14 ms·
Facebook was warned about app permissions in 2011
- Roritharr 9y agoI remember building very innocent Facebook Apps for Marketing purposes back in 2011-14 and being very annoyed at the privacy changes as they made our "cute" usecases basically impossible. At the time I always imagined Facebook would monitor their API usage to prevent aggressive mining as this would surely be against their own interests, but as it seems they didn't care. If only someone would have used this hole to seed something like Diaspora to help break the critical mass problem for those kinds of projects.
- makomk 9y agoFunnily enough, I vaguely remember there being articles on HN claiming that Facebook's lockdown of access to their social graph was an anti-competitive practice that needed to be stopped when it originally happened, though I can't seem to find them again so might be misremembering.
- dannyw 9y agoThere are comments in this thread suggesting that FB made the OpenGraph changes to preserve their competitive advantage. If they lock down their APIs even more, I wouldn’t be surprised to see more accusations of these.
- dwighttk 9y agohow long you think that hole would've stayed open if that were happening?
- fareesh 9y agoI remember doing security work for a few companies at the time and discovered some standard SQL injection vectors in databases with upwards of 50k access tokens. It's unlikely, but entirely possible that someone could have stolen access tokens from apps, and subsequently stole user data from Facebook too. At the time, signing into apps with Facebook meant you were not only giving the app access to your account, but also anyone clever enough to steal the token. In some cases, "clever" even meant anyone who had a basic understanding of sqlmap or other pentesting tools. In theory shady "analytics" firms could have hired a low level security researcher and had him use shodan and sqlmap all day to expand their databases. Today it's pretty rare for apps to ask for intrusive permissions, and people tend to be a bit more wary of apps that do. Facebook has also made an effort to alert users when the permissions requested are more intrusive than the usual email address and profile picture - often requiring explicit agreement to these permissions. Nonetheless, if Facebook's "audit" turns up apps that did a lot of suspicious queries, what stops them from saying "oh we were hacked someone took our tokens from our DB, we are conducting a full investigation". Sure it's still bad press, but it's probably better PR to look incompetent than creepy.
- philipwhiuk 9y ago> Facebook has also made an effort to alert users when the permissions requested are more intrusive than the usual email address and profile picture - often requiring explicit agreement to these permissions. Facebook were required to do this by the FTC in 2011.
- downandout 9y ago"[Facebook] systems were so laxly designed as to actively encourage vast amounts of data to be sucked out, via API, without the check and balance of those third parties having to gain individual level consent." That is a gross oversimplification of the issue. There were controls in place to stop excessive data collection. In fact, the only app in this situation that was allowed to "suck out" "vast amounts of data" was the Obama For America app. According to Carol Davidsen, Obama's Former Campaign Director "We ingested the entire U.S. social graph" [1], despite the fact that less than 1 million people actively authorized the app to access their data. Approximately 99.5% of the hundreds of millions of people whose data Obama took, with Facebook's blessings (actively allowing it to bypass its data collection limits for apps), never knew about or authorized Obama to have or use their data. So only one app was "actively encouraged" to suck out vast amounts of data in the history of the existence of the API. All the rest of them were subject to relatively strict controls, requiring months or years to collect even a small fraction of the data that the Obama app was allowed to collect. The API was not a data free-for-all, except in one unique case with the explicit authorization of Facebook. [1] https://www.washingtonpost.com/business/economy/facebooks-rules-for-accessing-user-data-lured-more-than-just-cambridge-analytica/2018/03/19/31f6979c-658e-43d6-a71f-afdd8bf1308b_story.html https://www.washingtonpost.com/business/economy/facebooks-ru...
- ec109685 9y agoWhere do you get that Obama’s campaign had special access that other apps didn’t have?
- downandout 9y ago"[Facebook] came to office in the days following election recruiting & were very candid that they allowed us to do things they wouldn’t have allowed someone else to do because they were on our side." - Carol Davidsen, Former Obama Campign Director [1] [1] https://twitter.com/cld276/status/975568208886484997 https://twitter.com/cld276/status/975568208886484997
- portofcall 9y ago
- kareemm 9y agoI built apps on FB back in 2011-2012 and was gobsmacked at how much data we got about the friends of our users. I also knew of several shady people building apps. Because I saw how much data we got without consent, I realized other shady people could get that data about me via my friends. Which is why I severely curtailed my FB use around that time.
