Facebook pauses app reviews, disables new user authorizations
developers.facebook.com
developers.facebook.com
People who believe in the idea in this kind of platform having an API should have long ago spoken up in Facebooks defense. This is exactly what I was afraid would happen, and I expect worse to come from this "platform review". Given the kind of media coverage here, Facebook seems to have more to lose than to gain from letting random Hacker News kids build on their platform. And if so, they won't in the future.
And it has zero privacy: everybody can see everybody's transactions.
One could equally make the point that Facebook is secure because no one has hacked their servers, and that it is open because it is free to join. That's a pointless thing to say though.
But in any case: yes, there is an inherent tension between privacy and openness.
How do I openly share social information with some people without sharing it with everyone? These principles are in conflict.
I did some work way back when FB got popular on the idea of using probabilistic data structures (ie, Bloom filters) to store contact lists, which could then be shared so that (in theory) only people who knew the same people would also know that they knew them. I built a FB app proving this could work technically.
But there are clear security issues with it - it gives a veneer of apparent privacy but doesn't stand up to attacks.
This is what everyone is talking about and the point you seem to be missing: you can't have this both ways. There is a conflict between privacy and openness.
Since you seem fixated on the crypto-payment thing: Monero mostly solves anonymous payments, but then what? Say I want to buy a pair of shoes with it - how do I stop someone knowing where to deliver it? Any attempt at solving this runs into the same problem: you have to tell someone the same thing you are trying to keep secret, and if that person is the attacker then the system falls to pieces.
That's the real trade-off: we reclaim ownership of our data with knowledge of where it goes and who's using it for what, but that means a full embrace of DRM (something our community has typically been against.)
I agree that could work though.
Well actually that’s very much still in dispute:
The problem is we can't try anything new - since it's all stored in FB's servers, we have to wait for them to build new granular capabilities.
The thought that they can't "do better" than dialogs / strings identifying each permission is laughable.
It's not rocket science.
Who has a financial incentive to build and maintain that system?
As platforms, blockchain is more open than facebook and for access control it's less open. GP was referring to security being at odds with openness in the sense of access control.
That's in direct opposition to security. When you grant people you don't even know much less trust access to your system, all bets are off. There's just no way to predict what is going to happen. You've lost the fundamental protection afforded by trust.
Today, computers are expected to be able to talk to and serve hundreds of thousands of random users. What if one of them has access to a 0day? They could own the machine. The world would be a lot more secure if servers dropped all incoming packets by default and talked to trusted users only.
Bitcoin is open to everyone and that's great, but it doesn't change the fact people managed to sneak a bunch of illegal pictures into its blockchain.
In other words: if you power and prestige comes from getting others to do the work for you, then whose fault is it when they misbehave? It’s your fault.
They didn't get it wrong because they know who butters their bread: customers. Developers are rightly prioritized last.
Fun to give this Paul Graham essay a read again [1].
Apple doesn't have a social network. They also don't rely on advertising and 3rd party data brokering.
It's easy for Apple to be the 'good guys' here when they have physical products as their profit generators.
FOSS would have worked better in the Facebook case too as people and developers would know/discover a) where their data is and b) what risks it faces
Of course part of the answer is that new comments have no votes so a quick downvote will make them grey, but there are frequent strange cases.
One thing for sure is that a lot of people downvote based on disagreement rather than a comment's quality - which in my opinion is not right (and I think against the intent of a downvote), but that's a different issue.
From what I gather (but I don't have any comments at hand), the mods do pay attention to voting behavior, both to detect up-voting rings and to penalize those abusing downvotes. Their usual recommendation, when coming across a comment you think is unfairly downvoted, is to silently apply a corrective upvote.
FYI, want to start off with that to help indicate the likely reason for any downvotes you got on this post.
> One thing for sure is that a lot of people downvote based on disagreement rather than a comment's quality - which in my opinion is not right
Everyone is entitled to their opinion, but it doesn’t make it any more valid than other’s and doesn’t make it a fact either.
