13 ms·
The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages.
by tsunamihippo 3y ago
The article skips a lot of context to make it sound significantly worse than reality. Facebook didn't just randomly give Netflix access to everyone's messages. Specific user would need to purposefully log in to the Netflix app with their Facebook account in order to grant Netflix access to the chat functionality (intended to send movie recommendations to Facebook friends inside the Netflix app).
https://about.fb.com/news/2018/12/facebooks-messaging-partnerships/ https://about.fb.com/news/2018/12/facebooks-messaging-partne...
Disclaimer: I work at Facebook but not on messaging or anything related to this article.
- notnmeyer 3y agoso you agree then that “private” messages aren’t private on fb? i don’t know how to interpret this in a way that isn’t terrible for fb users…
- scarface_74 3y agoIf you give access to your chat as the parent poster claims, why are you surprised that Netflix has access?
- bluefirebrand 3y agoYou would expect that giving permission to send specific pre-approved messages does not imply permission to read everything you've ever said to anyone or they've said to you.. Right?
- reissbaker 3y agoThat's not what the feature was. The feature was that you could use Messenger inside Netflix and Spotify to chat with your friends without leaving those apps. If you opted into using Messenger to chat with your friends inside Spotify, I'm confused why you think Spotify couldn't access your messages, given that Messenger was unencrypted at the time and you were running it inside Spotify. How else would the feature work? It's Messenger running inside Spotify; just like how iOS has access to the unencrypted files and network traffic of any app on your iPhone, Spotify could access any of the unencrypted files or network traffic in Spotify. It's a dumb feature and I'm glad they killed it, but the "gotcha" here isn't much of a gotcha IMO. It was an opt-in feature to use Messenger inside these other apps; of course the other apps could see your messages if you opted into that. It's like complaining that GMail "shares your private email" with Apple Mail if you use Apple Mail as your mail client.
- lupire 3y agoThink about the difference between accessing these specific messages, and accessing all messages.
- reissbaker 3y agoIf I give Apple Mail my credentials for my GMail account, I would expect Apple Mail to be able to access my email in my GMail account. Switching the word "email" to "DM" doesn't feel like a meaningful difference: if I'm using a third-party client to access and send messages, of course the third-party has access to my messages. Would I expect Tweetbot to be unable to access any tweets other than the ones sent from Tweetbot? That's... not a very useful third-party client. These were third-party Messenger clients; they had access to your Messenger DMs if you opted into using them.
- chatmasta 3y agoThe web was rampant with these patterns in the early 2010s when OAuth didn't exist, and HTTPS the exception rather than the rule. The most egregious example was probably LinkedIn's GMail "integration," ostensibly used to invite your GMail contacts to LinkedIn. Back then, that sort of thing felt innocuous. But the implementation was even worse. Due to lack of OAuth and MFA, you literally entered your GMail password into LinkedIn. Then LinkedIn logged into your GMail account where they could do anything. Even if they limited it to scraping your contacts, they still got every email address you'd ever sent or received an email to or from, over the lifetime of the account. In any other context this would be called phishing. And by the way, this pattern still exists. For example, apps that force you to log into a third party site in their embedded WebView can read the entire DOM (including your password). ..
- reissbaker 3y agoYeah definitely. There are still some pretty bad patterns out there; for example, if you try to add an event from Facebook Events to your Google Calendar, instead of generating a normal ICS file or event link, they... ask for read/write access to your entire Google Calendar account. No thanks! Similar to apps that ask for access to your entire Contacts list to "find your existing friends"... You can bet they're uploading that entire thing to their servers and trying to growth hack with it.
- hipadev23 3y agoBecause it’s not a reasonable expectation that your private messages would be shared with an advertising partner when you link your account to it, and “give access” is rarely a step that your average user actually reads, much like agreeing to TOS’s upon signup. And catering to the average user’s expectation is what should dictate policy, not a “technically we have permission” caveat.
- rezonant 3y agoIn the sense that some users may not have realized what they were allowing, that's fair. But that just implies that the permission dialog for this sort of thing should be pretty onerous while being very easy to understand. There are details that aren't clear here too: Did Netflix request read permissions when you signed in via Facebook? If so, that's shitty and is worthy of condemnation, but the onus falls more on Netflix than Facebook there. You should be able to sign in with Facebook without expecting your DMs to be sent to Netflix. It's still on Facebook, but to a much lesser extent: They should make what's being shared super clear when you sign in with Facebook, and that includes making the sign in super onerous and scary if its something like reading DMs, so the user doesn't miss these details. And they should be reviewing third party apps and what permissions they request, and making sure its inline with the functionality the app is presenting. However, if the normal Facebook authentication flow did not grant this permission, and the permission was only granted when the user accessed the "Netflix Chat" or whatever feature which obviously did, in actuality, require the read permission to function, then this isn't that big a deal.
