26 ms·
Facebook scraped call, text message data for years from Android phones
- sverige 9y agoThis is completely unsurprising. The question is whether they should be allowed to keep that data.
- 55555 9y agoWhy the hell should they be allowed to keep that data?
- jakeogh 9y agoBecause you gave it to them. The alternative goes right to rules that prevent everyone (not just FB) from remembering things, and ultimately more censorship. Is it just me or has a whole generation lost the concept of personal responsibility? I don't use FB because it's been obvious for a long time this was happening, and it's an awful platform, designed to socially engineer their flock of product people. Use products that you control. LineageOS + FDriod is a great start.
- Erlangolem 9y agoBefore you get too far up the ass of “this darned generation, personal responsibility, blabla yadda” you might just want to look at the facts. Eula’s are written to be obtuse and require a legal scholar to sift through, and most people are not lawyers. The tech itself is not something most poeple understand. A huge number of people getting their data mined are kids, who have been raised with this tech, but never taught to use it responsibly. Facebook has billions of dollars and users based on the premise that an army of amoral programmers and corporate goons can separate you from your data. Believe it or not, what’s obvious to you as someone who reads HN, isn’t obvious to most people. Of course, most people wouldn’t struggle to understand that, which gives them a leg up on you. How many people do you think even know what LineageOS is? Ten milllion? A hundred? Less than 7 billlion is all that matters to FB. Not being a programmer or computer buff isn’t lacking personal responsibility. You are not the standard by which all people are judged, in the same way that your obvious shortcomings don’t mean you lack personal responsibility either. You’re just human, and prone to error and misjudgment like the rest of us. You’re part of the flock, just with a bit more insight into tech and a bit less insight into other people and yourself. Get over it. When you go to a doctor, you’re given the standard of informed consent, because it’s understood that you don’t understand medicine. Presumably you appreciate that doctors can’t bullshit you and then berate you for a lack of personal responsibility because you got into tech, not medicine. Certainly your ignorance is no excuse to abuse your trust. Yet somehow you think software is different? If they can examine the code (and this is only going to get more important), then they, or the people they trust to look at it, can make informed decisions. You can’t be this out of touch with reality.
- bnj 9y agoI’m curious about what you’re saying here and I’ll certainly be thinking about it more, but here’s something I was thinking about: maybe a step in the right direction would be to require permissions to offer a user configurable time limit. I think that users should be able to set the permission they grant to expire after a term of their choice—if they want to grant perpetual permission, fine. I think it would be interesting to think about the implications of apps having to come back to get reauthorization. When permission expires, maybe that just means that no more data can be collected; maybe it means the vendor has to destroy those records. Either way, I don’t want large companies to be able to exploit people who click a button they don’t read. Maybe companies should be required by law to charge users some form of consideration just like other contracts so that we can do away with companies dangling their product as a free carrot in exchange for swaths of personal data, and then leaking it.
- jakeogh 9y agoA time limit would be a good idea, but putting that into law is not. This is the point of open source, we don't want to be required to do things, you let the consumers choose. If they can examine the code (and this is only going to get more important), then they, or the people they trust to look at it, can make informed decisions.
- visarga 9y ago> maybe a step in the right direction would be to require permissions to offer a user configurable time limit They can scoop your contacts and SMS messages in 10 seconds after the first permission was granted. Maybe permission should also limit the number of contacts/messages it can access.
- perl4ever 9y agoI don't think there has ever been a human society in which people took "personal responsibility" in the sense you are using the phrase. I don't think it's humanly possible for even the smartest person to keep track of their personal data given the quantity of it, the multiplicity of tracking mechanisms, and the uncertainty about how it all works. Not to mention, even if we all read all the agreements we click through, that doesn't mean they are all accurate, sufficient, legal, or adhered to by the authors. As I wrote in another thread, I have used LinkedIn for a long time, and I have never wanted it to spam my contacts, so I have always had it foremost in my mind to click "No" whenever it asks to import them. Yet at some point, it did it anyway, because it asks me if I want to connect with people who are only email contacts and not on LinkedIn. Now if you had complete logs of everything I did with my phone and computer, you might well be able to prove in court that I inadvertently gave permission at some point - perhaps I didn't read all of the legalese on something, or perhaps my finger slipped and I forgot. I can't imagine I would find anyone at LinkedIn who cared about figuring out what happened, regardless. There is something perverse, in my view, in appealing to "personal responsibility" of individuals dealing with corporations, as it seems to me that the entire concept of a corporation is a way for people to work together as an entity without taking personal responsibility. The reason we have corporations is because it's impractical for people to be held liable for their screwups.
