Earlier quoted context omitted.
Yes, people can and will write malicious programs. Those will sometimes take the form of third party clients for a service. That is not and will never be a valid argument against them being allowed to exist. Monopolies are not ok. Abusive behavior by the dominant market players isn't ok.
Yes, but my point is that said clients should have to talk through properly secured APIs and required by law. Until then, an app like this is a massive, MASSIVE security risk and I would question the sanity of any team that saw something like this and ignored it.
Meta has banned the personal Facebook accounts for everyone on our team
271–280 of 442 posts
Re: Meta has banned the personal Facebook accounts for everyone on our team
#272Oh wow, this app got pulled from everything because it's an unofficial 3rd party client for Instagram? I'll say it again, companies should be legally forbidden from blocking 3rd party clients. They don't have to explicitly support them, but taking action to explicitly thwart them (and writing ToS that forbids them) should be outlawed. There's no reason I should have to be subjected to untold tracking, snooping and ad…
However, Meta blocking the developers fb accounts is basically harassment. Let the courts sort it out if their app is illegal. Meta shouldn't take things into their own hands.
Re: Meta has banned the personal Facebook accounts for everyone on our team
#273Earlier quoted context omitted.
> should have to talk through properly secured APIs I don't follow what you mean by this. The API endpoints that a company provides ought to be secured properly. In practice they might or might not be but obviously they ought to be. I don't see what that has to do with third party clients though. A third party client is stuck interacting with whatever API the company provides, however secure or insecure it might be.
I mean from another perspective this is effectively a MITM style way of interacting with Meta's API. They are behaving as another unauthorized layer between the user and Meta's API. In actual secure systems involving third party clients the client usually authorizes itself on behalf of some user requests or permissions, so while it does things for the user there's a clear and secure delegation of permissions. Have yo…
"Is this secure?" fully depends on what the attack vectors you're considering are. Breach of the server's database? Make it an app instead of a website and make requests directly. Malicious code in the client itself? Make it open source. Now it's even more secure than the official client.
But regardless of all of this, how is it any of the service provider' s business what I do with my login details? It's my data on my account. If I use it in an insecure fashion, that's my problem. I am free to post my login details on Twitter for everyone to see, so why can't I put them in a database on some russian dude's basement server?
Re: Meta has banned the personal Facebook accounts for everyone on our team
#274Many folks on here might be too young to remember, but there was an era where cable companies served premium channels with a scrambled signal to all customers, and sold access by way of attaching the appropriate filter. In fact, all channels were protected in this way, with your cable box holding the necessary filters. Albeit, some were merely hidden by a band pass filter and not scrambled. Anyhow, those arguing that…
Doesn't seem like a valid analogy to me. Access to an API isn't the same thing as intentionally accessing a paid service for free. If someone writes an app that somehow bypasses needing a Netflix account and lets you stream video from them without paying them. That would be analogous. The intent would be to illegitimately access a paid service. Using a third party client with a valid account to access API endpoints t…
If you don't find those terms favorable the correct action is to not use their service; violating their consent is not morally sound.
Re: Meta has banned the personal Facebook accounts for everyone on our team
#275Earlier quoted context omitted.
Why should 3rd parties be allowed to make unauthorized api requests? Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business? I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.
By this logic, it should be illegal / a breach of contract for you to run an ad blocker, since the company may not make money? Should you also be forced to look at ads and not switch channels while they're on TV, with the channel being free to cut access if they find you haven been looking at the ads they serve? This logic really bends over backwards to support FB's and similar business models.
If you found out Netflix actually streams their content from a public endpoint. You would not be legally allowed to take advantage of that.
Re: Meta has banned the personal Facebook accounts for everyone on our team
#276Earlier quoted context omitted.
According to the source code, the link is broken for desktop (class="footer_component desktop"), but not mobile (class="footer_component mobile"). Privacy Policy is a non-functional link.
Probably has some javascript handler or something?
Re: Meta has banned the personal Facebook accounts for everyone on our team
#277Earlier quoted context omitted.
Sure, there's a risk there. But it should be my choice whether or not to accept that risk, not Meta's.
