Facebook scraped call, text message data for years from Android phones
arstechnica.com
arstechnica.com
Of all the things to not copy from iOS, of course privacy is the one that they decide to skimp out on. I'm glad they've started to catch up, but they have a ways to go yet.
Annoyingly I now need to "Request Desktop Site" to use messenger or else it tries to get me to install the app. The artificial friction they're put in place has pushed me ever closer to just deleting my account.
Unless you can audit the code, or someone you trust has, who knows what our devices are doing.
Or you can do it the way FB does it, by asking for permission to access all your pictures and build your own non-standard picker...
Because ultimately, developers don't really need to care. Too many users don't understand the implications at all. And if it's for example a messenger that all your friends use, you don't really have much of a choice than to trust it, if you want to talk to your friends.
http://www.plash.beasts.org/powerbox.html
Note: I'm using this link just to explain the concept rather than endorse anything on the site. It was top of Google results.
Don't you have your friends in a private contacts list/address book? Isn't it trivial to send a photo attached to an email? What is the problem?
Note: I do not and never have used facebook, genuinely don't understand what the deal is here.
The functionality is no different to iMessage. I don’t know why this happens. It just does.
With email, you have to explicitly select recipients. You're essentially saying "here are my photos, I think they are relevant to you specifically". The onus is on the sender to figure out what's good for the receiver, and it's considered rude to send many frivolous or irrelevant messages. Think of how you grumble when you unsubscribe from some company's mailing list - this is an example of this social norm.
With Facebook, you say "my photos are here, anyone may look at them if they want". Figuring out whether the content is relevant is now the job of the receiver, not the sender. Facebook's UI is well aligned with this role: unlike email, where you must explicitly download attachments and mark messages as read, on Fb image previews are displayed inline and to never see a message again you must only scroll past it. Advertisements aren't considered intrusive, it's just content from another source that is (in theory) just as easy to ignore. The social dynamic is very different, and so it's used to send a different sort of message than email.
Edit: ok maybe around 40, not 75. But point still stands, it’s indirect communication rather than remembering about that cousin of an auntie’s grandparent’s nephew’s sister-in-law that I met ten years ago.
Custom ROMs unfortunately can't really do much to implement the latter, they'd have to break compatibility with the whole Android ecosystem, which Google knowingly built this way.
The problem is that not many users understand the implications of just granting permission, so developers don't really need to care.
And this dialog that Android opens is roundabout the shittiest, least usable piece of software I've seen in a long while, so for an developer it actually can pay off to ask for full permission and then build your own file selector even if you have no malicious intentions.
Others here have mentioned that iOS also supports basically this the same way as Android, though presumably they have not quite managed to make their file picker quite as shitty.
And then, well, browsers have worked like this since forever. So, presumably Firefox OS works/-ed like this, too.
I do agree it would be nice to have “Just once” on pretty much every permission dialog. Apple’s change to mandate an “Only while using the app” on location info after Uber’s location tracking fiasco was a good step in this direction.
Instead, apps that want to steal your pictures request access to all of them.
Side note, there was also a project at one point to create Web Intents. I wonder what the web would be like if that had worked out.
But yes! It exists, and most applications could pretty easily use it instead.
But most of it seems to be laziness / misunderstanding. And Android's broadly terrible documentation does not help this at all. E.g. a huge number of apps that want external storage permissions just use it to store external caches outside your system partition, which is very nice for people with an SD card / limited internal space. Many companies don't seem aware that this no longer requires any permissions though - you can store internal and external data in your app-sandboxed folders by default.
If you don't request camera permission, you can still open the camera with an intent. This is great!
If you do request camera permission, and you are denied, you can't use that intent either. https://blog.egorand.me/taking-photos-not-so-simply-how-i-go...
I honestly can't tell if it's this way to be intentionally hostile to users, or by accident, or if they honestly think this is a positive quality.
Usually I hate the in-app cameras, because they're not optimized for my device. They're usually slower, have no flash control, no zoom, no manual exposure options, etc. I'd almost always prefer to use a dedicated camera app instead.
Because of this permissions decision, if an app wants to bake in a camera thing (nearly every app that might ever touch the camera does, even if e.g. only for a QR code reader or something), I can no longer choose. The app can't open my camera app when it makes sense.
