9 ms·
I was annoyed with sites asking for too many Facebook privileges and made this
- MartinMond 15y agoWow this is incredibly cool! Can you also package it as a Safari extension?
- chadrs 15y agoPresumably, I've never looked into Safari extensions though.
- deleted 15y ago[deleted]
- Swizec 15y agoThis looks awesome! Some sites certainly ask for way more than I am comfortable sharing.
- digamber_kamat 15y agoThis is awesome. Good work.
- dylangs1030 15y agoI like this so much, I may fork it and port it to Firefox...thank you for making one of the most practical extensions I've seen in a while.
- msumpter 15y agoAwesome extension! I just wish Facebook would include this as a standard option on the auth page. It would be great to just uncheck the things I don't want it to do on my behalf. Instead I was allowing the app and then editing it's permissions immediately afterward. Great job!
- ambition 15y agoIn the new Auth Dialog, extended permissions have this behaviour built in. https://developers.facebook.com/docs/beta/authentication/ https://developers.facebook.com/docs/beta/authentication/
- rhizome 15y agoI just wish Facebook would include this as a standard option on the auth page. Sadly, I believe you misunderstand Facebook's business case.
- tomjen3 15y agoAgreed, an really the same goes for Android Apps. Requesting permissions is a request, not a demand.
- LambergaR 15y agoYou're my hero :)
- there 15y agoi've just started working with the facebook api over the weekend to integrate into an app i've built and every permission requested has a checkbox next to it on facebook's auth dialog to allow the user to reject it. http://i.imgur.com/v4jAU.png http://i.imgur.com/v4jAU.png are those apps using a different api than the open graph? i don't see any setting in my app's page on facebook to allow those to be disabled (not that i would prevent users from doing it, just wondering).
- chadrs 15y agoIt looks like there's a "new" auth window in beta: https://developers.facebook.com/docs/beta/authentication/ https://developers.facebook.com/docs/beta/authentication/
- derwiki 15y agoAs the screenshot hints, that's focused around Timeline. In the developer versions I've seen, `publish to timeline` is a completely different step than the other permission collection -- which could have an impact on conversion (suddenly users have to 'accept' twice instead of just once).
- mrinterweb 15y agoIn the permissions section, https://developers.facebook.com/docs/beta/authentication/#perms https://developers.facebook.com/docs/beta/authentication/#pe..., it states "The user will be able to remove any of these permissions, or skip this stage entirely, which results in rejecting every extended permission you've requested. Your app should be able to handle revocation of any subset of extended permissions for installed users." I had no idea that individual permissions could be denied. This is a step in the right direction and good on Facebook for adding this into their new OAuth process.
- burgerbrain 15y agoI would have never suspected that this would actually work. Right on!
- singingwolfboy 15y ago<3
- gfodor 15y agoThis is a cool idea, but of course the warning is that if you are turning off certain permissions, there is a good chance the app you are adding is going to break since it's coded expecting certain behaviors from the API based upon those permissions being granted (even if the data is not going to be used.)
- rhizome 15y agoIn other words, it's a good test to see if an app is coded incompetently.
- ceol 15y agoTo be fair, I don't believe Facebook ever allowed users to opt out of certain permissions (barring their recent beta auth[0]). Certainly you'd want to handle missing permissions gracefully, but I can't blame a dev for making their app non-functional when 99.9% of their users will either accept all permissions or deny the app access. [0]: https://developers.facebook.com/docs/beta/authentication/ https://developers.facebook.com/docs/beta/authentication/ (bottom of page)
- rhizome 15y agoAs common as a lazy coding practice may be, there's no excuse for programmers not checking inputs, access, or the lack thereof.
- jarin 15y agoI guess it would depend on how "production" the app is, but I don't know if I would automatically call not handling that edge case incompetence.
- rhizome 15y agoIt's production if the people who are installing it have to worry about permissions.
- gfodor 15y ago
- GiraffeNecktie 15y agoTypical Facebook authorization: Give us permission to post on your wall, check out all your friends, and generally keep tabs on your entire life. Oh yeah, and allow us to verify that you are logged in to your Facebook account. Typical Google authorization: Allow us to verify that you are logged in to your Google account.
