Facebook’s Onavo Gives Social-Media Firm Inside Peek at Rivals’ Users
wsj.com
wsj.com
This is not clear from the app description -- there is only a generic message about monitored app use, to which users are so used as to not pay any attention.
> "The app's privacy policy says it may share information with "affiliates" that include its owner, Facebook. "As part of this process, Onavo receives and analyzes information about your mobile data and app use"
> A Facebook spokesman said it is clear when people download Onavo what information it collects and how it is used. "Websites and apps have used market-research services for years," the spokesman said, noting that the company also uses outside services to help it understand the market and improve services.
Then Facebook can attack the competition by seeing in real time how usage of competitive apps varies in response to new features and inform acquisition decisions.
> Onavo's data paved the way for the purchase of WhatsApp for $22 billion. Onavo showed the messaging app was installed on 99% of all Android phones in Spain -- showing WhatsApp was changing how an entire country communicated, the people said.
I remember how big a deal the News International phone hacking scandal was; this actually seems much worse.
I'm having a hard time imagining what they did is OK, but I'm probably wrong.
It would be great if an unrelated leak were to happen, though.
To be completely honest, I don't remember. It was 2 years ago and I sit on lots of these pitches. I remember pushing back on them about the methodology, hearing how the sausage was made, and noping right out.
I want my team to be able to spend marketing dollars efficiently but I would never compromise my ethics to do so. Luckily I work somewhere that I can give a justified 'no' and keep my job.
That is lucky! Where do you work?
Currently - head of data engineering at Minted
> That is lucky! Where do you work?
They'll even set their own search engine as your default homepage.
I'd put it this way. My first inkling that something was wrong was when Norton Anti-Virus shifted to a subscription model and charged me full retail for a renewal back around 2006. What does disabling virus updates for ordinary users with the explicit intent of leaving them vulnerable says about a company's attitude in regard to long term trust?
I left Norton for Kaspersky and paid it protection money for a few years. It seemed refreshing at first. One day, a few years later, I learned how to look at my LAN traffic and saw how often I was sending data to its servers. It was more often than seemed reasonable. That's about the time Microsoft started providing its own free anti-virus and I started switching machines...the Windows XP Professional x64 box stayed on Kaspersky despite my misgivings until I upgraded it to Windows 7 because Microsoft did not port its anti-virus to that platform.
Spyware is often the basis for free software. Adobe Reader and Google Chrome and the Ask toolbar that shipped with Java are pretty obvious examples.
DNS can't log your activity on a website, can it? All DNS does is resolve hosts, right?
DNS service can log that you resolved a host, but doesn't know what you did with the IP address it returned.
Is that technically correct?
It stands to reason the average internet user probably then made a visited that IP.
There is a huge segment of the semi-tech literate crowd that feel wise for using it. I think it's because it's the only time they get to type in an IP address and it makes them feel l33t.
It is probably better to use OpenDNS, but they used to do the same spammy redirect on NXDOMAINs that ISPs do (I think I heard they stopped that). To be honest, the real reason I don't use them much anymore is that their IPs are harder to remember. It's easier to do 8.8.8.8 or 8.8.4.4.
They could also ping you with a fb notification as soon as they see you reach for Snapchat, to get you back on their platform
I assume at least #3 should be achievable with additional encryption.
Shady af.
Given the amount of data Facebook has about everybody, I find that possibility worrisome. It seems obvious that a campaign strategist could segment individual states, regions and cities. They could target people based on likes and interests. They could get very granular with messaging—advertisers can do this through Facebook right now.
But what other information could be used that advertisers don't have access to? Application usage, website visits, WhatsApp message keywords?
Don't forget "private" conversations on messenger.
Having all your Likes - even the things you've unliked - so they know which celebrities to put in front of you.
Having all of your browsing history+who you interact with and the language you use gives them near-perfect understanding of your opinions on policies and politicians going back the entire life your account all over the internet.
That becomes incredibly simple to manipulate.. as I quoted yesterday:
> "We predicted that our manipulation would produce a very small effect, if any, but that’s not what we found. On average, we were able to shift the proportion of people favouring any given candidate by more than 20 per cent overall and more than 60 per cent in some demographic groups. Even more disturbing, 99.5 per cent of our participants showed no awareness that they were viewing biased search rankings – in other words, that they were being manipulated."
Ref: https://aeon.co/essays/how-the-internet-flips-elections-and-...
