Live data from Hacker News

Meta has banned the personal Facebook accounts for everyone on our team

twitter.com

301–310 of 442 posts

Re: Meta has banned the personal Facebook accounts for everyone on our team

#301
Founder of the company behind the OG app here.

Just wanted to give my thoughts on the whole situation. This is in addition to our official statement here: https://twitter.com/TheOGapp_/status/1575217497011200001

I want to start off by saying that everyone in this whole comments section has been making points as if what they are saying is "fact". Nothing here is "fact" because there are no laws around API usage. I don't think lawyers even know what HTML or JSON mean. Everything here is an opinion and there are clearly opinions on all parts of the spectrum.

Meta is currently completely within their rights to put in their terms of service that there should be no 3rd party clients, there should be no way to access their APIs, etc. That is true. However, we believe that shouldn't be the case. People should be allowed to have the freedom to choose how they use platforms. People should be allowed to control which apps access their data and what they do with it. Some people in the comments mentioned that this is very similar to "Ma Bell" and the whole anti-trust situation along with that, and it very much is. We are stifling innovation and creation of jobs, wealth, and truly wonderful products in the social space because of the stronghold Meta has over the market. For example, both Brazil (PIX) and India (UPI) have open instant payment systems that came about due to Government anti-trust regulation that encouraged competition. This led to a boom in digital payments and was a huge boon for both countries. If you have tried either of these systems, you would know that they are leagues ahead of more "modern" countries like the US. By not allowing interoperability and portability of social networks, and user data at large, we are stifling the growth of the economy and of the products that can be built. Listen, this is no small amount. Social networks were responsible for onboarding the first billion people onto the internet. These tools now help everyone in the world communicate at all times. Do not underestimate the impact they have and the reduction in value across the world because they are not interoperable. Users who use UPI in India have a choice of over a dozen payment apps, that work with all banks, and they can send money to any other bank, instantly, 24/7! This is HUGE. Similarly, social networks that allow for portability and interoperability will allow for dozens of different apps that fit specific use-cases, allowing for more internet users, and a greater value to the entire world.

So, we built OG because we thought this was the first step to realize this vision of the social internet that was truly open, portable, and interoperable.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#302

Earlier quoted context omitted.

> some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? They're welcome to find a different business model. Why should we sacrifice interoperability for everyone for their sake?

Why should you get to use their servers and resources if they don't want you to be using them without displaying ads?

TV channels don't want you to mute your TV when they display ads, should TVs block this functionality to force you listen to their ad?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#303

Earlier quoted context omitted.

In this case the risk you take doesn't matter (though I argue from a security standpoint this is something you should really care about in any argument around Meta), it's the risk Meta takes by allowing it. Because if the company takes your data and runs, Meta is the one also on the hook for not securing their APIs. If it turns out they're farming passwords from users to sell to whatever group ultimately the class ac…

What do you mean? On what planet is it a provider's fault if a third party farms logins through a custom client. It's not their fault if I get phished, if the little booklet I store my passwords in under my pillow gets stole, if my computer is infected with a RAT... so why would it be in this scenario? I only got a few posts into the thread before Twitter booted me out for not having an account, so maybe there's some…

> What do you mean? On what planet is it a provider's fault if a third party farms logins through a custom client.

Earth: https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Ana...

Re: Meta has banned the personal Facebook accounts for everyone on our team

#304
post #93
post #51

Earlier quoted context omitted.

This wasn’t competition though. This was straight up theft of resources/services. What? “extra-legal”? Don’t mix this with other behaviors Meta/Facebook/Instagram engage in, I hate them for all the bullsht they get away with too. However, this isn’t that, this is someone trying to build a platform on top of someone else’s platform explicitly against their terms of service and without reimbursing them.

It's hard to be sympathetic to a company that operates morally dubious amounts of data harvesting. If a program enables you to gain more privacy while using the internet, it's a moral good. I don't consider it to be stealing any resources or services. It's little different than an ad and tracker blocker on a browser. Any client-side user agent should have the right to act on behalf of the user. If it's not illegal to…

If you read the app’s official Twitter you will get several hints that this is likely not just a client-side app.

https://twitter.com/theogapp_/status/1574811388823732233

https://twitter.com/theogapp_/status/1574816036645314561

And they are a venture backed startup. Does none of this alarm you?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#305

Earlier quoted context omitted.

That would be awesome. Right now, you usually get an even less favorable choice than that! For example with Spotify, you either use their app and see ads, or you pay and don't see ads, but still are forced to use their app.

