Today you cannot see my FB page if we're not friends, an open API wouldn't allow you to access my data either. If we were friends, you could use your custom FB client to look at my page though, which would be very user friendly.
This was precisely the level of access which caused the Cambridge Analytica scandal.
So no, Cambridge Analytics did not have API access to everything that that that the users who used Facebook login had access to. This was a specific set of permissions granted to apps with which users used their Facebook identities as login identities.
Your browser has direct access to TONS of private data, if you install certain browser extensions they have access to all that data as well. A custom facebook client would be fundamentally similar and would clearly be considered a piece of software that requires trust to use. The level of trust you should have in the software provider who provides such clients is MUCH higher than a 3rd party site where you simply used facebook as a login provider.
https://securitywithsam.com/2019/07/dataspii-leak-via-browse...
https://www.zdnet.com/article/apple-neutered-ad-blockers-in-...
What I am saying is that these risks ALREADY exist with browser extensions and facebook and providing an API to allow alternative clients for accessing facebook would be an analogous type risk and security expectations. (Although I would argue that an API could be lower risk if you can grant the API key for your client a specific set of permissions.)
My point is: A site where you use facebook SSO carries a very different type of risk and set of privacy expectations than a client that you use to login to facebook.
Yes, this is what used to exist, and this is what Cambridge Analytica exploited. The level of access I'm talking about, and what people in this thread are advocating for, is allowing a third party app to see all info an authenticated user is authorized to see (including their friend's info).
People saw an ACL grant screen before Cambridge Analytica took their data. Too many of these screens and people just click "OK."
Defaults matter.
Of course, FB would have to be forced into it by law, and they'd lobby hard against being the only company so burdened, so they law would only pass if it applied to every option in every software... and every company in the world would scream "But users will hate us! Our profits! oh my!"
No doubt a huge number of people would be outraged by that much workload forced on them, but I like that world.
Yeah, I use uMatrix on maximum blacklisting on every site all the time, and Blockada on my phone, ...
I'm not sure you're entirely clear on how the Cambridge Analytica hack worked?
That's the nature of social data (and it's already this way for email -- Google knows what you email @gmail.com addresses even if you don't have one).
I personally see nothing wrong with this. I didn't think Cambridge Analytica was a big deal either, just something the media blew out of proportion. If you communicate with people, what you send them will be available to whoever they share it with.
There will always be the analog hole and many a user experience have been degraded in the quixotic attempt to close it.
Also, most people use one of three browsers. I don’t trust Google but I doubt they are surreptitiously using everyone’s FB login to crawl their social graph.
I just want API access to the content --I wrote-- that they are monetizing (even if it's just a lure to get my friends on their platform), and if my friends grant me access to something they have written or shared, the API should allow that.
I agree that there are likely ways this can be used to do all kinds of terrible thing. But so could bank APIs.
If you’re taking the position that Cambridge Analytica wasn’t actually that bad, and it’s worth the trade for a better developer experience, I think that’s an intensely unpopular but defensible claim.
I'll take that position. The media made a huge deal out of Cambridge Analytica but it didn't impact FB usage at all, so I don't think it's as intensely unpopular as you suggest. On most social media services, your friend list is public. I think people who feel that's somehow sensitive information shouldn't be on social media in the first place because there's nothing stopping any one of their friends from sharing all of your info with whoever they want.
I mean, you're advocating for an open API to let people access maybe some public photos and such, but nothing private and no personally identifiable connection information right?
Just as a matter of full disclosure, I believe anything sensitive should require explicit consent of the user for each bit of data you download from their profile. I don't believe in radically open data APIs on FB because there is a bit of an argument to be made that it's not FBs data, it's that user's data. If she doesn't want to give the world access to her messages to her lover there should certainly be no API level method that overrides her intentions there.