That appeared in 4.3, hardly accessible. Was made somewhat more accessible in 4.4 and then was patched out in something like 4.4.1 or so. I presume, some Google exec got to know of it and demanded it removed.
Starting with Android 6, there's the new permission model, meaning that a similar screen is added to the settings of each app, but it doesn't show when an access happened (or at least it does not for me on Android 8.1).
If you don't know why it's illegal: WhatsApp uploads all of your contacts to their server. Granted that their ToS are not themselves ruled illegal at some point, it is on you to get a written permission from all of your contacts that they are okay with you uploading their data to WhatsApp's servers.
So, unless you block access to all of your contacts or actually ask every single one of your contacts for written permission, it's illegal. With selective contact access, you could at least attempt to only grant access to contacts that you actually did get written permission from, or I don't know, of which you know for sure that they are using WhatsApp, too.
And yes, I do love the thought of hitting on someone in a bar and then pulling out this massive form sheet to ask for their written permission, just so you can ask for their number afterwards.
In your example, this sounds silly, but it's just not categorically different from examples where it doesn't, like say someone who stalks me asks you for my phone number, or a scam caller does.
Is some person a person I want to talk to?
Do you not know and are just hoping for the best without asking me?
Never installed the facebook app on any of my phones (In the odd event I REALLY need to check a cat picture on facebook, I use the browser version). Glad I went that route.
Now though I got a Samsung phone that has the facebook app preinstalled, but I never opened it (and all the other preinstalled apps DONT have the permissions on by default...so I hope it's true of the FB app too)
By pre-installed I mean impossible to uninstall without rooting and flashing a different ROM.
The only difference is the you don't get your space back since preinstalled apps occupy a different partition, but the app itself cannot run in any way.
AFAIK Android's current permission system is very similar to iOS's one with granular permissions granted at runtime for camera, contacts, etc.
Once you give something to Facebook; it's never truly erased.
Edit: May 25, of course.
The way things are framed to make them seem good is very interesting. What if I proposed we make keeping records of past information and actors encountered illegal if they don't want you to remember, while at the same time make it trivial for the same people to waste your time by demanding free consulting?
The stock is back to where it was in July. Up 100% in less than three years.
$464 billion market cap.
Things are really dire. They'll only earn $20 billion this year, growth will only be 30%+.
They only have ~$43 billion in cash right now with zero debt. That's barely enough to keep the lights on. They should shut down the business right now before they run out of money.
The speeding tickets they might one day get from the EU, could cost them hundreds of millions of dollars. But just imagine, what if it's $3 billion. I mean, it's not like Facebook can reluctantly change several of its policies while maintaining its massive 2+ billion userbase and keep right on printing money at their 50% operating income margins. Yeah, but just imagine if their operating income margins decline to only 40% because it crimps their business model by reducing the value of their ad targeting. And what if it cuts their growth rate in half? Under that scenario they might only earn $30 billion in net income in 2021. It's a rough road ahead.
The other fun part? They'll still net add global users in 2018. None of this is going to matter for the survival of their business, although it might improve user privacy around the globe and that'll be a big win.
If you think solid $ numbers are everything to keep "printing money" then see what happened to Kodak or Sony.
At this point, I’m very skeptical another company will unseat FB’s dominance for quite a while, if ever.
Instagram was growing quickly and could seed the next big FB competitor. So FB bought them for a $1B valuation almost everyone thought was crazy at the time.
WhatsApp could seed the next big FB competitor. So FB bought them for $20B or so, which again was mostly considered crazy at the time.
Neither of these is crazy in retrospect: FB's dominant position is easily worth what DB paid for these and more.
FB didn't manage to buy Snap, so they started waging war, adding Snap's features 3 times (to FB, WhatsApp and Instagram).
FB management is actively trying to stay dominant. MySpace was, in comparison, passive; and friendster was never as dominant.
I personally think what will kill Facebook is simply maturing internet and hence maturing people that use it. Most people (family) I had on Facebook deleted all their likes, and pages their follow, and artists they listening to; my brother told me "I have no idea why I added this dude guess I was young". Eventually I bet 30% of Facebook will wake up to privacy abuse FB made its business, and will move on.
