I believe, a reasonable person, would expect the limits of the access grant to end with the purpose of the app (a quiz) and not extend any further.
Most contracts/agreements have limits and this one is implicit in the working of the app. It is in no way clear that the app is earning it's money by selling/manipulating the data you're giving access to.
Additionally, it's disingenuous to ignore that a subversive app will make up/add features in no way benefiting the end user but for the sole purpose of scraping messages.
Intent is important, for some of these apps it is clear the only intent was to harvest data en masse.
Yes the user agreed to grant some permissions so a quiz could be taken. It cannot and should not be ignored that the app developer purposefully did not disclose the true nature of the app. This wasn't an accident. They didn't trip and fall into the data. They made something appear benign when it was really cancerous.
You had to authorize the messages permission separately from all other permissions. If you didn't want your messages accessed, you simply declined that permission. This one's on the user, not on anybody else.
The Obama For America app stole data from about 4x the number of profiles that this app did - about 200 million people, less than 1 million of whom gave them any form of consent, much less informed consent, as was given here with the messages permission. Do you have an issue with that app’s title?
Everybody (and Facebook best of all) knows that users will click [Accept] or [I've read the 27 page T&Cs] or [I hereby give Cambridge Analytica my firstborn child] without even slowing down to consider any consequences - in return for another tiny dopamine fix.
Perhaps the personality quiz example that seems to be the cornerstone of this whole CA story is different: I'm not sure what your expectations would be allowing such an app access to your messages would be. However, there are quite a few examples of strange behaviour of software running on phones that it's pretty clear that isn't what you had in mind when you opted in. An example that comes to mind is Facebook apps activating your microphone to log conversations with people you have in person (I'm not sure there is any proof of this one yet but would anyone be surprised?): when you opt in to microphone use it's so that you can make calls on the app not to invite spying. "But you opted in!" Yeah, okay. "Sorry!" - Zuckerburg
I feel like private messages are something that should never be granted to third party apps on Facebook. People just click allow because they assume whatever is listed, is being used for the purpose of the application.
Users are only being asked for permission to their "messages", are given no further information, and can not proceed if they do not submit to the request.
If you're a good hearted person, you assume that an app needs to use your messages for one specific purpose, much like some apps ask permission to your text messages just so they can automatically validate incoming sms code requests.
Anyway..
So permission to access your messages could mean "we just need to do one thing" or it could mean "we're going to siphon up all of your private data"
The generically worded option preys on the user to be trusting enough to give the other party the benefit of the doubt, which is not how the system should be handled and really is the entire focus of the GDPR being passed in Europe right now to prevent specifically this sort of thing from happening.
Waving 'user consent' around as a reason to do nothing is the wrong approach.
All people should have an expectation of privacy that when they send a private message to someone, that someone does not have the right to disclose the conversation.
We're getting a little ridiculous here. There are valid complaints against Facebook in all of this - this just doesn't happen to be one of them.
The difference is that email forwarding is part of the RFCs and IETF standards that define email, e.g.:
https://www.ietf.org/rfc/rfc5322.txt
Whereas with Facebook, while one or more parties might be bound by some agreement with the company, that doesn't create any clear agreement between users.
If you have a problem with usage implying consent to a TOS then you can make that argument, but this one is flimsy.
They see a "forward" button in their email client. Just like Facebook Messenger has a "forward" button on messages.
No one is expecting a different level of privacy in Facebook Messenger over email because of the IETF.
Facebook makes a lot of noise about privacy (using their own definition, naturally, being 'preventing anyone outside Facebook from seeing your data') so it's reasonable for a nontechnical user to not expect that an acquaintance installing a "what's your pirate name arrr" app should lead to their 'share with friends only' info being acquired and sold by a data broker.
Edited to add: Granting for instance access to your contacts fro an app is controversial from a legal perspective in Europe. Data protection agencies at least in Germany have the opinion that you need opt-in consent from everybody in the address book to do that.
No. I would impose a ban on selling our conversations for money or for services.
Edit: to clarify, I believe users on Facebook were bartering with data that wasn't theirs for access to Facebook's services.
> "The court here has taken hold, embraced the challenge of the technology and caused the law to catch up with the technology, in line with Canadians' values," Lonsdale said. "Canadians can expect that their private, one-on-one communications with each other remain ones that they have a reasonable expectation of privacy."
http://www.cbc.ca/news/politics/supreme-court-texting-privac...
I think the new CONSENT Act, by one of the authors of the child-privacy law COPPA, looks quite promising to make these things much clearer for users.
https://arstechnica.com/tech-policy/2018/04/facebook-would-n...
I watched the hearing and Zuckerberg kept evading questions about users "controlling data" responding with nonsense such as "Of course users control the data - they decide what to post on Facebook!"
Completely omitting the issue about what happens to their data once third-party developers have access to it, even in the context of sharing something with friends (and not "the public"), or in this case private messages.
And I agree with others here. Private messages should have never even been as part of a permission. I think now I understand why Facebook recently said that they see Messenger chat as "public". I thought it was just more of a metaphor, but they seem to be thinking of that quite literally. Your private messages on FB are no different than your public profile data to both Facebook and third-party developers.
Oh and by the way, Facebook also recently admitted that most of its 2 billion users' profile data, including email and phone numbers, have been scraped off the website.
I'm not sure if we have enough details to say if this was informed consent or not.
But I doubt it was informed consent if the messages were gathered by the Facebook app. Back when I had that app installed, Android did not support granular privacy. One day I got an update notification that said a new update would get the permission to read text messages. I believe the rational was so the app could automatically parse a text message confirmation code. Since I'm savvy, I never installed that update or any other update it ever again. Now it turns out Facebook used that permission to slurp up people's text messages into it profile of them.
This wasn't informed consent: I wasn't honestly told what they would use the permission for, the request wasn't clear (just the standard android notice), and it was an all or nothing ask.
https://developers.facebook.com/docs/graph-api/reference/v2....
For example, reddit’s API allows applications to access messages, which is useful for third party clients.
If someone at a gas station asks me "hey could you give me $5 so I can buy some gas. I'm out of cash." and I give them the money. Then they proceed to fill up a can and go burn down a house. Should I be arrested as an accomplice?
There was no indication that they would do that and if I knew there's no chance I would agree to give them anything.
You'd have to find additional evidence that I consented to that action. In this case, I really doubt anyone knew that their data would be used in this way when all they wanted to do is take a quiz.
It is disheartening to see people label it clickbait, this is a very important message that needs to be embedded in the public.