Our domain and 700 non-profit sites got blocked by Meta
simonbackx.com
simonbackx.com
At my previous company we had "Sign in with Facebook" – whatever your opinions on it are, it was probably the right thing for the company at that time.
Facebook decided to "audit" us to make sure we were doing sign in right. The tested it incorrectly, told us we were at fault and needed to fix it, and gave us 2 weeks to do so. We scrambled to figure out what the issue was, only to find after they eventually replied to our emails (all they told us up-front was "it doesn't work") that they had tried to use a sign-in only button to sign-up, similar on many websites, not at all for our flow and not something it was possible for us to do. We explained this and they dropped the audit.
2 weeks later, they audited us again, failed us again, and gave us a deadline to fix it. We replied pointing to the previous case and explaining again why it was working. We never heard back.
2 weeks later, they audited us again, failed us again, and gave us a deadline to fix it. We replied asking what the hell was happening (politely). We never heard back.
1 week later "Sign in with Facebook" stopped working with no other warning. We opened a support case, we emailed our ads account manager, we emailed our previous ads account manager as the first was on holiday, and all we got was "we're looking into it, but it looks legit, fix it".
I asked for a call and explained that the current user experience for users was that they would click "Sign in with Facebook" and see an error saying "Facebook is currently not working, please sign in another way", and that the only way we had to resolve this was to email all our Facebook auth'd users a password reset with an explanation that Facebook sign in no longer worked, and to then remove the feature from our site.
"Ah. Ok yeah let me see what I can do". It was working about 2 hours later, and we weren't audited again in the rest of the time I was at the company.
If the flagging is done by a human, is there really no "case file" that records the previous flags and why they were false positives? If it is done by an automated system, why is it allowed to flag things that a human has already cleared with no change?
Long time after I'd last used that account, I logged-in again and, you guessed it, the image was flagged. Requested yet another review, approved. Was it really that hard for them to trigger human reviews before restricting content that had already been reviewed?
Beyond their interest in doing, or their (low, low) budget to do at scale? Yes.
I completely disagree, there aren't many stories like this. In fact I don't remember reading any on HN.
Usually about 4 would get approved, and the other 8 would be rejected. All for different reasons. Usually it was something about Facebook Login - which we didn't use as an S2S integration. It was maddening.
We'd make token changes to the rejected reviews, resubmit, then keep resubmitting until they were all approved. On occasion an App would keep going to the same stubborn reviewer and we'd contact our Partner Manager. They're nearly powerless to do anything, since the Safety and Review team is firewalled off from the rest of Meta to prevent outside influence.
Funny nuance: when in development mode, Apps can't receive webhook events for wall posts. Only webhooks for Messenger (DMs) are active. We were adding support to reply to wall posts, but couldn't test or demonstrate the feature because public post webhooks weren't available. "How do we proceed?" "Well, you need to use the fetch API to get posts in batch for Approval, then you can use webhooks." Thing is, our platform wasn't interested in pulling posts in batch. Just routing public posts in real-time via webhooks.
So, we built a completely separate App to pull posts in batch and got it approved. Then used a proxy to slingshot webhooks through that App to our platform, bypassing the under-review Apps altogether. And we got them all approved.
It's a joke that Meta tries to enforce policy at the application level vs. API for enterprise S2S integrations. Workarounds "faking" the experience are always possible.
I advised simplifying things by having a single proxy service distributing messages to different cloud regions based on the customer. Or maybe 3 proxy Apps - dev, US, and Germany, as simple middleware shims. But not 12 Apps. It fell on deaf ears. Since I left, I hear with Instagram support and more granular permissions on Messenger, they're submitting 60+ App Review submissions every quarter. With the resubmissions and petitions it's nearly full-time position.
If I ever took another position working with Meta, it would have to be "retire in 3 years" kind of money.
I'm a pro and even I can't tell how this is supposed to be safe. How would you explain the security aspects to someone who can't distinguish between google-search and the browsers address-bar?!
When you force people to log in with their E-mail address, what percentage of the public also thinks they need to use their E-mail password? I'm going to guess at least half. Now, if that site is compromised by a hack or disgruntled employee or whatever, people's E-mail accounts are wide open and identity theft galore can ensue.