> (and I think against the intent of a downvote)
@Dang has said on multiple occasions that the intent wasn’t as you are assuming. Apologies I don’t have a link handy at the moment.
Thanks, I did know the price, no problem.
> @Dang has said on multiple occasions that the intent wasn’t as you are assuming. Apologies I don’t have a link handy at the moment.
I would be curious to read dang's opinion on this if anyone has it, it's not in the guidelines.
> Everyone is entitled to their opinion, but it doesn’t make it any more valid than other’s and doesn’t make it a fact either.
Yes, that is the definition of an opinion.
https://hn.algolia.com/?query=author:dang%20downvote&sort=by...
A couple of the more recent comments:
Although it's possible that there's some confounding happening here, such as the handful of people who hit refresh on HN hundreds of times a day are also ones who can't stand certain political viewpoints. But it seems unlikely. Far more likely is that there are a handful of downvote bots in operation on a keyword basis.
It's not a huge deal to me, but it does seem kind of obvious.
I do this :)
Who's calling me?
Is not possible since they turn downvotes off after 24 hours.
/pedant
As someone who incessantly refreshes HN and spends a fair amount of time on the Comments page, I see no reason why it wouldn't be people seeing new comments to older discussions via the Comments section rather than bots. Although I am a demographic outlier in multiple ways, I cannot possibly be the only person routinely cruising the new comments section.
The giveaway, imho, is a downvote on a completely inoffensive comment, combined with certain other increasingly common patterns.
Between those two facts, I think downvote bots aren't a terribly likely explanation. You would need to establish an account with downvote privileges and then hope the mods don't revoke its downvote privilege in short order. It seems like a lot of work for probably not much pay off.
That doesn't mean there can't be downvote bots, but it just seems to me a much more likely explanation is people cruising the Comments page.
They tried, and failed.
> They also don't rely on advertising
They tried that, too.
What are you thinking of -- iTunes Ping? That was never really intended as a general-purpose social network.
On a general note, I find it frustrating that a lot of the discussions around this area end up with people talking past each other. Some people are concerned about advertising, others about privacy, others about using user data, others about open source software/hardware, others about encryption. They've got some overlap when it comes to specific features, but often get conflated, making the discussion even more difficult. One thing I've appreciated about reading your comments is that you often are able to cut through that quite decisively. Thanks!
>“I don’t believe they are interested in this capability because they have a strict policy around what they do with user data,” Crawford said. “IAd has great assets and great capabilities, but they are going to follow Apple’s policy to the letter of the law.”
So they crippled a potential new revenue stream because of their privacy policy.
[1] https://blogs.wsj.com/digits/2015/07/13/drawbridge-hires-app...
Will be interesting to see what happens with Apple if the i-products do ever decline significantly. (I believe their Brand is strong enough to sell their other services effectively so long as they get the price right).
When iAd launched, it required mid six digit buys for ads. Users complained that they only would see the same half-dozen ads. Over the course of the next two years, that was steadily reduced, low six digits, fifty thousand, and the complaints stayed the same.
Before iAd shut its doors, you could get ad buys for a minimum of _fifty dollars_.
I tend to be a bit skeptical that instead of the platform being a failure, Apple realized after a few years of cutting buy prices that "hey, privacy is important".
That sounds a lot more like a PR soundbite.
And I don't think a former iAd exec has any reason to be doing PR for Apple when the purpose of that WSJ story and his cooperation with it was to pimp his new job/startup.
Perhaps so. And only a few companies bought ads, which pissed off their customers (the ones that Apple is "fighting to protect") because of the repetition.
So Apple lowered the barrier. A failure to realize.
Not sure how this is a dispute of what I said, or somehow proves that iAd wasn't a failure, but a planned exit.
> And I don't think a former iAd exec has any reason to be doing PR for Apple when the purpose of that WSJ story and his cooperation with it was to pimp his new job/startup.
If you think that Apple (or any company of that size) doesn't have non-disparagement agreements with any corporate officer or down to SVP level, at the _very minimum_, you're mistaken.
Even those "we screwed up" articles you see are very carefully stage managed. They're (almost exclusively, save some very isolated high profile situations) scripted as a PR effort to manage customer satisfaction.