- cheald 15y agoThis is mostly because Google provides very few useful operations. See also: authorization scopes.
- jluan 15y agoFight the system!
- DiabloD3 15y agoI think I did the ultimate opt out: I've never had a Facebook account, and I never will.
- 101010010101 15y agoThis may prove to be one of the smartest decisions you ever made. All you really need from Facebook are the email addresses of the people who sign up and want to contact you. It's a bit like the old idea of a "change of email" forwarding service. People change email addresses, but there's nowhere to leave a forwarding address and you lose contact with them. It's also a bit like zabasearch which implemented a way to see if someone is trying to contact you. Once you have those email addresses, you do not need Facebook. You are in contact, via email, with the people you want to be in contact with. You could set up your own private networks (startup hint). Advertisers are not invited to the party. Without email, Facebook cannot exist. Zuckerberg's unusually popular password protected website relies on something very old: email addresses. No email, no Facebook.
- iamandrus 15y agoI wish it was that easy for me. My generation almost refuses to use email or even text messaging -- everything has to be done through Facebook. I just wish the next big thing would pop up so we can stop worrying about what stupid privacy blunder Facebook will commit next.
- loveat528hz 15y agoDoes this actually work? I mean, wouldn't the application just go ahead and use those privileges anyway, since it was built into the API? I think this just makes you aware of the privileges it intends to use, and doesn't actually affect what the application can and cannot do. I'd love it if somebody could prove me wrong, though. This would be swell if it worked. :P
- chadrs 15y agoI included a link to the Facebook application settings on the extension's space so you can verify which permissions you've granted and which you haven't. Basically, when you generate a connect button, you list the which permissions you want to ask for and you get redirected to a page that asks for those permissions. My extension just changes the URL of the popup window so Facebook will be asking for different permissions. Before yesterday, I've always just done this manually, but I was surprised to learn that people didn't know this trick. So, last night at 10pm I decided to just sit down and finally write it as an extension.
- latortuga 15y agoPart of the API request sent to Facebook at the time of authorization specifies which permissions you want the user to grant. I have not inspected his code but I think it should be possible to modify those permissions before agreeing to them. The side effect of this is that the webapp you are authorizing may work unexpectedly when it cannot access services/functionality that they originally indicated that they wanted you to agree to. Short answer: your OAuth token includes permission status so yes, this should work.
- anonymous 15y agoThis should be part of the default UI
- BrainScraps 15y agoIdea for new names: AppBouncer, Blank Check, AppReduce
- jaymzcd 15y agoI wish there was a way to request permissions for a given time period, it seems it's all or nothing. I'm creating some apps at the minute and just need to checkin the once, I wish I could communicate that to the user but instead facebook insists that they authorize it 'for ever' (well, until they remember and go and remove it). In my opinion that would make take up and "throwaway" usage of apps a bit easier to sell.
- CGamesPlay 15y agoIf you request offline_access, the user will see "access your data at any time" as a requested permission. If you do this, the access token you are given does not expire unless the user does some action to expire it (such as updating her password). If you don't do this, the access token has an expiration date, and the user has to refresh the session (transparently happens with the JS SDK, I believe) in order for you to have continued access.
- bkaid 15y agoFacebook API does have a method where you can revoke the permission automatically (ie when you no longer need it). And also if you don't request offline_access permission, the token is only valid for an hour or two. But yes, Facebook doesn't make this very clear to the user.