Not to mention that your E-mail address is on thousands of spammers' lists. Combine that list with lists of common passwords, and you have a shitload of compromised E-mail accounts right there.
Nobody should have tolerated this amateur-hour policy, but here we are.
The sheer amount of support work that resetting passwords and fixing access issues (and dealing with hostile actions) generates for a small team is staggering.
I used to run a graduation photography company, we did professional graduation photos half the price of the 'officail' providers (who pay a huge commission to the university, but don't get me started on that).
We promoted our service with facebook events and advertised said events. One year without warning or explination they Facebook just deleted all our events (we would travel from one uni to another over the summer). I frantically tried to get a response from facebook. I never got one.
I sued in small claims court and they settled the case (not before being very threatening through high paid lawyers and trying to dodge the case altogether) they never did explain what had happend or why.
Ultimately it's partly the reason I shut the company down, facebook was our channel, without certainty we could host events and promote them it made no business sense to invest in the company.
What I suggest is for your and your clients to contact Meta through the Business Center support. Their support for paying clients is much better. I would also recommend you become a Meta Business Partner if Facebook/Instagram is important for your SaaS.
If you're running independent subdomains where a bad actor on one should not affect the reputation of the rest, you probably should add your domain to the public suffix list: https://publicsuffix.org
Perhaps worth it in this situation, but isn't that basically paying protection money? "Nice domain you've got there. Shame if anything happened to it."
But they aren't.
Their URLs are simply blocked by Facebook, who happens to be a popular third-party website.
It would really be a shame if something was to happen to your domain in our ecosystem because you're not a paying partner.
They're mobsters.
One could argue that is the whole point behind making life for non paying users harder.
Most of those services also let clients setup their own domain name, so a ban is a more of a inconvenience to deal, than business critical like in OP case.
EDIT: I will note, it has been a few years since I've submitted to the app store, so I hope things have changed.
And I'm only talking about the normal process, good luck if you happen to have a buggy developper account which loops during the sign-in...
However, the public hysteria over "big tech" should not be dragging Apple into everything, because developers are essentially the only aggrieved party. Unlike Google and Meta, Apple is not the gatekeeper to the Internet for millions of people. And I can almost always get a human being on the phone or chat from Apple, which today is truly worthy of praise.
As an example, look at the flu. It kills way more people than drunk driving, [1] [2], but society has been pretty casual about that. The massive covid-era drops in influenza deaths show that it was always possible to do much better; we just never cared much because we were used to it. Similarly, I think we're used to Facebook and Twitter being Facebook and Twitter, so there won't be much outcry for change unless they do something especially bad.
[1] https://www.cdc.gov/flu/about/burden/index.html#:~:text=Figu...
[2] e.g., https://www.valuepenguin.com/drunk-driving-statistics
"Predominantly target or serve an audience likely to have suffered from mental, emotional, financial or physical harm, or facing severe economic hardship that directly affects housing, food security or freedom."
I'm guess if a single one of your non-profit sites does all the sites would be blocked. Apart from pleading with FB, using domains for each would be a better solution to stop this happening the next time rules change or one of your sites does something not allowed
[1] https://www.facebook.com/business/help/851247612299604?id=18...
This article is just another reminder of this. At scale that Meta operates, this algorithmically decided domain blockings mean nothing to them, but everything to hundred's of non-profits. There need to be legally mandated protections so things like this never happen again.
My guess is that American companies like to pretend it doesn’t matter in case it gave idea to US customers and silently fight it in courts in Europe.
Google? Definitely. Meta? Not really. All Meta has is two social networks and one messaging service. They haven't really experienced huge success in anything else. They MAY hit big in VR/AR space, but that's yet to be determined.
https://inspirationfeed.com/what-companies-does-facebook-own...
Feels like a lot and not just three entities.
Additionally, Facebook primarily does acquisitions as a form of hiring, according to Mark Zuckerberg himself. They buy the company so they can get the employees to come and work at Facebook.
It's not like Google which has 1)Search 2)YouTube 3)Maps 4)Android 5)Chrome 6)Gmail 7)Analytics just from top of my head
Just like Google's successes, the "successes" are actually built by others (almost all you list were acquisitions), but the difference (as mentioned before) is that Google sometimes acquire products for the product itself, while Facebook generally doesn't.
