418 karma · joined September 3, 2011
You're applying a false equivalence here. Some things are positive changes and make sense, and some are not. Grouping everything together isn't helpful.
I am male, and my first thought on reading the title was that it was juvenile to a point that I was surprised to see it as a title on HN. Hearing someone else echo that feedback is helpful and will hopefully help the author in their growth.
This is not a "bend over backwards" request, it's a dumb sexual joke on HN, and your response comes across as very condescending.
My private messages are a whole different category of private. Facebook had a phenomenal engineering team and I put the same trust in them that I put in google for my email. A hack is still possible, but it's the highest level of trust that I can have in a service that I can't control (sure things like Signal exist, but 99% of my friends don't use it, so there's a tradeoff). So this particular incident, and the dismissiveness of the response, is my dealbreaker
I am an engineer. I understand technology better than most of the general population. When I sign in to my Facebook account to use Spotify, I am absolutely not expecting that Spotify will now have access to read every single one of my private messages. This is a gross violation of trust, and if this is what happened, then the fact that you not only made this mistake, but also then published this blog post defending it, marks a low point for Facebook. Perhaps irrecoverably so for me.
"After signing in to your Facebook account in Spotify’s desktop app, you could then send and receive messages without ever leaving the app. Our API provided partners with access to the person’s messages in order to power this type of feature."
This is a write permission. So you needed to give Spotify permission to create a message. It seems that your system combines the read and write permissions, since you just grouped them together by saying "access to the person's messages". It also seems from your defense that you see absolutely no issue with this. In order to share a song through Spotify, you are giving them access to every single private message the user has ever written.
I find it hard to believe that Facebook refuses to acknowledge any fault in this: The initial product decision, the upholding of this decision through previous privacy investigations, and this PR response. Am I misinterpreting the facts or scale of this?
Is this true? If "super successful" can be understood as "the biggest tech IPOs of the last 15 years", then I think that Google, Facebook, LinkedIn & Twitter would be at the very top of that list. I guess it depends on how we define "very early".
I'd just like to stress that this doesn't address all the issues brought up, since some of them require more time, but I'm happy to answer more questions if you leave a comment on my post.
RE: email, we do have an email list. However, we really don't want to spam people, so instead of opting you into it automatically, we make it opt-in here: https://www.airbnb.com/techtalks.
It sounds like we may have err-ed too much on the side of being non-spammy, and this list is not very discoverable. I still don't want to automatically opt attendees in to the list, but given what you've said I think we'll pass around a signup sheet at the next tech talk.
Airbnb - http://www.airbnb.com/
We only have 27 engineers, and we need more!
I'm a backend engineer here, and we're hiring backend, frontend, mobile and ops engineers. Check out our (pretty sweet) jobs page: http://www.airbnb.com/jobs
I've been working at/founding startups for the last few years, and didn't think I would end up somewhere as "big" as Airbnb, but I love it here. Despite the large size of our customer service operations worldwide, the entire product team (PMs + engineers + designers) is still ~40 people, there's still a lot to do, and we need help doing it :)
Previously recorded airbnb tech talks will be posted here this week: http://www.airbnb.com/tech_talks