How To Cheat On Facebook Apps Permissions
homakov.blogspot.com
homakov.blogspot.com
Second, this is well known and has been discussed here previously a number of times.
There are already numerous browser extensions that allow users to customize these settings. for eg. FBSecure:
http://www.addictivetips.com/internet-tips/fbsecure-customiz...
and
https://github.com/chadselph/OOptOut-Chrome-Extension
previously discussed on HN here:
https://news.ycombinator.com/item?id=3287272
and a bunch of other threads that I can't find right now.
I didn't really call it a flaw. Just UX stupidity or whatever
>Second, this is well known and has been discussed here previously a number of times.
well known? :) is it mainstream to call smth 'well known' if you know something?
> There are already numerous browser extensions that allow users to customize these settings. for eg. FBSecure:
extensions are useless because actions are really routine. but it's nice to have them, anyway.
https://developers.facebook.com/docs/authentication/permissi...
I thought I would dump my previous links incase you jump into writing an extension. It would be better to contribute to the open source extension than to have yet another project (as we do with removing auth popups on news feed items)
Otherwise nothing against this making news again, the more people that know about it the better
My point is not just 'check this trick' but OAuth2 has no fixed-scope feature at all. You always have to check shit after user did something. This is just lifehack but i am interested in oauth2 spec overall
Edit: There's also an option to edit/disable the extended permissions during the authorization. Docs: https://developers.facebook.com/docs/opengraph/authenticatio... (Permissions section)
what is intended here? I am user and I cannot opt-out perms in user interface. So I have to use URL trick. Looks not intended
"This app can:" section with perms configuration is what I want to see on authorize URL.
Many developers request permissions they think they'll use in the future, so this trick is useful because it puts it back on the app to error out when the user is missing a permission it actually needs.
Facebook should either let me to opt out permissions in UI or make them required (if I press Allow then permission is granted anyway)
The only benefit I see of the all-at-startup solution is that it provides one single "interruption" to the user. But the list of things an app might do can be large, even though it only may need to do some of them rarely. So if I see a big long scary list I'm more likely to just cancel out.
Reference: https://developers.facebook.com/docs/authentication/
- Ask for permission
- Yes? -> Good you're in.
- No? -> Ok, np see you another day, maybe.
But what was happening is there was a third flow.. - Yes (But I don't give you permissions!!).
And that created a nasty bug later on in the app.I don't think it's a "flaw" because you can accept the first perm. dialog as a user, but deny the second one (Asking for more permission). But, I believe it should be more explicit that developers need to verify permissions on every actions requiring them.
Does it really matter how much you can limit your own apps, if anyone on your friends list can install any app and silently give away your information to some unknown third party without your knowledge or consent?
although any non programmer human being is smart enough to just modificate 'scope' param in URL :)