And a payment service, an ad platform, a marketplace, a VR R&D company, I never used them but I guess they also have a line of business services centred on social network communication, I’m probably forgetting plenty of things.
They literally dominate the social network landscape along with Twitter. They can literally set public agenda. That's too much power.
There are plenty of rules and procedures in every nation which screw over random 'little guys'... For example, "oh, you have a disability and can't work? Here, have some state support. Oh - we just found you helped look after your neighbours children once. That counts as work. Therefore you lied to us. Thats fraud. All your state support will now be withdrawn."
No. Giving this additional power to the government will not have the outcome you want. When something becomes too powerful, the solution is not to further concentrate that power into less accountable hands.
Well, it depends on the governance obviously. If you talk some autocratic regime, where the king proclaimed "I am the state", that fits your description for sure.
On the other hand, if you are looking at a direct democracy regime, you could hardly make the power more pervasive, and every citizen has to carry its part of accountability on every social matter.
Three reasons why nationalization is a bad idea:
* Power disparity. As it is, Facebook is destroying people and business without any accountability. Now we hand that to the state who:
* Has all the incentive to destroy anything that competes, and the government has the ultimate way to do it: just outlaw the competition. If you think the product is bad today, imagine how fantastic it will be in 10 years of no competition.
* Has all the incentive to make people use it. So, it becomes oppressive and horrible and the government decides, hey, let's make everyone use this thing for essential services like payments and democracy!
All in all, nationalization of a social network is one of the worst directions we can take, regardless of politics. It's just a bad idea.
> So, it becomes oppressive and horrible and the government decides, hey, let's make everyone use this thing for essential services like payments and democracy
These things can only fly in a non functioning democracy, which, while the US is coming dangerously close to, is not there yet.
Most functioning democracies outlaw competing with the postal service - as the US has for centuries.
Any examples of this? The USPS doesn't seem to have much power and other shipping companiea do alright.
Last I looked UPS and Fedex are legally barred from competing for letter postage and can only ship parcels (so the hack is the overnight envelope which packages your letter in a parcel.
Bonus: The postal service can arrest you and prosecute you. Last I looked, UPS and FedEx cannot.
And uh... I can count on 0 hands the number of times I've heard of the USPS arresting anyone. Bet you can too.
The USPS is a bit of an anomaly in that its responsibilities are carved out in the constitution! Still interested to hear of other real world examples.
You have other options. One is the following:
- 1/3 government (adapted to the size of the business: federal for Facebook, but local for a sawmill)
- 1/3 workers (including the owner if he's working his business)
- 1/3 investors (owner or shareholders).
That would makes the owner who also work at the company the final decision maker for stuff that doesn't involve the government (like investment), but allows more balanced power balance.
That might be the funniest thing I've read in weeks, actually.
While I'm not totally behind "nationalize all the things", do you really think the government is less accountable than Meta? (or Alphabet etc?)
I guess that raises the question "accountable to whom", but in general, for all it's problems with accountability (and there are many), and acknolwedging that different US governments can stack up differently (say local vs federal) -- I'd still say that the government is in general definitely more accountable to "society", or the population at large, than giant corporations are.
If I were king of the world, maybe I'd try having 1/3rd of board members appointed by government, 1/3rd elected by users, 1/3rd elected by employees. Oh, right, there's stockholders too I guess... ok, 1/4th all around. I know this is only my utopian fantasy.
The employees work for a paycheck of course, but I suppose there needs to be sufficient incentive to start a company. It probably doesn't need to be multi-billion-dollar payout possible to incentivize though. And talking about an already existing company like facebook, I think founders and early investors have already received quite enough reward to incentivize, being able to make as much money as they've made off meta up to this point is plenty of incentive to start a company.
(There are also other incentives than money to start a company).
Anyway, I was mostly responding to the suggestion that the government is "less accountable hands" than Meta -- I really don't think so, if we're talking about accountability to society at large. I think it's actually a problem that an entity with so much power over society isn't accountable to it; the first step is admitting we have a problem.
Companies are held accountable via market pressure, public relations pressure, investor pressure, and government/regulatory pressure. Governments, just via voters. Given that authoritarians of various stripes are working hard to neutralize or delegitimize voting and election results, yes, I think that giving Facebook to governments that are or may soon become authoritarian is absolutely at risk of reducing total accountability.
