Facebook can now read your texts
tony.calileo.com
tony.calileo.com
> As for the READ_SMS permission, we require that so we can automatically intercept login approvals SMS messages for people that have turned 2-factor authentication for their accounts, or for phone confirmation messages when you add a phone number to your Facebook account. Unfortunately, the Androids permissions system does not allow us to specify that we would like to be able to read only SMS messages from a specific number (plus that wouldn't scale well because the list of numbers varies per country, but that's a separate issue).
[0] http://www.reddit.com/r/WTF/comments/1t5z45/facebook_why_the...
Typical tradeoff: It's a nice feature, but adding it requires permissions that are off-putting to some users. I'm not sure there is a good solution here.
But perhaps if it were implemented better it might make some sense.
e.g. Given the explanation that it's only for 2-factor authentication, I accept and install. When the next version is released (which does more with that permission), I see no new permissions required and install.
ericcumbee's suggestion of sending a URI makes much more sense to me. A per-request permissions model would likely need to include a "yes to all" checkbox, which would be checked in short order by the vast majority of users.
Besides that, two factor is a bit of a joke in an app (on your phone) that caches your password, and then sends a message (to your phone) which is automatically read and accepted, before allowing you to login. What exactly are we achieving here in terms of security? Every 30 days the app authenticates itself with no user intervention.
It would be much more secure to just force a password login.
For all other cases going via cell networks is a good enough secondary channel of communication which leaves out any chance of being mitmd over WiFi or something.
I'd argue that a corporation other than the phone company being able to read all your text messages is significant pain.
Given that FB seems to want to take over all communication between users (contact list/blog/email/photos/messaging) FB being able to track and access anything you do is the inevitable endpoint of such aspirations, but many people are not comfortable with that, and the farther FB go down that road, the more people they'll alienate.
It's not really. The point is to verify that the device used for 2FA is still with you, whether you entered the code manually or it got entered automatically isn't the point of the system - and in practice has no real difference (unless your 2FA app requires password for access)
>What exactly are we achieving here in terms of security?
Verifying that the phone is still using allowed SIM card/phone number.
If you switch phones you can still get the confirmation message and access your account and if needed invalidate all other sessions.
If your phone is stolen you can do the same thing. The app password caching doesn't matter then.
It is no different than 2FA app that you have on your phone except that it's more tied to your SIM card than your phone.
tl;dr: Android's permission system does not allow for transparency from the developers. It makes the app developers look like douchebags going 'I WANT TO READ ALL YOUR TEXTS', instead of a 'I'd like to make things a little easier for you by automatically intercepting two-factor authentication texts'.
You can't just peek into the entirety of user's SMS and justify it's for the security of your users.
At least put an option to give users a choice and not force them to have their their SMS read in the name of innovation, or explain why you read them and that need just that one SMS.
The Facebook app is probably the fastest way to find a list of all permissions in the Android system. "Draw over other apps", "Read battery statistics". I don't know what part of facebook requires either of those options, and the mobile version of their website offers me the minimal amount of functionality I need.
The act of writing this comment has made me uninstall the damned thing. Just reclaimed 17.61MB, and probably a fair amount of space in my mind since I'll check Facebook less often.
I'm sure, as the author of the linked article asserts, most people blindly accept the permissioning changes, but I hope this permission-creep starts to cost them installs.
Facebook is now wrapped by Tinfoil-Facebook and Twitter is now relegated to the browser.
I can't possibly state emphatically enough how user-hostile that feature is. It is so disruptive to my thought process...it's nearly as bad as that awful focus-stealing thing that Windows does.
Yes, sometimes it does get in the way of what I'm doing, and in those cases I just swipe the chat head down to the bottom of the screen and it goes away. And considering turning it off is one of the options in the first page of the settings, I'm not really understanding why it would make you furious or think this is user-hostile. Overall it's a pretty unimportant change that is easy to disable if you don't like it.
Is there no meaningful way to push back against Facebook for demanding this permission?
Android apps ask you if you want to update to the new version or stick with the old one indefinitely; privacy settings are non-negotiable. iOS apps ask you as they go: If iOS had an SMS API, Facebook wouldn't need to ask you until you enabled two-factor authentication (assuming that's all they use it for). And you could turn it back off later if you weren't comfortable leaving it on.
On Android it's all or nothing.
Though I don't think I'd be tracing out "Hello". Unless you speak Bronx.
[1] http://www.dailytech.com/Google+Removes+App+Ops+Privacy+Cont...
One engineer can't launch a product alone. Just isn't possible unless its under a personal name.
"and likely ended up paying with his job."
0% chance.
Also, it’s better for Chrome’s security reputation to allow AdBlock from within their store than to allow it from a third-party site. You don’t want to train users that it’s OK to install extensions with broad permissions from anywhere but the Chrome store!
It may become the case in the future that they re-evaluate these priorities, of course.
Same as Cyanogenmod without having to root your phone.
I think "not using the app" is the most meaningful way, really.
Alternatively, spoof its private data hose and flood Facebook with garbage data, but I presume that's illegal.
Less intrusive, less privacy issues.
And it probably works better than the app.
In that situation, I cannot send or receive SMS messages, but FB, etc., work just fine.
You can use my Facebook client, which definitely doesn't read your text messages, emails and calendar.
Link: https://play.google.com/store/apps/details?id=com.flipster&h...
</shameless plug>
Does this constitute a privacy policy?
On Android you can see for yourself whether an app tries to access data such as text messages, emails or calendar.
My app doesn't ask for those permissions, therefore it can't access that data.
This should be a standard part of Android, in my opinion.
