Facebook is using the iPhone’s camera as users scroll their feed
thenextweb.com
thenextweb.com
You know what? I think I'd like your physical kill so much better. It could cleaner to implement, too. If the manufacturer couldn't offer it, I'd be happy to do business with a modder who could.
An existing exterior button like the iPhone's ring/silent switch seems like an ideal starting point to work a third-party hardware solution around. But given what little free space exists inside these devices, here's hoping that solution is more wiring than components!
I'm so sick of reading daily the scummy tactics these tech giants are using to hoover up private/personal data, and then reading their little acolytes on HN defending them ("Oh, it's probably just an A/B test, nothing to worry about!" or "It's too hard to monitor what our company is doing, even when presented to hard facts on the daily, what's a dev to do!").
On the down side switches are expensive and can fail though so they add warranty cost and another 'hole' in the case.
That said, a phone case that covers up all of those bits until you expressly open access to them would probably sell well.
Uh, no they aren't.
In addition, since switches are an electromechanical component, they also affect your mechanical case engineering which electronic components don't do.
Finally, if your device is "water resistant" or somesuch, you now have an even bigger engineering headache waiting for your design team. Especially since you don't want a pushbutton, you probably want a slide switch.
Switches and buttons are really expensive on electronics components from a relative cost and engineering cost standpoint.
The easy way to ensure that a switch is waterproof is to use something like a magnetic reed switch or hall effect sensor, so the switch just moves a magnet, which is sensed thorugh the plastic case. It uses more real estate than a pure switch, but requires no open holes through the case.
This is at odds with the (apparent) consumer preference of smaller everything.
Um, using a hall effect sensor is exactly the kind of "soft switch" we're trying to avoid, no?
And magnetic reed switches are big, very expensive, vibration sensitive and failure prone. Since this is security, you're going to want it to fail open and you're not going to want a switch that closes briefly if you vibrate the phone.
Mechanical engineering is hard. Let's go shopping! ;)
Reed switches are available that are a few mm long, they aren't exactly huge.
We already have good enough technology that a phone should last us 10 years at least without having issues with the performance. The only problem is having replaceable batteries.
We need to move back towards things that last and backwards compatibility. Then it would make sense to pay $1000 or even $2000 on a phone, since you know it works perfectly and it'll last you 10-20 years.
I don't think it's that nobody _likes_ the idea, I think the problem is that very few people really care. You see this in products everywhere. Rough edges sacrificing the user experience which could be technically solved but are punted in favor of More Important Things.
What happened to this feature? If Bezos wanted this it would be there.
I don't know why it was axed, but my best guess is that it aesthetically looked pretty bad, and it was probably a pain to produce at high yields. Also, I can imagine users finding it more confusing than an obvious well-labelled button.
Maybe the Echo team said it was too hard, and Bezos had to "disagree and commit".
-- Bezos in his 1997 letter to shareholders
How so?
i assume you're referring to the West/EU/USA here. i share your skepticism, especially around the EU's own GDPR. "government agencies and law enforcement", as well as "activities under the scope of Chapter 2, Title V of the Treaty on European Union" are exempted from GDPR.
The GDPR isn't very topical here, because big conglomerates have been violating it since it's inception. Until the teeth have been enforced, we have to assume that a US company is not only shovelling all of your data to every government agency (which would happen even with the GDPR being followed, as you say) that blinks at them a few times but is also selling it to every marketing agency that is capable of paying.
The problem I see with this - other than being cool - that it requires motion, so more likely to fail with time.
> Two hardware kill switches, microphone/camera and wireless/bluetooth
> Now with a physical toggle switch, when your camera and microphone are switched off, you know they are off. Wireless and Bluetooth are combined in a second hardware switch to control all your radio signals inbound and outbound.
That would be a flat out lie if it wasn't actually a hardware switch which is hard to believe for a company whose entire identity and reputation is tied to these exact features.