I still find it shocking to think that Meta is more accountable (to society?) than government. It seems to be arguing over how low the bar can be, since Meta has very very little accountability. Like, as in the thread we are actually on, they can decide to ruin someone else's business with no notice or consequences or even acknowledgement there's any reason they ought not to. "Market pressure" and "investor pressure" don't seem to be doing much good in accountability to society, do they?
And you mention "government pressure" as something making them accountable to society right after arguing that government is less accountable than Meta is without government control, which seems odd.
That is not something I said. I'm not even sure it's quantifiable enough to say "more" or "less", as the kinds and mechanisms of accountability are so different.
> arguing that government is less accountable than Meta
I did not say that either. My point is that an authoritarian government nationalizing Facebook is even worse in accountability terms that either one on its own.
> "Market pressure" and "investor pressure" don't seem to be doing much good in accountability to society, do they?
I think your baseline is off. The social media platforms have made huge strides since their early days. Could they do more? Yes. Could they be worse? Incredibly so.
Yes. Absolutely, and without any qualification whatsoever and in every jurisdiction at every level.
Government enjoys sovereign immunity, qualified immunity, direct statutory immunity (laws that prevent suing the government) and operates the forum where they are held to account (be it a regulator or a court). It is very difficult to sue the government, and even more difficult to mount a campaign to change a law in a non-corrupt country. This applies to a tiny sanitation district,
Private companies are easily sued, regulated, and if their behavior is bad enough, reputation damage alone suffices to hold them to account.
You are doing a good job of calling them out here. Last I looked, Meta's stock has taken a beating this year, to the point that their largest shareholder has lost roughly half of his wealth. Facebook's loss of users is having a huge effect.
> Good luck passing pro consumer regulation when industry is allowed to lobby, fund political advertisements, and donate money to campaigns.
Yes, getting the government to do anything is very hard, especially when they own a company or a service. You'd have to do all of the same things you have to do to regulate a private business, but with limited rights for redress. Government can incarcerate, take your property or kill you if they want to silence you. Meta can only shut off your account.
Governments are always more accountable than private companies, because the only way an ordinary citizen can force a private entity to cease its abuse is... through the government. (No, "voting with your wallet" isn't a thing, especially when the abuse is profitable.)
Giving more power to the government on INFRASTRUCTURE at this scale always gives the desired outcome everywhere arount the world except the US.
I stressed the word infrastructure. Because at this level, these companies are literally the gatekeepers of the Internet. Who control literally 70%-80% of what we see, hear and do among themselves. Especially when doing business as a small business, there is no way to avoid them. And they can make or break their business within a day with their arbitrary decisions.
Imagine that your local road network was owned by a private, unaccountable company that was able to change the traffic flow within one day at a whim. Literally breaking all the logistics of your small shop by causing it to be much more expensive. Or your local power company doing the same thing.
To avoid such things, we keep infrastructure in the hands of public companies or we VERY tightly regulate them. Allowing a society's infrastructure to be controlled by private actors is as crazy as it gets.
I don't think most government are better than any corporation.
"government are better than any corporation" (or its reverse) means nothing if you don’t provide some specific topics and possible metrics to evaluate them.
Also, not all government and corporations behaves in the very same way.
Such protection for websites would be an implicit protection for Meta's de facto monopoly on text-based social media. What needs to happen is for these sorts of bans to still happen, but for the public to understand the impact of those bans and move away from a single website for all their social media needs if they want to see posts from everyone.
Competition in the space would fix the problem. It'd mean the impact of a ban is massively diminished, and that companies are incentivized not to issue unwarranted bans because their users would go somewhere else.
While both users and advertisers have no real choice where to go Meta will hold on to their monopoly.
Nationalised by what country? US? UK? France? Russia? Saudi Arabia? India? China?
Would we have country-specific and isolated social media and search engines?
Even in nominally free western countries, do you really want the government controlling what can be in a search engine or posted on social media?
Plus why what the government do with a social network? They’d still need to moderate it — at atrocious prices at that.
Separately I'd also like to see us outlaw the kind of data collection & retention that lets Facebook's business model exist, but I do think making it so offering free services doesn't absolve you of all responsibility is something we should do, too, and is more directly relevant to this.