What about iMessage?
Facebook has open-sourced a few internal projects, but none of them had much to do with our personal data.
In fact, it's difficult to blame the API when the problem was that the data was collected in the first place. Surely Zuckerberg has some political opinions of his own, if CA hadn't triggered this media storm what would have stopped him from supporting his own favorite candidate internally? In fact, what's stopping him from doing that right now? Would it even be illegal?
Can you produce any quote from any Free Software or Open Source developer or advocate that supports your statement in this context of Facebook being better than Apple because they're "open"? Because even though both companies are terrible at freedom, they're terrible in very different ways, turning any comparison into a false equivalence.
Being a walled garden is independent of privacy. The calendar app on macOS Calendar app allows me to share my calendars in an open format (ICAL) and interoperates with other calendar apps through that specification. It respects my privacy by not sharing anything I don't ask it to without being "walled".
Signal is open and secure; iMessage could be a non-proprietary format and remain just as private.
> all the press coverage of some app developer crying about App Store rejections or onerous rules.
As far as I'm aware a lot of these weren't for privacy matters [1] and are sometimes a little much [2] (this one is specially absurd: [3]).
[1]: https://techcrunch.com/2017/12/08/apples-widened-ban-on-temp...
[2]: https://www.theverge.com/2018/2/8/16992830/apple-emoji-crack...
[3]: https://medium.com/@alariccole/apple-literally-stole-my-thun...
PS:
> all the "open always wins" from the FOSS types
I don't think that means what you think it means. FOSS and privacy are tangential matters.
I totally agree (because it's true of course). But do recognize that it's in Apple's interest to conflate the two. To make it even more interesting, add "secure" to the list of matters.
Actually, the only way privacy can be guaranteed is with code you control running on a machine your control. Free Software (and not Open Source) has everything to do with privacy, as it is about control.
Nobody is complaining about being able to install a Facebook app that harvests your data. The issue is it could also harvest your friends' data by default.
Although honestly I think this is all manufactured outrage. The fact that this could happen was totally public in 2012 and the public weren't outraged about it then.
1 - I've yet to learn about a major open source project stealing data from its users.
2 - Open source guaranty the users have the right and access to check how it's data can be used. Apple's products do not. Actually, we discovered they were part of the PRIMS program, which means basically they gave ALL your data away already while actively lying about it (https://www.theguardian.com/world/2013/jun/06/us-tech-giants...).
3 - FOSS people like interoperability and choice, which is one of the major problems they blame Apple not to take care of. This has ZERO relationship with privacy.
So on one hand you have privacy savvy communities, giving their free time and work so that everybody can use it to built a better word an understand transparently what's going on.
On the other hand you have a multi-billion dollar black box giving away user data, using massive PR to pretend they are privacy oriented while they make money out of locked in devices.
Now I get people enjoy the Apple product experience.
I get they make a lot of things right for this experience, especially for user friendliness, and integration.
And I certainly get they made the industry progress from a technical point of view.
But do not compare their moral scale to the one from the FOSS folks. This is literally insulting them.
Ironically, the “scandal” that caused this whole thing is a non-issue. Pre-2014 Facebook apps could collect a lot of information about you and your friends, along with their Facebook user IDs, and that was scary because there was a time when you could simply submit a list of user ID’s that you wanted to show a specific ad to. But since Facebook advertising cannot be targeted by user ID anymore, and this policy was in place well before the 2016 election, all of that data was essentially useless to any participant in the 2016 election other than for aggregate things like general campaign strategies. I am intimately familiar with the advertise by ID issue - I was awarded a $2k Facebook bug bounty for spotting an exploit in the Custom Audiences feature that allowed an equivalent version of targeting by ID after they disallowed it.
So while it’s possible that Obama used his special access to the entire US social graph to successfully influence his elections, it is impossible for Trump or Hillary to have done it even if they had the data because of the changes in the FB ad platform in between 2012 and 2016. This entire “scandal” was created and promoted by people that don’t understand, or actively ignored, this concept. If you ask everyone that has read the recent headlines, including reporters that wrote the stories, I’ll bet 99%+ will tell you that they believe they could be specifically targeted with ads.
