Live data from Hacker News

Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

arstechnica.com

181–190 of 226 posts

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#181
post #104

Earlier quoted context omitted.

I hope you’re being sarcastic? Or is that actually your stance on people’s privacy rights?

Lots of comments here look like some sort of astroturfing made by a PR agency

I've been on HN since 2007 man.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#182

Earlier quoted context omitted.

I hope you’re being sarcastic? Or is that actually your stance on people’s privacy rights?

Google docs literally has the exact same feature and we're not even talking about it. Using the exact same OAuth framework as here you can grant Netflix and Spotify the right to read everything and all comments in your Google Docs. You can even grant them the right to read all your emails in Gmail! In all seriousness i believe anyone providing oauth should just shut it down at this point, Cambridge Analytica was enti…

In order to write something that reads user emails in Google APIs you have to go through multiple levels of hell, so I don't think that's a fair comparison

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#183
post #109

Earlier quoted context omitted.

This should make it a no-go for any sane person that is aware of that, unfortunately not many are. I always try to convince people I know to ditch Messanger/WA/etc. in favor of Signal, and in many cases I've succeeded.

What is good about signal? It does not allow unique account names (!), but uses telephone numbers - what is just absurdly bad security. The state can make a duplicate of your sim at any time. Not to mention linking phones to people is relatively easy.

Complete E2E encryption, only you and the person that you're talking to can read the messages. Yes, having you be identified by phone number is not great but they introduced usernames recently.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#185
post #38

Earlier quoted context omitted.

And if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.

This isn't how permissions work in most OAuth APIs. When you request permissions on apps like this, you request an "action" on a "subject". The "action" can be read/write/delete, the subject can be "DMs". How does Facebook determine whether a specific DM is a Netflix DM? In the database it's just a message from one user to another, with a certain text content. By the way I'm not suggesting that it cant work this way,…

Slack has a notion of private channels to which a bot can be added. Even a bot with full OAuth scopes can’t read private channels it hasn’t been granted access to. Of course, many people wouldn’t explicitly add the Netflix bot to their DM with their friend - but that’s exactly the point here.

OAuth is absolutely compatible with bots being treated as principals in a social graph, it’s just that that’s incompatible with the type of passive surveillance that was desired here.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#186
post #73

Earlier quoted context omitted.

Is that different for any other encrypted instant messenger, though?

No not at all, its a universal risk since you have to trust the UI. I should have been more clear there. Its interesting to me that I often see concerns over whether Facebook has encryption backdoors when the UI can do all the work.

That's arguably still a backdoor, no?

At least I'd call an instant messenger that which claims to provide end-to-end encryption between conversation participants and then surreptitiously inserts itself as another participant.

However, something very active like that would be much easier to detect and prove than a "true" cryptographic backdoor that could possibly be explained away as an oversight in design or auditing.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#187

Earlier quoted context omitted.

"Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data." - https://news.ycombinator.com/newsguidelines.html

The root comment is literally a Facebook employee who is intentionally trying to change the narrative. An employee of a company that has been fined billions for privacy breaches, that was responsible for literal voter suppression https://www.opendemocracy.net/en/dark-money-investigations/t... etc etc HN "guidelines" say "Please don't post shallow dismissals" -- Don't allow FANG to astroturf these forums.

Are you suggesting that people working at companies you don't like should be banned from HN simply because of who their employer is, or that they should not be allowed to reveal conflict of interest when discussing topics related to their employer?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#188
post #150
post #83

Earlier quoted context omitted.

What incentive does FB have to limit that access? Feels like MBAs would just see that as a cost/burden? We know FB does give a fuck about privacy, so that’s never gonna be a reason.

If you believe FB is in the business of selling user data, then giving out user data for free is not an optimal move.

Absolutely. So the question is, did FB view this through that lens? If they did, then maybe the ROI wasn't there. So they said fuck it.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#189
post #186

Earlier quoted context omitted.

No not at all, its a universal risk since you have to trust the UI. I should have been more clear there. Its interesting to me that I often see concerns over whether Facebook has encryption backdoors when the UI can do all the work.

That's arguably still a backdoor, no? At least I'd call an instant messenger that which claims to provide end-to-end encryption between conversation participants and then surreptitiously inserts itself as another participant. However, something very active like that would be much easier to detect and prove than a "true" cryptographic backdoor that could possibly be explained away as an oversight in design or auditing…

Yeah I think that would fall into the backdoor category. My point was mainly that concerns over E2E encryption usually stop at the level of encryption and transmission.

If one really doesn't trust that Facebook isn't honest about how messages are encrypted and who has access to decrypt them, they also shouldn't use an app made by the same company that by design must have access to the decrypted text.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#190

Earlier quoted context omitted.

As a former employee until 2018, I heard the words “Project Ghostbusters” two days ago. I was peripherally aware of something called Onavo but I had no notion that anyone was talking about “kits”, we all thought it was some kind of metrics thing that was sort of iffy sounding but lots of iffy ideas got proposed by some PM looking to make a name and shot down by the grownups, what is alleged would have provoked a riot…

My guess: you were in ads/targeting. And at most a Director. i.e. mostly operations. The people in targeting/demand/supply knows absolutely nothing about profile building. And there is where all the competitive advantages lies. And also all the shady deals. We usually keep everything very secret in profile building because that is the knowledge that allows people to leave and start competitors, but we disguise it as…

A remarkably astute analysis based on very limited information.

My job was to use information retrieval, machine learning / AI, auction theory, and pragmatic statistical sampling to both accurately model and stably price ads inventory and later dollarized organic inventory to drive specific policy agendas about what got clicked on, dwelled on, commented on, seen in recommender systems in equilibrium to achieve specific policy agendas of various kinds but all ultimately tying out at top-line revenue and engagement metrics.

It did not take me long to work out that PII was useless in this pursuit, there’s no entropy in the off-property like button table as concerns CTR.

It did not take me long to realize that I didn’t want to know what it was useful for.

I easily had the seniority to run queries against Hive tables that I had an explicit personal priority of never querying.

And I left the senior leadership track at the last stop before a directorship.

Post reply on HN