Live data from Hacker News

Facebook scans system libraries on Android and uploads them to their server

twitter.com

51–60 of 68 posts

Re: Facebook scans system libraries on Android and uploads them to their server

#51
post #28

Earlier quoted context omitted.

It's not an angle it's literally copyright infringement. Users aren't given the right to distribute their copies.

So are they allowed to make point in time backups / snapshots of their phone or is that also “copyright infringement”? Usually copyright infringement focuses on distribution for piracy and/or fraudulent sales — this is neither.

Yes, users can copy this data for backup purposes, that is covered by fair use.

> Usually copyright infringement focuses on distribution for piracy and/or fraudulent sales — this is neither.

I'm not sure what you mean. Copyright infringement is the act of infringing on one's copyright. It's not a question of focus.

Copyright law does focus on certain aspects of it but it's not up to Facebook to decide when it's copyright and when it's not. The law is pretty clear here.

This is clearly distribution and clearly not licensed copying.

The purpose here is largely irrelevant.

Further, this is clearly unauthorised access and removal of user data. This is quite likely a criminal act under US hacking laws.

Re: Facebook scans system libraries on Android and uploads them to their server

#52
post #45
post #20

Earlier quoted context omitted.

How does this provide any more data for fingerprinting than just checking the model of the phone?

Harder to spoof, less likely to be faked, plus additional meta information.

For starters, I'm not convinced it would be harder to spoof that than the library information (which also seems pretty easy to spoof if not easier).

But even if that were the case, why would they spend this level of engineering effort just to be able to fingerprint people in that extremely rare case of having a spoofed phone model? Do you think that kind of customer would even be receptive to targeted ads in the first place? It just doesn't make sense to me.

Re: Facebook scans system libraries on Android and uploads them to their server

#53
post #28

Earlier quoted context omitted.

It's not an angle it's literally copyright infringement. Users aren't given the right to distribute their copies.

So are they allowed to make point in time backups / snapshots of their phone or is that also “copyright infringement”? Usually copyright infringement focuses on distribution for piracy and/or fraudulent sales — this is neither.

FWIW the sibling comments are correct under USA's Fair Use but in the UK there is only a very restrictive Fair Dealing which last I looked did not allow backups without permission unless there is no digital protection in place. There is a right under S.50A to make a backup of a computer program but when paired with the rest of the act it's unworkable.

In the UK you can't (you could for a while) rip a CD/DVD, apps like iTunes are contributory infringers.

Re: Facebook scans system libraries on Android and uploads them to their server

#55
post #24

Okay what is the purpose of this even? Sure, everyone is going to talk about fingerprinting, but let's face it, there are way easier and more reliable methods of doing that than system libraries that mostly match between same devices. Must be for some sort of debugging? Still seems insane...

My guess is that it helps to detect spamming tools, flash game cheats, malware that affects Facebook apps, etc.

Re: Facebook scans system libraries on Android and uploads them to their server

#56
post #25

As someone who’s built my company’s mobile crash reporting solution, I have a guess why they might do this. It’s is extremely difficult to diagnose Android native code crashes. Unlike iOS where it is both straightforward to unwind on the phone, and where Apple makes the iOS system symbols available for symbolizing system frames in a stack trace, neither of these things are true on Android. My first approach for my co…

This is clearly not for crash reporting. They're sucking up libs to figure out what apps their users use.

Could be a few reasons, could be boring metrics, could be anticompetitive identification of acquisition targets, could be oppo research, could be user profiling.

None of these things I'm ok with Facebook getting off my phone.

Re: Facebook scans system libraries on Android and uploads them to their server

#57

Earlier quoted context omitted.

Not that many people do... This only includes system libraries which a phone OEM shipped. It doesn't include libraries which are bundled with an app.

The OEM isn't the copyright holder of the libraries they ship though.

Very few of the libraries will be owned by an individual though - I would bet >99% are owned by an OEM or software house. That OEM probably isn't interested in suing facebook for a small amount, because if facebook blocked that OEM's phones, it would probably spell the end of the OEM.

Re: Facebook scans system libraries on Android and uploads them to their server

#58
post #2

How is this not utterly illegal in the EU, per GDPR? (Which was drafted to stop indiscriminate data acquisition on human subjects: I'm assuming that metadata about the core libraries on your phone, in conjunction with FB's user metadata, are trivially de-anonymizable.)

Under which provision would this be illegal though? It's the operating system image Facebook can get by just buying the exact same model of phone the user owns. I'm having trouble finding under which definition of GDPR managed personal data does this fall over.

The only angle I see is copyright infringement for copying libraries owned by the phone manufacturer... but even that I'm not sure if it's really illegal in this case. Worth filing a complaint anyway I guess.

Re: Facebook scans system libraries on Android and uploads them to their server

#59
post #56
post #25

As someone who’s built my company’s mobile crash reporting solution, I have a guess why they might do this. It’s is extremely difficult to diagnose Android native code crashes. Unlike iOS where it is both straightforward to unwind on the phone, and where Apple makes the iOS system symbols available for symbolizing system frames in a stack trace, neither of these things are true on Android. My first approach for my co…

This is clearly not for crash reporting. They're sucking up libs to figure out what apps their users use. Could be a few reasons, could be boring metrics, could be anticompetitive identification of acquisition targets, could be oppo research, could be user profiling. None of these things I'm ok with Facebook getting off my phone.

> They're sucking up libs to figure out what apps their users use.

Hypothesis 1, debugging: requires full copies of system libraries

Hypothesis 2, fingerprinting: requires hashes of application libraries

Evidence: full copies of system libraries are being uploaded

How are you using that evidence to be so confident in hypothesis 2 and confidently against hypothesis 1?

Re: Facebook scans system libraries on Android and uploads them to their server

#60
post #39

What about the Instagram and WhatsApp apps? Do they behave the same way?

I'm really interested in an answer for this question, since WhatsApp is the only Facebook app I have installed/keep an account.

Unfortunately, everyone uses WhatsApp in Brazil, and very few people uses Telegram, for example. This makes it kinda impossible to be Facebook-free here.

Post reply on HN