Disclaimer: my view can be distorted, since I'm building a new social network.
It will look like something else but turn out to be a social network replacement in retrospect.
Microsoft was not dethroned by Linux or free software (cheaper and arguably better) - it was dethroned by mobile phones. And it’s still alive, just not the king anymore.
I'll try that. Then kill the fake account.
I don't want all my FB contacts to "see me" on Insta; I just have tonnes of people adding me with no real interaction. The integration is really quite obnoxious. I have in fact stopped using Instagram now due to this.
The best breakdown I've seen of this issue, including glib comments from Facebook: https://gizmodo.com/how-facebook-outs-sex-workers-1818861596
I understand that recent versions of Android have moved towards adopting a permission model closer to that of Firefox OS, though, and I suspect that the example given by Firefox OS at least showed that it was possible.
P.S.: Yes, Firefox OS had other problems. Let's not try and idealize the past :)
I don't see how revoking permissions solve that problem. Once an app has scraped your info, you can revoke it's permissions all you want, it is not going to delete your data from its server.
Other services ask you to give them your email username and password, so that they can scrape your inbox to discover your contacts. I think LinkedIn used to do this, but they appear to just use SSO with the largest providers now.
I can't see any justification for collecting the actual text of my messages.
But if I'm digging for justifications, I can see some benefit to me, the user, of collecting aggregate stats of who I contact regularly. It could be used to decide what content to surface in my feed. Or whose birthday to remind me of. Or which names to suggest when I create an event invite. They are a social platform, after all, so knowing who I socialize with seems relevant to making that work better.
Not that it isn't creepy, but if the question is whether there's an actual benefit to their having the data beyond just targeting ads, it's somewhat plausible.
> This screen in the Messenger application offers to conveniently track all your calls and messages. But Facebook was already doing this surreptitiously on some Android devices until October 2017, exploiting the way an older Android API handled permissions.
read your text messages (SMS or MMS)
read call log
Was nobody able to make the inference that facebook might be uploading this stuff to their servers? Remember this was during the whole "facebook is surreptitiously listening to our conversations" fiasco."It'd be too risky to their business for them to do something like that!"
"Someone would have leaked the secret by now!"
"There's no way a company that big could get by doing something that blatant!"
I think people just don't like uncomfortable truths, even when staring them in the face.
I think most people would be surprised if they discovered that apps were uploading their emails. And photos. And tax documents. Just because they happened to be on the hard drive, and there were no permissions to prevent it.
Expecting FB to not do similar and respect basic privacy by default is reasonable. FB doing such things just because they can is not.
It says read, not steal and keep in their own servers.
On mobile, suddenly, it's: lol, you gave it away!
That makes little sense. Yes, we should have better sandboxes - but we still have very few (none) usable general operating systems with Internet access that are "secure beyond trust".
Absurdly, I'd be more confident in a typical Debian install with thousands of programs from "main", some running in the kernel - than a typical Android device.
Because of presumed incentives for the volunteers/employees working on debian and the various upstream projects.
This is 99% about trust and incentives and 1% about capabilities.
But still, IMO it's an incredibly invasive, incredibly dumb thing to be doing in the current context for the small benefit it brings. I hope they wake the f* up to just how bad it makes FB look like to the outside world, and kill this feature with fire.
There are alternatives, such as using the mobile web interface, or any of the various apps that wrap the site, such as https://f-droid.org/en/packages/it.rignanese.leo.slimfaceboo...
So put me in the “not surprised” category, but I’m really glad there’s more discussion of this.
Now a lot of that data is dead data. Like it has no use after a couple of years. But just like Google cookie having an expiration date of 20 years, FB just does not know when that data becomes irrelevant.
FB and zuck have this manifest dream of figuring out connections and then figuring out the strength of those connections. Then they want to figure out social relevance. Then they want to use that info to bind people together on their platform. It is not a bad idea overall, until you add in government and corporate entities.
And by that time you know how evil of a thing you signed up for.
What throws me is that I'd expect security conscious developers to be clamoring for this. If I'm writing an app that should store data for users on the user's own accounts, it's not "I do not want to have access to everything" it's "I do want to NOT have access to everything."
