Live data from Hacker News

Meta has banned the personal Facebook accounts for everyone on our team

twitter.com

331–340 of 442 posts

Re: Meta has banned the personal Facebook accounts for everyone on our team

#331

Earlier quoted context omitted.

From my quick reading of the docs: It generates a public-private key pair that is stored in the secure enclave, then it sends that public key (or the hash maybe) to Apple for them to sign. The rest of the stuff is as you expect. One could simply figure out how the request to apple is made to get them to sign a key, and that's that. Get them to sign a key and pretend to be the app from now on. I guess this prevents sp…

The way these schemes usually work is that the pairing is done at the factory. Apple switch the iPhone on for the first time as it's being made, it generates a private key that never leaves the secure chip and then presents the public key. The public key is then signed to create a certificate chain and the certs handed back to the device for storage. So, there's no way to beat it except by extracting a private key, o…

You don't need to extract the private key though, just use it to sign things. So if you have shell access on the phone, you can tell the SE to sign the request you want.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#332

Earlier quoted context omitted.

>Of course they should be able to block 3d party clients. Just because it's technically possible to hijack an API, doesn't mean it's legal or ethical. If you don't want to be tracked, don't use Instagram. This is the bit that's confusing to me. If I want to access my FB/IG/whatever content, and present my credentials to the server along with a valid request for my data, why should Meta care how I do so? I could be us…

The data server via API isn't yours, that's FB's data. You can download YOUR data via a page on the FB site.

The data served via the API is ultimately what's displayed on the screen of the official client - if they're displaying it to you, they're happy for you to be seeing it and it shouldn't matter whether you're seeing it in the official client or third-party.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#333

Oh wow, this app got pulled from everything because it's an unofficial 3rd party client for Instagram? I'll say it again, companies should be legally forbidden from blocking 3rd party clients. They don't have to explicitly support them, but taking action to explicitly thwart them (and writing ToS that forbids them) should be outlawed. There's no reason I should have to be subjected to untold tracking, snooping and ad…

Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.

I think the perspective here is a very interesting one. Typically, such transactions are seen as between a user and a service provider. There is an agreed-upon protocol, and so long as everyone sticks to the agreed-upon protocol, the exchange can be successful: this is the basis of Email, the Web, etc.

Taking aside advertisement for a moment, what you're suggesting is that the level of control should go as far as which clients are allowed to speak a given protocol. This would be similar to the landline system during the monopoly days, where you were only allowed to connect an officially-approved phone (with a correspondingly high ongoing rental cost) to the copper lines.

From my perspective, there is no 3rd party involved here: there is an API surface which is developed and supported, and there is a client/customer who is interacting with the service through that API. Advertising either needs to be implemented into the API (good luck--see the demise of RSS), or the 1st party needs another business model.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#334

Modern ad-funded software is less a "bicycle for the mind" and more a "hamster wheel for the brain". Of course third party clients would be seen as a threat - they empower the user.

It's a threat because 3rd party clients like this circumvent payment for the service via ads. If you don't like the terms, don't use the service. There are plenty of alternatives.

If I'm allowed to close my eyes or mute the volume when an ad is playing why shouldn't I be allowed to get a machine to do this for me?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#335
post #99

Maybe I’m just a graybeard but all this is reminiscent of the shenanigans that Ma Bell pulled. Not exactly the same but similar. History doesn’t repeat itself but it rhymes, as they say. There’s a very simple solution here: common carrier. Treat social media as a modern utility. No viewpoint discrimination, censorship, algorithmic social manipulation or proprietary on-ramps. The bad behavior has gone on long enough.

There is plenty of freedom out there. If someone wants to be a Nazi/Antifa/Climate Skeptic (not you but the usual suspects) and try to stir up murderous crowds/riots/etc then do it on your own platform. There is Gab, Stormfront, Fox News comments, etc for that. There is no lack of platforms out there. All you have to have are the $$ and the grit.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#336
post #24

Earlier quoted context omitted.

Obviously they can , the surprise is that they did . Vindictive actions like this are rarely profitable, they tend to scare people off from doing business with you.

