Live data from Hacker News

Meta has banned the personal Facebook accounts for everyone on our team

twitter.com

441–442 of 442 posts

Re: Meta has banned the personal Facebook accounts for everyone on our team

#441

Earlier quoted context omitted.

Why would they have to circumvent anything? The app relies on the user providing valid credentials, no circumvention needed. It just has to mimic an official client.

> Why would they have to circumvent anything? The app relies on the user providing valid credentials, no circumvention needed. It just has to mimic an official client. Somebody else said they're using oauth. Afaik, instagram does not provide a public API. So it seems like they abused oauth for that?

Presumably "abusing" OAuth means they've just extracted the client ID and client secret from the official app, thus pretending to be the official app to the API.

There's no other way to "abuse" OAuth other than pretending to be an already-authorized client, and obtaining that authorization still ultimately relies on getting the user's username & password and would only be limited to what the client you're impersonating is allowed to access.

Re: Meta has banned the personal Facebook accounts for everyone on our team

#442

Earlier quoted context omitted.

> Work out standards, lobby for them etc. Back in the AT&T monopoly it required a third-party device (the Carterphone) to actually be released on the market for their anti-competitive terms to be challenged and eventually struck down in court. > circumvent the compliance of meta How? If an idiot user gives their credentials to a shady third-party, it's the user's fault for compromising their own data, not Meta's. If…

> Back in the AT&T monopoly it required a third-party device (the Carterphone) to actually be released on the market for their anti-competitive terms to be challenged and eventually struck down in court. That's so american to think that another company should fix this. It's the state's responsibility to fix that, if people want it. > How? If an idiot user gives their credentials to a shady third-party, it's the user'…

> It's the state's responsibility to fix that, if people want it.

So let's say there's a bad law on the books that prevents this. How do you get people to understand why they should revolt against it without giving them a tangible example? There's plenty of bad laws out there such as the CFAA, yet it's virtually impossible to get people/politicians to care about it because they're not affected by it directly. On the other hand, giving people a tangible example of why the law is bad, such as by breaking it to deliver something valuable, will immediately get people's attention when that valuable service stops because of the law and they got used to relying on the service.

> providers might be liable for not protecting the user enough

How do you effectively protect the user when they are voluntarily giving away their credentials? Furthermore, is it even "protection" (as opposed to rent-seeking) if the user consensually and voluntarily shares their credentials because they trust the third-party?

> I bet you take care of security in your job

Well my security model is that the user is only allowed to access the data they are entitled to. If the user gives away their credentials voluntarily, despite all warnings, there's really nothing I can do, and maybe I shouldn't do if it turns out the third-party is actually operating a legitimate service that the users find valuable.

> Still, liability is a bitch, as you can see

Well, all of this will have to be determined by courts, and ultimately depends whether there's any money to be collected in the first place. This entire operation may have been planned ahead of time with the company structured in such a way that there's nothing for Facebook/Meta to collect even if they end up winning any eventual lawsuit.

Post reply on HN