Live data from Hacker News

Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

arstechnica.com

61–70 of 226 posts

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#61
post #41

Earlier quoted context omitted.

So are you claiming Netflix is a “monopoly” and if so, how would you break them up? The same question for Facebook. This is a case of possible “collusion” not anti trust

Collision is part of antitrust. https://www.law.cornell.edu/wex/collusion#:~:text=Collusion%... .

You can have collusion without being a monopoly. Your two neighborhood grocery stores can illegally collude even if there are 100 in your city

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#62
The encryption concerns here are a bit confusing IMO. Facebook owns the UI that show you the text of the messages.

There doesn't have to be a backdoor into E2E encryption at all per say, a simple UI property check would give full access to message contents directly in the frontend code. Throw that into a private API and Bob's your uncle, decrypted messages that were transmitted with 100% secure E2E encryption.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#63

Earlier quoted context omitted.

So are you claiming Netflix is a “monopoly” and if so, how would you break them up? The same question for Facebook. This is a case of possible “collusion” not anti trust

open protocols in the case of Facebook and banning studios from owning/exclusivity with distributors in the case of Netflix.

So you are saying that no one can distribute their own work on thier own website? Where do you draw the line? Can I not create my own video and put it on my website? Can I not work with friends and we all post our own video on our own website that we jointly own?

How do we stop foreign studios from distribution over the internet? Do we block them too?

Why stop at films? Should book authors also not be slowed to self publish? Software developers?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#64

Earlier quoted context omitted.

Yes... meta data

Is metadata useful for ad targeting? If the claim is that they use the content of messages that's be one thing, but what kind of ad value is really pulled out of timestamps and phone numbers of who you messaged? That said, collection of metadata can still be a problem, I just don't see the ad value.

Yes it is useful. Knowing who you contacted and when tells advertisers demographic information and probably more that I can't think of

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#65

Earlier quoted context omitted.

If you give access to your chat as the parent poster claims, why are you surprised that Netflix has access?

it’s disingenuous to think that users read and fully understand the various permission scopes of a service. “private” has an unambiguous meaning—playing the “well, technically” card falls pretty flat imo.

When you give your mail client credentials to read your email , would you not expect your client to be able to read your mail?

On Android, when you give a third party client permission to receive SMS, you don’t expect it to have access to your SMS?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#66
post #6

I'm not clear whether I understood what the article is claiming. It's clear they claim that Meta shared customer's direct messages with a business partner without notifying the individuals who sent and received the messages. It also SOUNDED to me like the article was claiming they did so AFTER Meta introduced "end-to-end encryption" (which would ALSO mean that they were lying about offering end-to-end encryption). Am…

The cluster of allegations is that the Onavo acquisition put FB-designed and built rootkits underneath TLS on a significant fraction of all smartphones in the United States and that FB/IG (now Meta) used clear text access to ostensibly secure HTTPS sessions to extract arbitrary data from both competitors and partner companies to play poker with X-Ray glasses on as concerned all competition in an ostensibly free and f…

If this is true that sounds really, really, bad.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#67
post #32

Earlier quoted context omitted.

[flagged]

Care to back that up with any citations, or should everyone just take it on faith that what a throwaway says isn’t made up?

Facebook is on both ends of the e2e.

e2e encryption means no from client to client can read your messages.

Your client certainly can - and Facebook is the client. It would have no problem sending back signals on your messages (or the full message) to Facebook servers.

Doesn't mean it's happening. But it's interesting that e2e encryption alone makes you positive it isn't.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#68

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

> Disclaimer: I work at Facebook but not on messaging or anything related to this article.

So, it could work exactly as it sounds and you'd have no idea?

---

Although I'm not sure the complaint [1] (linked from articled) actually says that messages were given.

[1]: https://cdn.arstechnica.net/wp-content/uploads/2024/03/compl...

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#69
post #32

Earlier quoted context omitted.

[flagged]

Care to back that up with any citations, or should everyone just take it on faith that what a throwaway says isn’t made up?

Download a naughty gif/video from reddit and send it to someone on messenger. It will report you and say you are sending a naughty video and that multiple attempts will ban you. Fine for unencrypted chat.

Send same on e2e chat. The video will say "not sent".

Why is Facebook processing anything before being encrypted? The understanding is e2ee means content gets encrypted on device, sent to server in encrypted state and decrypted at other side. There is NO way Facebook should be able to analyze the contents of message, photo, video. .if they are doing this for csam/nudity, what stops them from using same tech for ad targeting and more seriously, for letting governments to spy on people?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#70

Earlier quoted context omitted.

That's not what the feature was. The feature was that you could use Messenger inside Netflix and Spotify to chat with your friends without leaving those apps. If you opted into using Messenger to chat with your friends inside Spotify, I'm confused why you think Spotify couldn't access your messages, given that Messenger was unencrypted at the time and you were running it inside Spotify. How else would the feature wor…

The web was rampant with these patterns in the early 2010s when OAuth didn't exist, and HTTPS the exception rather than the rule. The most egregious example was probably LinkedIn's GMail "integration," ostensibly used to invite your GMail contacts to LinkedIn. Back then, that sort of thing felt innocuous. But the implementation was even worse. Due to lack of OAuth and MFA, you literally entered your GMail password in…

Yeah definitely. There are still some pretty bad patterns out there; for example, if you try to add an event from Facebook Events to your Google Calendar, instead of generating a normal ICS file or event link, they... ask for read/write access to your entire Google Calendar account. No thanks!

Similar to apps that ask for access to your entire Contacts list to "find your existing friends"... You can bet they're uploading that entire thing to their servers and trying to growth hack with it.

Post reply on HN