The app, for those curious (I have no affiliation with it):
https://play.google.com/store/apps/details?id=com.colortiger...
My favorite permissions to revoke are: Wake lock, Location, Read contacts. As a result, I get almost 2 days on a full charge on my Nexus 5.
I used to think I could be 'safe', that my advanced knowledge of privacy settings and optimised usage patterns could somehow shield me from the fundamental nature of these data monger corporations. But the truth is concepts like cloud and social networking are fundamentally toxic to privacy and freedom.
I'm now pretty close to the day I delete my Google account, and that provides far more useful functionality than Facebook.
You could have a Facebook/Google account under a different name. I have one and its rather useful when websites have an option of logging in using facebook/google accounts.
>I'm now pretty close to the day I delete my Google account, and that provides far more useful functionality than Facebook.
What is this "far more useful" functionality ?
You can easily be identified by your network of friends. The name of your account doesn't matter.
Argh...paranoia...all consuming!
if facebook wanted to be nefarious with these newly granted permissions, they have an extremely large pool of data to mine.
Monitoring Location likely means continuously getting notification about device location as you are moving around.
Facebook's value proposition is going downhill fast. All but the dumbest users are now very careful about what they allow FB to know, if they stay at all. I suggest that their hallowed social graph contains less and less reliable info about the more valuable demographics.
That's a pretty crap feature to use to justify this.
http://android.stackexchange.com/questions/57726/twitter-rec...
- NEW: Receive text messages (SMS)
- NEW: Read phone status and identity
Another reason I haven't updated yet.The "strategy" is very straightforward - first to gain "popularity" offering a reasonable service "for free" and then, after accumulation what they call "user base" they just change the rules (permissions). The idea behind separate "messenger" app is exactly to "hijack" user's messaging service by "forcing itself to be" default messaging app.
I don't even want to talk what kind of spyware Skype is, using exactly the same "strategy" of quietly "adding functionality" and having permissions to do everything.
There is no other "working" way to monetize user's data, but collecting and selling it.
The next level is just adding malware functions in "next version".)
I will say that the app provides very little that the mobile web version doesn't give you. I don't even notice the difference.
It is also telling that OP is bothered by "read your messages" permission but doesn't seem to mind "record audio, take pictures and videos" just below it. Just because it is not new?
App Ops was not an ideal solution anyway. A specific permission couldn't be disabled until after the app used the permission at least once. So the Facebook app could read your SMS when launched, and only then you would be able to disable the permission.
[1]: https://play.google.com/store/apps/details?id=com.danvelazco...
http://developer.android.com/reference/android/media/AudioRe...
To my chagrin I find 31 apps on my phone now that have that permission.
2. Facebook gives explanation of all the permissions they need, including read SMS one, here: https://www.facebook.com/help/210676372433246
3. This is more android permission issue than specifically Facebook app one. Facebook, in order to implement automatic confirmation, didn't really have a choice.
And fwiw, I use the app daily and I've had this update for at least a month and the read sms permission was never used according to various privacy tools which allow you to see, disable and view usage history of app permissions.
Until facebook starts abusing this feature/permission I don't think it's really an issue like most articles about this make it look like.
Why facebook doesn't disable it? Because people use it.
Why don't users disable/deny it? Because you can't select which permissions you want to grant to application upon installation, it's either all or nothing, even though the permissions may never be used.
And it's not really a shitty feature, the auto confirmation is pretty good - the permissions needed for it are shitty though, but they don't really have a choice other than completely disabling that part of application and having users enter the code manually.
Try Tinfoil: https://play.google.com/store/apps/details?id=com.danvelazco...
CyanogenMod with Privacy Guard also works, but facebook's app is stupid bloatware anyway.
What do you mean by that? It asked me if I want it to handle my sms, I said no. It asked me again when I updated to 4.4, I said no again. I can (and will) keep saying no...
I suppose they reason that it would be too confusing to the people who would then try to SMS from their computer, as iPhone+Mac users are able to do so... but isn't segmenting my Hangouts history just as confusing?
Also it's a moot point regardless: Facebook can read all my messages to friends on Facebook already, and all their messages to their friends, and everything they publicly and privately share, including photos and videos, and they have access to most e-mail accounts around the globe. My texts are a relatively small deal in comparison.
Most of the time, they're here to make the app slightly more useful to the end user. But at the same time, you're potentially saying "yes" to a company who might, one day, use your most personal info for bleaker purposes.
It's thus something I've always been fighting against (at least at a personal level): I've stuck to the older, non-requiring-SMS-permissions version of these apps until I could upgrade to a version of Android with App Ops, then Cyanogen.
If SMS permissions is where you draw the line regarding your privacy, either run a version of Android with App Ops, or Cyanogen with Privacy Guard.
I find it sad that companies still think most users value simplicity over privacy.
Twitter is doing the same. It requests access to contacts list, SMS, phone call, phone Identity. I noticed the same and stopped updating. Andiord should enable users to control apps.
[1] https://play.google.com/store/apps/details?id=fr.slvn.appops
I personally don't use Facebook on phone now, but I would recommend using a third-party app for accessing Facebook on android. I have used Friendcaster, Fast and Seesmic before and found them pretty decent.
(Actually it's called AppOps and it's from Google but it's an hidden feature on stock Android)
Ref: http://www.businessinsider.com/facebook-might-be-reading-you... from Feb. 2012
I have it enabled default for all newly installed app.
Hello Owncloud !
It's kind of sad.
But if you ask them - they'll say it helps them deliver a better experience for their users and helps connect people, and that's what people really want ... to be more-connected.
I DELETED FACEBOOK!!!!!!!!!!!!!!!!!!!