Additionally, some apps are only monetized through advertisement, and 3rd party apps don't display them. How do you expect the 1st party to stay in business?
I don't align with Meta on a lot of issues, but they should be able to control what apps interact with their platform. Don't like it, don't use it.
Many 3rd party twitter clients have expressed a willingness to display ads if provided an API to do so.
As someone who has lost precious accessibility capabilities because of restrictions on 3rd party clients, I unfortunately have to point out that I don't really have a choice of what platforms I do or don't interact with in a lot of cases. I wouldn't stay at my job for very long if I didn't tolerate Slack's BS, for instance.
Like in this scenario to Facebook it is in theory effectively you. Not the app operating on behalf of you with a limited set of permissions.
I don't follow what you mean by this. The API endpoints that a company provides ought to be secured properly. In practice they might or might not be but obviously they ought to be.
I don't see what that has to do with third party clients though. A third party client is stuck interacting with whatever API the company provides, however secure or insecure it might be.
Have you done much work with authorization? To put it in another way let's say there was a website that said it authorized with Steam. It asked you to put in your steam username and password. Is this secure?
Now let's say that same website instead redirected you back to Steam (properly) and requested authorization on behalf of you. Is this secure?
Now which bucket does this app fall under?
"Is this secure?" fully depends on what the attack vectors you're considering are. Breach of the server's database? Make it an app instead of a website and make requests directly. Malicious code in the client itself? Make it open source. Now it's even more secure than the official client.
But regardless of all of this, how is it any of the service provider' s business what I do with my login details? It's my data on my account. If I use it in an insecure fashion, that's my problem. I am free to post my login details on Twitter for everyone to see, so why can't I put them in a database on some russian dude's basement server?
Unauthorized? Hasn't the user explicitly authorized this layer by installing the app?
Like this is a security problem, straight up. I would hope that you can agree on this and that not securing your API is bad.
I only got a few posts into the thread before Twitter booted me out for not having an account, so maybe there's some context I'm missing, but what kind of "not securing your API" are you talking about? The fact that a thir party, explicitly authorized the the user, was able to make actions on the user's behalf, doesn't make it secure, it makes it functional.
Earth: https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Ana...
FB gave them data about friends, when it was supposed to only give them data about respondents. Totally different situation.
If I approve an access request for a low level engineer to get a single repo from github, and github lets them access every repo on our orgs account, that's a huge fuckup by github, not me.
Why should the first party be serving content to people using third party apps that generate them no revenue? Just like websites are free to block adblock users, app apis should be free to block third party app users.
I currently have an Inbox of multiple messages from family members awaiting me, except I refuse to log into Facebook to view them. The only remaining notification email I have left enabled for Facebook is exactly that -- private messages. This way I can contact the relevant person elsewhere and ask them what the message was. This is the kind of "bending over backwards" I have to do to avoid the surveillance-capitalism crap I'm coerced towards by these platforms that can do essentially whatever they want AND demand exactly how we are _allowed_ to interact with them. Why can't I use an unofficial Facebook Messenger client and read the <100 bytes of communication my family member wanted to send me? Ahh yes I have to agree to a hundred-page ToS and subject myself to ads and privacy-invading user tracking to see those few bytes. This is fine.
It there was fraud invoved, one party may get damage/compensation.. But forcing someone to provide service is just not right.
(With the exception of monopolies of course. Let's regulate them.)
I can't come up with a good justification why a private company on the Internet cannot dictate how you interact with them. Facebook isn't infrastructure.
That should be forbidden too.
An equivalent one is a company not allowing Google employees to use their services for whatever reason. That's fine and acceptable.
Absolutely the best reason why businesses should move to Signal. Imagine if your business gets cut off from Meta products, or if at any moment some of your customers get cut off.
Facebook is an extremely limited and poor platform for representing a business, and it too should be avoided for the same reasons (and for being such a garbage fire in general).
The problem here is that Meta wants to plug things into the internet and then control who gets to ask for those things. This is not how the internet works, at all. If you don't want third parties accessing your APIs, lock them down.
> unauthorized api requests
The word "unauthorized" has two meanings here:
One is authorized by the user, another is authorized by the vendor.
You can't reasonably make the "go elsewhere" argument with the monopoly hold FB has on much social data. We need to choose yo regulate them and others to force interoperability, or at the very least allow comcom explicitly (competitive compatibility).
If FB blocked any requests from Firefox Focus they'd likely be in hot water from government agencies.
Do they have the right to block any other app?