In this case the risk you take doesn't matter (though I argue from a security standpoint this is something you should really care about in any argument around Meta), it's the risk Meta takes by allowing it. Because if the company takes your data and runs, Meta is the one also on the hook for not securing their APIs. If it turns out they're farming passwords from users to sell to whatever group ultimately the class ac…
I only got a few posts into the thread before Twitter booted me out for not having an account, so maybe there's some context I'm missing, but what kind of "not securing your API" are you talking about? The fact that a thir party, explicitly authorized the the user, was able to make actions on the user's behalf, doesn't make it secure, it makes it functional.
Re: Meta has banned the personal Facebook accounts for everyone on our team
#278Earlier quoted context omitted.
I think I should have the legal right to access private messages addressed to me by family members via the service explicitly designed to facilitate private communication between friends and family members. I don't think I should be forced to see advertisements and be subjected to historically-unprecedented surveillance to read those couple hundred bytes of text from a family member. When a platform's primary purpose…
I disagree. No one has the right to use facebook/twitter/etc as they wish, or even at all. They're not necessary for modern western society. SMS and phone calls are always an option. We aren't like China where if you don't have WeChat you can't do anything.
And, actually, have you tried just not using Facebook for a year? Don't even log in whatsoever? Try it, seriously. I have missed parties, concerts, family gatherings (seriously), news of births, marriages, new homes, major life events (including deaths). I found out my cousin had a kid like 6 months later. I found out a friend died months after it happened. I miss out on the opportunity to partake in things that would have greatly enriched my life. This is the cost to me, personally, by opting out of THE platform that EVERYONE uses. I can't just constantly SMS and call everyone I know asking them every detail of their life, because they exclusively share it all on Facebook. You simply cannot invalidate this very real cost as "yeah well, just use something else".
These huge costs of exclusion are exactly why I believe that I should have the right to access de-facto-standard communication services with software that respects my psychological stability, privacy, accessibility needs (including cognitive), of my choice -- again, as long as that software conforms with proper API usage behaviour. Right now, I'm in a pretty coercive position where I either subject to the objectively-harmful design of the Facebook platform, or face pretty adverse effects to my socialization. That's one reason case where governments enact laws, to protect individuals from these sort of extremely skewed power imbalances.
BTW, I get what you're saying. All these services are tecnically optional. I kinda used to feel that way, until I actually started not using the services that I felt were manipulating and coercing me. Then I realized just how much power these services have over us. I realized these services are optional in just the same way as the telephone and the automobile used to be. Totally still optional. Just mail a letter instead. To me it's like, at this point, as a society, we need to decide whether we care if someone can be seriously cut off from modern society because they don't agree to have advertising shoved in their face, manipulative "algorithmic feeds" selectively shown to them to "drive engagement", and unprecedented surveillance cataloguing their every action 24/7/365.
Re: Meta has banned the personal Facebook accounts for everyone on our team
#279Earlier quoted context omitted.
In this case, the third-party telephone is allowing unlimited free calls using Ma Bell's infrastructure... I agree with you that Meta is ass for society. Simultaneously, these third-parties are parasitic. Ultimately everyone sucks here.
The solution to that is to fix your infrastructure to not trust the client, rather than trying to enforce use of a particular client.
Re: Meta has banned the personal Facebook accounts for everyone on our team
#280Earlier quoted context omitted.
Rather than just blocking the request for the ad, if an ad blocker allowed the requesting site to make the request for the ad but then just sent the data to the browser's equivalent of /dev/null, I'd be fine with that as long as I never had to see/hear the ad. This is of course ripe for abuse, but that's just synonymous for digital advertising in general. I don't consider it any different than me hitting mute on the…
This makes absolutely no sense whatsoever. If you don't think sites have a fundamental right to push ads to sustain themselves (as I don't), then blocking the request is the best place to do it for performance reasons. But even if you do believe in that right - the site and advertiser care about a single thing: a human being seeing the ad. Serving the Ad request is not just useless for their purpose, it is actively c…
I disagree. The site just wants the advertiser's money. The advertiser wants the human to see an ad.