9 ms·
Facebook Android app sends phone number to Facebook servers without consent
- ferdo 13y ago"They "trust me". Dumb fucks." -Zuck
- grbalaffa 13y agoIn case anyone doubts the reality of this quote: http://gawker.com/5636765/facebook-ceo-admits-to-calling-users-dumb-fucks http://gawker.com/5636765/facebook-ceo-admits-to-calling-use...
- onedev 13y agoIt's wildly taken out of context. He said it when he was 19 (!!) in regards to a web form he made where people submitted their emails, phone numbers, and social security numbers with nothing else besides that form. The users were indeed stupid as shit in that situation. I'd also like to remind you that he's 29 now and running one of the most successful companies in the world. If you think he hasn't learned something in the span of 10 years, you're delusional and your comments as well as that article is sensationalist.
- stfsbrb 13y agoNice try, Zuckerberg.
- onedev 13y agoThis isn't Reddit. If you can't have intelligent, thoughtful discussion. Go away and never comment. You added literally nothing to this conversation.
- ferdo 13y ago> If you think he hasn't learned something in the span of 10 years He's learned to keep his little narcissistic mouth shut.
- hackinthebochs 13y agoAny insight to be gained from this quote (little to none) has long since ended. At this point its just pointless circlejerking/karmawhoring to post it.
- monkmartinez 13y agoYou don't need Facebook. Kill your profile.
- werid 13y agoin case you didn't read the article "The first time you launch the Facebook application, even before logging in, your phone number will be sent over the Internet to Facebook servers. You do not need to provide your phone number, log in, initiate a specific action, or even need a Facebook account for this to happen." so an accidental launch is all you need.
- Hoff 13y agoIt appears that Facebook may have recently leaked information related to their so-called dark profiles, too; from folks without FB accounts. http://threatpost.com/facebook-underplays-data-exposure-from-dyi-bug-to-users/ http://threatpost.com/facebook-underplays-data-exposure-from...
- daspianist 13y agoIts interesting that many of my post-college friends are finding content on Facebook increasingly less relatable, and therefore using it less. I think part of Facebook's appeal to those still in school is that it acts to reinforce the social bonds that are formed through physical encounters. Once those physical encounters die out, Facebook's use is also diminished.
- tehwebguy 13y agoWhy is there an API for phone number that does not require user consent? Facebook and Google are both at fault here.
- guelo 13y agoIn order to install the app the user has to approve a long list of required permissions including "read phone status and identity".
- mikecane 13y agoSurveillance isn't cool. You know what's cool? Privacy.
- mtp0101 13y agohaha, best comment
- yock 13y agoWe reached out to Facebook who investigated the issue and will provide a fix in their next Facebook for Android release. They stated they did not use or process the phone numbers and have deleted them from their servers. What utter garbage. They're really going to claim it was an accident?
- abraham 13y agoFacebook never said it was an accident.
- kryten 13y agoIndeed. Facebook are a rotten company like this. They'll throw something out, then yank it if they get caught. It makes you wonder what we haven't noticed yet.
- deleted 13y ago[deleted]
- kayoone 13y agoyep, the whole "move fast and break things" mantra doesnt really suit privacy concerns.
- smacktoward 13y ago"Move fast and don't get caught."
- bcRIPster 13y agoThat's annoying. But an app that's more intrusive in my mind is the Flickr app which sends your Geo location back to Flickr every single damn time you exit any camera on your Android phone. Even if you haven't launched Flickr in weeks/months. It's done this for as long as I've been monitoring the apps on my phone (a good year now). I started using LBE to selectively block security requests by apps last Summer after being required to install an e-mail app on my personal phone for work that harvests your contact lists and call history. I soon discovered lots of mischief going on with my phone from all kinds of apps and it was rather infuriating.
- Spearchucker 13y agoThe SkyDrive app on Windows Phone does it too, but because I use that app I just turn the location service off until I need maps. PayPal, for instance, wants access to contacts (why?!?) so I stick with the web site. Each platform has issues like this. We're so used to just feeding the beast that app developers are ok with unreasonable requirements.