I for one, am glad web apps are making a comeback. Now I use web apps wherever possible, fully aware that I can't do anything about what's already been shared.
Just FYI: a lot of other apps also utilize the same permission. Just an aside but Google also has the authority to whitelist certain applications for these permissions - meaning they can enable certain invasive permissions without asking the users.
We shouldn't just vilify Facebook. It was how the privacy framework was designed for Android that's the issue. This will change in the next upcoming versions.
Fake news for fake data:)
Right now, an app can force a choice: enable all the permissions, or you don't get to use the app. Users need to be able to feed fake data into the app. For example, maybe Facebook should think I am spending my time with Bill Gates in Bhutan. Users should be able to install dishonesty plugins to generate this data.
On one hand, its pretty reasonable to say that absolutely nothing changed at facebook. We are all witnessing the effects of latency.
On the other hand, the change(s) that has ushered in this uptick in negative opinions in regards to Facebook will likely be the source of vigorous debate for some time.
For one, this is just the latest example of habitual behavior on Facebooks part, selling third parties more access to personal data than the persons referenced are comfortable with. The response every single time has been for Facebook to say roughly "We agree in principle that we slightly messed up, and as our more than adequate self imposed penance, we will solve this problem in secrecy with the completely untested technology that we've been working super hard on ever since we discovered this problem 2 years ago, but only acknowledged publicly as a strategic move when no better alternative existed to preserve our viability as a corporation".
Additionally, the data subjects do not generally understand the power imbued to the purchaser of that data at the point they give away that data. Further, they possibly are giving up the legal right to any privacy stemming from what that data may tell third parties.
In the context of all of these generally nebulous problems, is the growing news story involving Cambridge Analytica's alleged use of Facebook's data, the Presidents use of both of those, and the extent to which it can be argued that voter outreach crosses a line in to deceptive psychological manipulation.
Its what folks in scientific fields refer to as evidence that supports, as opposed to weakens, a falsifiable hypothesis.
The Custom ROMs that exist around it do not play into this. They cannot influence how shitty the ecosystem is, as that's entirely in the hand of Google.
The problem is that it's hard to write an interesting Mac desktop application that runs in a sandbox. The kind of complexities that require a full blown desktop application just don't fit in a sandbox. (As opposed to a game, mobile, or web app.) Whatever runs in a sandbox turns out to be just a prettier version of a web app, or a self-contained game.
I struggle to find out how they are not "interesting" or usable. But I get that it can be hard for developers integrate all constraints of sandboxing.
App Distribution on MacOS was always different (even since pre OSX) compared to the rest of UNIX world. The drag-and drop to deploy for instance must seem ridiculous for people used to install via apt-get command line. Yet it’s way more users friendly because it put the burden of complexity in developer hands instead of users’s.
Put a few app developers in jail for what they do and render their businesses bankrupt and maybe we don't need to treat our phones as hostile to their owners?
Back in the day, apps that did this were called spyware and would be forcibly removed by Antivirus/Anti-malware programs. It's incredible that Facebook gets a pass for equivalent behaviour.
Right?! Remember when ad/spyware that tracked every site you visited were considered devilish and flagged by virus scanners? Now it's the norm. Crazy.
For example: which of the following permissions does the Facebook app currently get on Android?
- access Bluetooth settings
- access nfc settings
- view network connections
I bet you don't know off the top of your head, and I'm certain that fewer than one in a hundred users do.This is not because Android team is lazy. All of this information is already surfaced to those who care to look, right there in the play store app. There's a spectrum of options between removing capabilities, presenting them in more detail, and providing a UI that doesn't make people's eyes glaze over. There is a constant tension among these three poles, and no matter where you are, there will be some use case that isn't served well.
Often the "it's too complicated" excuse is really a cover for "we make out money off your data and fund the development of this software to harvest it".
Mass market customers don't read contracts and readily give out SSNs, credit card info, and other personal identifiers.
As a law prof. at NYU said,
>“For the most part [having read the contract] doesn’t matter,” she said. “Things don’t usually go wrong — except when they do. And then it matters.”[0]
[0]https://www.nytimes.com/2013/07/13/your-money/novel-length-c...
