Live data from Hacker News

Facebook can now read your texts

tony.calileo.com

131–140 of 226 posts

Re: Facebook can now read your texts

#131
post #32

Does anyone know what they are using this feature for exactly?

It helps expand their social-graph beyond what you've shared on their platform. It also gives them access to geolocation information for users that haven't shared it previously, as photos shared over text messages may contain geo-location coordinate information. It likely also gives them context about where people are, what they're doing, who they're talking to the most, and what they're communicating about so they c…

More connected than what ? I am conencted with all of my friends and business contacts, whats the next level of "more connected" ?

Re: Facebook can now read your texts

#132

Is there any recourse short of "don't use the app" that regular users have against this sort of thing? Is there no meaningful way to push back against Facebook for demanding this permission?

You can use the mobile web page for Facebook.

Less intrusive, less privacy issues.

And it probably works better than the app.

Re: Facebook can now read your texts

#133

This has been a thing for about a month and a bit now. A Facebook engineer posted the following on Reddit[0], explaining the rationale behind the SMS permission: > As for the READ_SMS permission, we require that so we can automatically intercept login approvals SMS messages for people that have turned 2-factor authentication for their accounts, or for phone confirmation messages when you add a phone number to your Fa…

It's bullshit, I'm sure they have a similar motivation for retrieving running apps. When I bought my Nexus 5 I installed a game on it and was surprised to see on the desktop Facebook constantly asking me to like it. I didn't see it before and now it was there just after I had installed it, it wasn't a coincidence. Turns out the Facebook app has the permission to retrieve running apps, and this obviously happens whether you actually open the app or not, since it's always running in the background. This is fucking bullshit and I'm tired of companies always trying to peer into our lives.

Re: Facebook can now read your texts

#134

Is there any recourse short of "don't use the app" that regular users have against this sort of thing? Is there no meaningful way to push back against Facebook for demanding this permission?

You can use the mobile web page for Facebook. Less intrusive, less privacy issues. And it probably works better than the app.

This is my preferred solution for the times I have to unavoidably use Facebook: https://play.google.com/store/apps/details?id=com.danvelazco...

Re: Facebook can now read your texts

#135
post #74

1. This has been a thing for quite a while now, there have been numerous articles about this. This is nothing new, although it may have not rolled out to all users. 2. Facebook gives explanation of all the permissions they need, including read SMS one, here: https://www.facebook.com/help/210676372433246 3. This is more android permission issue than specifically Facebook app one. Facebook, in order to implement automa…

Why not just disable the feature if you want to deny it? Seems like a pretty shit feature if you ask me.

I'm not sure what you're saying exactly.

Why facebook doesn't disable it? Because people use it.

Why don't users disable/deny it? Because you can't select which permissions you want to grant to application upon installation, it's either all or nothing, even though the permissions may never be used.

And it's not really a shitty feature, the auto confirmation is pretty good - the permissions needed for it are shitty though, but they don't really have a choice other than completely disabling that part of application and having users enter the code manually.

Re: Facebook can now read your texts

#136

Add Hangouts to the discussion. They incorporated SMS into the app, but the implementation doesn't look complete/polished, let alone the app. So, it doesn't provide me an alternative to the OEM provided messaging app, and at the same time they are accessing my SMS messages. I personally don't use Facebook on phone now, but I would recommend using a third-party app for accessing Facebook on android. I have used Friend…

They're not accessing your messages unless you use it as default SMS application.

Re: Facebook can now read your texts

#137
post #134

Earlier quoted context omitted.

You can use the mobile web page for Facebook. Less intrusive, less privacy issues. And it probably works better than the app.

This is my preferred solution for the times I have to unavoidably use Facebook: https://play.google.com/store/apps/details?id=com.danvelazco...

I love this app; I've been using it for years now. Never having to login to FB in the actual browser is a real boon; it's great at sandboxing their cookies.

Re: Facebook can now read your texts

#138
post #100

This has been a thing for about a month and a bit now. A Facebook engineer posted the following on Reddit[0], explaining the rationale behind the SMS permission: > As for the READ_SMS permission, we require that so we can automatically intercept login approvals SMS messages for people that have turned 2-factor authentication for their accounts, or for phone confirmation messages when you add a phone number to your Fa…

I feel like some sort of manual component to two-factor authentication is the whole point (a clickable link, copy+paste, or remembering a 4 digit number). Besides that, two factor is a bit of a joke in an app (on your phone) that caches your password, and then sends a message (to your phone) which is automatically read and accepted, before allowing you to login. What exactly are we achieving here in terms of security…

>I feel like some sort of manual component to two-factor authentication is the whole point

It's not really. The point is to verify that the device used for 2FA is still with you, whether you entered the code manually or it got entered automatically isn't the point of the system - and in practice has no real difference (unless your 2FA app requires password for access)

>What exactly are we achieving here in terms of security?

Verifying that the phone is still using allowed SIM card/phone number.

If you switch phones you can still get the confirmation message and access your account and if needed invalidate all other sessions.

If your phone is stolen you can do the same thing. The app password caching doesn't matter then.

It is no different than 2FA app that you have on your phone except that it's more tied to your SIM card than your phone.

Re: Facebook can now read your texts

#139

This has been a thing for about a month and a bit now. A Facebook engineer posted the following on Reddit[0], explaining the rationale behind the SMS permission: > As for the READ_SMS permission, we require that so we can automatically intercept login approvals SMS messages for people that have turned 2-factor authentication for their accounts, or for phone confirmation messages when you add a phone number to your Fa…

The problem with many permission systems, such as this one, is that the developer of an app can't indicate to the user /why/ it needs a certain permission. Second, that the user cannot allow/disallow the permission at the time of installation, and that the app / app developer can then indicate, like in this case, that automatic two-factor authentication won't work. Which is fine. tl;dr: Android's permission system do…

You're proposing to solve a non-tech issue (trusting the app's developer) with tech -- what's to stop the developer to lie anyway?

Re: Facebook can now read your texts

#140
post #100

Earlier quoted context omitted.

I feel like some sort of manual component to two-factor authentication is the whole point (a clickable link, copy+paste, or remembering a 4 digit number). Besides that, two factor is a bit of a joke in an app (on your phone) that caches your password, and then sends a message (to your phone) which is automatically read and accepted, before allowing you to login. What exactly are we achieving here in terms of security…

We are achieving the same security guarantee as before, just without the user pain. All two factor provides in this case is proof that you have the phone associated with your account. Why does it matter if the app does the legwork for you?

We are achieving the same security guarantee as before, just without the user pain.

I'd argue that a corporation other than the phone company being able to read all your text messages is significant pain.

Given that FB seems to want to take over all communication between users (contact list/blog/email/photos/messaging) FB being able to track and access anything you do is the inevitable endpoint of such aspirations, but many people are not comfortable with that, and the farther FB go down that road, the more people they'll alienate.

Post reply on HN