- blhack 15y agoFacebook is actually a bit scary even with most of the things you're disabling here disabled. (My point is that this is cool, but it really isn't enough) For instance, I'm using facebook auth on http://lanmarks.com http://lanmarks.com -- I wanted to be able to pull my users' facebook friends so that they could filter the data on my site to only their set of friends (this is one of the appealing parts of facebook auth, imho). I spent a bit of time looking around the API docs searching for the option for "allow me to see their friends", figuring that I would have to ask my existing users to re-auth against facebook with the new permissions. Nope. I get that by default, and I can pull a list of your friends silently in the background. This is with the most basic authentication mechanism that facebook offers. That's...scary to me. As I was building this out, I asked a friend of mine on gchat to go to the site and auth against facebook to check that the functionality was working. It was... I was watching my DB, and without facebook even telling her, it grabbed a JSON of all of her friends. Creeeepy _I_ tell people this on the site (this will get your name and people in your network), but I wish that facebook did too. At least I wish they made it more obvious. And you know what? Honestly, facebook, you're totally dropping the ball on oauth here. Where in your documentation does it explain how to exchange an expired token for a new one? Most devs end up requesting a permission called "offline_access", which facebook explains as "The application can access my data at any time" This, along with "stream_access" (which most apps also ask for) literally means that the developer can post to facebook, as you, without you knowing it, whenever they want and with whatever they want. That's bad, facebook. That's bad to the point where I actually disabled facebook integration on http://thingist.com/ http://thingist.com/. The idea that my application could just post a status as any of my users, and it could do so without any interaction from them...was just too much. C'mon facebook, stop making it so hard for me to defend you all the time. (By the way, you don't really need a plugin to do this. Have a look right here: http://developers.facebook.com/docs/reference/api/permissions/ http://developers.facebook.com/docs/reference/api/permission... then look at the URL in the window that you end up in at facebook.com -- the one prompting you for permissions. Just edit the URL to reflect the permissions that you want to give the app.)
- jarin 15y agoI think friend lists are part of their basic permission set precisely because it's one of the most appealing parts of the Facebook API. Offline access isn't needed on the majority of sites that ask for it though, it's usually just laziness on the part of the developer (without that permission your server has to request a new token on login every so often).
- psawaya 15y agoThis is a fantastic idea. I have a really simple Firefox port running. You can see the code and download it (.xpi) here: https://github.com/psawaya/OOptOut-Extension-Firefox/tree/master/Firefox https://github.com/psawaya/OOptOut-Extension-Firefox/tree/ma... I only tested it out on one website, so let me know how well it works (or doesn't) for you. I'd like to keep working on this and tighten up the interface. I think a lot of people will find this useful!
- mweibel 15y agoThanks mate. I tried it on vimeo.com (as author suggests) and it doesn't seem to work. One point is: The UI is somehow broken (no styling, and "application settings", "update" and the checkboxes each are on their own line). Second point: When removing the ticks from the checkboxes and click on update, I'm redirected to: "https://www.facebook.com/dialog/undefined/dialog/permissions.request?api_key https://www.facebook.com/dialog/undefined/dialog/permissions... so "dialog/undefined" needs to be stripped. (Maybe add the issues functionality to your repos.. :)) - Michael
- psawaya 15y agoGood call. I added issues, so file away. :)
- idoh 15y agoI'm working on a facebook app right now. In A/B testing the permissions, it doesn't matter how many things we ask for, the results are about the same. So might as well ask for anything we think will be useful.
- bkaid 15y agoI've seen a study that shows this isn't true, especially when prompting for offline_acces. Wish I could find the link. Also, Facebook's app analytics shows you the break down of how often permissions are rejected and from what I've seen with high usage, the permissions prompted did matter. I would disagree that you should just ask for ones you might not need, especially since you can always prompt the user later for more if needed.
- idoh 15y agoI'm looking at the Facebook Insights for the app right now. The bucket where we asked for the most permissions (excluding email) performed significantly better than the other options. I don't know why that is the case, but it is. As for asking for permissions later, since it doesn't seem to matter we ask for all the ones we need up front. We've found that gradually asking for permissions as needed annoys the user and breaks up the app flow.
- rhizome 15y agoit may be consumer psychology: more permissions means your app must have more functionality.
- deleted 15y ago[deleted]
- sshumaker 15y agoI hate the security model where all the permissions are requested up front, and you have to approve them all (e.g. Android and Facebook without this plugin). All permissions should be off by default, and the user should be asked the first time a permission is needed to perform an action (a'la GPS on iphone) - at least that way you know what it wants the permission for, and the app can gracefully handle rejection.
- bkaid 15y agoDevelopers can do this but for whatever reason they seems to always ask for them all up front.
- transmit101 15y agoThere's nothing to stop a Facebook app being built like this. In fact, Facebook recommends this approach. It's simply that many developers feel that it's easier to get all the permissions in one go, when the user first signs up.
