Live data from Hacker News

Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

arstechnica.com

151–160 of 226 posts

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#151

Earlier quoted context omitted.

Ex-FB here -- I do feel like I knew about the general scope of what Onavo did, which was to incentivize people so FB could snoop on TLS traffic and grab data about competitor usage.

Could be a question of what we worked on. I did Ads ML Infrastructure, Abuse Detection Systems (spam basically), and then more ML Infrastructure on IG Feed/Stories. I was deep enough in the engine room it was all more or less feature embeddings. So it’s probably fair to say I would have known less about strategic maneuvering than plenty of less tenured folks closer to the surface. I knew it sounded vaguely sketchy bu…

I was on devinfra/source control (worked 2012-2018 in that area before switching to Libra) so we weren't making decisions, but we got to saw a bunch of what happened as it happened. Onavo was always treated as pretty sus among the people I worked with, who were largely linux/free software/security types.

As Pedro said in the email described in [1], no sufficiently well-informed, security-minded person could ever be comfortable with Onavo.

[1]: https://techcrunch.com/2024/03/26/facebook-secret-project-sn...

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#152
post #109

Earlier quoted context omitted.

This should make it a no-go for any sane person that is aware of that, unfortunately not many are. I always try to convince people I know to ditch Messanger/WA/etc. in favor of Signal, and in many cases I've succeeded.

What is good about signal? It does not allow unique account names (!), but uses telephone numbers - what is just absurdly bad security. The state can make a duplicate of your sim at any time. Not to mention linking phones to people is relatively easy.

Signal introduced usernames about a month ago.

https://signal.org/blog/phone-number-privacy-usernames/

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#153

Earlier quoted context omitted.

My guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.

Although the frank meaning of "E2E encryption" is that a message is encrypted on the sender's device and only decrypted on the intended recipient's device, that is never ever what big tech companies mean when they use this term. For one, this would remove companies' ability to support lawful interception, which puts them afoul of American law.

Is lawful interception possible with Whatsapp? I thought it had actual E2E encryption.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#154

Earlier quoted context omitted.

> That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file. ...it occurs to me that this is in fact how most desktop apps work, and I do prefer it that way.

On windows idk but Unix has permissions for that reason.

There are permissions, but I think https://xkcd.com/1200/ is relevant here.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#155
post #103

Earlier quoted context omitted.

Courts across the world fining them.

The fines have to be more than 100% of global annual revenue if they are going to matter. The other option is long prison sentences for the board and CEO.

We often act as if corporations are unalignable super intelligences, but you're right, if there are consequences for the board/executive/shareholders, they would start caring.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#156

Earlier quoted context omitted.

I hope you’re being sarcastic? Or is that actually your stance on people’s privacy rights?

Boiling it down here... some users hit the "Yes" button when Facebook asked them if it was OK to allow Netflix to access their DMs for a feature that allowed you to chat (bidirectionally) with your friends inside the Netflix app. That's a privacy violation?

[deleted]

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#157

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

[flagged]

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#158

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

Note that everyone had access to the Inbox API at the time. We made an art project highlighting the invasiveness of such broad access:

"E-dentity is a project that asks a participant to login to its Facebook account, then takes his/ her private data from their profile and automatically prints them in an understandable booklet that is handed to the user. This booklet seeks to raise awareness of the hidden data we are sharing which we are often not aware of."

https://github.com/some1else/Edentity

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#159
post #38

Earlier quoted context omitted.

And if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.

This isn't how permissions work in most OAuth APIs. When you request permissions on apps like this, you request an "action" on a "subject". The "action" can be read/write/delete, the subject can be "DMs". How does Facebook determine whether a specific DM is a Netflix DM? In the database it's just a message from one user to another, with a certain text content. By the way I'm not suggesting that it cant work this way,…

So when it comes to adding value for advertising fb is able to separate every object and data piece into sickening degrees of detail… but when it’s about privacy and authentication it’s “not the way things are done around here”… As you’ve mentioned as well it’s a choice by fb. Just as we have a choice to call fb out on making immoral choices. Better yet, the developer(s) that coded this part, and the developers that make a daily choice to maintain it in its current form.

And yes, it’s a choice. Just because people don’t take responsibility to make a deliberate choice, doesn’t mean it’s not a choice.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#160
post #24

This is one of the litany of bad things that happens when antitrust precident is ignored and we allow a small number of companies to become large enough to dominate the economy.

But commenters here want that right? They're rilling up against an API that allows data export and user ownership and demand that they're removed and all interoperability to be killed because "users are too stupid". This cements and entrenches monopolies because noone is allowed to compete or interoperate.

In sense, things like Apple Mail is a problem for them because it uses full access to GMail account to extract private data over API.

Post reply on HN