18 ms·
Facebook let Netflix see user DMs, quit streaming to keep Netflix happy
- treme 3y agohow much effort did meta put into building a legit competition vs netflix/youtube? it's hard to imagine they couldn't put up a decent competition with max user reach and $ just how great of a moat do yt/netflix have? is Disney the only one mounting a decent fight?
- cherioo 3y agoThere’s plenty of competition to netflix. Tiktok is probably the biggest competitor to YT. But it had to come in from short form video angle, because the moat of YT in long form video is probably insurmountable. Its fate remains to be seen.
- Mindwipe 3y agoWha? Hacker News is literally constantly claiming that there are too many competitors to Netflix and there needs to be some kind of compulsory licensing to reduce competition. Like there are hundreds of posts on the front page every week to that effect. Meta never took Watch very seriously, just because it requires literally billions of dollars of investment and they clearly never wanted to spend that much. They licensed Buffy the Vampire Slayer for the US, clearly saw it didn't move the needle much and they'd need to spend $5 billion+ to get there, and scrapped the whole idea.
- _tk_ 3y agoTwo things are truly horrifying if this is true. 1. Just how normalized this behavior has become in Silicon Valley upper management circles. 2. That this has not gotten out earlier. Hundreds or thousands of employees at both companies could have reported this to the FTC or elsewhere.
- deleted 3y ago[deleted]
- rrr_oh_man 3y agoVesting period
- advael 3y agoGonna give it like two weeks before tech bosses posit that users don't have a reasonable expectation of privacy in their private messages
- cyost 3y agoIsn't that why they got renamed to "direct" messages basically industry-wide?
- deleted 3y ago[deleted]
- mcherm 3y agoI'm not clear whether I understood what the article is claiming. It's clear they claim that Meta shared customer's direct messages with a business partner without notifying the individuals who sent and received the messages. It also SOUNDED to me like the article was claiming they did so AFTER Meta introduced "end-to-end encryption" (which would ALSO mean that they were lying about offering end-to-end encryption). Am I reading that correctly?
- bastawhiz 3y agoIt sounds like it, and if true, is pretty damning.
- tobias2014 3y agoI find the article quite confusing and unclear to be honest. Are there any other sources? This is the original NYT article from 2018 https://www.nytimes.com/2018/12/18/technology/facebook-privacy.html https://www.nytimes.com/2018/12/18/technology/facebook-priva... "Internal documents show that the social network gave Microsoft, Amazon, Spotify and others far greater access to people’s data than it has disclosed." Facebook promised E2E at the end of 2023.
- dylan604 3y ago> Facebook promised E2E at the end of 2023. Wait, seriously? Like 4-6 months ago? Like, yesterday in terms of how long they haven't had it? Sheesh, a day doesn't go by that I'm not reminded of how happy I am to have dropped FB so long ago.
- ahahahahah 3y agoThey've had it for years, it was just opt-in. More recently they've applied it to everything.
- tssge 3y agoHere's the source media is probably using: https://www.courtlistener.com/docket/18714274/klein-v-meta-platforms-inc/ https://www.courtlistener.com/docket/18714274/klein-v-meta-p... To be honest I found I got much better grasp on the whole debacle by just reading the court papers themselves.
- staticautomatic 3y agoCue the FCC for yet another toothless Meta consent decree.
- deleted 3y ago[deleted]
- stephenm00 3y agoBuried in the article, but not just Netflix, Spotify as well. The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users’ private messages."
- timetraveller26 3y agoSo it's true that just talking to anybody about anything automatically triggers a flag in some server somewhere.
- neilv 3y agoI don't recall this potential bombshell (maybe because it was shortly before a Christmas, and the NYT headline looked like just more of the same ol'): > And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting. But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users’ private messages." 2018-12-18 https://arstechnica.com/tech-policy/2018/12/report-facebook-let-companies-get-even-more-data-than-previously-known/ https://arstechnica.com/tech-policy/2018/12/report-facebook-... 2018-12-18 https://www.nytimes.com/2018/12/18/technology/facebook-privacy.html https://www.nytimes.com/2018/12/18/technology/facebook-priva...