- cctt23 9y agoYour standard of “personal responsibility” includes the ability to audit code. I assume that you’re just irresponsible if a carmaker sells you a dangerous vehicle, because you don’t know how to detect the flaw? Doctors can just talk to you without consideration for your ignorance, because your failure to attend medical school represents your irresponsibility? If you can’t parse all of changing EULA’s in your life, you’re just irresponsible? What’s obvious to you in your very limited field of expertise is not obvious to everyone. You shouldn’t insult everyone who isn’t a programmer by equating that narrow expertise with personal responsibility. I wouldn’t assume that your inability to understand a conversation between two surgeons meant that it was acceptable to harvest your organs.
- jakeogh 9y agoYou are making it sound like I argued against standards, that's not the case. Yes, ability to audit the code is paramount, and I want to go that direction for everything. We are merging with our creations, people have their noses so far in their phones they are starting to head mount and have it overlay their field of view. Without source access, we wont even be able to check if our own experiences are real. Relying on experts to audit things is obvious and correct, but they must be "anyone", not just a select few that get to see the details. Maybe I am not qualified to evaluate something, but that is never a reason to prevent me from looking at the same information the experts have, in fact that's how those experts came to be. The fact that some people don't care is irrelevant. They get tricked, and learn. Consider how many people are re-evaluating what FB even _is_ right now.
- cctt23 9y agoMuch as I appreciate you responding to only the first sentence of my reply, I’m going to have to point out that your FOSS rant is only tangentially related to what I said, mate.
- jakeogh 9y agoHere, I'll address your EULA point, if you follow your own suggestion and respond to the "rant" I made which you walked right by: "The alternative goes right to rules that prevent everyone (not just FB) from remembering things, and ultimately more censorship."
- IAmEveryone 9y agoThis libertarian utopia obviously breaks down any time you're presented with a 200-page Terms of Service. Nobody has the time and/or skills to read and understand the content at the level required for "informed consent". Which is why societies have come up with a far better method: collectively decide (or collectively choose people to decide) on reasonable limits for certain types of transactions. My German law professor used to say that she never read ToS. Because under the country's law, they are either reasonable or unenforceable. Such laws have nothing to with censorship. If you really need your users private messages, you just have to more explicitly present them with the choice, and respect their decision to say no without unreasonably denying them service. The US has far more lenient standards for such one-sided contracts, but the basic principle is obviously the same: If Facebook were to add a paragraph giving them ownership of your house somewhere deep in the ToS, they wouldn't stand a chance in a court of law.
- cctt23 9y agoI’m always amazed by the ability of libertarians to believe that in the jungle, they’d be tigers rather than tiger shit. More often it turns out they just have a grossly inflated opinion of themselves, as in this case. We’re all human, all weak, and we all need to depend on each other a lot, it’s just the way it is.
- tmuir 9y agoI think that people who go out of their way to present what they believe are alpha male characteristics are essentially hanging a neon sign above themselves. That sign is begging for someone with those characteristics to come along and fix the worlds problems in the way that the stereotypical Clint Eastwood or Arnold Schwarzenegger character solved his problems. In other words, an alpha male exerting his will, delivering satisfying one liners, and saving the world. Why else would nearly every single popular conservative media "character" be so uncannily similar? Why did nearly all of those characters triple down on this machismo roughly 18 months ago? Could it be that they got back the results of their latest A/B test? I think this all drives at the most interesting, world changing possibility that could come out of this reckoning with Facebook. What will happen when it becomes conventional wisdom that the true power of collecting all of this data is not the ability to predict what you will do, but the ability to direct what you will do? What will happen when it truly registers with people that this necessarily removes their agency? What will prevent that critical mass from making the trivial jump in logic that advertisers and public relations firms have been progressively improving on these same skills to the same general ends for a century?
