Facebook Now Shares Phone Number & Address With Third-Party Apps
readwriteweb.com
readwriteweb.com
So the assumption is that I, as a user, am naturally more willing to share my contact information with anonymous application X than I am with my friends.
Naturally, this is indeed a transparent effort at lock-in.
What they are infact doing is now allowing third-parties to request extra, and very very personal, information about you using the same dialog that people have effectively now been trained to basically click-through.
I really think this dialog needs two things:
1) Something that highlights the fact you are allowing third-parties access beyond your basic profile. All personal information is not equal.
2) A way for the user to opt out of sharing this extra information. As a result, the app may have to deny you access if it really really does need your address (why it would is hard to imagine), but this "all or nothing" approach seems wrong to me.
2) While I agree that it would be good to give users a greater level of control, most apps are unfortunately not designed to play nicely with varying levels of permissions. Such a change would require significant advance notice to Platform developers.
They can obviously live without contact info since they haven't had access to it until now.
This is actually an interesting potential solution to the permission dialog problem: force apps to handle certain permissions in a granular way. Always let the user deny those permissions independently. Then the app can be forced to make a specific case for why it needs each of those permissions.
Of course existing apps can exist without this permission, it's a question of what new possibilities this opens up for app developers. I know it opens some up for me.
I'm a bit baffled as to why this has been voted up so hard, given its extremely conservative viewpoint.
The fact is that Farmville doesn't need my phone number or address to allow me to play the game, so why should I (as a user) be presented with an all-or-nothing decision? Your answer seems to be that the reason the user is presented with an all-or-nothing decision is because it would be too difficult for a developer to write some more unit tests. Writing unit tests takes away from time building new features, therefore unit tests stifle innovation (though by this logic bugfixes also stifle innovation).
Implementing a permissions system and allowing your program to not need an 'exponential' amount of unit tests is easy+. Just treat everything like a file. Seriously. Treat every piece of data like a file with an ACL allowing certain groups/users to have read/write/no access to the file. It's that easy. Return a standard error when an app tries to perform an operation on a piece of user-data that it doesn't have permissions for. The apps/frameworks should be able to easily handle this.
You don't see desktop apps with billions of unit tests just to cover file access. You don't see webapps with billions of unit tests to cover database access (databases also have permission systems). Why would it be so hard for Facebook apps to do the same thing? Why would it require an exponential number of unit tests?
As a final note, keeping the barriers to entry low when it comes to (apparently not-so) private user-data is a bad thing. Just look at what the 'ease of use' of PHP's database access did for SQL injection attacks on the web. All developers needed to do was to use bind params, but many of them didn't even know what bind params were. Keeping the barriers low to getting access to users' private data will only result in disaster.
+ For various levels of easy.
This is such an illogical statement that I'm not quite sure how to respond to it.
2) it'd actually be quite trivial, no notice required. If the user opts out of sharing a specific type of data, the app just gets an empty entry. Apps already need to deal with the fact a user may not have any photos/friends/whatever-data-they-want-to-access.
I looked through my profile info and I didn't see a way to hide my phone or address from applications, which means that I have to choose to not post them on Facebook, or provide access any time I want to use an app that requests them.
Obviously, this is much more useful to developers than it is users.
1. Does this apply to current developer/client connections? 2. Will the connection request specify that you are giving consent to address & phone #? 3. Will you be given the option to specify which data you give to applications or will it continue to be all or nothing?
I'm not a user advocate, but I can tell you this - I'm tired of FB constantly glossing over the details.
"Less sensational headline: Facebook Now Allows You to Share Your Phone Number & Address With Third-Party Apps"
The all of nothing mentality is flawed, much like most of Facebook's decisions it seems. (imo)
Newflash: I don't give a shit about how hard your job as a programmer is. If you don't like programming take up something else. I care about my security and not having to worry about what effect clicking "OK" is going to have. Plenty of apps ask you things that they don't need to function.
Facebook provides value and poor, lazy anti-security undermines that value and puts me in the inconvenient position of thinking of a move [1]. And for what value? So developers don't have to write a switch statement? Seriously?
[1] It's not as simple as "just take your business elsewhere". The only purpose of facebook for me is connecting with friends and family. So going while they all stay is rather pointless. Getting other people, who have a different circle of friends/family, to move with me would be practically impossible.
> Giving line-item veto to a user is a terrible idea.
Giving the user choice about whether or not they want to give up their personal information is a great idea. Suppose I don't want the app to have my email and phone number. Without finer-grained control, my only option is to say no to the entire app -- so they lose me as a user.
In other words, it's not really "all or nothing" as much as "whatever this particular app asks for, or pass on this app."
Most users of any service or product won't fully understand every single configuration option available to them. That doesn't mean we should give up on allowing configuration. And using the interface to subtly educate and inform users about their options is a worthy goal. But that doesn't seem to be in Facebook's immediate best interests.