I do have a video of the wifi in action though: https://tmp.thekyel.com/month/wifi.mp4
I reached out to them a couple of times, and they asked if I had rfkill installed, I told them no, but it shouldn't matter if it was a hardware switch.
They told me that they would look into it, and then never responded after that.
On the other hand, putting a signal onto disable pins is not exactly a kill switch. The description sounds like a hardware switch in front of a soft kill, which would make it some sort of quasi-HKS. A real kill switch would need to totally cut power to that controller rather than rely on it playing nice.
On the gripping hand, I find it hard to believe they would overlook something that crucial. Eg, if it didn't work, it would /have/ to show up during testing.
I wonder if the chip needs to be tightly integrated into the board and a proper HKS would require cutting signal to dozens of those pins -- something that is perhaps impractical -- so they went for a lesser option.
FWIW, there is at least one more person alleging the same broken functionality [2]
[1] https://puri.sm/posts/hard-not-soft-kill-switches/
[2] https://forums.puri.sm/t/wifi-killswitch-didnt-work-when-i-n...
As far as I remember Purism has always claimed that it's hardware switches on the phone, and I don't see why they'd lie because it would be very easy to verify.
I could go check this behavior.
I haven't tried freebsd - could it be freebsd doesn't check for a hotplug?
At my newish job I don’t communicate with anyone overseas but I can see why people would need to use WhatsApp.
Next up, Google Maps and Gmail. I plan to use Fastmail but I need a domain without my name in it for non-professional use.
However, WhatsApp is the killer app that I’m being peer pressured into keeping on the phone because of social effect. There is just no alternative to it in sight :-( I wish.
Gmail -> FastMail. I’d heartily recommend as a very happy customer.
Google maps is still another cancer I don’t know how to get rid of.
If FastMail could keep my data away from Google and other advertisement companies, I’m all good. Although I wish Australia doesn’t do something as stupid as this law.
Signal is great for when you want to talk about things that governments have decided shouldn't be talked about.
Obviously that might not be enough for everyone, but it's by far the best solution that works with existing hardware. Tomorrows phones might have indicator LEDs or hardware switches, but my current one doesn't.
something like this: https://www.amazon.com/C-Slide-Sliding-Computers-Chromebooks...
Hell, even integrating it into the phone and opening the camera app when i open the rear slider would be a killer feature.
edit: and they wont let you use messenger that way, for no good reason. So just use messenger on desktop or in desktop mode. edit: or mbasic.facebook.com for messenger
Also using Messenger lite on Android for whatever that's worth... Would love to hear any reasons to make me delete that as well.
I use Caprine on desktop for messenger, and Face-Slim (F-Droid) for mobile.
Facebook is the circus (as in panem et curcenses) that masses learned to crave
EDIT: same goes for twitter.
CONTEXTUAL EDIT: I understand that emotional weakness, unawareness, and gullibility of the general population is a controversial topic, it is still very useful to be aware of and hence put reminders in place.
If this is the new public square then lordy, I want no part of it. And it’s funny and really scary that people are so into Facebook that’ll come for the photos of a grandkid and stay for the misinformation and repeated privacy invasions.
I'd say email + SMS solves 99.9% of problems and also limits the garbage received because people can't be bothered to start/write an email and don't want to spend money on images in MMS/SMS.
My life is blissfully quiet because of this, or I have to physically see people which is much better than all the noise.
Perhaps most people would do alright with WhatsApp or Apple Messages for IM?
Seeing how much my wife's phone bings and beeps with her apps is enough to put me off it.
But I 100% acknowledge there's social gatherings and events I miss out on now because they're exclusively organised/promoted on FB. And mostly I'm OK with that.
Unlike the "delete my account" button which actually just deactivates your account until you're ready to come home, triggering the algorithms' sex-account ban is the cortez-burn-your-ships approach to account deletion.
https://gulfnews.com/lifestyle/fb-instagram-ban-eggplant-pea...
Just watch your veggies.
