Live data from Hacker News

Meta has banned the personal Facebook accounts for everyone on our team

twitter.com

371–380 of 442 posts

Re: Meta has banned the personal Facebook accounts for everyone on our team

#371

Earlier quoted context omitted.

The user is risking more than their own data; they are also risking the data of their friends. If I grant a friend permission to view my photos, I am not also granting some random 3rd party that permission.

>If I grant a friend permission to view my photos, I am not also granting some random 3rd party that permission. Assuming the "third-party" client is just that (a client app), there really shouldn't be an issue. If I use FluffyChat[0] instead of Element[1], do the FluffyChat folks have access to all my (and those with whom I communicate) Matrix communications? If I use Element, do they have such access? If you use Fi…

Those other third party apps usually have a monetization scheme that's clearly separate from a need to steal your data or are open source which allows you to see if there's any weirdness or build it yourself. And I shouldn't need to mention that if it was found out that Firefox was uploading data from every page you read to their servers that there would be a massive reckoning.

Tell me, for the OGApp what is the monetization scheme? How do they intend to make money? By default if you don't see anything upfront you should assume that your data is what is being monetized. And your data in this case includes everything the app can pull down from Instagram while it's acting as a proxy.

Similarly and I keep mentioning this: Just because there's no current evidence of them stealing your data does not make them trustworthy. A site asking you for Steam login details would be almost impossible to prove that it's phishing for login details, but it would be a bad, bad idea to put in your login info anyways.

If they want their app to be trusted then it should be made open source.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#372

Earlier quoted context omitted.

Of course they should be able to block 3d party clients. Just because it's technically possible to hijack an API, doesn't mean it's legal or ethical. If you don't want to be tracked, don't use Instagram. However, Meta blocking the developers fb accounts is basically harassment. Let the courts sort it out if their app is illegal. Meta shouldn't take things into their own hands.

>Of course they should be able to block 3d party clients. Just because it's technically possible to hijack an API, doesn't mean it's legal or ethical. If you don't want to be tracked, don't use Instagram. This is the bit that's confusing to me. If I want to access my FB/IG/whatever content, and present my credentials to the server along with a valid request for my data, why should Meta care how I do so? I could be us…

> why should Meta care how I do so?

They care because it is part of their business model. If you avoid tracking that affects their revenue.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#373

Earlier quoted context omitted.

I have some trouble with "telling a third party developer they can't replace parts of your server-driven app for their own profit is a dystopia."

Are you using any browser extensions that do something with website content?

No, and that isn't equivalent

Re: Meta has banned the personal Facebook accounts for everyone on our team

#374

Earlier quoted context omitted.

The data server via API isn't yours, that's FB's data. You can download YOUR data via a page on the FB site.

The data served via the API is ultimately what's displayed on the screen of the official client - if they're displaying it to you, they're happy for you to be seeing it and it shouldn't matter whether you're seeing it in the official client or third-party.

That's not how it works. If a badly configured NSA server displays confidential data on your screen, you're still a criminal if you make use of that to access data.

> it shouldn't matter

According to? That's an ethical stance one can take, but it isn't how our laws work.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#375

Founder of the company behind the OG app here. Just wanted to give my thoughts on the whole situation. This is in addition to our official statement here: https://twitter.com/TheOGapp_/status/1575217497011200001 I want to start off by saying that everyone in this whole comments section has been making points as if what they are saying is "fact". Nothing here is "fact" because there are no laws around API usage. I don…

If you want me to trust your app then open source it. Until then, your app is as far as I'm concerned a black hole of information that is potentially siphoning whatever it can from Instagram when you proxy for a user.

Without that and no privacy policy, no monetization scheme etc leads me to have zero trust in anything you say about a truly open and clear internet.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#376

Earlier quoted context omitted.

The data served via the API is ultimately what's displayed on the screen of the official client - if they're displaying it to you, they're happy for you to be seeing it and it shouldn't matter whether you're seeing it in the official client or third-party.

