Live data from Hacker News

If you care about user privacy, don’t use Facebook JavaScript SDK

simplelogin.io

101–105 of 105 posts

Re: If you care about user privacy, don’t use Facebook JavaScript SDK

#101
post #65

Earlier quoted context omitted.

I think willingly abusing user privacy for profit and lying to your government makes using the word “repugnant” pretty quantifiable.

How are they abusing privacy? Because it doesn't align with your views of privacy that constitutes abuse? You may have an expectation of privacy and we can argue whether or not that is valid. (not really IMO, facebook doesn't owe you anything for using their service. What a private company does with their service is really not abuse) Lying to the govt. is pretty vague. What lie in particular are you referring to?

> facebook doesn't owe you anything for using their service

I do not use their service, and yet they stalk me around the web, with countless tracking pixels and like buttons, assembling my shadow profile. Yes, they are abusing privacy as much as real-world stalkers are.

Re: If you care about user privacy, don’t use Facebook JavaScript SDK

#102

Earlier quoted context omitted.

WhatsApp calls and messages were used by Facebook. The point is that even Telegram does the same they have much less data about me that they can use. It is a good enough replacement of SMS and GSM calls even with broken crypto. For sensitive communication I would definitely use Signal or Keybase instead. Those are the tools that we use for work related things like software development. Keybase is actually pretty amaz…

> WhatsApp calls and messages were used by Facebook. If that's true that would be extremely serious, given that Whatsapp promises end-to-end encryption > WhatsApp end-to-end encryption ensures only you and the person you're communicating with can read what's sent, and nobody in between, not even WhatsApp. Your messages are secured with locks, and only the recipient and you have the special keys needed to unlock and r…

https://www.wired.com/story/whatsapp-security-flaws-encrypti...

Re: If you care about user privacy, don’t use Facebook JavaScript SDK

#103

Earlier quoted context omitted.

> WhatsApp calls and messages were used by Facebook. If that's true that would be extremely serious, given that Whatsapp promises end-to-end encryption > WhatsApp end-to-end encryption ensures only you and the person you're communicating with can read what's sent, and nobody in between, not even WhatsApp. Your messages are secured with locks, and only the recipient and you have the special keys needed to unlock and r…

https://www.wired.com/story/whatsapp-security-flaws-encrypti...

That's a serious issue I wasn't aware of. Do note however that for this attack to work you have to not notice a user you don't know added to your group chat. Nevertheless, this is much more serious than I knew.

Re: If you care about user privacy, don’t use Facebook JavaScript SDK

#104
post #77

Earlier quoted context omitted.

Indeed obvious to some but necessary to hammer until everyone gets it — especially the business types who make decisions, as new devs themselves would quickly grow to learn this. > What ever they are offering cost them money to develop, but they did not do that as a charity. True! Yet... I keep thinking about `http` (the protocol), or Apache, IRC, and countless other software techs that were just 'given' to (and are…

> True! Yet... I keep thinking about `http` (the protocol), or Apache, IRC, and countless other software techs that were just 'given' to (and are maintained by) the world, courtesy of their makers, and/or bodies like IETF work groups, etc. The difference here is that the social platforms have been developed as a for profit company. Granted, FB has improved some of their underlying technologies, and released them back…

You're totally right. I agree, and wasn't disputing these facts indeed. Just thinking out loud I guess...

> Other companies like Apache, Redhat, etc also offer us free things to use/play with while monetizing their enterprise/support services. A much more ethical method in my opinion.

Totally, this general business model can get as close as it gets to sustainable open-source. It seems hard to pull off though, lots of dead startups and projects out there, despite a few resounding successes.

Re: If you care about user privacy, don’t use Facebook JavaScript SDK

#105

Earlier quoted context omitted.

How are they abusing privacy? Because it doesn't align with your views of privacy that constitutes abuse? You may have an expectation of privacy and we can argue whether or not that is valid. (not really IMO, facebook doesn't owe you anything for using their service. What a private company does with their service is really not abuse) Lying to the govt. is pretty vague. What lie in particular are you referring to?

> facebook doesn't owe you anything for using their service I do not use their service, and yet they stalk me around the web, with countless tracking pixels and like buttons, assembling my shadow profile. Yes, they are abusing privacy as much as real-world stalkers are.

So the websites you visit use their service then?
Post reply on HN