It feels like a tiny act of resistance against the hegemonic steamroller that is Facebook.
We then used the Shortcuts app to set up a "desktop" icon to take a photo and share with IG.
It worked like a charm. It still gives her the option to edit the image/filter it/whatever, but she doesn't have to give her entire photo roll or camera access to the application.
She's actually thrilled (and sufficiently creeped out by these accounts). We don't keep FB around as an application so someone else might have to test that out.
Apple already solved this exact issue with location, where you can grant it for one time only and be re-asked next time.
Hope they use the same mechanics with camera & photos.
Honestly, I have no idea how one company can be so horrible. It's like they read the site about Dark Patterns and asked themselves: What if we combined them ALL?
He is successful at amassing billions of dollars. From my point of view, his success in the grand scheme of things is below zero. His actions have degraded quality of life and hurt future generations.
For me, looks like the only app I use with those permissions is Pokémon Go. I don’t think it’s very common.
It's the clearly most user-friendly option for folks not trying to scavenge your photo feed.
Another option is to accept photos via share sheet.
It's imperfect, but works fairly well.
That's also why the scheduled perms are nice, where I can enable the perm for a few minutes or until I close the app.
And besides, even if that is the intention... this company is way too big and influential to be making blatant privacy violations and having internet commenters try to sell the public on a corporation's ethics.
Does Facebook activate the camera during feed? The answer may depend on which user is logged in (A/B test), which device is being used, which version of the app (weekly releases), etc. A definitive answer may depend on when you ask, or not exist at all.
Maybe this is the default behavior, but it's possible that this is an experiment that Maddux happened to fall into. You can imagine that Facebook would be interested in gauging facial reactions to feed items.
It also may legitimately be a bug. It's reasonable that if you navigate to a camera surface, and then back, that the camera is not turned off. Because Facebook releases so often, the cost of bugs is reduced, so the number of bugs rises.
(Not trying to defend Fb here, simply answering the question.)
Why rock the boat when you can keep your head down and keep getting $500k/year? At that rate you can retire comfortably after 5 years.
https://twitter.com/alexstamos/status/1185954967086981125
[1]: https://www.vox.com/recode/2019/5/24/18637823/alex-stamos-fa...
Most of internet articles about Facebook is complete trash and over exaggeration. And most HN commenters are paranoids.
There are no leaks because there’s actually nothing to leak. Thousands of engineers routinely perform thousands of experiments on different features (including both UI and data), and there’s no mastermind who designs or even approves all these changes. Sometimes bugs happen, sometimes bug in data handling happen (like tables joined which are not supposed to be joined).
Also, I don’t know about Facebook’s significantly slimy practices. Facebook collected my phone number and matched it to something? I don’t care, because the worst can happen is I will get more interesting ads. I know that Facebook (despite these endless accusations on HN) does not sell data, my credit card won’t be stolen, I won’t get unwanted phone or email spam, and that’s good enough for me.
Routinely using throwaways is not fine, though. All this is in the site guidelines at https://news.ycombinator.com/newsguidelines.html.
I guess you could also define this whole scandal as millions of users getting "more interesting ads" https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Ana...
We discuss it over and over again simply because people have nothing serious to use against the company.
> There are a couple of big differences between Uber and FB that make whistleblowing less likely, namely 1) a much stronger HR culture and 2) the fact that even internal critics see external criticism as often unfair or incorrect.
> [...]
> On 2), there is a lot written about FB that is seen as directionally correct but unfair or incorrect in the details. This reduces the trust internal critics have in the external press; nobody wants to leak and have their statements twisted to fit the media's narrative.
> Even to internal Cassandras, it is clear that there is a moral panic around Facebook that reduces the pressure in the media to get the story straight. As a result, 20-70% of the details in any story are wrong and that is clear to most employees.
> For example, the NY Times has done a number of privacy stories that are directionally correct, in that the proliferation of partnerships and APIs creates a real data protection challenge.