- vel0city 3y ago> would be shared with an advertising partner In this case Netflix was not an advertising partner. You were signing into Facebook Chat inside the Netflix chat, and participating in Facebook chat messages inside the Netflix app. You were opting in and using the Netflix app as a Facebook Chat client. Its like being surprised the Pidgin executable could see your Jabber messages.
- notnmeyer 3y agoit’s disingenuous to think that users read and fully understand the various permission scopes of a service. “private” has an unambiguous meaning—playing the “well, technically” card falls pretty flat imo.
- scarface_74 3y agoWhen you give your mail client credentials to read your email , would you not expect your client to be able to read your mail? On Android, when you give a third party client permission to receive SMS, you don’t expect it to have access to your SMS?
- SoDmbIHadToRply 3y agoSo when I give thunderbird my email details, someone at thunderbird gets access to all my emails ?
- sashank_1509 3y agounless I’m wrong thunderbird software has complete access to all your emails when you give thunderbird your email details. Of course, that does not imply that a specific thunderbird employee can read your emails, it is probably encrypted on that end but if they pull a switcheroo and download all your emails into an AWS instance, yes that might be possible (and probably wildly illegal too)
- rezonant 3y agoIf Thunderbird had a hosted web version, yes. Are you arguing that data portability and interoperability should never be possible if the receiving app is an online service? Of course Thunderbird could send an automatic update that starts shipping your emails to Thunderbird's servers. You dont expect that, but only because you trust them.
- airtonix 3y agonot if you log in to enable and agree to share such messages. no.
- k8svet 3y agoSo... this sounds like OAuth, with a nice consent scene that says I'm giving Netflix this access to my FB DNs. That's what you mean, right? Otherwise, what the fuck is the difference?. And really, as if this makes anything better, wow. Imagine having the feeling of obligation that you have to stick your neck out over this. Just take your over-sized salary and be happy knowing you work for one of the worst companies of our time. (despite my tone, at this point, I honestly say that without judgement, just ... own it.)
- aardvarkr 3y agoWhen you give your mail client credentials to read your email , would you not expect your client to be able to read your mail? On Android, when you give a third party client permission to receive SMS, you don’t expect it to have access to your SMS?
- k8svet 3y ago[flagged]
- rezonant 3y ago> Is Netflix a secret Facebook client that I don't know about? Lmao, is this a serious comment I'm replying to? Yes, in fact, that's what the feature was. You could send a movie recommendation via Facebook within Netflix, and then continue the conversation with that friend, still in the Netflix app. It's a dumb idea for all of the obvious reasons that its in Netfix' best interest to hoover up the data, but that's why it doesn't exist anymore and hasn't existed for years.
- k8svet 3y agoLmao, love seeing what HN decides is controversial these days. God give me the power of some of y'all's utterly depraved self-serving self-delusion. I at least acknowledge the moral compromise of how my labor accrues in the system instead of burying my god damn head in the sand about it and offering poor incoherent defenses of my employee in public. And I make a third of what I could make at FB, and still probably don't contribute as negatively to the world.
- lupire 3y agoAnd if a user consented to Netflix-based chat, Facebook overshared all chat data, instead of only the Netflix chat data, because they couldn't be bothered to build a properly isolated API? That's like asking permission to read and write your entire phone, just to provide the ability to write and read back a file.
- toofy 3y agoi’d question the “…couldn’t be bothered to build…” i’d be more likely to believe they knew exactly what they were sharing and wanted it that way.
- vlan0 3y agoWhat incentive does FB have to limit that access? Feels like MBAs would just see that as a cost/burden? We know FB does give a fuck about privacy, so that’s never gonna be a reason.
- captn3m0 3y agoCourts across the world fining them.
- pooper 3y agoThe fines have to be more than 100% of global annual revenue if they are going to matter. The other option is long prison sentences for the board and CEO.
- exe34 3y agoWe often act as if corporations are unalignable super intelligences, but you're right, if there are consequences for the board/executive/shareholders, they would start caring.
- yen223 3y agoIf you believe FB is in the business of selling user data, then giving out user data for free is not an optimal move.
- lesuorac 3y ago> Disclaimer: I work at Facebook but not on messaging or anything related to this article. So, it could work exactly as it sounds and you'd have no idea? --- Although I'm not sure the complaint [1] (linked from articled) actually says that messages were given. [1]: https://cdn.arstechnica.net/wp-content/uploads/2024/03/complaint.pdf https://cdn.arstechnica.net/wp-content/uploads/2024/03/compl...
- trolan 3y agoYes I think they're giving their general nerd opinion while also being transparent about possible conflicts. Their comment reads like an analysis of the article not the technology.
- deleted 3y ago[deleted]
- cm2012 3y agoIf this wasn't Facebook it wouldn't even be news.
- soraminazuki 3y agoI hope you’re being sarcastic? Or is that actually your stance on people’s privacy rights?
