TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Facebook pauses app reviews, disables new user authorizations

234 pointsby humanfromearthabout 7 years ago

18 comments

miracle2kabout 7 years ago
The so-called &quot;data breach&quot; was always in reality a by-product of an open platform that hundreds of thousands of developers could easily build apps on top. You may err on the side of &quot;more reviews&quot; or &quot;less powerful API&quot;, but in the end, those ideals are in tension. The more open the platform, the more open to this kind of &quot;breach&quot;.<p>People who believe in the idea in this kind of platform having an API should have long ago spoken up in Facebooks defense. This is exactly what I was afraid would happen, and I expect worse to come from this &quot;platform review&quot;. Given the kind of media coverage here, Facebook seems to have more to lose than to gain from letting random Hacker News kids build on their platform. And if so, they won&#x27;t in the future.
评论 #16702673 未加载
评论 #16702608 未加载
评论 #16702784 未加载
评论 #16704923 未加载
评论 #16702595 未加载
downandoutabout 7 years ago
The Facebook API has been useless since 2014 when most access to friend data was cutoff. Since then, if your objective was data collection, that could be easily achieved by scraping publicly available information (many friends lists are public, there are many public posts, etc. - certainly enough to use in aggregate to formulate campaign strategies etc.). I suspect that will be the next “scandal,” since in 2018, people can’t possibly take personal responsibility for the things they post and allow to be public.<p>Ironically, the “scandal” that caused this whole thing is a non-issue. Pre-2014 Facebook apps could collect a lot of information about you and your friends, along with their Facebook user IDs, and that was scary because there was a time when you could simply submit a list of user ID’s that you wanted to show a specific ad to. But since Facebook advertising cannot be targeted by user ID anymore, and this policy was in place well before the 2016 election, all of that data was essentially useless to any participant in the 2016 election other than for aggregate things like general campaign strategies. I am intimately familiar with the advertise by ID issue - I was awarded a $2k Facebook bug bounty for spotting an exploit in the Custom Audiences feature that allowed an equivalent version of targeting by ID after they disallowed it.<p>So while it’s possible that Obama used his special access to the entire US social graph to successfully influence his elections, it is impossible for Trump or Hillary to have done it <i>even if they had the data</i> because of the changes in the FB ad platform in between 2012 and 2016. This entire “scandal” was created and promoted by people that don’t understand, or actively ignored, this concept. If you ask everyone that has read the recent headlines, including reporters that wrote the stories, I’ll bet 99%+ will tell you that they believe they could be specifically targeted with ads.<p>It would be interesting to see if the executives at any of the media companies that have managed to sell this scandal to the public took unusually large short positions in Facebook stock before releasing the story. Since the story is effectively fraudulent (it was not possible for the election to have been influenced in the way that the stories imply), I assume that would be securities fraud.
评论 #16702874 未加载
评论 #16702846 未加载
评论 #16702939 未加载
评论 #16703650 未加载
评论 #16702933 未加载
评论 #16705011 未加载
humanfromearthabout 7 years ago
Pausing app reviews is annoying for sure, but not allowing new users to authorize their app is really bad.<p>Meaning that new customers can&#x27;t connect with facebook anymore to access their own data using OAuth! We don&#x27;t need permissions about your friends, your photos, or whatever. Just accessing their own messages and posts (which is what our customers want to see in our app and pay for).<p>I know they are shell-shocked after #deletefacebook stuff, but this overreaction is ridiculous.<p>So glad it&#x27;s not our only channel of communication through. Times like this you appreciate email - crazy huh?
评论 #16702329 未加载
评论 #16704028 未加载
评论 #16703578 未加载