- wacheena 15y agoAndroid, unfortunately does not have this functionality. All permissions have to be requested up front, whether or not they are needed for all users.
- ch0wn 15y agoCyanogen Mod, however, allows you to revoke permissions afterwards.
- drivebyacct2 15y agoAnd most apps crash and burn when you do so, for obvious reasons.
- wizard_2 15y agoWhich is already too late.
- tlrobinson 15y agoWhoa, this actually works? I always wished Facebook would let me opt out of certain permissions, but I assumed Facebook would have to implement it themselves.
- JoshTriplett 15y agoI don't use Facebook, but I'd love to see the same thing for Twitter. In particular, I'd like to change requests for read/write permission into requests for read-only permission.
- cheald 15y agoWell, it's a good idea, but it needs a big, fat "hey, this might/will probably break stuff in the app you're authorizing" button. Apps usually request that stuff for some reason, and the vast majority of users don't have enough understanding of the systems to know which permissions are safe to revoke. Best case, things silently break and the user doesn't care. Worse case, things break and the user blames the developer and malign the application. You know how important the star ratings are in the mobile markets? You know how much effort developers put into managing the user experience, knowing that their app's success lives or dies based on their ability to keep from offending the luddites among their userbase? This is great for power users who understand and accept the risks inherent in doing something like this, but it's an awful idea for just about anyone except developers who understand what those permissions are actually used for.
- chadrs 15y agoI have to disagree. First, I actually do have this warning in the README. Second, if the app breaks when it doesn't have enough permissions, that's really just the laziness of the app developer. Handle the error gracefully if you really need the permission, and prompt for it again, explaining what you need it for.
- cheald 15y agoThe app "breaking" isn't necessarily as cut-and-dried as "Threw an unhandled exception". Functionality that fails to work as the user expected (because the user revoked a key permission enabling that functionality) is "broken", and results in bug reports, which results in developer time spent trying to reproduce an issue that was introduced because the user violated one of the basic assumptions in the app. You should still be checking your returns, but you can check a return, see that the value didn't come back as expected, handle it gracefully, and still deliver a "broken" user experience. I appreciate the idea and the impetus for it - a lot - but the end result for something like this is broken apps to one degree or another.
- bigiain 15y ago
- ThomPete 15y agoMaybe I am the only one on HN and I can't believe I am defending FB but I don't get this. I understand and can appreciate what is being done. I just don't understand why anyone would want to use a service that they are not comfortable giving out data to. FaceBook for better or worse is making money by knowing a lot of things about you. In return you have a place to hang out and share a lot of things. Is that such a bad deal? Personally by default I just assume that everything I post/share/say is going to be used.
- hack_edu 15y agoYou forget the huge numbers of users who willingly provide their login data to phishing or other malicious apps. If they don't pay attention to those, clearly more obvious sketchy things, you really expect them to make sense of opting in and out of an already confusing app permission step?
- ThomPete 15y agoThat can pretty much be said about everything online. As far as I am aware FB do a lot to get rid of those sites. You can also turn it on it's head. If normal good intentioned developers can't count on the kind of information they are asking to make their apps work then where does that leave them?
- hack_edu 15y agoI think we've found the crux of the problem here.
- daspion 15y agoThis is a great and much needed. It's unfortunate Facebook doesn't offer this as a general setting when you're prompted. Thanks for putting this together!
- daedelus 15y agoNice idea. Although I haven't allowed an app access to any of my data in years, I'm worried about what info my friends might be leaking to these apps. I wish there was someone to stop this / see which of my friends have made some of my data available to third parties.
- deleted 15y ago[deleted]
- dlevine 15y agoChrome should integrate this into the Browser. That way, Google could "protect" you against "privacy violations" by Facebook. It could show a little warning at the top of the screen, and allow you to edit the permissions (kind of like what the app does now, but as an official-looking browser message). Oh, and Google should also do this with the Android App Store...