- computerbob 13y agowhat if you don't have your gps on?
- wutbrodo 13y agoLocation services can always use data or wifi antennas. I believe most Android phones have an OS-level option to turn off app access to location from these sources (otherwise airplane mode would be the only way to do it, I guess).
- jbail 13y agoYou know what the super not cool part is? Tons of Android phones come pre-packaged with a Facebook app that you can't delete unless you root your phone.
- barredo 13y agoDon't you agree when buying the phone? Just curious
- eli 13y agoI supposed I could have googled it to find out, but I've certainly never had a carrier tell me in advance what apps would be on my phone. Perhaps it's buried in the fine print that I agreed to without reading, but honestly I doubt it.
- qwertzlcoatl 13y agoEvery Smartphone comes with certain pre-installed apps that you might not necessarily desire. But facebook certainly never was one of them. At least none of the Samsung series comes with it.
- archangel_one 13y agoIt certainly was one of them on some phones. I have had a "Facebook for LG" in the past that wasn't removable via the factory phone image.
- jbail 13y agoI just purchased a Motorola Defy XT from Republic Wireless and it came with the Facebook app pre-installed. I immediately checked for a system update (which there was one waiting), installed it and the FB app went away. Usually it doesn't work out that nicely though. My last Android was the HTC EVO and you couldn't get rid of FB unless you rooted it your phone.
- gohrt 13y agoThe Google Nexus One had Facebook force-installed; (I think) it came with one of the OS upgrades, which is even worse than pre-installed, because I really had no choice.
- boi_v2 13y agoFacebook is the best, why bother ask for your phone number if you already told them all your life.
- cseelus 13y agoFacebook grabs or publishes data without users consent. Does that really surprise anyone anymore?
- Bill_Dimm 13y agoThat must make it easier for the NSA to link your phone number to your Facebook account.
- 205guy 13y agoBingo!
- mcrmonkey 13y agoThis is something that has been going on for a couple of years you know
- deleted 13y ago[deleted]
- andymcsherry 13y agoThis is pretty standard in Android apps for analytics tracking to use the phone number, IMEI or other values. A while back, a few production phones shipped where Settings.Secure.ANDROID_ID returned invalid values (null, the same value for all devices of that model, etc). This is the reason that most apps you come across ask for the READ_PHONE_STATE permission.
- Steko 13y agoEveryone is focusing on FB but the bigger problem is that any app can probably take your phone number without permission. Paging Al Franken.
- andymcsherry 13y agoActually, when you install an application you accept the READ_PHONE_STATE permission. So you're explicitly giving them permission to take your phone number. This doesn't really apply to pre-installed applications, but there's really no argument that they're doing it without your consent if you download the application from the Play Store.
- lawnchair_larry 13y agoThere is an argument, because normal people don't know what the hell a READ_PHONE_STATE is.
- wutbrodo 13y agoI'm pretty sure it doesn't literally show them "READ_PHONE_STATE" and other permissions in enum form. There' s a heading and a description of what each permission entails.
- andymcsherry 13y agoThe description is PHONE CALLS READ PHONE STATUS AND IDENTITY Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call.
- guelo 13y agoAndroid's take-it-or-leaveit install-time permission model sucks. I just counted 32 permissions for the Facebook app. When the user goes to install the app they are supposed to review that long list and decide if they are going to take it or leave it. The reality is most users have no idea what they're being asked and just hit Accept. Which means for most practical purposes there is no permission security. Much better is the iOS model where there are a select few extra-sensitive permissions that cause a popup when the app requests it and lets the user decide if they're going to grant it at runtime, not install time. That lets the user know what triggered the request and decide if it's legitimate. It also allows them to continue using an app even if they don't want to share their location or whatever.
- scott_karana 13y agoI agree. I wish Android had denial or "spoofing" of permissions in stock form. I do appreciate that Android points out even smaller details, however: "access to your contacts" is one that works without prompting on iOS, if I remember correctly. It'd be nice if users could choose both the level of detail and choose piecemeal.