They're welcome to find a different business model. Why should we sacrifice interoperability for everyone for their sake?
Or require an API key that's tied to a particular account that pays for access.
Ad blockers are already a thing. Should they be forbidden?
Now, one could argue that by displaying ads in the first place, using an adblock is circumventing something therefore it isn't okay (basically remove one layer of abstraction from the previous sentence). That's also a fair position, but not mine because of entirely selfish reasons (it's inconvenient to me and non-adblock users are subsidizing my use of those websites).
One could argue that allowing adblock users is a strategic decision in hopes they can spread the use of the website and payoff their "debt" that way. I operate web games and I allow adblock users for that reason.
That's fair - you are knowingly subsidising adblock users. If you don't want to subsidise adblock users, you're free to use a different site.
(That's your basic argument, right? Freedom?)
This logic really bends over backwards to support FB's and similar business models.
This is of course ripe for abuse, but that's just synonymous for digital advertising in general. I don't consider it any different than me hitting mute on the TV during ad breaks or getting up and going to another room during that break.
If you don't think sites have a fundamental right to push ads to sustain themselves (as I don't), then blocking the request is the best place to do it for performance reasons.
But even if you do believe in that right - the site and advertiser care about a single thing: a human being seeing the ad. Serving the Ad request is not just useless for their purpose, it is actively costing them money, and potentially muddling their data.
I disagree. The site just wants the advertiser's money. The advertiser wants the human to see an ad.
Why not have the browser /dev/null them, and click a few for the heck of it? It would be in the user's interest.
Most people sometimes leave the room while ads play on TV. The advertisers know that and work the percentage of pepole that do that into their pricing, etc.
Also, non-organic click fraud is rampant already (and maybe even the majority of clicks). /dev/null + click would at least route ad income to reputable sites that at least have some human readers to view future ad impressions.
If you found out Netflix actually streams their content from a public endpoint. You would not be legally allowed to take advantage of that.
When a platform's primary purpose is communication, certain legal rights should be invoked immediately. In my opinion, one of those rights should be the ability to access those communications by any 3rd party client that doesn't intentionally function maliciously. How "proper 3rd-party client behaviour" is evaluated can be a problem for the industry to solve. They have the $trillions to figure something out. I think they'll survive.
The argument "don't like it, don't use it" isn't a very reasonable argument when, socially speaking, you "have" to use a given service (usually the regionally-omnipresent service) to be included in society. Communication is the foundation of society and of human existence. I miss out on a shocking and honestly depressing amount of social activity because of my boycotting of FB, IG, WhatsApp and other similar services.
I expect that our ability to communicate is carefully protected and treated as something crucially important. There's a reason there are SO MANY commercial services around communication and they are largely the most lucrative, because everyone NEEDS to communicate. People will subject themselves to extremely disadvantageous conditions to enable communication with others. Think about it. Facebook, Twitter, Instagram, TikTok, the internet, cellular phone service. These things are fundamental to communication in global society, and a TON of laws are written to govern their employment/usage. Internet communication just happens to still be pretty early in the stages of its effect on humanity, and as usual the legal world is well behind what those effects are. The effects are finally being felt. I believe my feelings on this subject will become more widespread as people realize how deeply they have been exploited by industry (once again).
And, actually, have you tried just not using Facebook for a year? Don't even log in whatsoever? Try it, seriously. I have missed parties, concerts, family gatherings (seriously), news of births, marriages, new homes, major life events (including deaths). I found out my cousin had a kid like 6 months later. I found out a friend died months after it happened. I miss out on the opportunity to partake in things that would have greatly enriched my life. This is the cost to me, personally, by opting out of THE platform that EVERYONE uses. I can't just constantly SMS and call everyone I know asking them every detail of their life, because they exclusively share it all on Facebook. You simply cannot invalidate this very real cost as "yeah well, just use something else".
These huge costs of exclusion are exactly why I believe that I should have the right to access de-facto-standard communication services with software that respects my psychological stability, privacy, accessibility needs (including cognitive), of my choice -- again, as long as that software conforms with proper API usage behaviour. Right now, I'm in a pretty coercive position where I either subject to the objectively-harmful design of the Facebook platform, or face pretty adverse effects to my socialization. That's one reason case where governments enact laws, to protect individuals from these sort of extremely skewed power imbalances.