It would be interesting to see if the executives at any of the media companies that have managed to sell this scandal to the public took unusually large short positions in Facebook stock before releasing the story. Since the story is effectively fraudulent (it was not possible for the election to have been influenced in the way that the stories imply), I assume that would be securities fraud.
Yes, that is exactly it. You seem to assume that the only way you can achieve this is by advertising to individual people by Facebook ID's and use this as the basis of your argument that the whole story is fraudulent and instead there is some media conspiracy to commit securities fraud.
Can you see where your logic might be faulty?
There is a lot of information at your fingertips about how they actually used the data, you can go to your favorite search engine right now, type in "how did cambridge analytica use the facebook data" and read the answer. I'd do this first before calling the whole thing bogus and accusing Channel 4 of committing securities fraud.
So yes, the story is fraudulent. The (years old) data that Kogan scraped and sold to CA years after the fact could possibly be used in aggregate to formulate campaign strategy (although because of its age even that use wouldn’t have been very effective). It couldn’t be used to target specific individuals or anything resembling that. If you’re saying they were able to target zip codes heavily populated by people in a given political party sure, they could. But that’s not remotely close to what is being described in the articles.
Also, since you and your friends at the Guardian are implying that they used this data in other ways, see here:
https://www.theverge.com/2018/3/20/17138854/cambridge-analyt...
Even that part of your/their narrative is inaccurate.
None of this implies in any way that they even took out a Facebook advert (in fact they preferred content that looked organic, seeded through various Facebook groups/Twitter accounts), so I'm not sure why your experience with using the Facebook self-serve advertising portal gives much insight here.
In short: they used the dataset to target people, but they did not specifically target people in the dataset.
1. https://blog.hubspot.com/marketing/buyer-persona-research
Finally, to put your comments to rest (hopefully), the data wasn’t used even off of Facebook in the way that you and these articles are claiming. See [1]. Enjoy the rest of your day.
[1]https://www.theverge.com/2018/3/20/17138854/cambridge-analyt...
More like "This specific group of people in X who like guns, willie nelson and dislike bananas would be receptive to a picture of willie nelson squashing a banana with Hillary Clinton's face on it with a caption about 2A". Then, spread this picture organically through facebook groups for people who hate bananas, love willie nelson and guns.
To be clear: the story is not at all "oh no they brought targeted facebook adverts", and it should be evident that perhaps your logic or understanding is faulty rather than a worldwide media conspiracy to short Facebook stock.
Classic liberal tactic: dismiss people that point out the obvious flaws in your rhetoric by painting them as conspiracy theorists. I don’t think it’s a “worldwide conspiracy to short Facebook stock”. I think that the media outlets distributing these stories, which are spreading false information and implying things that aren’t possible (as my comment points out), hate Trump, are pissed that they were unable to manipulate the election in the way that they wanted, and are doing what they can to ensure he doesn’t win in 2020. But it wouldn’t surprise me if they attempted to get a little cream on top and tried to profit from their false narrative by shorting the stock as well. There’s actually nothing wrong with that, as long as the stories are factual, but it’s illegal (at least under US law) when they are not.
the story is not at all "oh no they brought targeted facebook adverts"
That isn’t all of the story, but that is a part of the narrative that is being told, and that part is factually impossible. Further, even the rest of your claims that they actually used the psychographic profiles are simply not accurate. See: https://www.theverge.com/2018/3/20/17138854/cambridge-analyt...
This doesn't matter much if you can do essentially the same thing by targeting with extremely specific location and demographic data.
given the complete graph and add some external data, you can identify those users you should advertise to, i. e. jane@test.com.
BUT: what is still possible, and what Cambridge Analytica was actually building, is slightly different: with a statistical sample of maybe a few ten thousand complete profiles, you can build a statistical model that targets your advertisement not to a user, but a set of criteria: "Males between the ages of 35 and 40 living in a mid-sized town in Texas who liked curling and Star Wars Episode I, but has never traveled to Australia". This is still perfectly possible.
