24 ms·
Facebook pauses app reviews, disables new user authorizations
- thinkloop 9y agoI wonder if it's all still a net benefit for fb. I remember back in the day while doing heavy fb dev, being flabbergasted at what we were able to get. It solidified our decision to invest heavily in their platform. We were able to get millions of likes and other data by simply having a few thousand signups. At one point I thought it was a bug and had to ask around about it. We had to consider whether it is something that will be "discovered" and shutdown or not. The power of it cannot be understated, and without a doubt a major catalyst for the success of their platform. It's possible that they would be worth less today, including the $100B loss, without it.
- siquick 9y agoOur app which has only `email` permissions is still allowing new users to sign up.
- madrox 9y agoThis is a bit out of left field, but since the height of Farmville I've argued that Facebook should offer cloud services. I know these days everyone wants you to build on their cloud and it's a bit oversaturated, but a very easy way for Facebook to make data available to developers while maintaining security is to run the code that operates on that data on their servers. Seems like such a no-brainer I'm surprised they haven't done it. But maybe I'm missing something obvious.
- troygoode 9y agoI think that is what the Parse acquisition was about. Obviously didn't work out for some reason.
- ryanwaggoner 9y agoBen Thompson from Stratechery has convinced me that Facebook wanted to be a platform, but changed their mind. They realized that making the world's most valuable consumer dataset available to developers (and competitors) was dumb, as was letting those companies all pollute the core FB experience (like Farmville), and they would make far more money in the long run by letting advertisers target with that data. This lines up with my experience. I did a ton of (painful) Facebook platform development from 2007-2009 or so, but I haven't followed it as closely since. My sense back then was that there was this huge build-up of activity around the FB platform; they were creating all these new APIs and ways for developers to build super social experiences and deeply integrate with the core FB experience, there were huge companies like Zynga that were entirely dependent on Facebook and also were responsible for tons of FB revenue, etc. And then it all seemed to fizzle? It doesn't seem like there's really hardly any activity any more in terms of deep integration with Facebook as a platform, other than FB login. I never see anything on my news feed any more from weird apps, or get invites to take some dumb quiz, or whatever. I mean, I'm sure that stuff is there somewhere, but not anything like it was. That could be wrong though!
- downandout 9y agoThe Facebook API has been useless since 2014 when most access to friend data was cutoff. Since then, if your objective was data collection, that could be easily achieved by scraping publicly available information (many friends lists are public, there are many public posts, etc. - certainly enough to use in aggregate to formulate campaign strategies etc.). I suspect that will be the next “scandal,” since in 2018, people can’t possibly take personal responsibility for the things they post and allow to be public. Ironically, the “scandal” that caused this whole thing is a non-issue. Pre-2014 Facebook apps could collect a lot of information about you and your friends, along with their Facebook user IDs, and that was scary because there was a time when you could simply submit a list of user ID’s that you wanted to show a specific ad to. But since Facebook advertising cannot be targeted by user ID anymore, and this policy was in place well before the 2016 election, all of that data was essentially useless to any participant in the 2016 election other than for aggregate things like general campaign strategies. I am intimately familiar with the advertise by ID issue - I was awarded a $2k Facebook bug bounty for spotting an exploit in the Custom Audiences feature that allowed an equivalent version of targeting by ID after they disallowed it. So while it’s possible that Obama used his special access to the entire US social graph to successfully influence his elections, it is impossible for Trump or Hillary to have done it even if they had the data because of the changes in the FB ad platform in between 2012 and 2016. This entire “scandal” was created and promoted by people that don’t understand, or actively ignored, this concept. If you ask everyone that has read the recent headlines, including reporters that wrote the stories, I’ll bet 99%+ will tell you that they believe they could be specifically targeted with ads. It would be interesting to see if the executives at any of the media companies that have managed to sell this scandal to the public took unusually large short positions in Facebook stock before releasing the story. Since the story is effectively fraudulent (it was not possible for the election to have been influenced in the way that the stories imply), I assume that would be securities fraud.
- orf 9y agoIt's not possible to target by specific user id, sure, but that's not the story and in no way makes the whole thing fraudulent. It's also not what CA was doing or how they operated.
- thomble 9y agoIs it possible to create an app that can easily remove personal info, and delete all posted content that is, say older than n days old? If so, is there a new demand for this kind of app?
