The more able I am to interact with an interface programmatically, the more easily I can exploit it and turn it into a giant database.
The more able I am to interact with an interface programmatically, the more easily I can exploit it and turn it into a giant database.
People don't use Bibliogram (or other alternatives) to access unauthorized data (all it displays is the same data visible on the web or via the app), it's to be able to browse without being stalked by Facebook and avoid their dark patterns.
This is more or less how the Cambridge Analytica fiasco started. And yes, this was seen as a privacy problem.
This is a diverse Forum and people have various opinions.
To be honest I think they would have. I just don’t think they’ve fully thought through the consequences. Worse, maybe they have thought about the consequences, but are ok with being outraged at both ends of things. Lots of people get mad and try and skirt any security/password protection measure, but also get just as mad when they inevitably get hacked because they’ve skirted all the security measures. But even after that still won’t use the security measures because of the “inconvenience”.
Private accounts (where you have to approve followers manually) exist and as far as I know nobody is calling for making those public. A hypothetical API would still require the credentials of an approved account before returning data of such accounts.
> But it’s not all that hard to exploit this by creating a popular page that lots of people end up sharing some data with
I don't understand what this has to do with an API? You can create a phishing page now.
> This is more or less how the Cambridge Analytica fiasco started. And yes, this was seen as a privacy problem.
Cambridge Analytica created a malicious website that requested access to people's accounts and they granted it. Not only is it on idiots that approved the OAuth consent form, but it doesn't seem like it's got anything to do with what the parent comment was proposing? As far as I know all he was calling for is to provide an API that returns the public data that you can already get via the official web UI or app.