11 ms·
For those wondering why the Facebook SDK is so widely used in popular mobile apps: Facebook Login is actually in the minority of reasons to add the Facebook SDK
by yllus 6y ago
For those wondering why the Facebook SDK is so widely used in popular mobile apps: Facebook Login is actually in the minority of reasons to add the Facebook SDK to your mobile app. The vast majority of apps will add the Facebook SDK because it contains Facebook App Ads; a library that "completes the circle" in terms of finding out how effectively the ads you ran on Facebook were at getting people to download, install and run your mobile app. So really the Facebook SDK is there to collect data of that advertisement being effective and provides both Facebook and the mobile app developer with knowledge of how their ad spend went.
Is that "spyware"? Some would call it merely wanting to know if your marketing budget was wisely spent - I suppose a lot depends on what data it collects on people.
More info: https://developers.facebook.com/docs/app-ads https://developers.facebook.com/docs/app-ads
- w-j-w 6y agoWhy on Earth is it the advertiser's perspective that decides what is spyware. This is a consumer rights issue. As a user, I don't care what the intentions of the spying are.
- mrspeaker 6y agoIf you squint then the Venn diagram of "spyware" and "knowing if your marketing budget was wisely spent" is a circle.
- jagged-chisel 6y agoNo need to squint, just cross your eyes ever-so-slightly
- Nicksil 6y ago>Is that "spyware"? Yes, absolutely. It uses energy and bandwidth I paid for to surreptitiously transmit my information for use which will solely benefit Facebook and the software developer.
- cjhopman 6y agoThat definition is rather too broad. It makes basically everything spyware which dilutes the word too much to be useful.
- tossmeout 6y agoThis is what happens to every charged label. 1. People realize the label is powerful. 2. They begin applying the label to as many things they don't like as they can get away with. 3. This changes the definition of the label, causing it to become some blanket umbrella term. 4. The label loses its power, because it now describes many lukewarm behaviors instead of just the worst offenses. For example, it's popular nowadays to say "everyone is racist." Well, if everyone is racist, is being labeled a racist really that bad? Not compared to what it used to imply about you.
- Nicksil 6y ago>That definition is rather too broad. It makes basically everything spyware which dilutes the word too much to be useful. I don't agree. I was very specific in stating that the practice of consuming a user's resources to transmit their information, without their explicit consent, nor an indication of the activity, for the sole benefit of Facebook and the software developer, can absolutely be considered spyware.
- cosmojg 6y agoNowadays, lots of things are spyware. It's important that we acknowledge this fact. Back when the Internet had a more technical userbase, the shady nonsense software tries to pull nowadays would not have flown at all. Those people would be outraged, and they'd absolutely agree that things like Facebook, Spotify, and Windows 10 meet the definition of spyware. But slowly, the Internet population grew to include the masses, and it turns out most people don't care whatsoever about what their software is doing or how it works so long as it gets the job done, whether that's communicating with relatives, playing music, or providing a platform for other applications.
- blackflame7000 6y agoAnd you since you installed the app for some purpose.
- _jal 6y agoI'm not interested in arguing definitions. I look at what apps on my phone do, and delete anything that wants to talk to the surveillance shops. It is that simple - I don't trust or use FB, and of course that includes third party FB feeders.
- johnymontana 6y agoHow do you monitor this?
- rpdillon 6y agoNetwork blocking like PiHole can block it, but on Android, I also use Blokada, which traps and logs outbound requests to domains on the block list. I also sometimes use ClassyShark3xodus to scan apks for trackers. https://f-droid.org/en/packages/com.oF2pks.classyshark3xodus/ https://f-droid.org/en/packages/com.oF2pks.classyshark3xodus...
- kyleee 6y agoAlso Netguard, pay 6 euro or greater 1 time donation and monitor all outbound requests, among other things
- _jal 6y agoThere are several ways to do it. At home I run mitm-proxy and sometimes squid. For on-phone use, so you can grab cellular data, Charles: https://www.charlesproxy.com/documentation/ios/ https://www.charlesproxy.com/documentation/ios/
- trevor-e 6y agoGenuinely curious here, which apps have you kept and use daily? The number of monetized apps that don't talk to Google/FB (or other install trackers) is likely in a very small minority.
- Nextgrid 6y agoI am in the same position though I am not justifying this spying by any means. I have probably a handful of third-party apps and rely on built-ins as much as possible (Apple Maps, calendar, mail, etc) and use most third-party services through the browser with AdGuard to block spyware.
- Nextgrid 6y agoThis is also not GDPR compliant, not that anyone actually bothers to enforce the law. If we respect the GDPR then data sharing for Facebook Login should only happen once the user presses the Facebook login button (as at that point the data sharing becomes essential to provide the functionality). As far as ad/marketing attribution it should be opt-in as that is not an essential requirement to provide the service (and even less so for paid apps). In both cases the SDK breaches the GDPR as it calls out every time it's loaded and upon first launch it will "register" itself with Facebook by submitting device information (make/model, carrier name, locale, timezone, etc) and obtain a unique ID which is then used in subsequent requests, providing Facebook with a trail of your whereabouts and usage patterns based on IP addresses you connect from (which they can then correlate with any other information they have).
