Live data from Hacker News

Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

arstechnica.com

81–90 of 226 posts

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#81
post #73

The encryption concerns here are a bit confusing IMO. Facebook owns the UI that show you the text of the messages. There doesn't have to be a backdoor into E2E encryption at all per say, a simple UI property check would give full access to message contents directly in the frontend code. Throw that into a private API and Bob's your uncle, decrypted messages that were transmitted with 100% secure E2E encryption.

Is that different for any other encrypted instant messenger, though?

No not at all, its a universal risk since you have to trust the UI.

I should have been more clear there. Its interesting to me that I often see concerns over whether Facebook has encryption backdoors when the UI can do all the work.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#82

Earlier quoted context omitted.

it’s disingenuous to think that users read and fully understand the various permission scopes of a service. “private” has an unambiguous meaning—playing the “well, technically” card falls pretty flat imo.

When you give your mail client credentials to read your email , would you not expect your client to be able to read your mail? On Android, when you give a third party client permission to receive SMS, you don’t expect it to have access to your SMS?

So when I give thunderbird my email details, someone at thunderbird gets access to all my emails ?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#83
post #38

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

And if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.

What incentive does FB have to limit that access? Feels like MBAs would just see that as a cost/burden? We know FB does give a fuck about privacy, so that’s never gonna be a reason.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#84

Earlier quoted context omitted.

The cluster of allegations is that the Onavo acquisition put FB-designed and built rootkits underneath TLS on a significant fraction of all smartphones in the United States and that FB/IG (now Meta) used clear text access to ostensibly secure HTTPS sessions to extract arbitrary data from both competitors and partner companies to play poker with X-Ray glasses on as concerned all competition in an ostensibly free and f…

> If substantiated, such accusations would be among the most damning in the history of technology. If substantiated? Just search Onavo on HN search - I thought this was widely known for years.

As a former employee until 2018, I heard the words “Project Ghostbusters” two days ago. I was peripherally aware of something called Onavo but I had no notion that anyone was talking about “kits”, we all thought it was some kind of metrics thing that was sort of iffy sounding but lots of iffy ideas got proposed by some PM looking to make a name and shot down by the grownups, what is alleged would have provoked a riot at the weekly all hands.

If any of this is true they didn’t tell people like me about it, and at one point there were three people on the org chart between myself and the CEO.

I’m very skeptical of the allegations, but I’d be lying if I said I found them to be flat impossible. I tread very lightly on this sort of thing and I didn’t even acknowledge I’d ever heard the word Onavo until I read it on TechCrunch.

I certainly hope they’re false: FAIR seems to be the last real hope for an Open future on AI short of a complete housecleaning of the whole Valley.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#85

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

If this wasn't Facebook it wouldn't even be news.

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#86

The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/…

Thanks for the context, it's important. But from the link you posted:

  > In order for you to write a message to a Facebook friend from within Spotify, for instance, we needed to give Spotify “write access.” For you to be able to read messages back, we needed Spotify to have “read access.” “Delete access” meant that if you deleted a message from within Spotify, it would also delete from Facebook. No third party was reading your private messages, or writing messages to your friends without your permission.
So here Facebook acknowledges that an app that sends messages needs write permission, not read. I would assume that sending a recommendation is a write only thing, especially with something private as direct messages. And it is pretty well understand pattern. When you share something through iMessages, Signal or WhatsApp from the a different app, the app does not get an access to you chat history.

The allegation that Arstechnica are pretty sever:

  > By 2013, Netflix had begun entering into a series of “Facebook Extended API” agreements, including a so-called “Inbox API” agreement that allowed Netflix programmatic access to Facebook’s users' private message inboxes
Strange naming "Inbox" for sharing API.

  > in exchange for which Netflix would “provide to FB a written report every two weeks that shows daily counts of recommendation sends and recipient clicks by interface, initiation surface, and/or implementation variant (e.g., Facebook vs. non-Facebook recommendation recipients).
This is something that Netflix could do even without special access to the messages, since links originate from them. But so could Facebook, since they see the traffic in messages and can identify referral links. Looks like Titan API, whatever it is, gave even more access?

NYTimes article from 2018 [1] has more details, but it is still unclear if user consent was explicitly obtained for Netflix to read messages. But an interesting quote from Steve Satterfield, Facebook’s director of privacy and public policy:

  > With most of the partnerships, Mr. Satterfield said, the F.T.C. agreement did not require the social network to secure users’ consent before sharing data because Facebook considered the partners extensions of itself — service providers that allowed users to interact with their Facebook friends.
A rather conspicuous statement by someone who have properly collected consent from users.

[1] https://archive.is/DH17k

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#88
post #32

Earlier quoted context omitted.

Care to back that up with any citations, or should everyone just take it on faith that what a throwaway says isn’t made up?

It's both true and false. They don't do advertising with msg, and it's e2e encrypted. But they can use the metadata

It is end to end encrypted but facebook controls both ends so... ?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#89
post #6

I'm not clear whether I understood what the article is claiming. It's clear they claim that Meta shared customer's direct messages with a business partner without notifying the individuals who sent and received the messages. It also SOUNDED to me like the article was claiming they did so AFTER Meta introduced "end-to-end encryption" (which would ALSO mean that they were lying about offering end-to-end encryption). Am…

The cluster of allegations is that the Onavo acquisition put FB-designed and built rootkits underneath TLS on a significant fraction of all smartphones in the United States and that FB/IG (now Meta) used clear text access to ostensibly secure HTTPS sessions to extract arbitrary data from both competitors and partner companies to play poker with X-Ray glasses on as concerned all competition in an ostensibly free and f…

> such accusations would be among the most damning in the history of technology.

You're putting this up there with IBM in the holocaust?

Re: Facebook let Netflix see user DMs, quit streaming to keep Netflix happy

#90

Earlier quoted context omitted.

Is metadata useful for ad targeting? If the claim is that they use the content of messages that's be one thing, but what kind of ad value is really pulled out of timestamps and phone numbers of who you messaged? That said, collection of metadata can still be a problem, I just don't see the ad value.

Yes it is useful. Knowing who you contacted and when tells advertisers demographic information and probably more that I can't think of

What demographics can be gleamed from who and I contact and when?

This is one of those times where I feel like I'm annoyingly peppering someone with questions, hopefully it doesn't come across that away. I really am curious what ad-related use case I may have missed with regards to metadata.

Post reply on HN