Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

221–230 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#221
post #28

Earlier quoted context omitted.

If the feature was using the fact that the user supplied the email password, parsing the emails for contacts or logging in with the password and getting the contact list, how on earth could that have been a part of an earlier import contact feature? Did they already ask users for their email password for that? If not this is a feature that needed special code, impossible to be an accident.

> how on earth could that have been a part of an earlier import contact feature? Did they already ask users for their email password for that Yes they did. I remember people complaining about it many years ago. Here’s a page from 2012 describing it I found using google advanced search: https://smallbusiness.chron.com/import-email-facebook-44162.... > When you create a Facebook page for your business, you can import y…

Thanks! Unbelievable that this existed.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#223
post #17

Can someone use a throwaway e-mail address to sign up for Facebook? Once the e-mail address is validated, is there any further need for a valid e-mail address to continue using FB? Historical fact: Going back to the days when a university address was required, if the user created her Facebook account while at university and her e-mail address later expired when she graduated, FB did not disable the account. Unless on…

Yes. I use throw-away email addresses for everything. When a company gets popped or "accidentally" leak my email address, I simply add a header check and reject or discard them. I was on FB for 2 weeks when it started and I still see them in my logs from time to time trying to fish me back into the system.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#225
post #97

Why are companies even asking users to provide passwords for unrelated services? For example, when I added an external account on Etrade, they gave me the option of same day verification of that account if I provided them my online banking account credentials. This practice opens up a significant potential for abuse and should be illegal.

Is this question rhetorical? Your online banking is known to be verified, therefore another company can piggyback on that verification.

They can't really 'piggyback' since disclosing your account authentication details is against the ToS of the bank.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#226
post #132

Earlier quoted context omitted.

Interestingly, WhatsApp (and Telegram, and Signal) don't even ask and just upload all your contacts' phone numbers (this is before Android had the prompt "Allow this app access to your contacts?). It's very convenient, and also very sad. Also sad is the fact that BlackBerry already had a fine-grained permissions systems pre-iPhone days, but it took iPhone and Android many many versions and years before they built suc…

Permissions to read text messages is another one that gets me. I know not many people use SMS as their primary communication but how can you be so astonishingly blasé about your data to save typing in a code?

Thankfully there is now the SMS Retriever API that lets you do this without having access to all messages, and the Play Store no longer allows apps that require this permission without SMS handling being a core functionality of the app.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#227
post #149

Related: WhatsApp on iOS recently updated, and now will only show phone numbers for contacts UNLESS I upload my contacts. In the UI if I click on a number it will take me to the profile where I can see that users name ~Tom, but wow, waddamove... Have we reached the point where FB can't make any more money until they go deeper or is this just drag-net "data is the new oil"

It's the same on Android, with Contacts permission blocked it will show only numbers except for groups.

Furthermore it won't let you start a chat with anyone unless it can access your contacts to find them. However there's a great little app on F-Droid called 'Open in Whatsapp' that lets you start a chat with any arbitrary phone number.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#228
post #175

Earlier quoted context omitted.

> You can make similar money at several other companies without sacrificing your soul! I'm not so sure. Certainly Google, Amazon, et al are just as bad as facebook.

Who's the "et al" there? Microsoft and Apple would be the logical successors, but I don't think most people would consider them "just as bad as Facebook".

My, how times have changed, if Microsoft is not considered a bad actor. There was a time when MS was Satan personified for many people in the OSS community (myself being one of them).
Post reply on HN