- ClassyJacket 9y agoSaying I gave it to them is like saying a guest that robbed me should be able to keep what he stole just because I let him into my house.
- jakeogh 9y agoNa, a stranger gained your trust (nobody like to admit they they were fooled), asked your permission for access to something, and copied it. You found out later, and felt betrayed, but it's your fault. Outlawing your own ability to make that mistake again is a even worse outcome. Why should I need to follow more laws because you got tricked? Nobody wants to talk about the real issue, this _is_ an attack on memory. Letting the gov decide what people can remember (corps are made of people) is an awful result.
- empath75 9y agoIf I’m friends with anybody who gave it to them, they also have my private txt messages with them and phone call metadata. I have to think that violates phone tapping laws in certain states.
- romanovcode 9y agoUse GDPR soon if you are from EU. 60 days left.
- censorship 9y agoBut still... i cant delete my account. It's locked !! Why ?
- mankash666 9y agoGoogle is as much to blame here as Facebook is. It shouldn't have allowed apps with "contacts" permission to scrape sms & call logs. I hope both of them are held accountable
- ziikutv 9y agoI agree but I'd generalize this to Android. It is an open source system after all.
- Sylos 9y agoIt is an open-source system, which is decided over purely by Google. They don't have to have any fear of being forked, so they don't have to take the open-source community's opinion into account at all. The Custom ROMs that exist around it do not play into this. They cannot influence how shitty the ecosystem is, as that's entirely in the hand of Google.
- ziikutv 9y agoNoted. Didn’t know that was the case. Fle some reason, I imagined that it being open source would have meant a lot of outside involvement.
- stefan_ 9y agoIf I run a program, I don't expect it to scrape my home folder just because technically my OS granted it permission to do so. And I don't think that is a distinction the law makes, either. Intent and explicit consent matter.
- gruez 9y agoNot a fair comparison because there's no sandbox for desktop apps.
- perl4ever 9y agoNot everything that's permitted is compulsory. I mean, suppose you frequent a store with a penny tray and you decide, since it's ok to take one penny, why not take all of them? And if you get away with that, why not start cleaning out tip jars? Maybe you will get arrested, but maybe not. I feel like computers are training people that everything you are technically permitted to do is worth trying. I'm not even sure what the rules should be, but rather I feel like losing a common sense of unwritten rules is losing part of what it means (or used to mean) to be human.
- kristianov 9y agoTheir permission requests are outrageous. That's why I refuse to install any apps from Facebook on my phone, and pollute my Facebook account with false personal data. Fake news for fake data:)
- dexterdog 9y agoIf you need to use Facebook on your Android phone you should be using one of the many sandbox wrapper apps that exist.
- iKlsR 9y agoHas anyone seen the permissions being asked for recently, games want access to contacts and to make calls. wtf?
- jsemrau 9y agoIt would be fun if there were a service to create false profiles to pollute the data miners of this world.
- msoad 9y agoWhen you allow an app to access your contacts, they grab all of them and upload them to their servers. It's less severe in iOS because they can't access SMS and call logs.
- helloindia 9y agoI removed my phone number from Facebook profile months ago. Now and then, Facebook still asks me if "XXXXXX" is my number? Once I unintentionally linked my Facebook account with my insta account. And then I started getting follow suggestions from people in my Facebook friend list. I tried many thing to de-link the accounts. Ultimately, I created a fake Facebook account and linked it to my insta. Once you give something to Facebook; it's never truly erased.
- joering2 9y agoGood story. And I bet you there are lawyers in Europe sharpening their teeth right now waiting for GDPR to kick in to send Facebook discovery letters just a minute after April 1st pass. Need popcorn and comfortable chair, as the stock is down 10%, and we've just started!! Edit: May 25, of course.
- hawaiianbrah 9y agoDoesn’t it go into effect May 25?