- paraschopra 15y agoWon't it be anti-competitive? Facebook would probably sue Google if they specifically integrate such functionality into Chrome. (If they do it for all sites generally including G plus, then it would be fantastic)
- Splines 15y agoOT, but does anyone know of a way to find all the "things" that you've done on Facebook? It'd be nice to know if a rogue fb app has posted on me in some obscure location that I don't see on my screen. I've tried messing around with the graph API (looking at all posts by me), but I can only see activity on my own wall, and not any others. A few weeks ago my wife accidentally clicked on some fb malware and it auto-posted bad links on other people's walls. It was frustrating to find out where all those places were. A programmatic way to do this would be good to know.
- latchkey 15y agoIf FB served up that page with a hash of the expected permissions and then submitted the page with that hash, then this plugin would be rendered useless. I'm surprised for something like this (ie: permissions / security related), they don't do that already. The dialog is SSL, but if it was a man in the middle attack that added/removed permissions at will, then it kind of defeats the security of that dialog entirely.
- deepkut 15y agoI'm currently building a website that will request more permissions than average (which may incentivize some users to use this extension), but as a result, if my database isn't filled with the information that's expected, they won't be granted access to the functionality of the site. Thoughts? A bit stubborn, but my website hinges on the permissions I'm requesting.
- mwexler 15y agoThis is fantastic. Sad that so many feel we need it, but great to have.
- yanksrock777 15y agogenius.
- suyash 15y agoExcellent, thanks a lot for sharing, I'm sure we all have same problem with new facebook app authentication protocols.
- gospelwut 15y agoI just disabled the entire API. I see no difference in "user experience" save not being able to trade eggs.
- Jgrubb 15y agoYou are my hero, sir.
- JacobIrwin 15y agoThanks chadrs - I just loaded it into my Chrome extensions, great package!
- myoder 15y agoSeriously awesome. You are a hero to us all!
- thechangelog 15y agoIt would be interesting to have a follow up mechanism to indicate how many requested permissions were actually required by apps. I suspect it would end up around the 50% mark.
- gcanyon 15y agoDoesn't work for me -- I have it installed in Chrome 15.x on OS X. Using Facebook authentication, I get a dialog with the checkboxes at the top to disable some requests. I can uncheck some items, but then when I click apply nothing seems to happen.
- chadrs 15y agoYeah, I pulled in some style changes without testing them and they accidentally broke the onclick handler for the button. I fixed it here: https://github.com/chadselph/OOptOut-Chrome-Extension/commit/a937d2ccfeb7a7234bce2a786681e158b4445b10 https://github.com/chadselph/OOptOut-Chrome-Extension/commit...
- billmcneale 15y agoJust create an empty Facebook account and use it to authenticate, problem solved. Yes, it's against Facebook's TOS, which makes me feel even better whenever I authenticate with it.
- mmphosis 15y agoHere are some entries in my /etc/hosts file... 127.0.0.1 www.facebook.com 127.0.0.1 facebook.net 127.0.0.1 plusone.google.com 127.0.0.1 gooleapis.com 127.0.0.1 clients6.google.com 127.0.0.1 gstatic.com Anyone know how to filter out discussions containing "Facebook" in the title, on Hacker News?
- dspillett 15y agoI'm sure a GreaseMonkey script or Chrom{e|ium} equivelant (I'm told many GM scripts work as-is in Chrome, simpler ones any way, though sometimes a bit of tweaking is needed between environments) to do this should be easy to construct.
- cubik 15y agoHi. You mentioned in the GH desciption that you'd like some help with a name and logo. Logo-wise, how about something that resembles a door-chain? The concept is that while it allows you to talk to the person on the other side, it restricts their complete access to your property. With this in mind, you could call the plugin something like Book-chain (or something better ;) ). Either way, I'd be happy to help with the design.
- matthewj 15y agoLooks great. Though it could use some design help.
- quinndupont 15y agoAhh, Ghostery anyone? A polished product that nicely blocks Facebook requests
- jconley 15y agoCool hack. The site owners requesting a huge list of permissions like this should really test what happens to their conversion rate across various sets of permissions. Been there, worth testing. I'm just saying... ;)
- chadrs 15y agoChrome web store link: https://chrome.google.com/webstore/detail/lkllliihmodekgjcioihaaodkbpeleph https://chrome.google.com/webstore/detail/lkllliihmodekgjcio...