That's not how it works. If a badly configured NSA server displays confidential data on your screen, you're still a criminal if you make use of that to access data. > it shouldn't matter According to? That's an ethical stance one can take, but it isn't how our laws work.

> If a badly configured NSA server displays confidential data on your screen, you're still a criminal if you make use of that to access data.

If a badly configured NSA server gives you data, intentionally accessing it (and/or then misusing the data) would be the crime. I don't think it matters whether you view that data in a browser, a terminal or some third-party client.

Here, the third-party client is accessing the exact same data the official client is. It's not bypassing any access control, in fact it needs your credentials to be able to access the data you're authorized to view.

> According to? That's an ethical stance one can take, but it isn't how our laws work.

I'm not even sure if a law has been broken here? Breach of ToS != crime. As far as I know there is no unauthorized access taking place - the unofficial client is using your credentials to legitimately access the same API as the official one does; it's not giving you any extra data that the official client doesn't.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#377

Earlier quoted context omitted.

If I'm allowed to close my eyes or mute the volume when an ad is playing why shouldn't I be allowed to get a machine to do this for me?

Because you can use another service where you pay in money instead of attention like Apple products and services. Let’s not pretend like there aren’t many other alternatives

That's not actually answering the question.

Is it legal to look away from ads or mute the volume? If so, it's just as legal to delegate this work to a machine (or to an assistant you hire), or at least, it should be just as legal, though again, I'm not sure that any law has been broken here. Breach of ToS != breach of law.

Whether to use the service or not is a completely different question, but when it comes to Facebook, the problem is the network effects. Facebook has a monopoly on humanity's social fabric in a lot of locations, and since they don't want to intentionally interoperate and cooperate with third-party clients (so your Apple-branded client won't be able to message someone on Instagram), adversarial interoperability is the only way out.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#378

Oh wow, this app got pulled from everything because it's an unofficial 3rd party client for Instagram? I'll say it again, companies should be legally forbidden from blocking 3rd party clients. They don't have to explicitly support them, but taking action to explicitly thwart them (and writing ToS that forbids them) should be outlawed. There's no reason I should have to be subjected to untold tracking, snooping and ad…

Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.

Rules about things like DRM already have carve outs for "interoperability". A big example is back in the 90s, EA didn't like the rules Sega made for putting games on the MegaDrive/Genesis, so they did some reverse engineering work and made their own cartridges that worked great. Sega took them to court and got smacked down pretty hard, basically invalidating their entire anti-copy strategy.

We should push for MORE of the above, not less. We should push for laws that HELP people use the things they have, instead of locking them out of their own property. If Facebook doesn't like people trying to access their own content, Facebook shouldn't have built a business on everyone else's content. Nobody forced them to do that.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#379

Earlier quoted context omitted.

>Ask them to use something else, or get an exception by explaining that you were banned. It isn’t endemic and there are always options Good luck if it's a business or public org. Why change their process for what amounts to a minority of customers? It's not worth the cost. Whether these people can't do business with them despite these services being essential to everyday life... well tough luck for them I guess? Own…

It’s not as endemic as you make it out to be or there would be a public outcry. Banking and social media are also two very different industries. One is essential while the other is mainly bread and circus with a myriad of alternatives

> It’s not as endemic as you make it out to be or there would be a public outcry.

There's no [significant] public outcry because most people use facebook or whichever latest popular thing.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#380

Earlier quoted context omitted.

> Cambridge Analytica then arranged an informed consent process for research in which several hundred thousand Facebook users would agree to complete a survey for payment that was only for academic use. > However, Facebook allowed this app not only to collect personal information from survey respondents but also from respondents’ Facebook friends.[13] In this way, Cambridge Analytica acquired data from millions of Fa…

Yes, the reason this happened was that when a user authorized the Cambridge Analytica app, it would have the ability to view information about all of that user's friends. Sound familiar?

The fault was not in anything CA did, even though I think what they did was bad. The fault was in Facebook letting clients access more data than you authorized them to.

If I approve an access request for a low level engineer to get a single repo from github, and github lets them access every repo on our orgs account, that's a huge fuckup by github, not me.

Post reply on HN