3 ms·
People didn't seem to care back then, though. If you asked a random FB user about app permissions in 2011, I suspect that person wouldn't think it was a big dea
by methodover 9y ago
People didn't seem to care back then, though. If you asked a random FB user about app permissions in 2011, I suspect that person wouldn't think it was a big deal.
Social mores are changing, becoming better developed.
The Internet, social networking, OAuth -- these are not exactly well-trodden subjects in humanity's past. It's not like we have decades or centuries of precedence to look back on.
The important thing is what FB does now.
- Angostura 9y agoI think that’s an important point. Back then Facebook was more of a toy, a fun thing. “I don’t use it for anything serious, so it doesn’t matter”
- dboreham 9y agoWell, I remember working at a startup in 2006/7 on Facebook apps and having this exact conversation with my boss (specifically about the ability to de-anonymize users by joining across multiple different sites).
- mtgx 9y agoAgain with this "not caring" comment. In at least 90% of the cases people don't understand what the privacy policies or permissions mean or what they could be used for. People trend to trust others, in general. And many developers abuse that trust, especially when they're allowed to do it by design with the permissions they're given by the platforms. When an app asks me for "Access to media" I only give that access expecting that maybe it needs that access for when I will open a media file with that app or to download or create a media file inside the media folder. I do not expect the app to analyze my media for the type of content I have in there, and I do not expect the app to upload those files to its servers, or any other uses that developers may come up with for that particular permission. Yet, the permissions are set-up in such a way that they allow much more than people expect them to allow. Saying "well you shouldn't have given them access to media" or "you shouldn't be using the Internet or a smartphone" is really a nonsense type of comment to make. If it's a video player, of course I have to give it access to the media. That's why I need a video player. But I didn't intend to give it access to upload my media to its servers. That's what the platform developer allowed it to do, without me knowing or understanding that it can do that, not me "not caring." This is just an example, but it can apply to phone permissions, contact permissions, and other types of permissions just as well.
- methodover 9y agoSomeone elsewhere made a great point that I'm wrestling with. There are totally legitimate uses of friend-data for an API client, such as a custom news feed. Apps on Windows have access to pretty much everything. There are legitimate reasons for that. It could be abused. When a Windows app misbehaves, abuses the trust the users have placed in it, we don't blame Windows. We blame the app. Why then, in FB, in the same situation, have we mostly blamed FB?
- methodover 9y agoAlso, sorry for the double response, but I had one other thought. I'm not sure that most people understand even now, after the CA story broke, what the specific issue was with CA, FB, and app permissions. CBS news characterized it just like any other data breach. Slate's Political gabfest did the same. Most news articles near the tip of Reddit's front page were also light on details. Channel Four's original report didn't even focus that heavily on the FB/App problem. Friends in my FB news feed similiarly sound confused about what specifically happened. Everyone is outraged, but few seem to understand, even now.