- yllus 6y agoRe: Ad/marketing attribution, that's not necessary correct. If the data point that gets sent back to Facebook is a GUID type string that matches the GUID that got generated when you first clicked the Facebook ad for the app and doesn't include data about you specifically, I believe that's fine. I don't myself have up-to-date information what data Facebook receives via its SDK but I suspect it is GPDR compliant through such methods. GPDR specifically allows for anonymized/aggregated data on app usage or marketing feedback: https://gdpr.eu/eu-gdpr-personal-data/ https://gdpr.eu/eu-gdpr-personal-data/
- hedora 6y agoIn the eyes of the law, how is storing and sending the guid later different from storing and sending a cookie? Edit: the GPDR link specifically says identifier numbers are personal information, and I don’t see a carve out for allowing targeted marketing campaigns to use them to measure/improve targeting performance. Wrong link, maybe?
- yllus 6y agoSorry, use of the term GUID confused things - I meant that if an identifier string is generated when you click on the ad, and the purpose is to simply see if that identifier completes the app install and first use - that's not against GPDR. (In my head GUID means "unique identifier string".) Storing the GUID tells you nothing other than some device clicked on an ad and some device did or did not complete the app install.
- lucasar 6y agoThat is definitely not the case for the ~10 relevant apps I have worked on.
- monadic2 6y ago> Is that "spyware"? This seems like much less of a damning claim than openly supporting an ad network.
- Waterluvian 6y agoDon't mind me. I'm just going to come into your house and record what commercials you are watching. I'm not spyware I'm just _merely_ wanting to know about my marketing budget. Analogy may not be perfect but it takes serious mental gymnastics to fail to see this as spyware, in my opinion.
- bitcrazy 6y agoIt wouldn't be surprising if some Smart TVs are already doing this.
- userbinator 6y agoWe are already living in the world of 1984. "TV watches you", except this isn't Soviet Russia.
- kohtatsu 6y agoIn many ways; yes. In the most of the important ways; no. You can still fight back effectively. Don't go gentle into that good night.
- ethbro 6y agohttps://samba.tv/ https://samba.tv/ "We use anonymized data to provide a positive advertising experience, enable ad-supported TV networks to keep their shows free, and partner with TV manufacturers which reduces the price of TVs for you."
- caconym_ 6y agoDidn't Samsung literally get caught uploading screenshots of content played on their TVs to some server? Maybe it was some other company? These days, unless you take drastic measures to defend yourself from spyware embedded in consumer technology or forgo it all together, it seems that you'll be subject to this kind of surreptitious abuse as a matter of course.
- 6y ago
- sfifs 6y agoOne important distinction that often gets lost in these conversations is the difference between "linking" and "de-anonymization". In general, the bigger players in the analytics space are extremely careful about avoiding any risk of de-anonymization both contractually and in process. Salted hashes and minimum base sizes to report out are the norm. Some funkier approaches seem to be in R&D. There are of course bad players in the fringes but the big players have largely cleaned up their act.
- drdrey 6y agoHow does the Facebook SDK in a 3rd party app correlate that you're the same user if you don't log into the app with FB? Is there some universal device identifier all your apps have access to?
- Nextgrid 6y agoThe IP addresses (both WiFi and mobile), device make/model, carrier and locale can be combined into a fairly unique fingerprint, narrowing it down even more over time since the SDK phones home every time the app is opened.
- simonbr 6y agoThere was a static universal device identifier until iOS 6. Even today, while Apple has implemented many sensible restrictions on tracking, there's still a ton of information that can be used for device fingerprinting freely available to all apps. This blog post [0] pegs the amount of useful information at around 56 bits. [0]: https://nshipster.com/device-identifiers/#fingerprinting-in-todays-ios https://nshipster.com/device-identifiers/#fingerprinting-in-...
- Jarwain 6y agoThere's an "advertising id" that's assigned to your phone, accessible by apps you install. This ID can be reset by the user, but only if they are aware of it.
- ThePowerOfFuet 6y agoThat isn't even as useful as `identifierForVendor`.
- mcintyre1994 6y agoDo you know how common it is to use the Facebook SDK for app analytics even from outside the Facebook ads ecosystem? I can’t remember exactly where I got this from but I was under the impression that it was pretty widely used for general analytics in the same way that loads of sites use Google Analytics without being in their ads ecosystem.
- sbmthakur 6y agoMany apps on my Android device routinely send requests to edge-star-.facebook.com even when I don't use facebook login. Are these ad related requests?
- Nextgrid 6y agoThat’s most likely the Facebook SDK we’re talking about. The SDK phones home regularly regardless of whether it’s features are actually being used.
- cpv 6y agoYou can get NetGuard on Android and see how often and what is called (facebook.com, graph.facebook.com, other vendors, platforms, IPs, etc). You can choose to block what is not needed. Kind of uBlockOrigin for Android. Sometimes stuff breaks. And a lot of stuff is not related to FB Login. Facebook launched Facebook Off Activity a while ago https://news.ycombinator.com/item?id=22178917 https://news.ycombinator.com/item?id=22178917 You can go to your profile, and check which third parties, or advertisers uploaded contact data of you, download backup data to see in json files which apps what sent about you ("App activated", "Made some purchase").
- arrty88 6y agoCan’t you just use a simple tracking pixel?
- sneak 6y agoIt’s spyware when the user is unaware of it and their usage data is used without their consent. If the parties consent to it, it’s fine. When it’s hidden and nonconsensual is where the problem arises.
- coldcode 6y agoThankfully we removed FB several years ago when I found it sending data to FB servers that we did not authorize, we support our own logins for our own customers and there was no reason to use it (not sure the history before I got here). Sadly we do use Google Maps and got bit for weeks when that fiasco happened recently. I wish we could just use Apple Maps for iOS but somehow we have some marketing deal or something with Google.