14 ms·
iPhone protected you from Facebook call scraping. Android, not so much
- oldgun 9y ago> More recent versions of Android should prevent this kind of data collection. So the title made me think all Android are exposed to Facebook phone data scraping. But considering how slow it is for Android devices to upgrade to the latest, it's probably still a sad state.
- softawre 9y agoGet a pixel. I love mine, as an iPhone users for the past 6 years.
- lifthrasiir 9y agoThe app would have been trivially considered a malware if the same thing happened in Windows, where the app was traditionally allowed to access anything within the basic privilieges---just about anything. One can (rightly) blame Windows (and also Android) for allowing that, but more importantly, the Facebook app would have to be treated in the same way after all.
- GuiA 9y agoThis is very important to highlight. Mobile has tremendously changed the goal posts in terms of what are acceptable things to do on a system and what violates the privacy of the user, and no one noticed. Imagine a piece of software in the 2000s that sent all your emails, contacts, etc to a central server when running on your desktop computer, made by a large American company. There would have been utter outrage and legal ramifications.
- Larrikin 9y agoI believe this is something that regulation should address. Scooping up all this data should be a massive liability for companies. Depending on the severity of a hack or misuse of the data it should effectively bankrupt or significantly destroy profits of any company. But the OS should not completely prevent it. There are a number of programs for power users on macOS that have stopped selling through the App Store or warn against limited functionality for apps bought through the store. There are also a lot of extremely useful apps for Android that work most effectively when your phone is rooted. Google's Safety Net has effectively made rooting a liability for all power users. When the OS provider is limiting what a user can do the device quickly devolves into an entertainment consumption device. Bad actors should be treated as viruses and malware the same as they were before.
- gruez 9y ago>Depending on the severity of a hack or misuse of the data it should effectively bankrupt or significantly destroy profits of any company. counterpoint: equifax
- Larrikin 9y agoEquifax is exactly the kind of company that should not exist after a breach of that kind
- guitarbill 9y agoEquifax is exactly the kind of company that should have never existed, and should have never been allowed to exist. The same with the Facebook app (+ Android permissions, because even Facebook can't do full evil without Google apparently). And it's going to be the same result. Nothing is going to change, neither company will suffer much, nobody is going to jail. So his counterpoint is valid.
- nimbius 9y agoLineageOS prevents this type of access. If an application needs access to your phone or your contacts, you need to explicitly permit it to do so during execution. if you want to do this more than once, you need to set it up in the security options for the application in the settings menu.
- x0054 9y agoAre they seriously smart enough to collect this data but stupid enough to dump it in an archive copy?
- eganist 9y agoEU GDPR compelled this sort of inclusion. If it came out that any data was not included in such a request, Facebook would be hosed to the extent of whole percentages of revenue.
- justincormack 9y agoThe dump was originally to comply with EU law. If they miss out data they would be legally liable and would be in a very difficult position in Europe.
- txsh 9y agoAs an iPhone user I’d like to think iOS does not allow this. However, I understand there’s a private API that allows larger companies access to functions that are not available to regular developers. It allows them access to the microphone without the red bar showing even when there’s not a call. Like others have, I’ve received ads for products spoken about near my phone but never typed into a device I own or on my router.
- jtbayly 9y agoThen download your data file and see. I don’t think FB has this data from iPhone users, but I’d be happy admit I was wrong if you proved it.
- shrumm 9y agodo you have any citations to back this up? that’s a serious claim. Huge breach of trust by Apple if true.
- hrrsn 9y agoiOS doesn't. Apps using private APIs are not allowed on the App Store. Apple granted Uber an entitlement for a private API, but no other app has this: https://twitter.com/chronic/status/915930211941781504 https://twitter.com/chronic/status/915930211941781504
- vbezhenar 9y agoThis believe based on trust to Apple, not on technical limitations. I always wondered about this concept of private API: available to anyone but theoretically forbidden to be used. I'm sure that there's a million ways to circumvent Apple's static code analysis and slip through their review. Why didn't Apple limit their API usage with technical restrictions.