- jakeogh 9y agoI'm more than happy to see FB go down the tubes, but legislating away memory is foolish. It's part of the war on general purpose computing. The way things are framed to make them seem good is very interesting. What if I proposed we make keeping records of past information and actors encountered illegal if they don't want you to remember, while at the same time make it trivial for the same people to waste your time by demanding free consulting?
- adventured 9y agoI understand the blow-back against their privacy abuses, it's well deserved (as it was in the past). However, this kind of response is just funny. The stock is back to where it was in July. Up 100% in less than three years. $464 billion market cap. Things are really dire. They'll only earn $20 billion this year, growth will only be 30%+. They only have ~$43 billion in cash right now with zero debt. That's barely enough to keep the lights on. They should shut down the business right now before they run out of money. The speeding tickets they might one day get from the EU, could cost them hundreds of millions of dollars. But just imagine, what if it's $3 billion. I mean, it's not like Facebook can reluctantly change several of its policies while maintaining its massive 2+ billion userbase and keep right on printing money at their 50% operating income margins. Yeah, but just imagine if their operating income margins decline to only 40% because it crimps their business model by reducing the value of their ad targeting. And what if it cuts their growth rate in half? Under that scenario they might only earn $30 billion in net income in 2021. It's a rough road ahead. The other fun part? They'll still net add global users in 2018. None of this is going to matter for the survival of their business, although it might improve user privacy around the globe and that'll be a big win.
- koolba 9y agoWhat’s the supposed justification for scraping text message data? I mean the contact list could be justified as a means of cross referencing friends. I’m having a hard time coming up with a legitimate use for text message data. Best I’ve got is “who do you contact regularly?” which is still insanely creepy.
- augbog 9y agoThis is speaking speculatively but Facebook right now is heavily trying to go into Messaging AI (Messenger) and so it needs to train those AI. I'm actually kinda surprised if they foresaw that training data so early but yeah it's really creepy.
- rhizome 9y agoIt's not hard to foresee wanting "everything" with the goal of sorting it out later, but Messenger is a no-brainer for FB if they want to continue having access to message content.
- quadrangle 9y agoI think it's "This helps us orient both ad- and non-ad- content on Facebook to fit you optimally and keep you on Facebook and also figure out why people keep texting instead of using FB Messenger."
- lostlogin 9y agoThat’s not a justification that helps the user much though.
- adrianN 9y agoWho cares about the user?
- quadrangle 9y agobut it exploits them for profit much, thus serving the primary mission: shareholder value
- gruez 9y agoFunny how this is popping up now (presumably because some guy noticed his call logs were in his facebook data download and tweeted about it), even though the permissions in question (described in no unecrtain terms) were in the app for years, and there was an explicit setting in the app to turn this on/off http://i.imgur.com/NRarWdh.jpg http://i.imgur.com/NRarWdh.jpg.
- tylermenezes 9y agoThere was no explicit setting to turn this off until somewhat recently, and is addressed at the start of the article: > This screen in the Messenger application offers to conveniently track all your calls and messages. But Facebook was already doing this surreptitiously on some Android devices until October 2017, exploiting the way an older Android API handled permissions.
- gruez 9y agoRegardless, the permissions were there for years. read your text messages (SMS or MMS) read call log Was nobody able to make the inference that facebook might be uploading this stuff to their servers? Remember this was during the whole "facebook is surreptitiously listening to our conversations" fiasco.
- CaptSpify 9y agoAs someone who has rallied against FB for years, there's always some justification: "It'd be too risky to their business for them to do something like that!" "Someone would have leaked the secret by now!" "There's no way a company that big could get by doing something that blatant!" I think people just don't like uncomfortable truths, even when staring them in the face.
- Groxx 9y agoEverything you install on basically every desktop OS, by default, has access to practically everything. I think most people would be surprised if they discovered that apps were uploading their emails. And photos. And tax documents. Just because they happened to be on the hard drive, and there were no permissions to prevent it. Expecting FB to not do similar and respect basic privacy by default is reasonable. FB doing such things just because they can is not.