- throwaway2990 3y ago[flagged]
- zer0zzz 3y agoCare to back that up with any citations, or should everyone just take it on faith that what a throwaway says isn’t made up?
- fnordpiglet 3y agoFacebook is organized as a for profit company.
- deprecative 3y agoAnyone expecting capitalism to not capitalism is going to have a bad time.
- gloryjulio 3y agoIt's both true and false. They don't do advertising with msg, and it's e2e encrypted. But they can use the metadata
- 3y ago
- tsunamihippo 3y agoThe article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app). https://about.fb.com/news/2018/12/facebooks-messaging-partnerships/ https://about.fb.com/news/2018/12/facebooks-messaging-partne... Disclaimer: I work at Facebook but not on messaging or anything related to this article.
- notnmeyer 3y agoso you agree then that “private” messages aren’t private on fb? i don’t know how to interpret this in a way that isn’t terrible for fb users…
- scarface_74 3y agoIf you give access to your chat as the parent poster claims, why are you surprised that Netflix has access?
- bluefirebrand 3y agoYou would expect that giving permission to send specific pre-approved messages does not imply permission to read everything you've ever said to anyone or they've said to you.. Right?
- reissbaker 3y agoThat's not what the feature was. The feature was that you could use Messenger inside Netflix and Spotify to chat with your friends without leaving those apps. If you opted into using Messenger to chat with your friends inside Spotify, I'm confused why you think Spotify couldn't access your messages, given that Messenger was unencrypted at the time and you were running it inside Spotify. How else would the feature work? It's Messenger running inside Spotify; just like how iOS has access to the unencrypted files and network traffic of any app on your iPhone, Spotify could access any of the unencrypted files or network traffic in Spotify. It's a dumb feature and I'm glad they killed it, but the "gotcha" here isn't much of a gotcha IMO. It was an opt-in feature to use Messenger inside these other apps; of course the other apps could see your messages if you opted into that. It's like complaining that GMail "shares your private email" with Apple Mail if you use Apple Mail as your mail client.
- crmd 3y agoThis is one of the litany of bad things that happens when antitrust precident is ignored and we allow a small number of companies to become large enough to dominate the economy.
- scarface_74 3y agoSo are you claiming Netflix is a “monopoly” and if so, how would you break them up? The same question for Facebook. This is a case of possible “collusion” not anti trust
- waveBidder 3y agoopen protocols in the case of Facebook and banning studios from owning/exclusivity with distributors in the case of Netflix.
- scarface_74 3y agoSo you are saying that no one can distribute their own work on thier own website? Where do you draw the line? Can I not create my own video and put it on my website? Can I not work with friends and we all post our own video on our own website that we jointly own? How do we stop foreign studios from distribution over the internet? Do we block them too? Why stop at films? Should book authors also not be slowed to self publish? Software developers?
- waveBidder 3y agoit's about scale, obviously. the sorts of ventures you make a limited liability corporation for. you want to protect yourself from the potential risks? Then participate in the market in a fair and non-abusive manner. Same thing for publishing companies. individual authors can do whatever they like.
- JustExAWS 3y agoI ask the same question, if Netflix decides to incorporate in Canada are you going to make a law that forces ISPs to block them? Are large newspapers not allowed to produce their own content? Do you draw the line at newspapers and news organizations because of freedom of the press and the do you allow Netflix to produce thier own documentaries but not fictional shows?
- kylecazar 3y agoWhat is being claimed here? 'granted programmatic access to FB user's inboxes' could mean a lot of things. What privileges? I read the article and still can't tell. I don't believe that Meta allowed Netflix to read messages that a user sent or received, but that seems to be what they're implying.
- bicepjai 3y agoAn exec can interpret different meaning rather than a technical person. I assume that as full access to read the messages
- chatmasta 3y agoAgreed. I would like to read more details about the "access to the Titan API" that Facebook gave to Netflix. Has anyone read the lawsuit PDFs? Maybe more details are in there somewhere.
