Live data from Hacker News

TakeThisLollipop - really clever/creepy use of the Facebook API

takethislollipop.com

131–140 of 143 posts

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#131
post #102

Earlier quoted context omitted.

It's an example of how much personal data you actually leak through Facebook illustrated through a movie of a crazy serial killer browsing Facebook, with nicely done overlays of your actual personal data that the app pulled from you.

Since when does "leak" equate to "explicitly grant permission to access"? It is not like the app is getting information that some random hacker can access, at least if you have any privacy controls set on your Facebook profile.

No, it's getting information some random website can access by offering you a picture of a lollipop. Stranger danger?

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#132
post #83

I don't think I get it... when I let a facebook app access my facebook, it can... access my facebook and look at my pictures? anyone can look at my pictures, anyways. i'm missing something here

I think it's that you're giving them access based on a picture of a lollipop, while having absolutely no idea who you're giving that access to. Never take candy from strangers.

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#133
post #55

Funny, my hosts file seems to interrupt the flow of this prank slightly. We'll see how my s.o. reacts to it, but on my machine it does absolutely nothing. In case you're wondering what is in my hosts file: 127.0.0.1 www.facebook.com 127.0.0.1 facebook.com 127.0.0.1 connect.facebook.net 127.0.0.1 facebook.net 127.0.0.1 fbcdn.net 127.0.0.1 www.fbcdn.net 0.0.0.0 badge.facebook.com 0.0.0.0 blog.facebook.com 0.0.0.0 en-gb…

There was another discussion on this point, where a few others were added:

0.0.0.0 static.ak.fbcdn.net 0.0.0.0 www.static.ak.fbcdn.net 0.0.0.0 login.facebook.com 0.0.0.0 www.login.facebook.com 0.0.0.0 fbcdn.com 0.0.0.0 www.fbcdn.com 0.0.0.0 static.ak.connect.facebook.com 0.0.0.0 www.static.ak.connect.facebook.com

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#134

One interesting thing about how this was designed, it for some reason doesn't get your location from your facebook profile. It uses your IP address, which led to hilarious results because while my facebook rightly says where I am, I was using a SOCKS proxy to access this in a different city and when it showed him looking at a map it showed the route to my SOCKS proxy instead of me. I guess I'm safe and the crazy guy…

Not by IP, FWIW. I'm in Mountain View but the guy seemed to want to find me in Reykjavik, Iceland, where I'm from. (I moved to the Bay Area a month ago, but haven't update my FB)

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#139
post #23

This actually just freezes for me/nothing happens after I click "Connect with Facebook". Chromium 12.0.742.112 (90304) Ubuntu 10.10.

Flashblock?

I use both Adblock Plus and Better Popup Blocker. But both disabled/site allowed. :-/

Re: TakeThisLollipop - really clever/creepy use of the Facebook API

#140
post #113
post #108

Earlier quoted context omitted.

i'm guessing that you actually have a bunch of other sites blocked in your hosts file, as well. on the assumption that you do, do you ever see any network performance issues related to this? i used to maintain a rather large hosts file for this purpose, but eventually gave it up because i suspected that it had started doing more harm than good.

No, facebook has a special place in my heart, which is why they got 'special treatment'. Other than the usual suspects and FB my host file is empty. I can see how a huge hostfile would impact performance, and I would advice against using it to block a very large number of hosts.

Some of these hostnames are quite arcane to me (peace.facebook.com); did you get them from a list somewhere or did you identify each one of them yourself?
Post reply on HN