Live data from Hacker News

Facebook can now read your texts

tony.calileo.com

91–100 of 226 posts

Re: Facebook can now read your texts

#93
post #89
post #62

Earlier quoted context omitted.

This feature is nowadays called Privacy Guard and it works so well that I have it on by default for all apps. With the exception of apps that actually need to read my contacts (say WhatsApp), I have not had to disable it for any applications and haven't seen any complications. For example Facebook and Twitter apps, which require a whole rainbow of permissions, function just the way they used to. I've never made a lot…

This sounds excellent, I can't believe I never tried it yet! Of course, this should be part of core Android, but I guess there is no hope for that (given that Google makes its dough on advertising).

It used to be, called App Ops. It was in for (one?) point release before google promptly withdrew it again after realising that giving people tools to protect their privacy goes against their mission.

Re: Facebook can now read your texts

#94
post #19
post #10

Earlier quoted context omitted.

use cyanogenmod + privacy mode, you can disable what the app can do. for example, you can disable that. app still works, it just gets an empty sms list.

Sure would be nice if someone would jailbreak the iPhone, so we could have these sorts of options in our little walled-gardens too.

Are you sure that you have an iPhone?

Re: Facebook can now read your texts

#95
post #19
post #10

Earlier quoted context omitted.

use cyanogenmod + privacy mode, you can disable what the app can do. for example, you can disable that. app still works, it just gets an empty sms list.

Sure would be nice if someone would jailbreak the iPhone, so we could have these sorts of options in our little walled-gardens too.

The iphone has had fine-grained privacy before App Ops was released and then removed, and I also think before CyanogenMod had Privacy Guard. One of the few good things about the platform.

Re: Facebook can now read your texts

#96
Asking for SMS (read/send) permissions is a growing trend among mobile apps (Facebook, Facebook Messenger, Twitter, Google Hangouts…).

Most of the time, they're here to make the app slightly more useful to the end user. But at the same time, you're potentially saying "yes" to a company who might, one day, use your most personal info for bleaker purposes.

It's thus something I've always been fighting against (at least at a personal level): I've stuck to the older, non-requiring-SMS-permissions version of these apps until I could upgrade to a version of Android with App Ops, then Cyanogen.

If SMS permissions is where you draw the line regarding your privacy, either run a version of Android with App Ops, or Cyanogen with Privacy Guard.

I find it sad that companies still think most users value simplicity over privacy.

Re: Facebook can now read your texts

#97
I once talked to CTO of a quite popular app and he mentioned that he finds it best to ask for all permissions you might need upfront (on first install), even if you don't need them yet. Adding them in upgrades later results in lots of customer support questions (and negative reviews).

It is also telling that OP is bothered by "read your messages" permission but doesn't seem to mind "record audio, take pictures and videos" just below it. Just because it is not new?

Re: Facebook can now read your texts

#99
post #96

Asking for SMS (read/send) permissions is a growing trend among mobile apps (Facebook, Facebook Messenger, Twitter, Google Hangouts…). Most of the time, they're here to make the app slightly more useful to the end user. But at the same time, you're potentially saying "yes" to a company who might, one day, use your most personal info for bleaker purposes. It's thus something I've always been fighting against (at least…

I find it sad that most users value simplicity over privacy.

Re: Facebook can now read your texts

#100

This has been a thing for about a month and a bit now. A Facebook engineer posted the following on Reddit[0], explaining the rationale behind the SMS permission: > As for the READ_SMS permission, we require that so we can automatically intercept login approvals SMS messages for people that have turned 2-factor authentication for their accounts, or for phone confirmation messages when you add a phone number to your Fa…

I feel like some sort of manual component to two-factor authentication is the whole point (a clickable link, copy+paste, or remembering a 4 digit number).

Besides that, two factor is a bit of a joke in an app (on your phone) that caches your password, and then sends a message (to your phone) which is automatically read and accepted, before allowing you to login. What exactly are we achieving here in terms of security? Every 30 days the app authenticates itself with no user intervention.

It would be much more secure to just force a password login.

Post reply on HN