- rvba 3y agoFor me it sounds that they read the messages to measure sentiment (what people are watching / what they like and dislike / what they recommend / generic information about competition from other rv shows, movies and video games), but probably the system was "bugged" (plausible deniablity) so those with access could read everything they wanted - be it messages made by employees from some competitor startup, or perhaps partners and sweethearts. Creepy stuff.
- bhouston 3y agoThere is a lot of confidential information in Facebook private messages, probably people cheating, plans to leave one's job, political organizing, brides, illegal activities, etc. If Netflix gets access to this information, it is likely that other companies and 3rd parties got access either directly or indirectly. Very scary what can be done with that information.
- deleted 3y ago[deleted]
- _heimdall 3y agoThe encryption concerns here are a bit confusing IMO. Facebook owns the UI that show you the text of the messages. There doesn't have to be a backdoor into E2E encryption at all per say, a simple UI property check would give full access to message contents directly in the frontend code. Throw that into a private API and Bob's your uncle, decrypted messages that were transmitted with 100% secure E2E encryption.
- lxgr 3y agoIs that different for any other encrypted instant messenger, though?
- _heimdall 3y agoNo not at all, its a universal risk since you have to trust the UI. I should have been more clear there. Its interesting to me that I often see concerns over whether Facebook has encryption backdoors when the UI can do all the work.
- lxgr 3y agoThat's arguably still a backdoor, no? At least I'd call an instant messenger that which claims to provide end-to-end encryption between conversation participants and then surreptitiously inserts itself as another participant. However, something very active like that would be much easier to detect and prove than a "true" cryptographic backdoor that could possibly be explained away as an oversight in design or auditing.
- _heimdall 3y agoYeah I think that would fall into the backdoor category. My point was mainly that concerns over E2E encryption usually stop at the level of encryption and transmission. If one really doesn't trust that Facebook isn't honest about how messages are encrypted and who has access to decrypt them, they also shouldn't use an app made by the same company that by design must have access to the decrypted text.
- pc86 3y agoThis is literally the first time in my life I've heard of Facebook Watch.
- rezonant 3y agoFor important context on my post here, please read tsunamihippo's post first: https://news.ycombinator.com/item?id=39859319 https://news.ycombinator.com/item?id=39859319. This story seems very overblown. Are we arguing that Facebook should not ever allow any third party app to ask permission to read the user's Facebook DMs? There are valid use cases for this permission, and every case where an app asks for it is not a "privacy violation". Sure, did Netflix or Spotify actually need the ability to read back DMs instead of just write them so that they could send recommendations? No, they shouldn't have needed that. If Facebook's API required that they have read access just to send a message, then that's crap design. But is it nefarious? No. As long as the user is appropriately briefed on what they are granting (and it appears that they were), and as long as Facebook addresses over-scoped permissions requested by third party apps in a timely manner, then this should not be an issue. I for one believe that we need to mandate that FAANG companies have these sorts of permission-driven systems to avoid the vendor lock in we're all too commonly stuck with today. Because these things are needed for competition to thrive and to avoid the big companies from creating moats that prevent us, the startups out there, trying to dethrone them, its all the more important that these companies invest in better UIs that help a user understand the implications of what they are doing, and better review processes to stop bad actors from exploiting users' ignorance on an ongoing basis. I despise Meta, but come on. Don't throw the baby (interoperability) out with the bathwater (interoperability can enable exploitation).
- deleted 3y ago[deleted]
- izacus 3y agoRemember that this site is full of people outeight supporting monopolies and walled gardens when it comes to companies they like. So yes, they're absolutely defending removal of APIs that allow data sharing with explicit user consent.