Mc_Big_Gabout 7 years ago
Reading Facebook&#x27;s PR as they try to fix &quot;problems&quot; that they previously leveraged to profit massively is like someone purposely tripping you and as you stand back up they spit in your face and say &quot;Oh, sorry. I&#x27;ll try not to do it again&quot; in a condescending tone. [edited to remove things HN can&#x27;t handle]
评论 #16702431 未加载
评论 #16702415 未加载
评论 #16702462 未加载
评论 #16702486 未加载
ihumanabout 7 years ago
Where does it say that facebook is disabling new user authorizations? I don&#x27;t see it on the page OP linked.
评论 #16702343 未加载
madroxabout 7 years ago
This is a bit out of left field, but since the height of Farmville I&#x27;ve argued that Facebook should offer cloud services. I know these days everyone wants you to build on their cloud and it&#x27;s a bit oversaturated, but a very easy way for Facebook to make data available to developers while maintaining security is to run the code that operates on that data on their servers. Seems like such a no-brainer I&#x27;m surprised they haven&#x27;t done it.<p>But maybe I&#x27;m missing something obvious.
评论 #16703923 未加载
评论 #16702923 未加载
siquickabout 7 years ago
Our app which has only `email` permissions is still allowing new users to sign up.
评论 #16704544 未加载
thinkloopabout 7 years ago
I wonder if it&#x27;s all still a net benefit for fb. I remember back in the day while doing heavy fb dev, being flabbergasted at what we were able to get. It solidified our decision to invest heavily in their platform. We were able to get millions of likes and other data by simply having a few thousand signups. At one point I thought it was a bug and had to ask around about it. We had to consider whether it is something that will be &quot;discovered&quot; and shutdown or not. The power of it cannot be understated, and without a doubt a major catalyst for the success of their platform. It&#x27;s possible that they would be worth less today, including the $100B loss, without it.
timthimmaiahabout 7 years ago
Not sure if this headline is 100% accurate. oAuth for apps that have already passed Login Submission is still functioning. For example, new users to an app that is already in the FB app ecosystem can still create accounts via oAuth.<p>However, apps that request scopes like &quot;user_friends&quot; or &quot;pages_messaging&quot; [1] may error out during authentication.<p>[1] <a href="https:&#x2F;&#x2F;messenger.fb.com&#x2F;newsroom&#x2F;messenger-platform-changes-in-development&#x2F;" rel="nofollow">https:&#x2F;&#x2F;messenger.fb.com&#x2F;newsroom&#x2F;messenger-platform-changes...</a>
dwortsabout 7 years ago
Seems kind of late for this kind of thing doesn&#x27;t it?
评论 #16702509 未加载
seem_2211about 7 years ago
Interesting how it&#x27;s all about &quot;sharing&quot; and &quot;community&quot; when they want you to get on Facebook and all about &quot;well you know you signed your privacy away&quot; when you ask any questions. It&#x27;s so disingenuous - I&#x27;m loving Facebook&#x27;s self-created troubles.
drnexabout 7 years ago
facebook privacy through restricting the api is an illusion, a lot of content can be extracted with scrappers
评论 #16702489 未加载
Animatsabout 7 years ago
Just turn off all Facebook apps. I never turned them on, and don&#x27;t seem to be missing anything.
评论 #16702768 未加载
Zarathabout 7 years ago
How does one even pause app reviews? They don&#x27;t own the app stores do they?
评论 #16702404 未加载
评论 #16702592 未加载
评论 #16702500 未加载
评论 #16702409 未加载
评论 #16702402 未加载
paulsutterabout 7 years ago
Can anyone think of a useful Facebook app? I can’t think of one. They’re not as intrusive&#x2F;awful as they were in the FarmVille era, but are any actually useful for users, not marketers?
评论 #16706515 未加载
thombleabout 7 years ago
Is it possible to create an app that can easily remove personal info, and delete all posted content that is, say older than n days old? If so, is there a new demand for this kind of app?
egypturnashabout 7 years ago
&quot;people have noticed that a lot of horses get stolen from our barn, we guess it&#x27;s maybe time to finally close the barn door&quot;
footaabout 7 years ago
Seems like the right answer here is analyzing usage of the API and looking for malicious patterns