Do you have any studies or sources that support a permissions dependency tree approach for mass market customers?
I like "just-in-time" permissions (i.e. This app wants to use your location. yes/no?) That way, you aren't faced with accepting or not using the service at all, at the outset. [0]
[0] https://news.engin.umich.edu/2017/10/nobody-reads-privacy-po...
This "just in time" stuff is awful, in it's simple form, the user only has to click incorrectly once. The obvious way is a dep tree. Start with:
"should any app be able to download your contact list?"
if no (global!!) -> "can I have one contact right now" and tag that information for the provider "I don't expect you to keep this" or "please keep this info and use it to market to me". Really, it's mostly just excuses, there is no reason to upload the data 99% of the time, only the local software "needs" it for a instant, and even then, that's because the OS stack is designed wrong. I don't want new law to mandate this stuff, I want users to demand it with existing contract law.
Making it "per app" instead of global settings with very deliberate and specific (one time unless instructed otherwise) exceptions is exactly what I would do if I wanted to design a system to maximize my user data snarf ability.
Android is new, nothing is "great" at first, I'm not expecting it to be right yet, but ignoring obvious fixes like this going forward is (hopefully) going to give it's forks more power.
Android started off with a blanket permission screen required to even install an app — all or nothing.
I think Apple didn't always have that. There was the Path scandal and outcry that caused Apple to introduce better privacy options.
The issue is (in old versions of Android) you cannot be selective about which ones you grant.
The relevance is that when it comes to transparency, the big dialog of all permissions can disclose a fair amount of detail to the user about exactly what they're being asked to allow.
The difference is that before Android, in the world of windows - we already had a culture of spyware bundled with freeware - as well as viruses/RATs - and plain malicious software - that made it plain that simply allowing random code to execute in a context where it could read data and/or sensors (gps,mic,camera etc) would be a disaster.
There were to workarounds: stewardship (the Linux distro model, like software in debian main etc) or sandboxing.
Android chose too little of each, which essentially amounted to a false sense of security. And here we are.
But in other cases, this is also just Google that we're talking about. There's for example a presentation [1] where a Google dev introduces this new permission system and afterwards someone from the audience asks, if it's also possible to block internet access with it.
And the Google dev responds in the most innocent of ways that it doesn't need to be possible, because clearly the rest of their permission system works so flawlessly that no critical information one could want to upload to the internet would be available to apps anyways.
I know, never attribute to malice that which is adequately explained by stupidity, but it's not like the guy should be able to be this ignorant in the position that he's in. And Google does have reason to be malicious here. Without internet permission, their ads can't be displayed.
Especially the example in the video of the flashlight app is one where the permission system falls completely flat. In order to toggle the flashlight, you need to ask for full access to the camera, meaning you can take pictures as you like. And since you have internet, you can actually do something malicious with those pictures, too. Clearly, the user did not intend for their flashlight app to take pictures and much less so for it to upload them to the internet.
[1] Relevant question is at 18:07: https://www.youtube.com/watch?v=f17qe9vZ8RM
Just being able to write an app (code on the device) and deploy an ad (code on the Internet - possibility to run "code" like fonts, or trigger calls to site/unique.jpg) - would make preventing data exfiltration and/or tracking absurdly hard while continuing to cater to advertisers aka the paying customers.
Technically it is NOT google's fault to open those access to Apps.
Just like credit card CVV, the right to grant you the access to it, prohibit you to store in your server. For personal information, I think social networks need to be held responsible to live up to the same standard.
By granting Facebook permission to read my contact, my understanding is that they should only use my contact to match against their DB and find those who are on FB. I don't think this require them to persist all my contact/conversation history in their own server.
That's why, of course, chips for physical purchase have moved to one-time codes, effectively, so that your credit card number can't be stored without permission. Ideally, someday our online purchases will work the same way.
I am not a fan of operating systems that deliberately obfuscate things that could technically be done. If I was developing my mobile customer service app then I would like to develop it in such a way that it would not mysteriously fail due to some overly complicated access keys. Or to require a 'rooted' device.