BTW, I get what you're saying. All these services are tecnically optional. I kinda used to feel that way, until I actually started not using the services that I felt were manipulating and coercing me. Then I realized just how much power these services have over us. I realized these services are optional in just the same way as the telephone and the automobile used to be. Totally still optional. Just mail a letter instead. To me it's like, at this point, as a society, we need to decide whether we care if someone can be seriously cut off from modern society because they don't agree to have advertising shoved in their face, manipulative "algorithmic feeds" selectively shown to them to "drive engagement", and unprecedented surveillance cataloguing their every action 24/7/365.
I disagree with calling the question ridiculous. If we’re involving legality like the poster up thread implied with making this illegal then there needs to be some sort of test or rule put in place on what constitutes illegal activity. We currently don’t have one and whenever a new rule is put in place you quickly find out that there is a significant chunk of people who would find anything you think is obviously wrong to be obviously right and vice versa
Arguably third-party apps that are scrapers are somewhere in between these two in acceptability, but that's a question of "are scrapers morally fine and should they be legally allowed", not a question of whether third party clients are to be allowed at all.
The distinction is about whether you should be able to offer something publicly, taking advantage of public infrastructure to do so, and then make demands about what the public do with that.
Companies want to do the electronic equivalent of putting copyrighted media on a billboard in a public square then claiming you need to sign a contract to look at it and then only through special glasses they provide.
Here is a different way to look at what is going on lately in the short history of the internetowrked computer. To me, there is no legitimate "business". Meta cannot charge IG users a fee. They will not pay. If they would pay, then why not charge them. Instead Meta exploits IG visitors by spying on them. Advertisers will pay. Third parties will be interested in the data Meta collects. What Meta is doing with FB, IG or WhatsApp is not legit "business" IMHO, because, IMO, a business generally produces something of value that people pay for. Generally, Meta does not do that.
Newspapers sold advertising, but people were willing to pay for newspapers. Because newpapers produced something of value. They employed people to produce a product that people paid for: journalism.
Meta does not employ people to produce something of value that people will pay for. The content on these apps comes from the people who use them, and from journalists emplyed by newspapers, but not Meta. Meta make people the product, access to and data on which they sell to paying customers. Websites and apps are not "products". In this "business" the people who use them, their behaviour and the details of their lives, are the product.
A kid's lemonade stand looks more legit as "business" to me than a "tech" company producing so-called "products" that are given away for free, as bait. These are not the product that customers pay for, that no one likes to talk about.
Billboards owners sell advertising. They own or lease real estate with high visibility to traffic. It is difficult to avoid billboards because we generally use the same paths to travel in physical space. As such, billboards are regulated. Not everyone with land adjacent to high traffic routes can erect billboards. See, e.g., Highway Beautification Act of 1965.
Perhaps Meta is like a billboard company in a world that has yet to regulate billboards. IMO, Meta is far more of a hazard to life than a billboard is to the beauty of a highway. Meta does more than display advertising to people who use their websites and apps. Meta's "business model" is a threatening the stability of society. If it is allowed to continue, it should be heavily regulated.
Imagine someone telling you, "If you don't like the billboards, don't look at them." Or "If you don't like the billboards, don't use the highway." It is not so simple. Now imagine Meta tells you, "If you don;t look at the billboards, you cannot use the highway".
Meta is obscuring the true potential of the internet. It has given the internet a bad rap. Meta is not the internet nor its potential to improve people's lives anymore than billboards are the scenery. If left unregulated, billboards can obscure the scenery and eventually they can destroy it.
Billboards are regulated because they’re inevitable. You’ll see them just walking around. On the other hand, no one is forcing you to use Facebook nor Instagram.
I don't like it and I don't use it, but unfortunately it's more complicated than that because of the network effect.
Taking aside advertisement for a moment, what you're suggesting is that the level of control should go as far as which clients are allowed to speak a given protocol. This would be similar to the landline system during the monopoly days, where you were only allowed to connect an officially-approved phone (with a correspondingly high ongoing rental cost) to the copper lines.
From my perspective, there is no 3rd party involved here: there is an API surface which is developed and supported, and there is a client/customer who is interacting with the service through that API. Advertising either needs to be implemented into the API (good luck--see the demise of RSS), or the 1st party needs another business model.
We should push for MORE of the above, not less. We should push for laws that HELP people use the things they have, instead of locking them out of their own property. If Facebook doesn't like people trying to access their own content, Facebook shouldn't have built a business on everyone else's content. Nobody forced them to do that.
I make no particular comment, here, on whether we should be defending that business model.
Additionally, phones are only monetized through leasing, and 3rd party phones aren’t leased. How do you expect the 1st party to stay in business?