- kazinator 3y agoRather, it seems like cynicism about the media, than a stance on rights.
- rvba 3y agoLots of comments here look like some sort of astroturfing made by a PR agency
- robocat 3y ago"Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data." - https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- choppaface 3y agoThe root comment is literally a Facebook employee who is intentionally trying to change the narrative. An employee of a company that has been fined billions for privacy breaches, that was responsible for literal voter suppression https://www.opendemocracy.net/en/dark-money-investigations/they-were-planning-on-stealing-election-explosive-new-tapes-reveal-cambridg/ https://www.opendemocracy.net/en/dark-money-investigations/t... etc etc HN "guidelines" say "Please don't post shallow dismissals" -- Don't allow FANG to astroturf these forums.
- YeBanKo 3y agoThanks for the context, it's important. But from the link you posted: > In order for you to write a message to a Facebook friend from within Spotify, for instance, we needed to give Spotify “write access.” For you to be able to read messages back, we needed Spotify to have “read access.” “Delete access” meant that if you deleted a message from within Spotify, it would also delete from Facebook. No third party was reading your private messages, or writing messages to your friends without your permission. So here Facebook acknowledges that an app that sends messages needs write permission, not read. I would assume that sending a recommendation is a write only thing, especially with something private as direct messages. And it is pretty well understand pattern. When you share something through iMessages, Signal or WhatsApp from the a different app, the app does not get an access to you chat history. The allegation that Arstechnica are pretty sever: > By 2013, Netflix had begun entering into a series of “Facebook Extended API” agreements, including a so-called “Inbox API” agreement that allowed Netflix programmatic access to Facebook’s users' private message inboxes Strange naming "Inbox" for sharing API. > in exchange for which Netflix would “provide to FB a written report every two weeks that shows daily counts of recommendation sends and recipient clicks by interface, initiation surface, and/or implementation variant (e.g., Facebook vs. non-Facebook recommendation recipients). This is something that Netflix could do even without special access to the messages, since links originate from them. But so could Facebook, since they see the traffic in messages and can identify referral links. Looks like Titan API, whatever it is, gave even more access? NYTimes article from 2018 [1] has more details, but it is still unclear if user consent was explicitly obtained for Netflix to read messages. But an interesting quote from Steve Satterfield, Facebook’s director of privacy and public policy: > With most of the partnerships, Mr. Satterfield said, the F.T.C. agreement did not require the social network to secure users’ consent before sharing data because Facebook considered the partners extensions of itself — service providers that allowed users to interact with their Facebook friends. A rather conspicuous statement by someone who have properly collected consent from users. [1] https://archive.is/DH17k https://archive.is/DH17k
- rezonant 3y ago> So here Facebook acknowledges that an app that sends messages needs write permission, not read. I guess the feature at issue here is that you could actually hold a conversation with a Facebook friend inside of Netflix or Spotify which does indeed necessitate the ability to read back messages from the other user. Whether it was wise to allow that instead of the kind of sharing systems we use today in 2024 is another question.
- ionwake 3y agoI only read the headline and this reply gave me even greater concern. wtf they shared ALL msg data for logging into Netflix chat?!? I dunno I’m surprised I’m still surprised these days
- deleted 3y ago[deleted]
- rmbyrro 3y ago[flagged]
- some1else 3y agoNote that everyone had access to the Inbox API at the time. We made an art project highlighting the invasiveness of such broad access: "E-dentity is a project that asks a participant to login to its Facebook account, then takes his/ her private data from their profile and automatically prints them in an understandable booklet that is handed to the user. This booklet seeks to raise awareness of the hidden data we are sharing which we are often not aware of." https://github.com/some1else/Edentity https://github.com/some1else/Edentity
- choppaface 3y ago> Disclaimer: I work at Facebook but not on messaging or anything related to this article Same as "Hey, Googler here. Let me tell you how I'm right and why you should think this way." > Facebook didn't just randomly give Netflix access to everyone's messages. That's not at all what the title alleges, nor what the article says. The article (1) provides evidence that Facebook monetized user private messages in a data-sharing project with Netflix and (2) cites court documents that litigate Facebook having Jedi-Blue-like monopoly-preserving interaction with Netflix. It doesn't matter what the Facebook TOS says or how the tech works. Human users never provided informed consent that their private comms would be monetized as well as used for anti-competitive un-American purposes (un-American as in the Sherman Act, altho creating a monopoly is perhaps very American indeed). And Facebook has done that time and time again.
- aihkas 3y ago[flagged]
- dang 3y agoYou can't attack another user like this on HN, no matter how you feel about their employer. Since you've unfortunately done this before (https://news.ycombinator.com/item?id=37430894 https://news.ycombinator.com/item?id=37430894), I've banned this account. If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future. They're here: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html.
- aihkas 3y ago[dead]