Live data from Hacker News

TakeThisLollipop - really clever/creepy use of the Facebook API

takethislollipop.com

121–130 of 143 posts

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#122
post #102

Earlier quoted context omitted.

It's an example of how much personal data you actually leak through Facebook illustrated through a movie of a crazy serial killer browsing Facebook, with nicely done overlays of your actual personal data that the app pulled from you.

Since when does "leak" equate to "explicitly grant permission to access"? It is not like the app is getting information that some random hacker can access, at least if you have any privacy controls set on your Facebook profile.

Right, because Facebook would never change their privacy policies on a whim without giving users warning ahead of time. At least they probably won't. Anymore. Well, only if they really need to.

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#123

Why would anyone authorize Facebook access for a random site like this? No privacy policy, no about page, no terms. You have no idea what they're actually doing with your data.

Sorry, but seeing a privacy policy and about page is not a valid way to judge if an app is malicious or not.

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#124
post #55

Funny, my hosts file seems to interrupt the flow of this prank slightly. We'll see how my s.o. reacts to it, but on my machine it does absolutely nothing. In case you're wondering what is in my hosts file: 127.0.0.1 www.facebook.com 127.0.0.1 facebook.com 127.0.0.1 connect.facebook.net 127.0.0.1 facebook.net 127.0.0.1 fbcdn.net 127.0.0.1 www.fbcdn.net 0.0.0.0 badge.facebook.com 0.0.0.0 blog.facebook.com 0.0.0.0 en-gb…

You can achieve a similar thing with the ghostery extension. http://www.ghostery.com/

thanks, also didnt know about this one - was using 'abine' which is similar. I like the ghost icon though :-)

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#125
post #110

I don't have facebook. Anyone mind writing a tldr?

Here's a video of what happens after you log in: http://www.youtube.com/watch?v=-_GhKkXQrqo

thanks. no-way i was going to allow some random site access to facebook ... video/insertion is pretty well done indeed! :-)

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#126

Looks like it's connected with the ad agency Evolution Bureau ("EVB") (clients: [1]), the same people who did the Office Depot-braded "Elf Yourself" sensation [2]. Why do I think it's EVB? This is the only other site on the same IP as manipulation.com, and manipulation.com is registered clearly to EVB. The agency's creative work is consistent with this project too. [1] http://evb.com/work/ [2] http://elf.evb-archive.…

It's not Evolution Bureau.

It was Jason Zada (http://jasonzada.com/) a Commercial and Music Video director who may have one point been at EVB (and was the one who registered manipulation.com) but apparently he's now at Tool of North America.

http://bits.blogs.nytimes.com/2011/10/18/mysterious-site-cre...

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#127

One interesting thing about how this was designed, it for some reason doesn't get your location from your facebook profile. It uses your IP address, which led to hilarious results because while my facebook rightly says where I am, I was using a SOCKS proxy to access this in a different city and when it showed him looking at a map it showed the route to my SOCKS proxy instead of me. I guess I'm safe and the crazy guy…

I don't think the Facebook API allows you to find your location (although it is possible to retrieve your Facebook location by scraping the Security page for your current login session (which displays your location)).

Also, the location data that is displayed on that page is kind of inaccurate (it says I'm in another state).

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#129
post #86
post #55

Funny, my hosts file seems to interrupt the flow of this prank slightly. We'll see how my s.o. reacts to it, but on my machine it does absolutely nothing. In case you're wondering what is in my hosts file: 127.0.0.1 www.facebook.com 127.0.0.1 facebook.com 127.0.0.1 connect.facebook.net 127.0.0.1 facebook.net 127.0.0.1 fbcdn.net 127.0.0.1 www.fbcdn.net 0.0.0.0 badge.facebook.com 0.0.0.0 blog.facebook.com 0.0.0.0 en-gb…

You're better off using a browser extension or other technique. Facebook uses a lot of subdomains like static.ak.fbcdn.net and there's no way you can include them all in your list.

Just point your dns cache to an instance of tinydns that is configured to be authoritative for fb's domains.
Post reply on HN