- wlesieutre 9y agoAndroid's permissions system for stuff like that is indefensible. Anything with severe privacy implications like "years of text message history" should explicitly opt-in with a permission request popup at runtime like iOS has done for features like camera since launch. Of all the things to not copy from iOS, of course privacy is the one that they decide to skimp out on. I'm glad they've started to catch up, but they have a ways to go yet.
- jon_richards 9y agoI hate that I can't send a photo to a friend without giving facebook access to all of my photos. Where's the "just this one" option?
- starik36 9y agoThat bugs me too. I've resorted to placing the photo on the clipboard, then paste it. A workaround, but well worth preserving your sanity.
- xvf22 9y agoHeh I don't bother with the app and suffer with the web interface. Annoyingly I now need to "Request Desktop Site" to use messenger or else it tries to get me to install the app. The artificial friction they're put in place has pushed me ever closer to just deleting my account.
- prutschman 9y agoIf you go to mbasic.facebook.com you'll get the low-end phone version, which allows messenger access.
- xvf22 9y agoThank you, I remember using this at some point but forgot it. I'm still probably going to trash my account but this does make it much more tolerable. This and i.reddit.com make life on mobile a bit more pleasant.
- noarchy 9y agoThe mile-long list of app permissions requested by Facebook's app should have been a red flag for most. There are alternatives, such as using the mobile web interface, or any of the various apps that wrap the site, such as https://f-droid.org/en/packages/it.rignanese.leo.slimfacebook/ https://f-droid.org/en/packages/it.rignanese.leo.slimfaceboo...
- spookyuser 9y agoThe app permissions should have been a red flag, except some users probably never even saw them since Facebook was pre-installed on their phones.
- shubidubi 9y agoI really don't get why people use the fb app. It drains your battery and privacy, not to mention the notifications. I use web app only.
- TaylorAlexander 9y agoThis is one of the things that led me to stop using Facebook last year. In order to use the app you have to give it all manner of permissions. And of course, if Facebook can access your data they’re going to suck in as much as they can. They don’t respect you, they want to use you. So put me in the “not surprised” category, but I’m really glad there’s more discussion of this.
- renaudg 9y agoI'm ex-FB and have it on good authority that this is indeed used to improve the relevance of friend suggestions (i.e. distinguish between your best friends and the plumber in your contacts). I'm also told it's opt-in, and the app dialog (not just the system dialog) does say call logs will be scraped. But still, IMO it's an incredibly invasive, incredibly dumb thing to be doing in the current context for the small benefit it brings. I hope they wake the f* up to just how bad it makes FB look like to the outside world, and kill this feature with fire.
- paulie_a 9y agoI hope it is getting to the point that having Facebook on your resume should be considered a huge red flag
- jeswin 9y agoPeople had been running untrusted apps in the browser and collaborating over the internet for more than two decades now. Mobile OSes threw out all the safety lessons codified into web browsers and built an entirely new permissions model. A decade later, here we are - there are hundreds of companies holding varying levels of access to your entire contacts list, text messages, GPS data, photos and other media. And all of them will hold on to it for eternity. I for one, am glad web apps are making a comeback. Now I use web apps wherever possible, fully aware that I can't do anything about what's already been shared.
- foobaw 9y agoFrom my insider source, I'm told that permissions will change significantly in the near future. Just FYI: a lot of other apps also utilize the same permission. Just an aside but Google also has the authority to whitelist certain applications for these permissions - meaning they can enable certain invasive permissions without asking the users. We shouldn't just vilify Facebook. It was how the privacy framework was designed for Android that's the issue. This will change in the next upcoming versions.
- jernejzen 9y ago1. Convenience is fuckup of all the privacy 2. Old enemies Google and Facebook unite when it goes to privacy breaches. 3. Do they know my porn preferences (damn you cross browser fingerprinting) 4. Well, Instagram showed my that pretty unknown girl follow, suggestion just hours after getting out of train. That was pretty coolscary. 5. Insomnia made it. I woke up in the middle of the night just day after I put custom mod on my ole Android phone. Found out that Google Keep wanted to have my location (just like from nowhere). Went to the store next day and bought iPhone. Never looked back.
