Facebook says a bug caused its iPhone app’s inadvertent camera access
techcrunch.com
techcrunch.com
Thinking long term (playing the infinite game) is so overrated...
It's perfectly plausible that this could have been a bug. It could also have been some type of performance enhancement, e.g. initialize the camera in the background so you can begin a video call more quickly.
But do you believe them? Facebook has scourged any goodwill I ever had for them.
There are plenty of bugs that result in less data... many of them are called crashes and FB has them just like any other app.
It's a pithy sardonic addition to the chorus of scorn rightly directed at Facebook, rearticulating the consensus opinion that one consequence of their persistent malfeasance and its regular public disclosure is a profound loss of trust, such that genuine mistakes will never be perceived as such; and furthermore, this creates a self-perpetuating cycle in which embarrassing true bugs are interleaved with further documentation of bad faith in such a way that the distinction is not only lost but essentially irrelevant.
The comment I replied to is not nearly as pithy as it thinks and comes across as more corny than commentary.
I asked ISC2 in particular that if a certain employee was shown to be on XYZ team that handled XYZ task, if they had say ignored multiple outreaches from the community, and then also (this is key) not raised concerns internally to a reasonable degree that a single individual can in a megacorp...could their say CISSP be revoked. The answer I got was a strong yes in the hypothetical stories I proposed.
I also emphasized that I would be writing an apology to said employee, and offer to resign / terminate my CISSP/CCSP if wrong because we have to prevent this process from becoming a no-lose vindictive game.
I’ve also noticed that when certain ad platforms inject their code into Safari taboola/outbrain the same heating occurs. This would make sense as taboola and outbrain appear to be linked to Israeli intelligence.
I guess they not only don’t care about our privacy they also don’t care about our battery life / health of our devices either.
It sort of reminds me of how windows would spin up your HDD In the middle of the night and scan through your entire hard drive causing it to prematurely fail. All under the guise of windows update or whatever the cover was for what I consider criminal damage.
I’m sure any battery usage from this would just be listed under Facebook.
Then we learned about PRISM. Hard proof that Apple, Facebook, Google, and the NSA secretly collaborate to mass-collect data on US citizens. It's 100% reasonable (and perhaps in our best interest) to assume any large tech company will and does cater to the NSA/CIA/GCHQ/Mossad's interests before their customers' - or even their shareholders'. Revenue and market share are important, but a powerful agency threatening your company takes priority over anything.
Until proven innocent, we should assume that any and every large tech-centric corporation either has been or can be forced to cooperate with PRISM. IMHO now that the public has access to the Snowden leaks and Vault 7, it is irresponsible (and perhaps dangerous) to think otherwise.
There’s also people looking to crack huge swathes of the population, but state level actors seem more interested in breaking key individuals for blackmail, and espionage.
Although some state level actors are interested in mass surveillance as well.
Tl;dr: yes, Zuckerberg has more to worry about with his devices than the average individual.
Not trying to start a conspiracy, but given the data and reach FB has, they could potentially target unknowing/non-techy people somewhere in the world and do it without their knowledge/care.
My immediate hunch is rather that they love tracking emotional responses such as widening eyes as people interact with content. Because knowing the true emotional responses instead of just hitting "like" on a post would be extremely valuable data.
The same Guy Rosen who was the CEO of Onvao - the infamous data grab app that Facebook purchased.... yeah, that integrity guy...
https://en.wikipedia.org/wiki/Ministries_of_Nineteen_Eighty-...
And what does VP of integrity do? Manages organization that handles abuse on the platform.
It's facts that they all avoid or diligently rework to fit their version of the truth.
That's what _I'm_ imagining a "VP of Integrity" at Facebook does.
So? The point is people can if they want too. Even if only w small portion do, it's better than having closed sources code.
https://assets.documentcloud.org/documents/5433555/Note-by-C...
It is an ADDITIONAL privacy step. He runs a company with thousands of employees, and with any company like that you never know if someone may decide to become a bad actor, and physically compromise him.
But yeah lets continue to hate on facebook.
Yes, because they're voracious collectors people's personal information. We can hate on "bad actors" as well, we don't have to choose one or the other. But as long as Facebook is behaving creepily, whether deliberately or inadvertently, let's hate on them. There is no reason to tolerate their mistakes.
No, he’s not protecting himself from any external threat.
Sure, but they are protecting themselves from the Russian hackers that are in all the US government networks. Zuck is protecting himself from Facebook itself.
> > > [Camera shutters are] just good (paranoid?) OPSEC to defend against remote takeover exploits.
> > > [Camera shutters are] ... good ... [defense] against remote takeover exploits.
Clearly I misunderstood your intent, but the comment does seem to indicate what I thought.
I don't use facebook, I actually never did. Its not the fact that I'm loosing a few MBs of storage that really bothers me, it's the fact that this is the facebook app.
I wonder if the camera app leaves some by-product that the Facebook app can exploit to derive some data that the user would not usually give to FB.
Perhaps it initializes the GPS without being prompted (as camera uses it for geotagging). Or maybe it checks for the time required to enable the camera, comparing with previous attempts in a kind of A/B test, so it can know if the camera was being used for another app?
They definitely initialize the camera in the background. That is how you are able to simply swipe to your camera view and it is immediately active. Otherwise you would get a slight delay while the camera is initialised.
What they are calling a bug is that the user actually saw it it rendered to a view...
Have no doubt - this happens on ALL apps that dont have an apparent delay on switching to a camera view. That facebook are saying this is a bug that they have "fixed", rather than admitting that they intentionally initialize the camera in the background makes me concerned as to why they would want to hide that fact...
Their layering system also pushes the view slightly to the right to create a perspective effect when it transitions back to the app from viewing an image.
Of course, this triggers the component that thinks the app is starting to pan to the right - and starts the camera and renders to the view behind the main view.
This seems totally plausible to be a bug - and I'm not sure why other commenters on HN aren't bringing this up.
Their app is fairly complicated, and it's totally reasonable that the team that worked on the story feature assumed that the only thing that would cause the view to move right was a user gesture. However, it looks like their layering system also caused it to move right as part of a perspective transition. This sounds like a bug to me.
If you really wanted to keep the camera open in the background, there are other ways to do so, such as literally not rendering the image to a visible framebuffer upon initiating the AVCaptureSession. iOS does not require you to attach a AVCaptureVideoPreviewLayer to the capture session - and you could very easily just take those frames and process them without ever showing a preview to the user.
The bug is not that they were capturing in the background, but that the perspective transform of the main view caused the view behind it (for the story camera feature) to think the user was swiping the main view to the right and to start up the camera to make sure it's ready asap. Running the camera in the background is actually pretty expensive - you don't want to suck power doing so. As much as facebook wants your data, it also wants you to regularly interact with the app. If users think the app is draining battery too fast - they'll use it less throughout the day to preserve battery life. Making sure it isn't a power suck is important to their core business.
Previous versions used to take an age to load up the camera screen/swipe action was blocked (assuming the initialising process). So looks like this may of been their attempt of fixing the UX
Or did I miss some part.
Facebook have demonstrated capability to do accurate face recognition, and it's hardly a stretch to assume they couldn't do enough object and possibly brand recognition from a live video feed from you phones camera as you're using the app.
Perhaps people might not make assumptions or jump to conclusions like those, if the company was one that had a solid track record of respecting user privacy and getting the protection of privacy right. That company is not Facebook...
But what would I know, I'm just "a dumb fuck"...