- drexlspivey 3y agoFacebook also installed root certificates through Onavo to spy on their competition. Some email exchanges from this court doc https://storage.courtlistener.com/recap/gov.uscourts.cand.369872/gov.uscourts.cand.369872.735.0.pdf https://storage.courtlistener.com/recap/gov.uscourts.cand.36... From Zuck: Whenever someone asks a question about Snapchat, the answer is usually that because their traffic is encrypted we have no analytics about them. . . . Given how quickly they’re growing, it seems important to figure out a new way to get reliable analytics about them. Perhaps we need to do panels or write custom software. You should figure out how to do this. From Danny Ferrante (FB Data Scientist): - We developed "kits" that can be installed on iOS and Android that intercept traffic for specific sub-domains, allowing us to read what would otherwise be encrypted traffic so we can measure in-app usage (i.e., specific actions that people are performing in the app, rather than just overall app visitation). This is a "man-in-the-middle" approach. - Our plan is to work with a third party—like GFK, SSI, YouGov, uTest, etc.—who will recruit panelists and distribute the kits under their own branding. We already have proposals from several of these providers. - The panelist won't see Onavo in the NUX or in the phone settings. They could see Onavo using specialized tools (like Wireshark).
- deleted 3y ago[deleted]
- 2muchcoffeeman 3y agoFacebook had a streaming service? This is the first I’ve heard about it.
- dbg31415 3y agoFacebook is always going to pull stunts like this. They don't do creepy things on occasion by accident, they do them intentionally by default. Same old story for the last 20 years. Zuck is creepy AF, everything he touches is creepy AF. https://www.businessinsider.com/well-these-new-zuckerberg-ims-wont-help-facebooks-privacy-problems-2010-5 https://www.businessinsider.com/well-these-new-zuckerberg-im...
- 1vuio0pswjnm7 3y ago"Meta said it rolled out end-to-end encryption "for all personal chats and calls on Messenger and Facebook" in December. And in 2018, Facebook told Vox that it doesn't use private messages for ad targeting.1 But a few months later, The New York Times, citing "hundreds of pages of Facebook documents," reported that Facebook "gave Netflix and Spotify the ability to read Facebook users' private messages."" 1. "Does Facebook use info from your private messages to target you with ads? No. Facebook says it might look at your private messages to determine if they violate the company's policies, but it doesn't use that information for ad targeting. Facebook won't use the contents of your private messages to target you with ads on Facebook Messenger, WhatsApp or Instagram either, according to a spokesperson." https://www.vox.com/2018/4/11/17177842/facebook-advertising-ads-explained-mark-zuckerberg https://www.vox.com/2018/4/11/17177842/facebook-advertising-... If the messages are encrypted "end-to-end" or whatever the chosen marketing buzzwords, so that Facebook cannot read them, then how is FB able to "use" messages for anything. One accustomed to normal communications services might think FB is storing and delivering messages and that's all. But in truth, it's "using" them. (For purposes other than complying with any request from a court of comptent jurisdiction.) Exactly what they might be doing is of course highly confidential. You are free to take guesses. FB may answer yes or no. Answers cannot be verified, so their value outside of marketing is dubious. NB. Meta _is_ a third party. It feels as if some people believe they can redefine terms like "end-to-end", "third party", etc. As if they know many readers will happily go along for the ride.
- leidenfrost 3y agoMy guess is that FB stores the keys to reverse the encryption. The point of e2e is to block any third party to to see your conversations by sniffing packets. Not to stop Meta themselves.
- pushedx 3y agoThe OpenWhisper protocol, which is supposedly implemented by Messages and WhatsApp, was designed specifically to enable anonymous key agreement between the two or more parties sending messages, and no one else, including the service provider. Whether or not Facebook actually implements it this way is a great question.
- ozfive 3y agoThis is wiretap level.
- mgoetzke 3y agoWhat is Facebook Watch ?
- frogpelt 3y agoIf the product is free, you and ALL of your data are the product.
- tored 3y agoNever use Facebook or any other of the big ones as a login provider. Always use a separate account for each cloud service.
- itioo 3y agoMy solution is to not use online products. I have a Gmail account because everyone needs email these days, and an iPhone with Gmail and banking and little else “online” Sorry not sorry tech people but I never really asked to be born or have your existence specifically but on me specifically. You’re society’s problem, not mine. It can deal with it without knowing I exist.