I don’t align with AT&T on a lot of issues, but they should be able to control which phones connect to their network. Don’t like it, don’t use it.
tweetdeck.twitter.com exists and I use it regularly, what am I missing?
Would you be ok with a usage plan? Something like $1 per 10,000 tweets read? I mean, the developer could save money by caching the most popular tweets and serving them from their cache, I imagine they’d have to charge for that infrastructure though and somehow they would pass the costs into the user. Maybe the could offer a monthly plan, with some kind of fixed cost that would keep most users fed with tweets while also not making uses worry about usage based billing.
Maybe Twitter/Insta/whatever could just require you to have a paid plan to use 3rd party clients?
Previously there was App.net, which was effectively "Twitter but you pay for access". It had a free tier which had very reasonable limits. It was actually super awesome, and it actually provided a whole identity platform, enabling 3rd party applications of different kinds (for example an Instagram-like, Favd[0]). Unfortunately it didn't pan out, not sure the whole backstory, but it was a really amazing platform and I would love to see more internet services like that.
[0] https://www.eriksoderstrom.com/p/favd-app-nets-gateway-drug
If anyone could make an App, how would Spotify be able to properly track song plays and whatever else they need in order to pay the rights holders?
Plus, someone would end up creating a 3rd party client that silently plays some song, unbeknownst to the user, in order to rack up plays and earn more money.
While, in cases like this, I agree with you, I think there needs to be nuance to a rule like this.
Consider what would happen in the reverse case. A competitor arises to some aspect of Facebook's services—say, an app that does something kinda like Instagram, but not quite—and becomes somewhat popular.
Facebook adds support for accessing this competitor's service from their own app—look how convenient! You don't need to download two apps, just our app!
They replace the ads from the service maker with their own, thus starving them of revenue...or they just wait until some critical mass of users access the other service through their app, then offer free and easy migration from the other service to their own. Then they start introducing UX problems with the other service—oh, but it's not their fault. It's because of changes to the API or ToS of the other app!
In short, if this sort of thing is mandated universally, it simply tips the scales back in favor of the behemoths already ruling the roost, who can afford to build support for a dozen competing apps right into their own, and use the good old Embrace, Extend, Extinguish (or any similar playbook) to make sure the competitors die of asphyxiation.
So, obviously 3rd party clients are thus able to perform malicious acts, but existing laws already forbid this.
My suggestion to ensure 3rd party clients are always legally permitted isn't mutually exclusive with existing laws protecting the creators of services and software. :)
https://developer.apple.com/documentation/devicecheck/valida...
Brilliant, in a scary way. In a way it makes data portability regulations all the more important.
It generates a public-private key pair that is stored in the secure enclave, then it sends that public key (or the hash maybe) to Apple for them to sign. The rest of the stuff is as you expect.
One could simply figure out how the request to apple is made to get them to sign a key, and that's that. Get them to sign a key and pretend to be the app from now on.
I guess this prevents spam from someone signing thousands of keys using a specific phone's serial number, though. Assuming there's an unique public-private key for each phone apple makes, one can't simply get them to sign keys with random serial numbers.
So, there's no way to beat it except by extracting a private key, or by using some software exploit to confuse it into signing the wrong thing.
Unfortunately for some types of games (first person shooters), a modified client can be game ruining for other players. For me, as long as it's only running while the client is running, and doesn't send private data remotely, I'm okay with it.
At least on Windows there's not much difference in terms of privacy of something running in the kernel vs userland in the same user as your important documents. It can read your entire filesystem and attach to running apps anyway without needing kernel access. So the "in your OS kernel" part is only concerning if their anti-cheat is coded poorly enough to cause a BSoD.
As I’ve already mentioned, meta isn’t a utility that people can’t live without like a phone. If they don’t like it, they should use something else. There are many alternatives
This is not true for large parts of society.
There are many institutions which force you to communicate via facebook, so not having access to it means you're locked out of parts of your real life.
This is horribly wrong by those institutions, of course, but here we are. It should be illegal, but isn't yet.
Good luck if it's a business or public org. Why change their process for what amounts to a minority of customers? It's not worth the cost. Whether these people can't do business with them despite these services being essential to everyday life... well tough luck for them I guess?
Own example: in $COUNTRY almost all banks use either their app or Viber to send 2FA. I refuse to use Viber out of principle, and also their app refuses to work on phones that don't use Google services. Should I be locked out of my banking because of me refusing to support the practices of other, unrelated services that happen to be 'popular'? Note that there is no other way to get the codes - other banks may use SMS but that is expected to be sunset next year and they will switch to the same methods.
