4 ms·
> It would just mean that the data and interactions you as a user already have in Facebook's proprietary walled garden, would be API callable from 3rd parties.
by traek 7y ago
> It would just mean that the data and interactions you as a user already have in Facebook's proprietary walled garden, would be API callable from 3rd parties.
This was precisely the level of access which caused the Cambridge Analytica scandal.
- shkkmo 7y agoIn what way? They were not using user level permissions.
- traek 7y agoYes, they were. https://www.vox.com/2018/3/17/17134072/facebook-cambridge-analytica-trump-explained-user-data https://www.vox.com/2018/3/17/17134072/facebook-cambridge-an...
- shkkmo 7y ago> Facebook also allowed developers to collect some information on the friend networks of people who used Facebook Login. So no, Cambridge Analytics did not have API access to everything that that that the users who used Facebook login had access to. This was a specific set of permissions granted to apps with which users used their Facebook identities as login identities.
- SpicyLemonZest 7y agoThat's right, so I'm not sure how we're drawing different conclusions from it. Cambridge Analytica got an API that was only moderately open, with much less than the full access you'd need to implement something like a Facebook client, and that amount of access still wasn't okay.
- shkkmo 7y agoAgain, this access was granted when you used your facebook identity to log into a 3rd party site, not using an API to provide an alternative client to the user. Those are very different use cases and have very different expectations of privacy and levels of concern. Your browser has direct access to TONS of private data, if you install certain browser extensions they have access to all that data as well. A custom facebook client would be fundamentally similar and would clearly be considered a piece of software that requires trust to use. The level of trust you should have in the software provider who provides such clients is MUCH higher than a 3rd party site where you simply used facebook as a login provider.
- bryan_w 7y agoYou would see ads for people to install the "Cambridge Facebook Client -- Earn $2/month just by using Facebook!" While they silently slurp up the same information on not just that person, but their friends.
- shkkmo 7y agoWhy would this be any different from browsers and browser extensions?
- SpicyLemonZest 7y agoIt's not different. The current state of the browser extension ecosystem can cause and has caused massive data privacy violations; browser vendors are locking down previously open APIs to try and remediate that, breaking some functionality that developers want. Context: https://securitywithsam.com/2019/07/dataspii-leak-via-browser-extensions/ https://securitywithsam.com/2019/07/dataspii-leak-via-browse... https://www.zdnet.com/article/apple-neutered-ad-blockers-in-safari-but-unlike-chrome-users-didnt-say-a-thing/ https://www.zdnet.com/article/apple-neutered-ad-blockers-in-...
- shkkmo 7y agoI'm not saying that browser extensions don't present risks of data privacy violations, they clearly do and you should only use extensions from companies that you are willing to trust with this level of access. What I am saying is that these risks ALREADY exist with browser extensions and facebook and providing an API to allow alternative clients for accessing facebook would be an analogous type risk and security expectations. (Although I would argue that an API could be lower risk if you can grant the API key for your client a specific set of permissions.) My point is: A site where you use facebook SSO carries a very different type of risk and set of privacy expectations than a client that you use to login to facebook.
- buckminster 7y agoBut if I access data through the API how does Cambridge Analytica influence me?
- gfodor 7y agoFalse, the level of access which caused that scandal and others was the fact that the early versions of the Facebook API granted access to second degree nodes in the network once you approved an app. Cambridge did not manage to get hundreds of millions of people to take their survey, they got access to the hundreds of millions of friends of those who did.
- traek 7y ago> If we were friends, you could use your custom FB client to look at my page though, which would be very user friendly. Yes, this is what used to exist, and this is what Cambridge Analytica exploited. The level of access I'm talking about, and what people in this thread are advocating for, is allowing a third party app to see all info an authenticated user is authorized to see (including their friend's info).
- toast0 7y agoA FB api that doesn't provide information about my friends can't replace the feed.