- seem_2211 9y agoInteresting how it's all about "sharing" and "community" when they want you to get on Facebook and all about "well you know you signed your privacy away" when you ask any questions. It's so disingenuous - I'm loving Facebook's self-created troubles.
- timthimmaiah 9y agoNot sure if this headline is 100% accurate. oAuth for apps that have already passed Login Submission is still functioning. For example, new users to an app that is already in the FB app ecosystem can still create accounts via oAuth. However, apps that request scopes like "user_friends" or "pages_messaging" [1] may error out during authentication. [1] https://messenger.fb.com/newsroom/messenger-platform-changes-in-development/ https://messenger.fb.com/newsroom/messenger-platform-changes...
- foota 9y agoSeems like the right answer here is analyzing usage of the API and looking for malicious patterns
- humanfromearth 9y agoPausing app reviews is annoying for sure, but not allowing new users to authorize their app is really bad. Meaning that new customers can't connect with facebook anymore to access their own data using OAuth! We don't need permissions about your friends, your photos, or whatever. Just accessing their own messages and posts (which is what our customers want to see in our app and pay for). I know they are shell-shocked after #deletefacebook stuff, but this overreaction is ridiculous. So glad it's not our only channel of communication through. Times like this you appreciate email - crazy huh?
- olliepop 9y agoDrastic action and outcry from developers may be necessary to attain enough media coverage. The spin from Zuckerberg as a result will be along the lines of "We're really glad you asked that question, and it's one that's really important to all of us. We are prioritising the safety and privacy of our users, and unfortunately that might upset some over-reaching applications."
- cmac2992 9y ago>not allowing new users to auth their app Where does it say this? Is that in separate reporting? That would be huge.
- paxys 9y agoThey are blocking new apps, not new users in existing apps.
- ihuman 9y agoWhere does it say that facebook is disabling new user authorizations? I don't see it on the page OP linked.
- humanfromearth 9y agoIt's not mentioned in the post specifically, but this is what you get when a new user tries to login with Facebook: https://imgur.com/a/iAf6r https://imgur.com/a/iAf6r
- BillinghamJ 9y agoIt sounds like this might only affect apps requesting the "pages_messaging" scope... https://twitter.com/search?f=tweets&vertical=default&q=platform%20access%20disabled&src=typd https://twitter.com/search?f=tweets&vertical=default&q=platf...
- egypturnash 9y ago"people have noticed that a lot of horses get stolen from our barn, we guess it's maybe time to finally close the barn door"
- Mc_Big_G 9y agoReading Facebook's PR as they try to fix "problems" that they previously leveraged to profit massively is like someone purposely tripping you and as you stand back up they spit in your face and say "Oh, sorry. I'll try not to do it again" in a condescending tone. [edited to remove things HN can't handle]
- jazoom 9y agoDidn't he plan to give away almost all his money over time?
- fishtank 9y agoHe plans to "give away" money to an LLC he controls, which makes donations and invests in companies with some kind of social mission. Not saying an LLC that makes investments in for-profit tutoring companies is bad, really, just not a charity in the usual sense, and not a gift to the public good.
- negamax 9y agoWow man that's some top level hate. You do realize that Zuck has pledged away 99% of his wealth? Providing third party apps access to friends list was a strange permission. I have never used an app that asked for it. But there are plenty of dating, games and social apps that could only work with a permission like that. I think people are reading too much into this fiasco. We are better off fixing Facebook. It serves its purpose well.
- DeusExMachina 9y ago> It serves its purpose well. It’s purpose being? Maybe it’s the use I make of it, but it doesn’t add much to my life. It could go away and I could replace any of its function with something else, or not miss the function at all. Cambridge Analytica/Obama campaign data fiascos aside, many are arguing more and more that Facebook is doing more damage than good to society. Granted, this is hard to measure, but it’s a valid concern.
- drnex 9y agofacebook privacy through restricting the api is an illusion, a lot of content can be extracted with scrappers
- aylmao 9y agoYou have to be someone's friend to extract that same info with scraper though, no?
- miracle2k 9y agoIf a user account authorizes to for the API, you could only see the data of that account's friends, too.