Unless you're a monopoly and then you can do whatever you want because your customers have no alternative. Which Meta is (well, it's a duopoly with Google). Anyway Meta's customers, and the only entities it cares about, are large ad buyers. None of them will give a crap about this random app and these random human beings getting banned. This has zero impact on their ability to continue writing checks to Meta and cont…

There are plenty platforms out there besides meta; numerous places, fox comments, stormfront forums, gab, truth social, 4 chan, reddit, your own blog, twitter. No one can say that there aren't other platforms.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#337

Founder of the company behind the OG app here. Just wanted to give my thoughts on the whole situation. This is in addition to our official statement here: https://twitter.com/TheOGapp_/status/1575217497011200001 I want to start off by saying that everyone in this whole comments section has been making points as if what they are saying is "fact". Nothing here is "fact" because there are no laws around API usage. I don…

Getting to interoperability won't be achieved by questionable third party clients essentially abusing the API of a company. What a weird way of thinking. Work out standards, lobby for them etc. You very well knew what you were doing and what you'd risk. > People should be allowed to have the freedom to choose how they use platforms I absolutely despise meta but this is just weird. If a company provides a service, the…

> Work out standards, lobby for them etc.

Back in the AT&T monopoly it required a third-party device (the Carterphone) to actually be released on the market for their anti-competitive terms to be challenged and eventually struck down in court.

> circumvent the compliance of meta

How? If an idiot user gives their credentials to a shady third-party, it's the user's fault for compromising their own data, not Meta's. If a user were to print out pages of the Facebook web UI containing private data and then start distributing them in the streets, would you also blame Meta, and not the user? What about if the user writes down the private data manually, and then distributes it? Etc.

> essentially proxy all user data

What's wrong with proxying? Plenty of mobile e-mail clients for example do proxying as well because there's just no way to maintain a persistent connection or do regular polling on mobile devices due to network & battery life constraints.

Is there any evidence they captured or misused the proxied data for beyond what's needed to provide the service?

Also keep in mind that a vast majority of Instagram data is public by design - people put it out there because they want it to be seen, and it can be seen by anyone accessing the web interface. The people who ultimately own the data often don't want it to be private.

> who on earth would fund that?

Someone who's actually interested in setting the legal precedent that would allow this behavior and invalidate ToS preventing it?

Re: Meta has banned the personal Facebook accounts for everyone on our team

#338

Earlier quoted context omitted.

> These companies can ban the US President from their platforms. Good, you should be able to choose who you do business with, or at least that’s what conservatives argued for years.

Pretty sure “the free market” has decided that Parler and Truth Social are terrible social media products based on their relative lack of adoption

that isn't facebook's problems that they regular folks don't want to join a bunch of fascist platforms. No one is -owed- an audience of a billion people. I don't think the -means- of those shoudl be blocked. ISP, cloudfront, AWS, etc shouldn't be able to block such orgs (as long as they aren't doing anything illegal) as they are providing a source that means the internet does fall apart because they are providing the most basic of what makes up the web/internet and it's easy to argue that they should be able to pick and choose like a facebook/amazon/twitter/etc, who provide something that isn't a commodity.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#339

Earlier quoted context omitted.

You don't think this violates apple's developer guidelines? Just persusing them, I can see violations of sections: 1.6 Data Security 4.1 Copycats 5.1.1 Data Collection and Storage 5.2 Intellectual Property 5.2.2 Third-Party Sites/Services 5.2.3 Audio/Video Downloading

I think they also statically analyse the code. So who knows what weird thing they did to circumvent auth.

Why would they have to circumvent anything? The app relies on the user providing valid credentials, no circumvention needed. It just has to mimic an official client.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#340
post #85

Earlier quoted context omitted.

An app downloading on behalf of the user isn't a privacy issue. Are their servers acting as a proxy? Whether that's a privacy issue depends on how they configure/limit/audit their servers.

An app downloading data on behalf of the user is basically what Cambridge Analytica was doing. The problem is that data ownership is complicated. If I know your phone number, can I share it with other people? That was CA (me downloading data about all my friends). Here the issue is private messages — is it okay for me to share the messages you sent privately to me? A lot of people will get quite upset if you do that!

> An app downloading data on behalf of the user is basically what Cambridge Analytica was doing.

Nowhere close. CA was asking permissions from users and then got the data from those users and all of their FB friends who did not agree to anything nor did they know their data is being collected.

Post reply on HN