It's likely the latter model performs at least 90% as well as the former, with an upward trajectory as methods are improved. Note that CA probably didn't get this working terribly well. But someone else definitely will.
Intuitively, I am far more uncomfortable with the first. But practically, I can't really think of a reason why.
Prediction: It won't be after the government is done with a new set of regulations, at least for election purposes. I continue to believe this is about the ability to wield political influence, not privacy. The privacy issues have been well known for years, and there's very little evidence of public concern over the privacy, other than newspaper article after newspaper article claiming there is, each one "coincidentally" making reference to Donald Trump, as if he was somehow personally responsible for this debacle, and almost no stories on the Obama campaign who did largely the same thing on a much grander scale.
If someone knows of any convincing independent public polls, with published questions (with the right questions, you can get whatever "answer" you want to produce) that shows that there are in fact widespread public privacy concerns, I'd love to read them. Until then, I'm going to continue to believe this is about the power to influence the public in the political sphere, and predict that the Facebook platform is going to be stripped of that power.
Both of these things were wrong, but it should have been a huge deal back in 2008 and again in 2012, when 4x the number of profiles were accessed and used, about 99.5% of which never authorized Obama to have or use their information.
(a) This was 8 and 4 years earlier. A lot changed in that timeframe. While, yes, there were always concerns about privacy, the string of data leaks, and the increasingly obvious power of statistical methods for targeting, have had a strong effect on the general public's attitude towards the practice.
(b) The Obama campaign did not break their contract with Facebook. Facebook did apparently turn of their API limits, either because of sympathy or because that's just what they did for big clients back then (FarmVille got the same privilege). But in the end, it appears that nobody broke any rules back then.
Now this probably won't convince everybody. So let me say this: even if the reaction now is hypocritical, it seems everyone agrees that the current outrage is justified. If so, it would be foolish not take action now just because "your team" got caught while the other got away. After all, the chances of each party being advantaged by such practices going forward seem to be exactly equal.
(Not to mention the vastly larger universe of threats not involving the two US parties)
While I generally agree with the rest of your comment, Obama did in fact break their contract with Facebook. The developer TOS said that any data obtained through the API was to be used exclusively for the purpose of the operation of your app. Unfortunately, by all accounts, they used this data for purposes outside the app, such as campaign strategy and voter targeting. Further, this was back when targeting Facebook ads by ID was allowed. So they likely did far scarier things than either Trump or Hillary were able to accomplish. We don’t know, because the media was OK with his win, and as a result, nobody investigated the specifics.
This seems like common sense, but do we have substantial evidence proving this, and to the degree of newspaper coverage we're seeing claiming public outrage? And if so, did the outrage precede the news coverage or follow it?
Why DO we have to accept that “public” means big data? Why can’t we legislate access so that aggregate collection of public personal data requires _consent_?
If you can get enough people to agree with you, then great - go for it. But that’s not the point of my comment. It’s that even if they did collect the data, it couldn’t have been used to microtarget you through Facebook ads, even though that is exactly what all of these articles have said happened here.
https://www.facebook.com/business/help/606443329504150?helpr...
Facebook actually cares about this issue. The bug bounty I was awarded arose from the fact that you could build a custom audience email list using user_nickname@facebook.com without knowing their actual email address. So you could simply write a bot that visited Facebook.com/profile.php?id=4 and see that it redirected to Facebook.com/zuck, and now knowing that “zuck” is the user nickname corresponding to user ID 4, you could then put him in your custom audience list using zuck@facebook.com. That worked for all 2 billion people on the platform, because at one point Facebook gave everyone an @facebook.com email address that mapped to their account. However, that issue has been fixed and was fixed before the election.
Meaning that new customers can't connect with facebook anymore to access their own data using OAuth! We don't need permissions about your friends, your photos, or whatever. Just accessing their own messages and posts (which is what our customers want to see in our app and pay for).
I know they are shell-shocked after #deletefacebook stuff, but this overreaction is ridiculous.
