Live data from Hacker News

Facebook Android app sends phone number to Facebook servers without consent

symantec.com

71–80 of 91 posts

Re: Facebook Android app sends phone number to Facebook servers without consent

#72
post #65
post #58

As much as I wanted to install their app, I never did because I didn't trust them. I clicked to the requested permissions screen a few times. But, I just couldn't get myself to go any further. Now, I feel vindicated for my paranoia. I'm sure they're doing many more nefarious things.

Meh. It is just your phone number. What is the big deal?

Meh. It is just your ______. What is the big deal?

^This is a slippery slope!

Re: Facebook Android app sends phone number to Facebook servers without consent

#73

Earlier quoted context omitted.

There is an argument, because normal people don't know what the hell a READ_PHONE_STATE is.

The description is PHONE CALLS READ PHONE STATUS AND IDENTITY Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call.

I am sure that most users will not even read/understand that description.

If the user puts some effort into parsing it, they will understand it and what it means for their privacy. But most people will not put that much effort into installing an app.

Despite being perfectly clear to you and I, it is wrong to ask for these permissions at install time.

Imagine if every time you visited a web site you were given a list of 5 - 10 permissions requested by the website before you could visit.

Re: Facebook Android app sends phone number to Facebook servers without consent

#74
post #52

Earlier quoted context omitted.

> When the user goes to install the app they are supposed to review that long list No, the user is supposed to see the first 2, ignore the hidden "show more" button, and then just hit Accept. This is one of Android's more obnoxious user-security flaws.

90% of users (including me) don't bother reading the even first two.

It's wrong to expect user to read them. No wonder Android is a malware haven

Re: Facebook Android app sends phone number to Facebook servers without consent

#75
post #42

This is pretty standard in Android apps for analytics tracking to use the phone number, IMEI or other values. A while back, a few production phones shipped where Settings.Secure.ANDROID_ID returned invalid values (null, the same value for all devices of that model, etc). This is the reason that most apps you come across ask for the READ_PHONE_STATE permission.

Thanks for mentioning this. It's always annoying when stuff like this is taken out of context and reinterpreted by people who don't have intimate knowledge about the topic, resulting in the kind of useless knee-jerk reactions seen in this comment thread. If you told the average web-using person that whenever they visit google.com Google gets to know which internet provider you use and from which country, possibly eve…

Well what it also means is that its not just Facebook who does it. Many other apps you have installed are probably doing this as well without you knowing about it.

Re: Facebook Android app sends phone number to Facebook servers without consent

#76
post #58

As much as I wanted to install their app, I never did because I didn't trust them. I clicked to the requested permissions screen a few times. But, I just couldn't get myself to go any further. Now, I feel vindicated for my paranoia. I'm sure they're doing many more nefarious things.

It's more of Android's fault letting this happen than Facebook's.

Re: Facebook Android app sends phone number to Facebook servers without consent

#77
post #69

I assume this is the same app that hacks Dalvik to even work? ( https://www.facebook.com/notes/facebook-engineering/under-th... )

It's a shame they had to do that. I find that Android is painful to develop for.

We had issues where certain Android versions were unable to install our app. The workaround involved renaming some of our data files to use a .jpg extension so that they would be treated as image assets and not loaded entirely into memory on install, causing the device to run out of RAM. (I forget the exact details, as my coworker discovered the issue and workaround at the time.)

Re: Facebook Android app sends phone number to Facebook servers without consent

#78
post #2

"They "trust me". Dumb fucks." -Zuck

In case anyone doubts the reality of this quote: http://gawker.com/5636765/facebook-ceo-admits-to-calling-use...

It's wildly taken out of context.

He said it when he was 19 (!!) in regards to a web form he made where people submitted their emails, phone numbers, and social security numbers with nothing else besides that form. The users were indeed stupid as shit in that situation.

I'd also like to remind you that he's 29 now and running one of the most successful companies in the world. If you think he hasn't learned something in the span of 10 years, you're delusional and your comments as well as that article is sensationalist.

Re: Facebook Android app sends phone number to Facebook servers without consent

#80
post #50
post #28

Earlier quoted context omitted.

Indeed. Facebook are a rotten company like this. They'll throw something out, then yank it if they get caught. It makes you wonder what we haven't noticed yet.

yep, the whole "move fast and break things" mantra doesnt really suit privacy concerns.

"Move fast and don't get caught."
Post reply on HN