3 ms·
Yes, they were. https://www.vox.com/2018/3/17/17134072/facebook-cambridge-analytica-trump-explained-user-data https://www.vox.com/2018/3/17/17134072/facebook-c
by traek 7y ago
Yes, they were.
https://www.vox.com/2018/3/17/17134072/facebook-cambridge-analytica-trump-explained-user-data https://www.vox.com/2018/3/17/17134072/facebook-cambridge-an...
- shkkmo 7y ago> Facebook also allowed developers to collect some information on the friend networks of people who used Facebook Login. So no, Cambridge Analytics did not have API access to everything that that that the users who used Facebook login had access to. This was a specific set of permissions granted to apps with which users used their Facebook identities as login identities.
- SpicyLemonZest 7y agoThat's right, so I'm not sure how we're drawing different conclusions from it. Cambridge Analytica got an API that was only moderately open, with much less than the full access you'd need to implement something like a Facebook client, and that amount of access still wasn't okay.
- shkkmo 7y agoAgain, this access was granted when you used your facebook identity to log into a 3rd party site, not using an API to provide an alternative client to the user. Those are very different use cases and have very different expectations of privacy and levels of concern. Your browser has direct access to TONS of private data, if you install certain browser extensions they have access to all that data as well. A custom facebook client would be fundamentally similar and would clearly be considered a piece of software that requires trust to use. The level of trust you should have in the software provider who provides such clients is MUCH higher than a 3rd party site where you simply used facebook as a login provider.
- bryan_w 7y agoYou would see ads for people to install the "Cambridge Facebook Client -- Earn $2/month just by using Facebook!" While they silently slurp up the same information on not just that person, but their friends.
- shkkmo 7y agoWhy would this be any different from browsers and browser extensions?
- SpicyLemonZest 7y agoIt's not different. The current state of the browser extension ecosystem can cause and has caused massive data privacy violations; browser vendors are locking down previously open APIs to try and remediate that, breaking some functionality that developers want. Context: https://securitywithsam.com/2019/07/dataspii-leak-via-browser-extensions/ https://securitywithsam.com/2019/07/dataspii-leak-via-browse... https://www.zdnet.com/article/apple-neutered-ad-blockers-in-safari-but-unlike-chrome-users-didnt-say-a-thing/ https://www.zdnet.com/article/apple-neutered-ad-blockers-in-...
- shkkmo 7y agoI'm not saying that browser extensions don't present risks of data privacy violations, they clearly do and you should only use extensions from companies that you are willing to trust with this level of access. What I am saying is that these risks ALREADY exist with browser extensions and facebook and providing an API to allow alternative clients for accessing facebook would be an analogous type risk and security expectations. (Although I would argue that an API could be lower risk if you can grant the API key for your client a specific set of permissions.) My point is: A site where you use facebook SSO carries a very different type of risk and set of privacy expectations than a client that you use to login to facebook.
- SpicyLemonZest 7y agoI think that's a fair claim.