- whitepoplar 9y agoAny chance you can expand on this? What data, in particular, did you obtain that would make people feel uneasy?
- liveoneggs 9y agoI also worked on a quasi-popular facebook app in a similar time period and you got a lot of data but the specifics would change from month to month so it was sometimes more and sometimes less. The worst, for me, was posting on behalf of other people and getting replies to your app like "I'm so glad to hear from my favorite grandson after so long!".
- lawnchair_larry 9y agoWhy would you post on behalf of other people?
- goldenkey 9y agoBecause it was allowed and it is an easy way to spread an app virally? "John Doe via ViralApp: [This app is great! Get your own Virus today by clicking here!]"?
- mercer 9y agoIronically, considering the current kerfuffle, I remember my biggest frustration being The Guardian, as they'd spam my feed with 'friend X read article Y on The Guardian'.
- 9y ago
- philipwhiuk 9y agoThey weren't just warned by Ireland. They had to agree to oversight following an FTC decision in 2011.
- wellboy 9y agoI have to say, I have never seen so much bad press about facebook in such a short time frame. Seems like this is picking up a lot of steam.
- deleted 9y ago[deleted]
- methodover 9y agoIt's astounding. And much of the reporting is really, really terrible. Like just not describing things with any degree of accuracy at all.
- criddell 9y agoI don't understand why Facebook ever shared friend data. It's one thing for a user to opt in to sharing things like their likes. But as soon as you share friend lists, you are sharing stuff about other people.
- methodover 9y agoThere are non-evil uses of that data, of course. A custom-built news feed for example. That would actually be pretty nice...
- rootlocus 9y agoThere are non-evil uses for anything. That doesn't mean we don't need security.
- methodover 9y agoNever said that there wasn't. I was responding to someone who couldn't fathom a legitimate use of the friend data.
- criddell 9y agoThat's okay when it comes from Facebook. Everybody on Facebook signed up with Facebook. It's sharing with third parties that I don't think is cool.
- feelin_googley 9y agoThe article does not mention the issue FTC took with "Verified Apps" in 2011.1 This was before FBs IPO. WSJ had reported several times about apps leaking FB IDs and about companies such as RapLeaf linking them to users.2 They were apparently combining Facebook data with some data from public sources to identify Facebook users, in 2011. Zuckerberg in his statements so far has used the term "derivative" data a couple of times, as if the word derivative is significant. Does Facebook believe this somehow takes it outside the scope of what they are responsible for? 1. https://www.wsj.com/amp/articles/SB10001424052702304772804575558484075236968?tesla=y https://www.wsj.com/amp/articles/SB1000142405270230477280457... 2. https://www.wsj.com/amp/articles/SB10001424052702304410504575560243259416072?tesla=y https://www.wsj.com/amp/articles/SB1000142405270230441050457...
- yorby 9y agoDid Facebook try to block this company from interacting with affected users after this happened? or did they just let them target anyone with any ad?
- tcm19 9y agoThe real problem with app permissions is that developers are allowed to even REQUEST permissions that are not necessary for the functioning of their app. This is not just an issue with apps on facebook. It's also an issue with Android apps (and, I presume, iOS apps). The fact is that the majority of users can not be expected to look out for themselves. People hit install and then hit accept to whatever permissions request pops up. It is like agreeing to the TOS that no one reads. I tried to download an alarm clock app on Android. It wanted access to virtually everything. Why do you need so much information for a fucking alarm clock? My analog alarm clock doesn't know my name but it still wakes me up each morning. Platforms (Facebook, Mobile OS's, Desktop OS's) need to reject apps that request unnecessary permissions.
- shady-lady 9y agoExactly this. Part of the reason is pre-emptive cost cutting by these companies to remove human review from these apps. Google also played a massive part in this with their strategy for growing the Android app store. (as did Facebook) Favouring quantity over quality puts users at risk.