I would not expect my app to be fit for the Google store though. Or any other online app store. Maybe rather than permissions it is the store and what is allowed in the store that is a problem.
Is it just me or has a whole generation lost the concept of personal responsibility? I don't use FB because it's been obvious for a long time this was happening, and it's an awful platform, designed to socially engineer their flock of product people.
Use products that you control. LineageOS + FDriod is a great start.
They can scoop your contacts and SMS messages in 10 seconds after the first permission was granted. Maybe permission should also limit the number of contacts/messages it can access.
As I wrote in another thread, I have used LinkedIn for a long time, and I have never wanted it to spam my contacts, so I have always had it foremost in my mind to click "No" whenever it asks to import them. Yet at some point, it did it anyway, because it asks me if I want to connect with people who are only email contacts and not on LinkedIn.
Now if you had complete logs of everything I did with my phone and computer, you might well be able to prove in court that I inadvertently gave permission at some point - perhaps I didn't read all of the legalese on something, or perhaps my finger slipped and I forgot.
I can't imagine I would find anyone at LinkedIn who cared about figuring out what happened, regardless.
There is something perverse, in my view, in appealing to "personal responsibility" of individuals dealing with corporations, as it seems to me that the entire concept of a corporation is a way for people to work together as an entity without taking personal responsibility. The reason we have corporations is because it's impractical for people to be held liable for their screwups.
What’s obvious to you in your very limited field of expertise is not obvious to everyone. You shouldn’t insult everyone who isn’t a programmer by equating that narrow expertise with personal responsibility. I wouldn’t assume that your inability to understand a conversation between two surgeons meant that it was acceptable to harvest your organs.
Relying on experts to audit things is obvious and correct, but they must be "anyone", not just a select few that get to see the details. Maybe I am not qualified to evaluate something, but that is never a reason to prevent me from looking at the same information the experts have, in fact that's how those experts came to be.
The fact that some people don't care is irrelevant. They get tricked, and learn. Consider how many people are re-evaluating what FB even _is_ right now.
"The alternative goes right to rules that prevent everyone (not just FB) from remembering things, and ultimately more censorship."
Which is why societies have come up with a far better method: collectively decide (or collectively choose people to decide) on reasonable limits for certain types of transactions.
My German law professor used to say that she never read ToS. Because under the country's law, they are either reasonable or unenforceable.
Such laws have nothing to with censorship. If you really need your users private messages, you just have to more explicitly present them with the choice, and respect their decision to say no without unreasonably denying them service.
The US has far more lenient standards for such one-sided contracts, but the basic principle is obviously the same: If Facebook were to add a paragraph giving them ownership of your house somewhere deep in the ToS, they wouldn't stand a chance in a court of law.
Why else would nearly every single popular conservative media "character" be so uncannily similar? Why did nearly all of those characters triple down on this machismo roughly 18 months ago? Could it be that they got back the results of their latest A/B test?
I think this all drives at the most interesting, world changing possibility that could come out of this reckoning with Facebook. What will happen when it becomes conventional wisdom that the true power of collecting all of this data is not the ability to predict what you will do, but the ability to direct what you will do? What will happen when it truly registers with people that this necessarily removes their agency? What will prevent that critical mass from making the trivial jump in logic that advertisers and public relations firms have been progressively improving on these same skills to the same general ends for a century?
Don't use Facebook - it's basically a tool for turning any little aspect of your social network into ad revenue. Communicate directly with people you actually value and fuck the rest of 'em.
Don't use Dropbox, their employees have access to all your data, so does someone who breaks in. Encrypt your data before it hits the internet or forget about it.
Don't use a paid VPN service for anonymity, they have your billing data and connecting IP directly and you have no way to verify if they "don't log". Don't trust them. Use an anonymity network which tries its damnedest using technical means to mask those sorts of details.
If you give someone else your data, think not what they can legally do with it, but what they can technically do with it. Write laws all you want, Facebook will still abuse your data to the maximum, attackers will still get access to far too much data, it doesn't help. Personal responsibility is the final solution to the problem. When you give someone data, always assume the worst. Computers have an amusing tendency to tend to make technical feasibility into reality.
I have to think that violates phone tapping laws in certain states.