- bricestacey 13y agoiOS 6 I believe made requesting contacts require permission.
- rimantas 13y ago> "access to your contacts" is one that works without > prompting on iOS, if I remember correctly. It used to work, but was fixed in iOS6.
- ojiikun 13y agoObviously, we'll never see it in stock/vanilla, but there is something to be said for the fact that you do spoofing at all via pdroid, which takes less than half an hour to set up if you're of the hacker persuasion. I dreamt of such a security setup for two decades before android ever came to be.
- 13y ago
- HackerClues 13y agoDon't forget this app comes pre-installed on several phones too..
- nivla 13y agoI thought this was a known fact. Isn't there numerous articles were people were surprised how Facebook knew and was recommending their dentist/plumber/clients to be added? Towards the end it turned out to be from the contact list uploaded from the user's phone. I am not going to say to avoid FB, but if you really want it on the phone, please use a non-official version for privacy sake. Atleast on android, they are less sucky than the official version. One of those times I am happy a company doesn't make an official version for Windows Phone and the MS version doesn't suck.
- snom380 13y agoNot only that, it seems they will match your phone number if any of your friends upload their contact list to Facebook.
- akaBruce 13y agoThat's not so bad compared to the other permissions on there. With Facebook, I'd guess (maybe incorrectly) you're already listing your phone number on there and they'll eventually get it anyway. I'd like to know the reason behind some other things on that permissions list... https://play.google.com/store/apps/details?id=com.facebook.katana https://play.google.com/store/apps/details?id=com.facebook.k... * Directly call phone numbers: Allows the app to call phone numbers without your intervention. This may result in unexpected charges or calls. Note that this doesn't allow the app to call emergency numbers. Malicious apps may cost you money by making calls without your confirmation. * Read phone status and identity: Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. * Write call log: Allows the app to modify your device's call log, including data about incoming and outgoing calls. Malicious apps may use this to erase or modify your call log. * Read call log: Allows the app to read your device's call log, including data about incoming and outgoing calls. This permission allows apps to save your call log data, and malicious apps may share call log data without your knowledge. Account management I can understand. Location makes sense for checking-in and what not. Reading/modifying contacts also makes sense if you'd like it to manage your contacts automatically. The call logs are the ones that really confuse me. The only thing I can think of that would make sense is charging for Facebook Credits via your carrier and trying not to confuse the user into thinking they're getting charged twice (once via the Facebook App and once more via the phone call).
- vabmit 13y agoAs much as I wanted to install their app, I never did because I didn't trust them. I clicked to the requested permissions screen a few times. But, I just couldn't get myself to go any further. Now, I feel vindicated for my paranoia. I'm sure they're doing many more nefarious things.
- lampe3 13y agoin the newest cyanogen mod nightlys there is the new privacy guard. it basically shows the app a empty contacts lists and other stuff
- ivanca 13y agoDon't worry guys, the data is only for prism so its in good hands </sarcasm>.
- blinkingled 13y agoBetween a UI that looks exactly like the mobile page loaded in Chrome/Stock Browser, draining battery and abusing location/privacy why would anyone want to use Facebook on their Android phone? Delete it, disable it or just don't sign in as applicable.
- meshko 13y agoI assume this is the same app that hacks Dalvik to even work? (https://www.facebook.com/notes/facebook-engineering/under-the-hood-dalvik-patch-for-facebook-for-android/10151345597798920 https://www.facebook.com/notes/facebook-engineering/under-th...)
- interpol_p 13y agoIt's a shame they had to do that. I find that Android is painful to develop for. We had issues where certain Android versions were unable to install our app. The workaround involved renaming some of our data files to use a .jpg extension so that they would be treated as image assets and not loaded entirely into memory on install, causing the device to run out of RAM. (I forget the exact details, as my coworker discovered the issue and workaround at the time.)
- lucb1e 13y agoI'm surprised we're surprised really, to me this is what I'd expect it to do.
- ChrisAntaki 13y agoIf you are afraid of your privacy being violated, why are you using Facebook in the first place?