Live data from Hacker News

Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

arstechnica.com

51–60 of 226 posts

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#51
post #39

Earlier quoted context omitted.

That's not what the feature was. The feature was that you could use Messenger inside Netflix and Spotify to chat with your friends without leaving those apps. If you opted into using Messenger to chat with your friends inside Spotify, I'm confused why you think Spotify couldn't access your messages, given that Messenger was unencrypted at the time and you were running it inside Spotify. How else would the feature wor…

Think about the difference between accessing these specific messages, and accessing all messages.

If I give Apple Mail my credentials for my GMail account, I would expect Apple Mail to be able to access my email in my GMail account. Switching the word "email" to "DM" doesn't feel like a meaningful difference: if I'm using a third-party client to access and send messages, of course the third-party has access to my messages. Would I expect Tweetbot to be unable to access any tweets other than the ones sent from Tweetbot? That's... not a very useful third-party client. These were third-party Messenger clients; they had access to your Messenger DMs if you opted into using them.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#52

Earlier quoted context omitted.

You would expect that giving permission to send specific pre-approved messages does not imply permission to read everything you've ever said to anyone or they've said to you.. Right?

That's not what the feature was. The feature was that you could use Messenger inside Netflix and Spotify to chat with your friends without leaving those apps. If you opted into using Messenger to chat with your friends inside Spotify, I'm confused why you think Spotify couldn't access your messages, given that Messenger was unencrypted at the time and you were running it inside Spotify. How else would the feature wor…

The web was rampant with these patterns in the early 2010s when OAuth didn't exist, and HTTPS the exception rather than the rule.

The most egregious example was probably LinkedIn's GMail "integration," ostensibly used to invite your GMail contacts to LinkedIn. Back then, that sort of thing felt innocuous. But the implementation was even worse. Due to lack of OAuth and MFA, you literally entered your GMail password into LinkedIn. Then LinkedIn logged into your GMail account where they could do anything. Even if they limited it to scraping your contacts, they still got every email address you'd ever sent or received an email to or from, over the lifetime of the account.

In any other context this would be called phishing. And by the way, this pattern still exists. For example, apps that force you to log into a third party site in their embedded WebView can read the entire DOM (including your password). ..

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#53
post #16

I don't recall this potential bombshell (maybe because it was shortly before a Christmas, and the NYT headline looked like just more of the same ol'): > And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting. But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users’ pr…

The problem isn't whether Facebook used private messages for ad targeting (the claim they denied), its whether Facebook used private messages at all.

Who cares if it was for ads, giving third party companies access should be a huge problem with or without ads.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#54
post #32

Earlier quoted context omitted.

[flagged]

Care to back that up with any citations, or should everyone just take it on faith that what a throwaway says isn’t made up?

Can you point out where in their contracts or privacy policy they have legally binding terms that irrevocably dismiss their right to give your messages to advertisers?

If they have no intention to sell, then they have nothing to fear by putting it in writing with a appropriate liquidated damages clause. Otherwise it is quite suspicious why they reserve the right to do that in the contracts that they wrote.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#55
post #38

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

And if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.

i’d question the “…couldn’t be bothered to build…” i’d be more likely to believe they knew exactly what they were sharing and wanted it that way.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#56

There is a lot of confidential information in Facebook private messages, probably people cheating, plans to leave one's job, political organizing, brides, illegal activities, etc. If Netflix gets access to this information, it is likely that other companies and 3rd parties got access either directly or indirectly. Very scary what can be done with that information.

[deleted]

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#57

Earlier quoted context omitted.

FB has supported e2e messaging since 2016, but it wasn't the default until 4 months ago (Dec 2023). So likely very few users had it enabled (much less on both ends needed to protect a message from FB). The netflix deal starts in 2013. Even after 2016, e2e would just mean netflix would get slightly fewer messages. So I don't see anything that would necessarily indicate FB is lying about e2e.

I wonder if there’s a timing connection here with FB Messenger “upgraded the security of this chat” messages I’ve had on a couple of long-running conversations recently

sheer coincidence, not to google-slide.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#58

Earlier quoted context omitted.

It's both true and false. They don't do advertising with msg, and it's e2e encrypted. But they can use the metadata

Yes... meta data

Is metadata useful for ad targeting?

If the claim is that they use the content of messages that's be one thing, but what kind of ad value is really pulled out of timestamps and phone numbers of who you messaged?

That said, collection of metadata can still be a problem, I just don't see the ad value.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#59

What is being claimed here? 'granted programmatic access to FB user's inboxes' could mean a lot of things. What privileges? I read the article and still can't tell. I don't believe that Meta allowed Netflix to read messages that a user sent or received, but that seems to be what they're implying.

Agreed. I would like to read more details about the "access to the Titan API" that Facebook gave to Netflix. Has anyone read the lawsuit PDFs? Maybe more details are in there somewhere.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#60
post #6

I'm not clear whether I understood what the article is claiming. It's clear they claim that Meta shared customer's direct messages with a business partner without notifying the individuals who sent and received the messages. It also SOUNDED to me like the article was claiming they did so AFTER Meta introduced "end-to-end encryption" (which would ALSO mean that they were lying about offering end-to-end encryption). Am…

I find the article quite confusing and unclear to be honest. Are there any other sources? This is the original NYT article from 2018 https://www.nytimes.com/2018/12/18/technology/facebook-priva... "Internal documents show that the social network gave Microsoft, Amazon, Spotify and others far greater access to people’s data than it has disclosed." Facebook promised E2E at the end of 2023.

Here's the source media is probably using: https://www.courtlistener.com/docket/18714274/klein-v-meta-p...

To be honest I found I got much better grasp on the whole debacle by just reading the court papers themselves.

Post reply on HN