- wruza 9y agoiOS asks for a permission only when an application actually tries to use protected data. It is very clear to user and was like that since forever. You simply tap “deny” at runtime and never care that it will access something you don’t want. Android has similar behavior, but only for new-style apps (starting with 6.x, as someone corrected me in last year’s thread). Trillions of old-style apps still enjoy TOS-like god permissions, afaik.
- thinkcomp 9y agoI'm just going to keep posting this. I told Mark about this exact problem in 2005. https://twitter.com/AaronGreenspan/status/975957889767505920 https://twitter.com/AaronGreenspan/status/975957889767505920 And I warned him about FTC liability if he ignored it. https://twitter.com/AaronGreenspan/status/976331044084264960 https://twitter.com/AaronGreenspan/status/976331044084264960 After that, we stopped talking.
- emmelaich 9y agoWhere are those screenshots from? Why is Zuckerberg's nick 02? Who is 01?
- bmarquez 9y agoAOL Instant Messenger (which was super popular at the time) had this format. You could choose your own screen name, maybe he wanted 02 instead of 01 for whatever reason.
- truj 9y agoPresumably because he registered his nick in 2002 (which was a popular "naming scheme" at the time). thinkcomp should tweet someone like @pinboard, @nitashatiku, @karaswisher etc.
- thinkcomp 9y agoI graduated high school in 2001. Mark graduated high school in 2002.
- hunterjrj 9y agoPresumably Zuckerberg did not consent to this conversation being captured/recorded and shared. Do you feel even the slightest bit of embarrassment at the irony and hypocrisy of using this content, that you acquired without consent, to further your argument against the trustworthiness of this guy?
- jsemrau 9y agoIn the last couple of years the company I work for wanted to build social scoring methodologies. In 2013, Facebook revised their privacy rules and we were not allowed to collect the data we needed. However, there are paid partner programs with different rules. Same as LinkedIn, afaik.
- dawhizkid 9y agoAny app developer will tell you that Android is much more invasive...you can suck so much location/device data with no (or very standard) permissions. Apple was bad too until a few years ago.
- coding123 9y ago"We also asked why Facebook users should trust Zuckerberg’s claim, also made in the CNN interview, that it’s now ‘open to being regulated’ — when its historical playbook is packed with examples of the polar opposite behavior, " It's like when Trump said he could shoot someone on the street and still win... It's when your supporters start to back off that you start giving in to demands, not before.
- beagle3 9y agoThere is literally nothing new about facebooks invasive practices in all this news (except that CA took their lunch money). I have a feeling all this coverage is driven by quite a bit of schadenfraude from the traditional media. This coverage is well deserved, but I am sad that people are only taking notice now.
- roadbeats 9y agoCoverage is well deserved but only focused on one single case: Trump's campaign. Syrian Civil War began in social media first. The journalists criticising Facebook nowadays used to run campaign for how social media helps protesters organize. What if Arab spring wasn't an organic movement? Isn't it weird that some "experts" suddenly changed their mind about social media after Trump's election? Also, why noone even talks about Google? It's much bigger weapon for manipulating facts if you consider millions of people trusting its results for their questions. People ask Google if Brexit is good, people ask Google if Trump is doing good. And we don't even know how Google picks the best results. What if there are some SEO tricks shared with only a few companies?
- Feniks 9y agoHere in the EU Facebook, Amazon and Google have been distrusted for years. I have a sneaking suspicion that the tech sector WANTS to make this political.
- Groxx 9y agoNews sites largely care about what brings in the money - when a wave starts, they all pile on, and the ad revenue goes up for a while. I don't entirely blame them - it's driven by extremely perverse incentives, and alternatives haven't worked out (yet). But it's undeniably terrible for everyone, and IMO contributes to undermining their usefulness.
- Feniks 9y agoHaven't had Facebook on my phone since I dumped Samsung for OnePlus. I remember back then FB was pre installed on a lot of devices. Is that still a thing?
- methodover 9y agoPeople didn't seem to care back then, though. If you asked a random FB user about app permissions in 2011, I suspect that person wouldn't think it was a big deal. Social mores are changing, becoming better developed. The Internet, social networking, OAuth -- these are not exactly well-trodden subjects in humanity's past. It's not like we have decades or centuries of precedence to look back on. The important thing is what FB does now.