> However, sloppy details like the idea that Netflix is reading your Messenger messages or the mixing of real data-sharing with APIs that allow for 3rd-party clients makes it clear to employees that the story is getting mangled.
> Likewise, the discussion of Myanmar. This is a spectacularly complicated situation that a lot of Facebook employees feel sick to their stomachs about. But there isn't a clean issue to blow the whistle on nor does the external discussion encourage FBers to participate.
> [...]
> The media portrayal of the situation as simple or FB as not caring does not match up to the experience of the hundreds of people working on this problem, which makes it much less likely that they will talk to the press.
> This doesn't mean the media should go easy on FB, but if you portray mistakes as intentional decisions made for the most venal of reasons, then don't be surprised when the actual people working on these problems don't DM you for your Signal.
[1]: https://twitter.com/alexstamos/status/1185954967086981125
And since the laptops all have that feature... it looks like Apple is aware of the problem. Surely there is some crosstalk in the company between product designers. With a company like Apple, anything less is inexcusable.
It always takes some time until the camera is initialized and the first frame rendered on the canvas. I bet the Instagram app, Snapchat, Twitter and WhatsApp are doing the same thing. I honestly think it is a feature to improve the user experience when starting the camera.
That being said, while they are already using the camera, they'd probably be able to do some on device ML to detect faces, emotions etc. But I'm pretty confident they're not constantly streaming your private camera feed.
Is that normal?
FTFY. Also, it's Facebook. Surely they have some strategic/political strings they can pull?
Down side is that on newer iPhones you’ll have to cut it down to not block all the screen, small price to pay for a little extra privacy.
Also why does iOS have a blinking status bar when the camera is on or at least provide on the settings app how much camera was used per app (in minutes or frames and at what time stamps), this way one can easily validate if the app is using the camera without the user prompting for it.
Yes, we are surrounded by people who live and breathe these sorts of details. For many of us, it's our day jobs.
We have to uphold some sense of decency and ethics at the highest levels in order to protect those who are otherwise unaware of the threats.
I was joking, damnit.
Also, the hypocrisy [1].
[1] https://www.theguardian.com/technology/2016/jun/22/mark-zuck...
i mean, it's Facebook, no way it's malicious right?
“Apple announces apps will no longer have access to the camera for more than a minute after authorization, will have to tell call new iOS methods to say when they’re done using the camera, indicators will appear in the status bar when camera is on, ...”
When they could have just had a green light like macbooks, at least on the front (or if they care about rights of others to know when they are being recorded, the back too)
https://pastebin.com/raw/FAV2f9eA
On Android you could prevent Facebook by blacklisting same hosts via Firefox + NoScript.
[I have used Pixelfed from a browser]
Hyperbolic, but simply boycotting the products isn't enough here.
"I don't know why. They "trust" me. Dumb fucks." — Mark Zuckerberg (https://www.businessinsider.com/exclusive-mark-zuckerbergs-s...)
I'm sure YOU'VE not changed a bit in the past 16 years (the Zuck IMs were from 2003).
Yeah, it was a stupid thing to say, but again... 19.
[disclaimer: FB has no interest in me speaking on their behalf, unofficially or otherwise]
[0]: https://www.theverge.com/2018/4/6/17203114/facebook-mark-zuc...
But in the years since, it's become clear that Facebook is not a trustworthy platform. It is, in essence the social credit score AND great firewall of the US (and much of the world).
No data in Facebook is off limits to governments, period. Think about the many trillions of crimes that have been committed where solid evidence (even confessions) is on Facebook's servers.
It's just a matter of time until Facebook's data is used for law enforcement and profiling in ways that dramatically violate the 4th amendment and human rights in general.
We learned recently that two Twitter employees had been Saudi agents. I think it ought to be considered obvious that most state actors have various employees in key roles in major tech firms, so it doesn't really matter what Facebook's official policies are with respect to warrant compliance, crime preemption, etc., state actors have access.