Just delete Facebook, it's not worth it.
We issued LetsEncrypt certificates automatically using Caddy and it works remarkably well for us. It also led us to become a paid LetsEncrypt sponsor and we have been for the past 4 years.
I’m not sure how to ask this in an answerable way, but did they ask you not to talk about what happened and/or how it got resolved?
Before any big tech appeasers and bootlickers reply and attempt to defend this rubbish with 'private platform' nonsense or 'you knew you violated the TOS', in each of these cases do you know specifically why they got blocked as well? [0] [1] [2]
[0] https://twitter.com/llsceptics/status/1567658400573448192
[1] https://www.telegraph.co.uk/news/2022/09/21/paypal-shuts-acc...
[2] https://twitter.com/flipper_zero/status/1567194641610465281
Instead of client.your domain.tld, register client-your domain.tld. This would prevent one bad actor from nuking your whole business.
Yes it has a cost, but it’s like $10 a year for a new domain, which I bet pales in comparison to other direct costs of running a SaaS.
Or here is our 75/year plan which includes a domain to ensure you don't run into problems with social media
- Well the person who set that up stopped responding, isn't there another way to get this going? - I've added all the record in what do you mean they don't match? - I don't even know what DNS is, why is this necessary? - I added in the record but the system didn't take one of them because it started with an underscore and they said that was invalid. - We just switched websites to WIX, why is our shop page not loading, is your system down? - Will this break my email, I don't want it to break my email. - Here is my login, just go in and change what you need.
So in all, it's not just $10, it's a significant investment in time and resources to do this "simple" change that until this point did not have any downside. Hindsight is like that every time.
The best reason not to do full domains is the risk of bad actors re-registering domains you release, as schroeding points out in another reply.
Client.SaaSdomain.tld
not
Shop.clientdomain.tld
If you’re setting up your service as a subdomain off the client domain, you won’t face the risk that one customer will get your entire service domain blocked (since it’s the customers domain).
They already have to do that, only currently they have to put it into customername.shop-saas.com, not customername-shop.com, or even shop.customername.com.
For Facebook: decentralized social networks built on open protocols.
For the ISP: normalizing the use of VPNs (through a local server) for all internet traffic.
Yes there are tradeoffs. I'm personally happy to make them.
Also, it should be noted that blocklists are not a solution for things like phishing. Things like MFA and WebAuthn are the solution.
I guess it's actually the same thing as the social media "Free speech" wars... meta has the first ammendment right to deny service to whomever they want for whatever they want (sans discirmination against protected classes), they can legally decide to ruin this company's business just cause they don't like them, even if it wasn't an accident? Yeah, the problem is facebook is too powerful, they aren't just any random business choosing not to work with you.
Even if you get unblocked this time, it could easily happen again. Until there’s systematic reform to this nonsense, you just have to work around it with redundancy.
If they’re going to treat you like a scammer, work around it like the scammers do.
(Even if it were a satisfactory solution to say "message all your customers and tell them they have to start using the new domain for ticket sales, including for events that are already promoted with ongoing ticket sales" which of course it isn't, although I follow you that it would be perhaps better than nothing).
https://developers.facebook.com/docs/threat-exchange/getting...
The use of "users marked this as spam" as a signal is a cheap but lousy shortcut and it's bad news that we became reliant upon it.
Of course this doesn't take away from the validity of their claim and I wish this stupid shadowban is lifted. Also I hope (at least in Europe) we can get some laws passed that force large online service providers like FB to act responsibly (past record of attempts to regulate the Internet by our beaurocrats and its results notwithstanding).
Plus scam coins, etc.
It’s probably far easier for them to just say “none of that” until it gets easier to tell the good from the bad.
It's not hard to imagine that a lot of these companies are now using outsourced 'moderation' where the moderators themselves are the scammers, intentionally permitting scams and intentionally flagging legit stuff. But sadly the truth is probably more boring, indifference instead of intrigue.
Some people view porn as far less damaging to society than crypto (at least how crypto has been primarily used YTD).
“fake news” is can very easily be abused to mean “news that doesn’t agree with my world view”.
“Violence” is vague but would coverage of what’s happening in Ukraine be put there?