Turns out "move fast and break things" is a shitty policy when it comes to privacy concerns.
I highly doubt anyone would consent to allowing third party companies to read their private messages if that was actually made clear to them.
The average user seems to assume that the information is used to provide the service and nothing more. The last person I asked if they were worried about how much information FB has about them replied something among the lines of "Yes, but it's only things that I deliberately chose to share." (paraphrased)
Users signed in to services they already had accounts with, and therefore trusted, knowing they were enabling features they wanted to use with their data. These services were hand selected big name companies. This is a far cry from selling data to the highest bidder for profit.
Congress needs to lay the hammer down and come up with privacy rights akin to GDRP.
[1]https://www.theverge.com/2018/12/18/18147616/facebook-user-d...
This is exactly where we need congress to step in and regulate personal data.
I’ve built rest APIs at work and I almost always restrict this type of behavior. Why weren’t they only given access to create PMs and update PMs they create? No requests to pull all the PMs of a certain user.
>Giving Apple access to users’ Facebook contacts and calendar entries, even if they had disabled data sharing, as part of a partnership that still exists.
First, the Verge article (https://www.theverge.com/2018/12/18/18147616/facebook-user-d...) did not do any original reporting, they are referencing the New York Times. This is another thing - people think stories have more weight and truth than they do because you've got a 100 publications writing about some other publications article.
The New York Times article makes this claim, but does not explain what "explicitly disabling data sharing" means.
Are they saying that I sign in to Spotify, I am asked to give access, I say no, but Spotify still gets the data? That would indeed be bad. It is unlikely this has happened. If this did happen, it would be worth a couple of words of explanation more, no?
They are instead likely referring to this dialog: https://c-7npsfqifvt0x24dofu4x2edctjtubujdx2edpn.g00.cnet.co...
Best guess, they are saying, although my friend disabled all the options in this dialog, I was still able to grant third parties access to my contact list and my messages, which included my friends data - that makes sense to me: I can't use a chat app if half the messages you sent me are missing.
In any case, we have to guess what really happened, because the New York Times can't be bothered to tell us.
Facebook said:
> Did partners get access to messages?
Yes. But people had to explicitly sign in to Facebook first to use a partner’s messaging feature. Take Spotify for example. After signing in to your Facebook account in Spotify’s desktop app, you could then send and receive messages without ever leaving the app. Our API provided partners with access to the person’s messages in order to power this type of feature.
Spotify pushed "log in with Facebook" and as far as I know, for a while it was the only way to use Spotify, and I would have expected Facebook to word the above stronger if they had additional steps to give access to messages. Do you know additional details? (really wish both sides here would present detailed flows)
So why wasn't the access write-only? If the only purpose for 3rd party access to messages was to send messages, there is no reason they should have been able to read any messages. Seems like a pretty trivial, obvious function - I certainly have keys for send-only access to email accounts to let web apps send things on my behalf with minimal possible privacy exposure.