This seems like a good way to move the burden of auditing partners onto the users for Facebook to me. Make application fill in information about why they call specific operations, make those operations and reasons available in an audit log that any user can review.
Hmm. It seems this may sound weird to you and many others, but that's exactly how I interpreted it. When looking at that screen I was wondering why anyone in their right mind would grant Spotify these rights?
The only thing Spotify does is play songs for you, right? They shouldn't really need access to any of your FB data to do that.
Just play "Grandma's Hands" for me while I code. I don't need my friends in Paris to know I'm listening to Bill Withers.
Seriously, why do people think they need this stuff?
Only now does FB reveal themselves to the be treacherous jerk they've always been and abuse whatever leeway you give them. Use recovery phone number for marketing? Why not!
It did not expand the permissions of what could be accessed.
That scope was retired in 2012 https://developers.facebook.com/docs/roadmap/completed-chang...
Giving FB the benefit of the doubt, I suppose it’s possible that there could have been an additional permissions dialog that popped up whenever messaging integration happened. But I’m usually pretty good at being paranoid about giving apps unnecessary FB perms.
Personally I derive zero utility from integrating Spotify and messenger, and my private FB messages are one of the most sensitive data streams, period. So I find it hard to believe that I would have missed this. Which makes facebook’s latest vigorous non-apology feel a bit off to me.
Otherwise, this of the same type (though not magnitude) of thing as "Spotify may induct my firstborn into a satanic cult."
"Access my data at any time" is truly deceptive. The icon is one specifying "time" - a moon in the dark; night time. And the operative context seems to be "at any time". However, the grant is actually for, "data". Which is itself seemingly already being granted by the above "Posts", and "Public Information". If Facebook presumed that "data" included everything, then why did they ask for access to posts and public information above?
It is clearly deceptive. If they thought what they did was in the right, then why deceive? And if they felt like they made a mistake, why not make the new dialog boxes not deceptive?
That they do not feel that they can sustain their business model without being deceptive makes NYT articles like this all the more necessary; if people really don't care about their privacy, then go ahead and ask for their privacy - don't dance around and say you're providing a service (and omit that you're also taking their private data). If they asked clearly and they were granted the ability to farm out to third parties whole read/write access to all data, then I'd be more inclined to believe that their users were actually acquiescing.
It takes a very cynical perception to accurately assume what they mean by this, and they absolutely take advantage of this. Cynics wear the tin-foil hats in the minds of many, and nobody wants to be like that.
On the other hand, Facebook is known to make a lot of one-off arrangements with specific preferred partners such as Spotify to grant permissions and access normal apps can't use. I suspect that money changes hands for some of these special arrangements, or if not outright cash then intangibles with significant value, hence the "selling data" accusations.