Live data from Hacker News

Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

github.com

361–370 of 376 posts

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#362
post #126

Earlier quoted context omitted.

I’ve got tons of apps in my App Store’s update queue, some that I haven’t updated for a couple months and they still work perfectly. Uber is one that comes to mind. They keep changing the UI while I keep using the same version from ages ago. I don’t bother updating anymore, it’s just noise.

What about security?

I do update banking and critical apps (say, VPN clients, PDF reader), though.

In the consumer app cases, either I'm hitting somebody's backend with wrong data, which fails and so I update the app, or more frequently, those whiny apps with almost daily updates are just a WebView shell to some website.

Otherwise, what a hacked iOS sandboxed app can do? If there's an exploit to escape the sandbox, like in the WhatsApp case, we have a way larger issue and I wouldn't expect a random hacker to waste such an exploit that could be better targeted at Jeff Bezos or so.

Other exploits are for system apps (Mail, Safari, etc) and are handled by OS updates.

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#363

Earlier quoted context omitted.

I tried adding spotify.com as a limited adult website and I can still use the Spotify app normally. So either I'm missing something or it can't be used as a firewall.

You might be using their magical p2p network.

I tried with various app and I can’t break any of them. I’d be really interested in a firewall for iOS

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#364
post #52
post #36

For those wondering why the Facebook SDK is so widely used in popular mobile apps: Facebook Login is actually in the minority of reasons to add the Facebook SDK to your mobile app. The vast majority of apps will add the Facebook SDK because it contains Facebook App Ads; a library that "completes the circle" in terms of finding out how effectively the ads you ran on Facebook were at getting people to download, install…

>Is that "spyware"? Yes, absolutely. It uses energy and bandwidth I paid for to surreptitiously transmit my information for use which will solely benefit Facebook and the software developer.

If it benefits the software developer and this is what allows their business to work, then that benefits you. If it didn't then you wouldn't have the app.

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#365
post #199

Earlier quoted context omitted.

If the software developer would charge a reasonable price directly to the user, they wouldn't have to use intrusive and unreliable libraries like Facebook SDK.

So they can charge directly to the user. They're still going to advertise to acquire that user though.

> They're still going to advertise to acquire that user though.

There would be no reason to put advertising in the app the user has already paid for.

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#366
post #330

Earlier quoted context omitted.

Can we agree that each restaurant having a separate app is one of the dumbest outcomes imaginable?

>Can we agree that each restaurant having a separate app is one of the dumbest outcomes imaginable? Nope, can't agree there. Every outlet/brand should have it's own app in my book.

For what purpose? Why not just a good website? Why do I need some integrated solution when its probably just a shim around their website anyway? That sounds awful tbqh, download a binary for every website that I have little control over.

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#367

We found a couple workarounds while Facebook was busy fixing this. 1. Airplane mode 2. Block facebook.com as adult content under Settings | Screen Time | Content Restrictions | Web Content | Limit Adult Websites | Add a site. 3. Block facebook.com at your router. Option 2 could be helpful if you want to block it for privacy reasons.

I added YouTube.com under the restricted sites (not specifically as an adult site, just restricted) and it did stop my kids from going there directly, but they figured out that they can Shazam a song, use its “show song on Youtube” feature to get a fully functioning YouTube page and start working from there.

They can’t even read yet.

I am at the same time very proud at the l33t hacking skills and upset at their disregard for rules. But mostly proud.

I will check if “adult” blocking works better.

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#369

Earlier quoted context omitted.

I cannot easily see what information goes through an ASP form submitted with a ViewState parameter (where the page state is encoded in a blob buried in a JS var or HTML comment). Is that also surreptitious?

>I cannot easily see what information goes through an ASP form submitted with a ViewState parameter (where the page state is encoded in a blob buried in a JS var or HTML comment). Is that also surreptitious? I can't say I completely understand the scenario, but if you're talking about a user filling out a form, then submitting that form, then no. That would be expected behavior. Data may be encoded in any number of e…

> That would be expected behavior.

That's exactly my point. "Surreptitious" is being used to mean "I think it's bad, and I think it's not expected." The "bad" part is obviously subjective, but even if we agree on that, the latter is where you really need standards bodies to agree on what is acceptable technology practices. To me, ad tracking is definitely expected (regardless of whether I think it's bad). I suspect it's also expected by nearly all HN participants, and ubiquitous ad tracking is even in the mainstream public consciousness outside of tech circles.

Re: Facebook iOS SDK Remotely Crashing Spotify, TikTok, Pinterest, Winno and More

#370
post #337

Earlier quoted context omitted.

> It's all about what the software developer wants, not the user and that's not OK. I work in Software Development. Most of the time, the user doesn't know what he or she wants. They might feel that something is just not right, but don't know why, or cannot express why, because they don't know. Or don't care: I used to send out surveys, and the response rate was usually around 300 out of 50.000 confirmed users. That'…

You wanting more data does not give you license to assume consent for using a device you do not own to spy on a user. Even if a majority would have consented, assuming consent means that you are now co-opting some number of devices which do not belong to you to do things the owners of those devices do not want to happen. It’s extremely unethical, and should be illegal.

Well - the user is using the device with a part that I created. If the user doesn't want to participate in enhancing the product, we need to go the old school way of enhancing products: Research. We need to conduct studies, do testing with test persons, etc. This can be done, sure. But then your off-the-shelf app won't be available for 99 cents or for free, but cost more like 19.99 USD.

Might help streamlining the market, so I‘m open for that.

Post reply on HN