meta services. There are many alternatives. I use iMessage myself which is great

It's not just my personal choice. I can't choose to use SMS to communicate if the people I need to talk to don't also make the same choice. And iMessage falls back to SMS when you send messages to people who don't have it.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#295

Earlier quoted context omitted.

Again, I'm asking _the person in the thread above_ who made these claims that the app is stealing user data to provide any supporting evidence, perhaps via the methods I described in my last comment. I'm not talking about Meta.

Yes, an individual can do that. That is not the point. The person you replied to wasn't saying they know for sure they were stealing user data, just that Meta has no way of knowing they aren't, and even if they aren't right now, no way of knowing if they will start in the future. It doesn't matter what the app does at this moment, it can be changed at any point.

>That is not the point. The person you replied to wasn't saying they know for sure they were stealing user data, just that Meta has no way of knowing they aren't, and even if they aren't right now, no way of knowing if they will start in the future.

But isn't such an application running on the end-user's hardware and making requests at the end-user's behest?

If so, what does Meta have to do with it at all? Should they be allowed to tell me what software I'm allowed to run on my hardware?

The risk you mention is all on the user's side and none of it on Meta's side. If the user decides they want to accept that risk, AFAICT it's no skin off Meta's nose. Or am I missing something here?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#296

It is absolutely incredible to me that people are defending Meta in this thread. - Yes, Facebook had the right to do it. They're terrible for doing it, though. Meta is terrible? No way! - I'm extremely exhausted of the "tough luck, it's a private company" shtick when it fits someone's personal interests, but cry corporate capitalistic Hell when it doesn't. - There is nothing I've seen in the Apple Developer Guideline…

You don't think this violates apple's developer guidelines?

Just persusing them, I can see violations of sections:

1.6 Data Security

4.1 Copycats

5.1.1 Data Collection and Storage

5.2 Intellectual Property

5.2.2 Third-Party Sites/Services

5.2.3 Audio/Video Downloading

Re: Meta has banned the personal Facebook accounts for everyone on our team

#297

Earlier quoted context omitted.

Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.

No one should be able to control what apps interact with their platform. Companies should have exactly zero control over how people interact with endpoints they open to the internet and it should be illegal and unenforceable to try to create any contractual obligations about how someone interacts with your APIs.

This seems extreme. Do you support fair use limits, or is blocking a DOS attack also a violation of these rules?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#298

Earlier quoted context omitted.

> some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? They're welcome to find a different business model. Why should we sacrifice interoperability for everyone for their sake?

Why should you get to use their servers and resources if they don't want you to be using them without displaying ads?

They're welcome to take the servers down altogether, if they can't pay for them without displaying ads.

Or require an API key that's tied to a particular account that pays for access.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#299
post #163

Earlier quoted context omitted.

Again, I'm asking _the person in the thread above_ who made these claims that the app is stealing user data to provide any supporting evidence, perhaps via the methods I described in my last comment. I'm not talking about Meta.

THat's not the what you were asking. You asked 'What evidence do you have that this application was acting as a "proxy" where the developers can "intercept and see all data"?' The app is by definition acting as a proxy, and therefore the developers can intercept and see the data, though they might not be doing so currently.

>The app is by definition acting as a proxy, and therefore the developers can intercept and see the data, though they might not be doing so currently.

You're making an assumption here that hasn't been confirmed. That assumption being that any app accessing user data from Meta is proxying (i.e., streaming the requested data to the app publisher's servers and then passing that data along to the end user) that data through their servers.

Is that the case with the app in question? Is it the case with every such app?

Or are there apps that directly connect to Meta's servers from the user's hardware without streaming the requested data through the app publisher's servers?

The app in TFA may be proxying (see above) data through their servers (that's the definition of a proxy in this context), but I don't know if they are doing so. If they are, there certainly are serious privacy/security issues with that process.

But again, no one has provided evidence that's what the app in question is doing. If they are, you should run screaming in the other direction.

However, if the app is simply performing the same API calls as Meta's app and returning the data directly to the end user, the risk profile is pretty similar for both apps (dependent on code quality, the ethical stance of the publishers, etc.).

Re: Meta has banned the personal Facebook accounts for everyone on our team

#300

Earlier quoted context omitted.

This makes absolutely no sense whatsoever. If you don't think sites have a fundamental right to push ads to sustain themselves (as I don't), then blocking the request is the best place to do it for performance reasons. But even if you do believe in that right - the site and advertiser care about a single thing: a human being seeing the ad. Serving the Ad request is not just useless for their purpose, it is actively c…

>the site and advertiser care about a single thing I disagree. The site just wants the advertiser's money. The advertiser wants the human to see an ad.

The user wants to support the site, and doesn't want to see the ad.

Why not have the browser /dev/null them, and click a few for the heck of it? It would be in the user's interest.

Post reply on HN