- nashashmi 9y agoYawn! We knew this was happening for years. FB scraped data for one purpose only: To figure out who your close friends were offline. And they wanted all sorts of information that could indicate closeness. From location data that would show how often you meet up together and how long you hang out. To phone call and sms data. Now a lot of that data is dead data. Like it has no use after a couple of years. But just like Google cookie having an expiration date of 20 years, FB just does not know when that data becomes irrelevant. FB and zuck have this manifest dream of figuring out connections and then figuring out the strength of those connections. Then they want to figure out social relevance. Then they want to use that info to bind people together on their platform. It is not a bad idea overall, until you add in government and corporate entities. And by that time you know how evil of a thing you signed up for.
- caretStick 9y agoHere's your sekurety code
- daveheq 9y agoMySpace allowed viruses on their platform; Facebook IS the virus.
- johnnyOnTheSpot 9y agoWhat has changed at facebook to create all this negative feedback?
- tmuir 9y agoThe richness of the irony in your question makes me wonder about your level of sarcasm. On one hand, its pretty reasonable to say that absolutely nothing changed at facebook. We are all witnessing the effects of latency. On the other hand, the change(s) that has ushered in this uptick in negative opinions in regards to Facebook will likely be the source of vigorous debate for some time. For one, this is just the latest example of habitual behavior on Facebooks part, selling third parties more access to personal data than the persons referenced are comfortable with. The response every single time has been for Facebook to say roughly "We agree in principle that we slightly messed up, and as our more than adequate self imposed penance, we will solve this problem in secrecy with the completely untested technology that we've been working super hard on ever since we discovered this problem 2 years ago, but only acknowledged publicly as a strategic move when no better alternative existed to preserve our viability as a corporation". Additionally, the data subjects do not generally understand the power imbued to the purchaser of that data at the point they give away that data. Further, they possibly are giving up the legal right to any privacy stemming from what that data may tell third parties. In the context of all of these generally nebulous problems, is the growing news story involving Cambridge Analytica's alleged use of Facebook's data, the Presidents use of both of those, and the extent to which it can be argued that voter outreach crosses a line in to deceptive psychological manipulation. Its what folks in scientific fields refer to as evidence that supports, as opposed to weakens, a falsifiable hypothesis.
- burfog 9y agoUsers need to be able to mislead the apps. Right now, an app can force a choice: enable all the permissions, or you don't get to use the app. Users need to be able to feed fake data into the app. For example, maybe Facebook should think I am spending my time with Bill Gates in Bhutan. Users should be able to install dishonesty plugins to generate this data.
- Yoric 9y agoI realize that it's too late to cry over spilled milk, but that was one of the reasons for which Firefox OS was developed. We wanted to push a different permission model in which permissions were much more fine-grained and could be audited and revoked easily. Sadly, one of the reactions of the development community (including HN commenters) at the time was along the lines of "Android is just fine". I understand that recent versions of Android have moved towards adopting a permission model closer to that of Firefox OS, though, and I suspect that the example given by Firefox OS at least showed that it was possible. P.S.: Yes, Firefox OS had other problems. Let's not try and idealize the past :)
- deftturtle 9y agoBRING BACK FIREFOX OS
- on_and_off 9y ago> and revoked easily . I don't see how revoking permissions solve that problem. Once an app has scraped your info, you can revoke it's permissions all you want, it is not going to delete your data from its server.
- aj7 9y agoIs this possible with IOS? Or for people who have never shared their contacts with Facebook?
- deftturtle 9y agoI already suspected this due to getting more posts from my friends based on who I texted, and they were Android users. It's fucking annoying. Also, using the same wifi network leads to getting friend suggestions
- fencepost 9y agoI'll throw in another place where permissions aren't nearly granular enough - online file storage (Dropbox, Onedrive, Box.com, etc.). Perhaps I'd like to allow an app to save information for cross-platform use or just because I want it on my own personal cloud storage - 1Password's older versions are a great example of this. I haven't looked at it recently, but I'm not aware of any changes that add that level of granularity to the APIs. What throws me is that I'd expect security conscious developers to be clamoring for this. If I'm writing an app that should store data for users on the user's own accounts, it's not "I do not want to have access to everything" it's "I do want to NOT have access to everything."