Live data from Hacker News

Facebook Android app sends phone number to Facebook servers without consent

symantec.com

61–70 of 91 posts

Re: Facebook Android app sends phone number to Facebook servers without consent

#63
post #33

Android's take-it-or-leaveit install-time permission model sucks. I just counted 32 permissions for the Facebook app. When the user goes to install the app they are supposed to review that long list and decide if they are going to take it or leave it. The reality is most users have no idea what they're being asked and just hit Accept. Which means for most practical purposes there is no permission security. Much bette…

I agree. I wish Android had denial or "spoofing" of permissions in stock form. I do appreciate that Android points out even smaller details, however: "access to your contacts" is one that works without prompting on iOS, if I remember correctly. It'd be nice if users could choose both the level of detail and choose piecemeal.

Obviously, we'll never see it in stock/vanilla, but there is something to be said for the fact that you do spoofing at all via pdroid, which takes less than half an hour to set up if you're of the hacker persuasion. I dreamt of such a security setup for two decades before android ever came to be.

Re: Facebook Android app sends phone number to Facebook servers without consent

#64
post #52
post #33

Android's take-it-or-leaveit install-time permission model sucks. I just counted 32 permissions for the Facebook app. When the user goes to install the app they are supposed to review that long list and decide if they are going to take it or leave it. The reality is most users have no idea what they're being asked and just hit Accept. Which means for most practical purposes there is no permission security. Much bette…

> When the user goes to install the app they are supposed to review that long list No, the user is supposed to see the first 2, ignore the hidden "show more" button, and then just hit Accept. This is one of Android's more obnoxious user-security flaws.

90% of users (including me) don't bother reading the even first two.

Re: Facebook Android app sends phone number to Facebook servers without consent

#65
post #58

As much as I wanted to install their app, I never did because I didn't trust them. I clicked to the requested permissions screen a few times. But, I just couldn't get myself to go any further. Now, I feel vindicated for my paranoia. I'm sure they're doing many more nefarious things.

Meh. It is just your phone number. What is the big deal?

Re: Facebook Android app sends phone number to Facebook servers without consent

#67
post #19

Earlier quoted context omitted.

I supposed I could have googled it to find out, but I've certainly never had a carrier tell me in advance what apps would be on my phone. Perhaps it's buried in the fine print that I agreed to without reading, but honestly I doubt it.

Every Smartphone comes with certain pre-installed apps that you might not necessarily desire. But facebook certainly never was one of them. At least none of the Samsung series comes with it.

Nope. The Samsung SGH-T959V (T-Mobile Galaxy G 4G) came with it preinstalled. I had to root the device to get rid of it (among other things).

Re: Facebook Android app sends phone number to Facebook servers without consent

#68
Between a UI that looks exactly like the mobile page loaded in Chrome/Stock Browser, draining battery and abusing location/privacy why would anyone want to use Facebook on their Android phone? Delete it, disable it or just don't sign in as applicable.

Re: Facebook Android app sends phone number to Facebook servers without consent

#70
post #33

Android's take-it-or-leaveit install-time permission model sucks. I just counted 32 permissions for the Facebook app. When the user goes to install the app they are supposed to review that long list and decide if they are going to take it or leave it. The reality is most users have no idea what they're being asked and just hit Accept. Which means for most practical purposes there is no permission security. Much bette…

It would be great if Android collected all the permissions that are commonly disabled for an app and then presented the permissions on an app-by-app basis sorted from most disabled to least disabled.

This way users of any app in the Android ecosystem can rely on the wisdom of the crowds to quickly see which permissions people who know better commonly disable.

Should every user look over the entire list? Yes, in an ideal world. But since that isn't realistic, the best we can do is present them with those they will mostly likely want to disable right at the top.

Post reply on HN