- Angostura 9y agoI think that’s an important point. Back then Facebook was more of a toy, a fun thing. “I don’t use it for anything serious, so it doesn’t matter”
- dboreham 9y agoWell, I remember working at a startup in 2006/7 on Facebook apps and having this exact conversation with my boss (specifically about the ability to de-anonymize users by joining across multiple different sites).
- mtgx 9y agoAgain with this "not caring" comment. In at least 90% of the cases people don't understand what the privacy policies or permissions mean or what they could be used for. People trend to trust others, in general. And many developers abuse that trust, especially when they're allowed to do it by design with the permissions they're given by the platforms. When an app asks me for "Access to media" I only give that access expecting that maybe it needs that access for when I will open a media file with that app or to download or create a media file inside the media folder. I do not expect the app to analyze my media for the type of content I have in there, and I do not expect the app to upload those files to its servers, or any other uses that developers may come up with for that particular permission. Yet, the permissions are set-up in such a way that they allow much more than people expect them to allow. Saying "well you shouldn't have given them access to media" or "you shouldn't be using the Internet or a smartphone" is really a nonsense type of comment to make. If it's a video player, of course I have to give it access to the media. That's why I need a video player. But I didn't intend to give it access to upload my media to its servers. That's what the platform developer allowed it to do, without me knowing or understanding that it can do that, not me "not caring." This is just an example, but it can apply to phone permissions, contact permissions, and other types of permissions just as well.
- barell 9y agoI was also working on Facebook apps from 2011 to 2013 using Facebook APIs. At this time whenever we have released any app, useres could login to it using OAuth which means they were presented with a list of privileges our app needs from them (eg. Friends list, photos, posts etc). Once user has authorised the app we could fetch all of this data. This was how Facebook worked at this time, you can’t say it is a leak of data because we explicitly ask user for permission. You basically say, I want to use your app, here is my profile if you need it. I don’t really understand why people are so mad about their data privacy. If you publish your photos, list of friends, what you like, where you live and work, who are you merry to, then it shouldn’t be a surprise this data can be viewed by not only your neighbour but also a dodgy automated scripts. Once the data is fetched then you can only imagine what people can do with it. It’s not really Facebook fault. It’s people who thinks when they publish things on the Internet, it’s safe and can be only viewed by other people. Maybe Facebook only role should be to make people more aware of all of this, but is it in their interest? I don’t think so.
- mercer 9y ago> I don’t really understand why people are so mad about their data privacy. If you publish your photos, list of friends, what you like, where you live and work, who are you merry to, then it shouldn’t be a surprise this data can be viewed by not only your neighbour but also a dodgy automated scripts. I don't understand why I keep reading comments like this. One of the main issues is that your data could be leaked to an app developer even if just ONE of your friends installed said app. So even if you diligently made sure only your friends, or even particular friends, could see your stuff, it'd still be accessible to the app developer. That is absolutely not something even a privacy conscious person would've expected, and absolutely enough to get mad about.
- barell 9y agoAs I said I was developing Facebook apps back in 2011 and at this time as far as I remember, your friends list was publicly available to any logged in user. API was only making this easier for apps to fetch the data about you. There was an explicit permission about accessing friends list and their data through the API so yes, any of your friend at that time could just give away your profile to a third party. I stopped using Facebook back in 2011 (only used it to manage and test my apps) as I was really concerned how easy is to collect personal data. But I guess for me, as a developer, it is easy to imagine how things works and when to get suspicious online. On the other hand it makes me really happy, Facebook privacy issues like this one with CA, got much attention and finally more people, hopefully, will understand how things works.
- mgkimsal 9y ago2011? I can't recall that far back with FB app perms, but I do remember working on a few projects in ... 2013 IIRC? And one of the pieces of feedback I got the most from people I'd asked to test was "why do you need all these permissions?" They weren't all an overly tech-geek crowd, but many seemed to question it. "I can't not ask for these permissions - even just for a basic login - facebook forces this information to be available to my systems. I'm not using it for anything, and I don't take much of the information I'm given, but to connect via Facebook, they require me to have access to this information". That became my standard-ish response, and it wasn't that surprising why many people got miffed, especially if I was just doing basic "login with facebook" stuff. IIRC, FB has changed the minimum permissions a couple of times in the last several years (or, at least it's seemed like it - maybe names or presentation of the info has changed?)