That is probably a licensing requirement for the providers of the music. They likely require some form of DRM in their agreement with Spotify. If anyone could make an App, how would Spotify be able to properly track song plays and whatever else they need in order to pay the rights holders? Plus, someone would end up creating a 3rd party client that silently plays some song, unbeknownst to the user, in order to rack u…

The same way spotify does: it's using APIs. Design them in a way that can't be trivially circumvented and bob's your uncle

Re: Meta has banned the personal Facebook accounts for everyone on our team

#306
post #4

Privacy proponents should cheer for this. Legally Meta must take down the app to comply with FTC's order (obligatory not a lawyer): https://www.ftc.gov/business-guidance/blog/2019/07/ftcs-5-bi... > Another way the FTC says Facebook violated the order was by failing to adequately assess and address privacy risks posed by third-party developers. Other than getting developers to click an “I agree” terms-and-conditions b…

Are you accusing these developers of violating privacy? If not, you're twisting things to the point of deception. Facebook is supposed to crack down, yes, but it's a specific thing they're supposed to crack down on, not ad-removal.

Let us go read their own twitter for fun.

https://twitter.com/theogapp_/status/1574811386613334017

The app logs you in from a different location, requires an intermediate login if you use 2FA (they promise they log out immediately after), is sold for free by a venture backed startup, long-term vision is to export your data to other social media, and says logins always show up as Android (even on iOS).

Maybe they aren’t doing anything malicious, but wow I would not trust it.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#307
post #297

Earlier quoted context omitted.

No one should be able to control what apps interact with their platform. Companies should have exactly zero control over how people interact with endpoints they open to the internet and it should be illegal and unenforceable to try to create any contractual obligations about how someone interacts with your APIs.

This seems extreme. Do you support fair use limits, or is blocking a DOS attack also a violation of these rules?

Let’s not be ridiculous. DOS is not use, it’s abuse.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#308
post #207

Earlier quoted context omitted.

Given that this only runs on certain Apple hardware, I wouldn’t be surprised if the Secure Enclave holds that certificate and can confirm at an extremely low level that it is being used only to sign a hash of of the app code itself and a shared secret with the app developer. Brilliant, in a scary way. In a way it makes data portability regulations all the more important.

From my quick reading of the docs: It generates a public-private key pair that is stored in the secure enclave, then it sends that public key (or the hash maybe) to Apple for them to sign. The rest of the stuff is as you expect. One could simply figure out how the request to apple is made to get them to sign a key, and that's that. Get them to sign a key and pretend to be the app from now on. I guess this prevents sp…

The way these schemes usually work is that the pairing is done at the factory. Apple switch the iPhone on for the first time as it's being made, it generates a private key that never leaves the secure chip and then presents the public key. The public key is then signed to create a certificate chain and the certs handed back to the device for storage.

So, there's no way to beat it except by extracting a private key, or by using some software exploit to confuse it into signing the wrong thing.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#309
post #141

Earlier quoted context omitted.

Why shouldn't I be able to uae the software of my choosing? If i habe an account and have properly authenticated, the client I use is my choice. You can't reasonably make the "go elsewhere" argument with the monopoly hold FB has on much social data. We need to choose yo regulate them and others to force interoperability, or at the very least allow comcom explicitly (competitive compatibility).

Because your access to their API is conditioned on an agreement not to use unauthorized clients. You are free to use the software of your choosing in conjunction with your own computers, but not necessarily with everybody else's.

“You shouldn’t be able to do something because it’s not allowed” is a tautological argument. Parent comment is arguing that it should be made allowed.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#310

Earlier quoted context omitted.

What do you mean? On what planet is it a provider's fault if a third party farms logins through a custom client. It's not their fault if I get phished, if the little booklet I store my passwords in under my pillow gets stole, if my computer is infected with a RAT... so why would it be in this scenario? I only got a few posts into the thread before Twitter booted me out for not having an account, so maybe there's some…

> What do you mean? On what planet is it a provider's fault if a third party farms logins through a custom client. Earth: https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Ana...

> Cambridge Analytica then arranged an informed consent process for research in which several hundred thousand Facebook users would agree to complete a survey for payment that was only for academic use. > However, Facebook allowed this app not only to collect personal information from survey respondents but also from respondents’ Facebook friends.[13] In this way, Cambridge Analytica acquired data from millions of Facebook users

FB gave them data about friends, when it was supposed to only give them data about respondents. Totally different situation.

Post reply on HN