- anigbrowl 9y agoIt depends on their privacy settings. Some people expose a lot of information, and you can (if you're pateitnt) put together a great deal of information about a person with their privacy settings locked down if you study enough of their friends. Of course, FB could just resort to making everyone's info private. But then it would suffer a serious loss of utility, as many friendships and social connections are validated by the existence of mutual acquaintances. Most of the time this is completely innocent and desirable for all parties, which is what allowed FB to become so popular in the first place.
- dworts 9y agoSeems kind of late for this kind of thing doesn't it?
- aylmao 9y agoAs in, a week late? No. Changes like this take time; some of these Facebook devs and managers are probably already working around the clock on this and related changes. Or as in many years late? In that case yes. A bit more privacy from the start would've been nice.
- Zarath 9y agoHow does one even pause app reviews? They don't own the app stores do they?
- 0x0 9y agoTheir "app store" is all the facebook app IDs that developers register to enable "login with facebook" and so on, in their own apps. Without an fb app, you cannot access the facebook api or sdk. For example, pokemon go might offer "login with facebook" and that makes your in-game account gated by a working facebook app integration.
- yourarm 9y agoI think this means that they're not allowing new apps into the app store.
- aylmao 9y agoAll those apps/sites with "login with facebook" or asking you for facebook permissions (ie, Tinder, Spotify, etc) are reviewed by Facebook.
- BillinghamJ 9y agoThis is the review process for getting extended scope permissions on Facebook apps.
- shafyy 9y agoThey are talking about apps on Facebook. E.g. if you want to build a chatbot on Messenger, you have to create an app on Facebook.
- Animats 9y agoJust turn off all Facebook apps. I never turned them on, and don't seem to be missing anything.
- Fnoord 9y agoOr how about: "Don't use Facebook. I never seem to miss anything."
- miracle2k 9y agoThe so-called "data breach" was always in reality a by-product of an open platform that hundreds of thousands of developers could easily build apps on top. You may err on the side of "more reviews" or "less powerful API", but in the end, those ideals are in tension. The more open the platform, the more open to this kind of "breach". People who believe in the idea in this kind of platform having an API should have long ago spoken up in Facebooks defense. This is exactly what I was afraid would happen, and I expect worse to come from this "platform review". Given the kind of media coverage here, Facebook seems to have more to lose than to gain from letting random Hacker News kids build on their platform. And if so, they won't in the future.
- ericflo 9y agoThis is buying into the idea that security and openness are at odds. Bitcoin is extremely secure, and also open to all. The way forward is people owning all their data encrypted, and revealing zero knowledge proofs about that data to services that want access.
- ot 9y ago> Bitcoin is extremely secure, and also open to all. And it has zero privacy: everybody can see everybody's transactions.
- ericflo 9y agoThat's because privacy was not a goal of that particular system. Pseudo-anonymity was the goal. (That's unrelated to my point about security and openness though.)
- nl 9y agoIt seems pretty related in this case, since the kind of security that is being discussed here is around access to private data (and I'd note that it was you that used the word security here, not the OP who made the more correct contrast between openness and powerfulness). One could equally make the point that Facebook is secure because no one has hacked their servers, and that it is open because it is free to join. That's a pointless thing to say though. But in any case: yes, there is an inherent tension between privacy and openness.
- doubtfuluser 9y agoSo in the end the whole change means, that groups like Cambridge Analytica won’t develop psycho tests, but dating apps that shouldn’t show you your friends, to have legitimate reasons for the access they request... and of course they need to store that information on their servers then... and none will ever sell this data to anyone... never. This is ridiculous. Even assuming Facebook has good intentions, opening the platform will always mean that malicious developer will find ways to abuse. The only way I see to prevent this, would be sending the user always a pop up message whenever any app wants to access some kind of detail, including the worst kind of abuse the developer could use this for. “The App “MakingTheWorldMoreOpenAndConnected” wants to access your list of friends. This will enable evil developers to blackmail you by threatening publishing your behavior to your friends. [ok, give up ownership of that Information] [cancel]”
- paulsutter 9y agoCan anyone think of a useful Facebook app? I can’t think of one. They’re not as intrusive/awful as they were in the FarmVille era, but are any actually useful for users, not marketers?
- jnmandal 9y agoI mean just having a Facebook login on your own website can be useful. I believe even that qualifies as a Facebook app.
- supercarsw 9y agofacebook is having "INVESTIGATING" going on :-)