So glad it's not our only channel of communication through. Times like this you appreciate email - crazy huh?
The spin from Zuckerberg as a result will be along the lines of "We're really glad you asked that question, and it's one that's really important to all of us. We are prioritising the safety and privacy of our users, and unfortunately that might upset some over-reaching applications."
Where does it say this? Is that in separate reporting? That would be huge.
Not saying an LLC that makes investments in for-profit tutoring companies is bad, really, just not a charity in the usual sense, and not a gift to the public good.
I think people are reading too much into this fiasco. We are better off fixing Facebook. It serves its purpose well.
He hasn't. He has pledged to donate 99% of his wealth to a private, for-profit organization that he owns.
I also pledge to donate 99% of my wealth to my bank account.
I initially thought you were being overly critical here. It looks like you're right, the "Initiative" he created is an LLC and not a non-profit.
https://en.wikipedia.org/wiki/Chan_Zuckerberg_Initiative#Com...
https://en.wikipedia.org/wiki/Bill_%26_Melinda_Gates_Foundat...
The money is out of their hands, and can't be distributed back to them.
If the political benefit really outweighed the costs, then every single billionaire would be doing the same thing, purely out of selfish interest. How many of them are?
Well, they are doing for the selfish interest of feeling and looking good.
And I'm completely ok with that!
There's no visible effort at giving beyond the US Zuck Feelings Tour and hiring professional political hacks as his CZI staff.
Please stop spreading PR. He put the money into a limited-liability corporation, and spread a bunch of articles about a "pledge." It's nothing more then a tax-sheltered investment vehicle.[1] This is not the same as putting it into a charitable trust. He can use the money to influence whoever he decides to give it to.
1. http://fortune.com/2015/12/02/zuckerberg-charity/
"Corporations can make for-profit investments and political donations—and unlike charitable trusts, they don’t have to report their political donations."
Actually, he put his wealth in a tax-exempt “””charity”””.
It’s purpose being?
Maybe it’s the use I make of it, but it doesn’t add much to my life. It could go away and I could replace any of its function with something else, or not miss the function at all.
Cambridge Analytica/Obama campaign data fiascos aside, many are arguing more and more that Facebook is doing more damage than good to society.
Granted, this is hard to measure, but it’s a valid concern.
Connecting people. Communication between friends. Social events.
> Maybe it’s the use I make of it, but it doesn’t add much to my life. It could go away and I could replace any of its function with something else, or not miss the function at all.
So, maybe learn to use it better? Less? Not at all?
> many are arguing more and more that Facebook is doing more damage than good to society.
I wish people who actually use it and benefit from it would be taken more seriously on HN. This is pretty stark "silent majority" scenario.
They will actively ignore problems that deal with public health and security, but promise to "cure all disease" through philanthropy. Please.
But maybe I'm missing something obvious.
This lines up with my experience. I did a ton of (painful) Facebook platform development from 2007-2009 or so, but I haven't followed it as closely since. My sense back then was that there was this huge build-up of activity around the FB platform; they were creating all these new APIs and ways for developers to build super social experiences and deeply integrate with the core FB experience, there were huge companies like Zynga that were entirely dependent on Facebook and also were responsible for tons of FB revenue, etc. And then it all seemed to fizzle? It doesn't seem like there's really hardly any activity any more in terms of deep integration with Facebook as a platform, other than FB login. I never see anything on my news feed any more from weird apps, or get invites to take some dumb quiz, or whatever. I mean, I'm sure that stuff is there somewhere, but not anything like it was. That could be wrong though!
However, apps that request scopes like "user_friends" or "pages_messaging" [1] may error out during authentication.
[1] https://messenger.fb.com/newsroom/messenger-platform-changes...
Or as in many years late? In that case yes. A bit more privacy from the start would've been nice.
Of course, FB could just resort to making everyone's info private. But then it would suffer a serious loss of utility, as many friendships and social connections are validated by the existence of mutual acquaintances. Most of the time this is completely innocent and desirable for all parties, which is what allowed FB to become so popular in the first place.