1. If you look at the docs, that's from Exhibit 44 which indicates that it's actually an excerpt from a messenger discussion, not email 2. Twitter had previously blocked both Instagram and Tumblr in the same way 3. Facebook had previously blocked Twitter in the same way 4. In some of the other docs here, you can see that there was much more discussion about what their policy should be around reciprocity and apps competing with facebook's features 5. The first line of that indicates that there was likely discussion/planning about this before that conversation
And for the record, Facebook did not "share data with Cambridge Analytica for shady research purposes". A rogue third party developer created one of those shitty quiz apps for Facebook, and then proceed to get users to signup for it; several million did, which allowed said developer to harvest data thanks to the very permissive APIs that Facebook provided at the time. He then proceeded to sell this data to Cambridge Analytica. Facebook has a responsibility in what happened there, but "Facebook sold data to Cambridge Analytica" is a widly misconstrued story.
We are all rogue third party developers, and clearly, the priority, much like most businesses is to make a profit, and the customers/ethics come second.
I love the fact that you get bent out of shape that Facebook didn't sell it though, it's a theme I've seen with Facebook employees: "But we didn't sell it!"
I'm not sure if they are lamenting the fact they didn't sell it but I sure as hell can tell what they give a damn about. If you want to hide under "anybody would have done it", lets take a trip down histories gravestones and figure out whether or not we should bother trying to do the right thing because it is the right thing to do.
Dubious, but still good point. Meaning legislation to force companies to behave slightly less unethically is all the more direly needed.
This isn't true. Lots of companies wouldn't steal users' call logs - eg, Mozilla, Signal, and plenty of boring, normal ones who make TODO list apps or whatever.
It also isn't relevant. See how that argument flies in criminal court. "Anybody else would have stolen that car."
What we see here (again) is that FB does nasty things and it's in the public interest to stop them - along with "any other company" who does the same things.
All this anger over Facebook is ridiculous.[1] Now, if you want to talk about Android and Google's decision to make it more difficult to not only control but to know what data apps (especially theirs!) will take, that's a different matter....
[1] Especially from geeks, and particularly geeks from the 1990s and earlier when we were told that unless we promoted non-centralized publication models that we'd see the very constellation of centralized, user-antagonistic, profiteering services we now have. Whenever someone says, "but why would you want to host your own e-mail/web/chat server, my head wants to explode." It's always "why would you" (or "why would you, it'll never be as good as GMail/Facebook/Twitter/etc"; never, "maybe I should promote and help work on projects that make it easier".
thanks to the very permissive APIs that Facebook provided
Why did they do this?
The discussion revealed in this release is pretty fascinating. For example, you can see that at some point Zuck's friends authorized 31 apps and 76% of those apps had "read_stream" access giving access to their entire newsfeed.
Through one lens this is Facebook locking down their API in an anti-competitive way, which is somewhat true, but mostly this feels like an API change making privacy improvements for users. (The Cambridge Analytica data came from an older app that was running before these changes were made...)
This is the same elision they use. My question was, in the face of almost two generations of awareness of the principle of least privilege (almost typed "lead" again!), why did they design the API so that it gave away so much information and data in the first place?
Through one lens this is Facebook locking down their API in an anti-competitive way, which is somewhat true, but mostly this feels like an API change making privacy improvements for users. (The Cambridge Analytica data came from an older app that was running before these changes were made...)
https://newsroom.fb.com/news/2018/12/response-to-six4three-d...
Read the "Whitelisting" section. The only change they mention is turning off the ability to request permission to access the now-problematic data and information (let's say "D&I"). Of course, we also know that this is selectively applied. That's not "somewhat" anticompetitive, it's not necessarily different that the CA problem, and at any rate is only a marginal privacy improvement for users because there's (my estimate) no way in hell they're going to tell us who still has access to the APIs.
Facebook is far from blameless, and should be held to account for its scummy behaviour, and for enabling scummy behaviour.
Facebook is not a good actor, anyway you look at it. They are selling data to first or second parties, who are using it to damage our country.
http://mattmckeon.com/facebook-privacy/
In April 2010 basically everything a new user posted to facebook was public by default. They didnt "care deeply about peoples privacy."
Funny that the committee ended up being the open ones.
But being forced to give away half your physical retail space is hardly the same thing as just letting them keep using an API that you provide explicitly for such use.
Also, more broadly: one would have quite a hard time making the case that Facebook isn’t nakedly, gleefully, and rapaciously user-hostile.
I think a lot of people who hate Facebook just have a hard time believing that most people just don't care about the same things you do, or to the same degree. They're still on Facebook and Instagram and Whatsapp because they see the world differently from you.
In this case, Facebook was deprecating the API and declined to provide special whitelist access to a competitor.
No? Where are you getting this read from? The documents clearly show them discussing it from a year prior to shutting down Vine's API access, and planning on announcing it publicly ~6 months prior.
I can't find anything from a quick google search on when the API deprecation actually took effect, but assuming the timeline from Exhibit 43 is accurate, Twitter actually had whitelisted access for over 3 months before being shut down.