- Klathmon 9y agoIt's pretty trivial to bypass Apples code analysis for private API usage, at least a few years ago it was.
- deleted 9y ago[deleted]
- sjwright 9y agoThere are two major philosophical differences between Google and Apple which led to this outcome. The first is the difference in business model, i.e. advertising versus whole-product. The second is that Google starts with a permissive ecosystem mindset and locks stuff down as they go along; Apple starts with a conservative mindset and opens stuff up as they go along. Neither approach is inherently better than the other—the competing platforms are converging towards equilibrium—but Apple's approach does prove to have the upper hand when it comes to consumer privacy.
- sjwright 9y agoThe amusing thing is how much flack Apple received early on for their closed product approach. It's arguable that Google traded heavily on the relative freedom of the Android platform, and sucked in a lot of early adopter / tinkerer types on the promise of openness. Kind of ironic that for most people, most of the time, the open source nature of Android is now barely a historical footnote.
- piracykills 9y ago> barely a historical footnote. Certainly not for those tinkerer types. Often it's the tinkerer types who are concerned about privacy, and it's those types who install Copperhead OS or XPrivacy, which allows you to deny exactly this kind of thing. Not only that, but it'll let you block all those smaller ways of spying - like unique device IDs being phoned home to 6 different ad, analytics and crash handling services that the silly game you just installed uses. It's hard for me to imagine using a phone on which I see ads, especially on YouTube, can't background apps like SSH clients, syncthing, even direct IMAP and SIP connections used to be a struggle for people on iOS (still may be?) or run app that Google/Apple have decided are evil piracy tools, like a manga reader or a torrent client manager and search tool. I have friends who even run emulators and use memory editors to cheat at mobile games regularly on their phones... very, very different models. Android is just a lot more flexible for a tinkerer to this day. All this is possible without exploits on most devices, allowed and accepted by many manufacturers. There's this weird attitude on HN I see frequently where it seems like everything has to be "for the masses" for it to be of any value - tinkering by definition is not for the masses. Android devices probably shouldn't be for the masses, but for tinkerers, they really do pack a respectable punch in my opinion.
- htk_ 9y agoI was a Facebook user before I have my first Android phone, it was on 4.0.3 ICS, then I'm on 4.3, 4.4, 5.0, 6.0, 7.1...etc, and before I delete my Facebook account, I see no call logs in the backup data archive downloaded from Facebook, guess what, there's at some point, some users just simply say yes to let Facebook 'manage' your SMS, or calls, if an Android user's call log got scrapped, it's partially his/her own fault.
- JustSomeNobody 9y agoWhile this may be true, Rene Ritchie certainly has his own agenda here.
- Finnucane 9y agoNow my paranoia about never using Facebook from my phone is retroactively justified.
- deleted 9y ago[deleted]
- megy 9y agoIf you use it from a browser, rather than the app, you are safe.
- deleted 9y ago[deleted]
- robotcookies 9y agoWhich is why they keep trying to push the app on you. I've gotten emails from Facebook saying a friend wants me to download messenger. Like, huh? Why would they care if I'm using an app or a browser?
- sohkamyung 9y agoThis updated piece by Android Police [1] provides some more pieces of information (see the bottom of the article for the updates): - The company [Facebook] reiterated that it wasn't saving the actual content of calls or SMS/MMS messages—something neither Ars Technica nor we claimed, but presumably other outlets did. - It's actually a part of Facebook Lite and Messenger (and users can opt out [...] respectively). Facebook considers the data collection opt-in since the apps in question directly ask if you'd like to upload that information during setup. [1] https://www.androidpolice.com/2018/03/25/facebook-gathering-call-sms-mms-metadata-years-via-app/ https://www.androidpolice.com/2018/03/25/facebook-gathering-...