IMHO it's disingenuous to say that there are options, when most of the time there aren't any.
Banking and social media are also two very different industries. One is essential while the other is mainly bread and circus with a myriad of alternatives
There's no [significant] public outcry because most people use facebook or whichever latest popular thing.
It's a matter of time. Even if it's not endemic in the US (which I severely doubt) it's endemic elsewhere. Don't underestimate the public's ability to put up with things, especially if they are mostly kept in the dark about the most sinister effects.
> Banking and social media are also two very different industries. One is essential while the other is mainly bread and circus with a myriad of alternatives
Both are essential. Social media is what you make of it. It can be bread and circus, yes, but it is also an invaluable tool for communication. Losing access to them can stifle your communication efforts by a lot. Why, you may ask? Because network effect is in full swing: "Phone call? Who still does that? Just use messenger like a normal person". No one's gonna bother to call you or SMS you cause 1) you're not on messenger or whatever app they use and 2) can't be bothered to contact you at your preferred non-app way, when the whole friend group has a group chat from which every single interaction and update is broadcasted to everyone. In the end, keeping you in the loop is too much work, and then you start missing out on outings etc. And even if you somehow persuaded all of your friends to use alternative methods of communication, 99.999% of the planet just can't be bothered, especially when they have friends that are reachable over 5-6 different apps, one on each friend.
Don't underestimate the network effect.
Social networks are not an essential service. There are other social networks and there are other forms of communication including SMS which is standard on all phones. If you’re not willing to pay for a better service like iMessage instead of an ad supported one, that is your problem
You don’t! Just don’t use meta products at all!
However, Meta blocking the developers fb accounts is basically harassment. Let the courts sort it out if their app is illegal. Meta shouldn't take things into their own hands.
This is the bit that's confusing to me.
If I want to access my FB/IG/whatever content, and present my credentials to the server along with a valid request for my data, why should Meta care how I do so?
I could be using nc[0] piped through openssl, rather than a web browser (do you believe Meta can mandate which browser you use and/or what add-ons/extensions it runs?). Is that "hijacking" the API?
If the answer to that question is "no," then shouldn't I be able to write my own client, to access my data, too? If you think I should, then how are either of those (nc, write my own client) really different from using software written by someone that's not me or Meta, as long as I (providing authentication/authorization for my own access) use it to access my own data?
> it shouldn't matter
According to? That's an ethical stance one can take, but it isn't how our laws work.
If a badly configured NSA server gives you data, intentionally accessing it (and/or then misusing the data) would be the crime. I don't think it matters whether you view that data in a browser, a terminal or some third-party client.
Here, the third-party client is accessing the exact same data the official client is. It's not bypassing any access control, in fact it needs your credentials to be able to access the data you're authorized to view.
> According to? That's an ethical stance one can take, but it isn't how our laws work.
I'm not even sure if a law has been broken here? Breach of ToS != crime. As far as I know there is no unauthorized access taking place - the unofficial client is using your credentials to legitimately access the same API as the official one does; it's not giving you any extra data that the official client doesn't.
> Breach of ToS != crime.
Breaching a contract is not generally a crime either. But it might lead to a civil case.
What law? Please be specific here as I'm not clear what you're getting at.
If you're referring the Computer Fraud and Abuse Act (CFAA)[0], it states:
The law prohibits accessing a computer without authorization, or
in excess of authorization.
WRT NSA servers, accessing classified information (assuming you don't have clearance and/or a need for that information) would violate the CFAA and possibly the Espionage Act[1].However, in this particular case, an end user is accessing data (with appropriate credentials that have access to no more and no less than the data they are authorized to access) for which they have appropriate authorization. As such, it can't be a violation of the CFAA. So, where's the "crime" here?
I'm not sure how you're getting from point A to point B here. If you could help me out, I'd appreciate it.
[0] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
Just to clarify, that means your answer to the question:
I could be using nc[0] piped through openssl, rather than a web
browser (do you believe Meta can mandate which browser you use
and/or what add-ons/extensions it runs?). Is that "hijacking" the
API?
Would be "yes." Is that correct?If so, please consider what that means for your property rights.
They care because it is part of their business model. If you avoid tracking that affects their revenue.
> There's no reason I should have to be subjected to untold tracking, snooping and advertising functionality to be able to post or look at photos and comment on them.
Stand up your own PixelFed instance for your family and friends today!
Given that, what should a company do?