- elorant 9y agoThe thing that never ceases to amaze me is just how easy it is to scrape Facebook profiles. Every other social network has strict usage quota but with FB you can scrape tens of thousands of profiles with a single ip. With a thousand proxies you could scrape all profile pages of any given country. I won't be surprised if there are companies out there doing exactly that as we speak. And FB allows it, probably because it enhances the ecosystem by providing useful insights to corporations.
- drawkbox 9y agoFacebook always required the initial user to give permissions including access to friends. But for many years once that was granted all public/friend shared friend data was available that others shared with their friends by design. They closed that off with OpenGraph v2 where they even changed friend ids/invites to be unique to the app so that data was not able to be correlated easily across apps. They did it for privacy but mainly because other groups were pulling in the social graph and maybe it became a competitive threat. People that weren't developers or in marketing probably had the expectation Facebook was a private walled garden where they were only sharing with their friends but once one friend gave those permissions, many bad apps started to see how they could pull down the entire social graph. This has since changed with OpenGraph v2 in 2013-14 but it was exploited by nefarious groups for a time. I think most of the permissions model was fine before the bad apps and shady groups that are using your data for targeting purposes beyond games, apps and ads. Once it started to be used for aims beyond harmless fun like games that is where people got angry especially in targeted politics.
- sAbakumoff 9y agoThis story seems to be very carefully planned attack to Mr. Zuckerberg to oust him from Facebook CEO. Recently they exposed some IM history from the past decade where he calls user "dumb" http://www.businessinsider.com/exclusive-mark-zuckerbergs-secret-ims-from-college-2012-5 http://www.businessinsider.com/exclusive-mark-zuckerbergs-se... everything that they know about me. Z to be revealed.
- AHMagic 9y agoDelete and forget it existed. Ignore and move on. Give up the benefits and pay the cost. Do you really want to live your days feeling dependent on this sort of "service"? Do you really want to say, "but I need Facebook!". In today's age, you need a phone number and e-mail. It's ok - they are decentralized. Don't let a centralized platform of Facebook's evil nature become necessary for you to live your life.
- dschuetz 9y agoI think that the whole point about this Cambridge Analytica and Facebook scandal is not that Facebook collects all sorts of data, but that Facebook shares that data to third party services via "Login With Facebook" without any previous consent of users. The privacy settings of your Facebook account lose their purpose when Facebook creates an advertising profile (which may or may not be very accurate) which all said third party services may use to fuel their own advertising strategies. The contents of said ad profiles include your interests which also may reflect your ethnic background, sexual preferences, political views, et cetera. All of which CA (mis)used for analytics. But, (I checked today) users are able to disconnect ad profile sharing or delete some data. So, there is no scandal here, yet I didn't know until today that such settings even existed. So, it is convenient for Facebook to say that users usually have full control over their data. That Facebook now feels betrayed by CA because such data (generally available to service providers) has been used inappropriately shows either that they were complicit by enabling CA to do so and knew about it all along, or they didn't know what they were doing at all. I'm not sure which is worse. If a third party says "trust me, I'll handle all the data responsibly" doesn't mean anything, because there is no oversight whatsoever. Additional clauses in contracts do not make Facebook a victim of contract breach. The product in itself is flawed, because it handles the data irresponsibly.
- fleitz 9y agoUsers are also highly irresponsible with their data, you didn’t even know the settings available, and others know they are giving up psychological profiling info and do it willingly. No one really cares until the media overhypes what is possible with the data, P&G knows it can’t use FB ads to get users to buy things but somehow Trump was able to get people to vote for him? What about the idea that maybe as the emails disclose it was Hillary who gave the MSM the idea to promote Trump, how about maybe she was so unlikable that she had to rig the primaries to win against a political neophyte because when she ran against the rookie obama she also lost. Maybe it wasn’t CA, FB or Russians that lost the election but her perennial unpopularity. Fundamentally if you want to keep your ‘privacy’ it’s pretty dumb to go posting intimate details of your life on the internet.