I see Zuckerberg being in a position to do the same several steps in advance. If you send the right corporate execs the right embarrassing information they could certainly refrain from recommending that their company donate to an anti-Zuckerberg PAC.
- Expire non-critical data after 30 - 90 days, e.g. activity data, not account data.
- When feasible, have the client encrypt the really private user data, only store encrypted blobs on the server (Protonmail does this).
- Send out a positively worded, subtle email notice to warn the more savvy users of a pending acquisition, as soon as that news is no longer private. Let them disseminate the real sitrep on social media and in the news. We did build a community, after all.
- Propose a data architecture update for great efficiency, in which redundant and superfluous data is cleaned and aggregated, before the big handover.
Are there any other suggestions? I am particularly curious if the laws of any one user's country could be used to complicate or thwart a bulk handover of private user data to a new owner. Europeans, I'm looking at you for advice.
And then only keep the data you actually need. And even of what you need you can probably anonymize a large chunk
> A Facebook spokesman said it is clear when people download Onavo what information it collects and how it is used. “Websites and apps have used market-research services for years,” the spokesman said...
This is such a bullshit, disingenuous statement. It is not at all clear how Onavo uses your information. They have just one line in their description: "Onavo receives and analyzes information about your mobile data and app use." Here's why this is deceptive:
1. It is buried. It is the last line, below the "more..." fold so most users don't see it. Something this privacy-invasive should have a prominent, clear disclaimer at the top.
2. It is misleading. Even for the users that see it, they make no mention of using your data for market research. They prominently advertise a feature that reports on your overall data usage -- to you, the user. So this statement is just vague enough to imply that's what they're doing, without setting off alarm that they're spying on your every move for their own purposes.
And then they have the nerve to equate it with "market-research services" that everyone uses.. no big deal.. move along, nothing to see here.. What baloney. Typical market-research services do not involve spyware that you trick people into installing. Participants are supposed to know exactly what they're participating in. That is clearly not the case with this deceptive, exploitive app.
[1] Some previous discussion: https://news.ycombinator.com/item?id=14970877
and IIRC also enumerates running tasks. So it's probably simple to do analytics for the whole phone...
I would be curious to hear your feed back on Xposed oand Xprivacy. Also it sounds like you stopped using them, maybe you could say why? Cheers.
Otherwise, Xprivacy's UI is a bit of a pain, but it's usable...
What's next? Giving every child a free phone on their 13th birthday? They already "gifted" the world's poorest with free internet. It's easiest to abuse those who have the least power to fight back.
"By accepting this gift, you agree to our Terms and Conditions and Privacy Policy."
https://facebook.com/l.php?u=https://www.wsj.com/articles/fa...
Maybe that's the kind of data they need to reconsider their approach to privacy.
http://www.mydatamanagerapp.com/privacy-policy/
I wonder how many apps like this are out there?
Does anyone have any other sources that can confirm or deny whether Google/Apple use their mobile OSes like Facebook uses Onavo?
One commonality among all of them is being marketed as a service for smaller-scale companies while having the double-edged sword on the backend that is most likely what they are really after
EDIT: smaller scale companies and individuals
Although not quoting until now (my mistake), my reply was specifically in response to your previous point:
I don't think that's a reasonable comparison [...] it doesn't give insight into competitors metrics unless those competitors choose to share that information
The lines begin to blur especially when discussing means of accessing the internet (especially most efficiently/safely) and/or core (semi-artificially-required) mobile phone operating system components!
If nothing else they offer the path of least resistance. Any best-of-breed solution (GMail, Google Docs, Chrome - all somehwat a matter of opinion) or de facto monopoly-ish position (search, free analytics, Google Play Services?) by Google offers the potential for them to gain info on competitors in much the same way Amazon can take over succesful verticals originally occupied by a third party.
I've had to submit photos for online financial services/compliance, but not a social network that is tied into all kinds of other data.
And that's what they asked because I wasn't running javascript. It raised my concerns about what they do when I do have javascript enabled on their services. And I work in a company that collects data from its clients -- but nowhere near their scale.
Wonder what their TOS allows them to do with just that data.
If you can't replicate it through a standard browser, try through a VPN or TOR browser.
It's also incredibly shady.
[1] https://www.howtogeek.com/180175/warning-your-browser-extens...
https://www.facebook.com/l.php?u=https://www.wsj.com/article...
I work in a small company of less than 50 people and different teams/depts. barely know what each other is working on.
https://blog.mozilla.org/security/2010/03/31/plugging-the-cs...