Android also has a similar dialog when downloading/installing new applications that provides "all-or-nothing" control just like this Facebook dialog. I think it's bad there as well.
This has happened. Since most things on the site are an app, Photos is an app. There used to be an option which ultimately disallowed an app to post certain kinds of stories to your stream (I don't recall the details). You could set this option on the Photos app, meaning you would never see any more photo stories in your stream. The option was very buried, so people had to specifically go to Photos and turn on the option... and silly users did this, forgot about it, and then complained that Facebook was broken since they never saw photos stories. Nevermind that it was their own fault. This option has since been removed in one of the Platform permissions revamps recently (IIRC it was simply forced to "off" for all apps, with Photos and similar internal ones special-cased to be forced "on".)
As a developer, you are responsible for asking for the information your app requires to function properly. You are required (by the Facebook TOS) to specify what information you will get, and how you will use it.
The user than has to choose if it is worth it or not, for this particular app.
If Facebook offered the users "more granular control" over what would be sent, this would result in apps not knowing in advance what information would be available to them, which would result in a pretty crappy user experience.
Opt-out..hahaha maybe opt-out of only the really obvious ways Facebook is selling your info.
One of the permissions read: "Send me email" (optional: send through a facebook proxy)
So now, you can also let the apps know phone number through the graph? I don't find that too big of a step. CAN-SPAM still applies. Perhaps they should set up proxies for the phone number, though.
What I find more funny is that ReadWriteWeb writes:
"Thankfully, this sort of information cannot be shared via your friends' careless actions, unlike other profile information."
which is in direct opposition to the attitude that blogs had on the same issue when Google complained that facebook was "trapping your contacts" by not letting you export them. Now they are thankful facebook doesn't do this :)
That is, thankfully your friend can't decide they want to share there contact information with some app and vicariously share yours too.
Big difference.
However, this really could be quite useful if used legitimately, i.e. Facebook commerce, having shipping address available; location aware apps etc.
It's also one of the most useful features of the whole site, if I'm out somewhere and realise I suddenly need to call someone whose number I can grab from Facebook.
I'm not afraid of my friends.
Very easy way to check which of your friends has published their phone number.
I'm sure my relative would appreciate her abusive ex getting his hands on her phone number. (And given past problems with third parties, I have to think this information -- speaking generally if not specifically -- is going to leak.)
You use the cell phone number as part of password recovery / identity verification (as I understand it). And then you do this?
1) There are UI issues that have been raised elsewhere in this thread - mainly, that users get confused when shown a set of complex options. Having watched usability studies where users are given a lot of relatively complex options, I'd suspect that a model where users have to pick among the permissions to give an app is going to fail massively (ie, user turns on everything without actually understanding anything, turns off everything by default or just cancels out of the app install altogether.) A model where apps request permissions right when it's needed will be annoying users with all the dialogs needed.
2) Some apps don't work if they don't get all the permissions they need (imagine an address book app for an email program - if you don't get email address it just doesn't work.) Adding a lot of conditionals to change how your app works based on what permissions they get can be expensive and adds a lot of unnecessary test cases.
In my opinion, Facebook's decision give more granular permissions, but to make it an all or nothing proposition allows them to protect their users by removing spammy/malicious apps, and simplifies the applications built on their platform . This puts responsibility on them to actively remove malicious applications, and on developers to pick only the permissions they need. Given that users tend to make bad decisions given a set of complex options that they don't understand, it seems like they made a rational choice. AppStores on the various phone platforms have a similar decision to make as to how to best protect users from apps, and there isn't consensus as to the best model in that arena either.
They do need to step up their activity to remove malicious apps in light of giving regular applications this option.
It's the same on Android. Why do I have to give any app that wants to display ads in my face permission to read my phone number and device serial number? Hell, on some carriers that's all you need to clone the phone and steal service from it. What possible reason could there be for that? It's poor design, and there's no reason I need to give "Bob's Fun Game" my telephone number just so it can have a unique ID to datamine later. Generate one on startup and use that.
The problems are similar and the solutions are similar - line-item veto for permissions, period. If your app can't handle it, crash - I'd rather have a broken app than risk my privacy for it.
Well, as long as we are not allowed to partially denie permission requests (which of course would make certain apps not able to share our information to other third parties)
http://www.readwriteweb.com/archives/facebook_identity_the_c...
http://webapps.stackexchange.com/questions/1/how-do-i-delete...
but the phone book doesn't call up the websites you visit to tell them that it's you that's visiting them. It's not about the specific information being available; it's about the context it's available in and what other information it could be connected to.
Not to mention phone books have been sliding down a steep slope of irrelevancy for the past 10 or 15 years as cell phones increased in popularity.
:)