God, I hate posting a Reddit comment, but this is huge. Every claim is sourced (I have not verified personally).

Edit: Well, Reddit does what reddit does, it's been removed. Here is a github link: https://github.com/upper-up/meta-lobbying-and-other-findings

cross-posted from: https://lemmy.bestiver.se/post/985257

Comments

you are viewing a single comment's thread
view the rest of the comments
[–] 152 points 4 months ago* (last edited 4 months ago) (5 children)

tl;dr it was Meta (because of course it was). It is a little strange though, I would think they would absolutely want this sort of PII but they're pushing for Google and Apple to deal with it.

  • source
  • hideshow 10 child comments
  • [–] 80 points 4 months ago (2 children)

    I'm guessing one of the motives is to be able to get more data from non meta users. If the API exists at the operating system level, they can then use the code behind that stupid little Facebook button that every website has to get user age as well as the normal browser fingerprinting data.

  • source
  • parent
  • hideshow 4 child comments
  • [–] -4 points 4 months ago (1 child)

    My understanding is the API only applies to app stores.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 35 points 4 months ago (1 child)

    Nope. Most of these legislations are pushing for OS level.

  • source
  • parent
  • hideshow 2 child comments
  • [+] -9 points 4 months ago (3 children)

    Yes, and the OS communicates this to the app stores.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 24 points 4 months ago (1 child)

    App stores and anything else that makes a call to that API.

  • source
  • parent
  • hideshow 2 child comments
  • [+] -11 points 4 months ago (1 child)

    Your browser would have to allow that.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 4 months ago (1 child)

    You mean the browsers all based on code from Google and Apple, who also want that info, and will be pressured to use that API to "protect the children" from adult websites?

  • source
  • parent
  • hideshow 2 child comments
  • [+] -8 points 4 months ago (1 child)
  • [–] 5 points 4 months ago (1 child)

    That question was rhetorical. Apple and Google account for 95% of the browser market.

  • source
  • parent
  • hideshow 2 child comments
  • [+] -6 points 4 months ago (2 children)

    I know what you meant, but I guess you've never heard of this little thing called a fork. Or Firefox.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 4 months ago (1 child)

    You honestly believe that the general public is going to suddenly rush to chromium or Firefox forks?

  • source
  • parent
  • hideshow 2 child comments
  • [–] -4 points 4 months ago (1 child)
  • [–] 5 points 4 months ago (1 child)

    Then why would they be relevant to a discussion about legislation that affects the general public?

  • source
  • parent
  • hideshow 2 child comments
  • [+] -6 points 4 months ago (1 child)

    No one said anything about "general public".

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 4 months ago (1 child)

    We are talking about legislation. Unless it's very specifically targeted legislation, the conversation always is about the general public.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago (1 child)

    Hi, I am here to tell you that it is not particularly trivial to make the kind of changes required to make the websites keep working while also preventing stuff similar to JS fingerprinting.
    Some extensions do a decent job in certain cases, but the only ones that completely fix the problem are the ones that simply turn off JS. I checked out what Librewolf's changes do, using amiunique.org and in some tests it even ends up increasing the uniqueness.


    You will essentially require identifying different parts of the JS engine that expose said vulnerabilities and then creating mitigations for each of them, with either the "blend in" or "randomise" strategy and will also require to make sure they are not detected over any domain (due to partial overlap of either change).

    This kind of change for a single person will require properly understanding the JS engine codebase and then making and maintaining all required patches over the course of the fork as the main project goes forward. This is pretty much a full time job.
    Even if multiple people are working on it, one would still require a good understanding of the codebase.

    I suggest recruiting one of the retired/laid-off Firefox engineers, if you have the funds.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 4 months ago (1 child)

    ...why are we talking about JS and fingerprinting?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago* (1 child)

    The application of age indication is just going to be another metric that these companies use for fingerprinting and person identification, one that some analyst on their inside possibly considered a useful data point.

    And while this particular API might be an easy one to target, for removal as a patch, it might end up being part of a JS framework that many websites use and will break in case the return value is not available.

    So if people require sites to work, this will become just another feature, requiring similar mitigations to other JS features I mentioned, that will need to be handled in a way that it increases the anonymity of the user, lest the user be subjected to harassment.


    By "harassment", I mean the actual inescapable kind, not just random internet trolls.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 4 months ago (1 child)

    The application of age indication is just going to be another metric that these companies use for fingerprinting

    As I said, there's nothing to suggest they would receive such an indicator, as far as I'm aware. The indicator is only required between the app store and the OS.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 4 months ago* (1 child)

    Facebook has "apps", no?

    Last I checked, it had stuff like FarmVille, FrontierVille, etc.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 4 months ago (1 child)

    We weren't talking about apps, we were talking about Facebook like buttons on websites.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 4 months ago (1 child)

    Causation:

    1. FaceBook website has apps
    2. FaceBook website is an App store
    3. FaceBook website requires access to Age API
    4. Firefox needs to passthrough Age API to Facebook's domain
    5. All embedded FaceBook buttons now get to see your OS's age
  • source
  • parent
  • hideshow 2 child comments
  • [–] -1 points 4 months ago (1 child)
  • [–] 0 points 4 months ago (1 child)

    Does the Court ask you?
    Does the legislature?
    Does Meta come to ask what you call an "App Store"?

  • source
  • parent
  • hideshow 2 child comments
  • [–] -3 points 4 months ago (1 child)

    The legislation clearly states what is and is not an app store. I'd recommend you mull it over.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago

    (3) APP.—The term “app” means a software application or electronic service that may be run or directed by a user on a computer, mobile device, or any other general purpose computing device.

    (4) APP STORE.—The term “app store” means a publicly available website, software application, or other electronic service that distributes and facilitates the download of an app from a third-party developer by a user of a computer, mobile device, or any other general purpose computing device.

    100% sure they all come in the category of an "App Store" when convenient for the lobbyist.

  • source
  • parent
  • [–] 5 points 4 months ago (1 child)

    That is incorrect, the OS communicates the data to any "app" running on the system that asks for it. The text of the bill (the CA bill specifically is the one I have read) states that any developer of any app must ask for the age bracket from either the OS or the App Store, so the OS will have to have the API open to any "app" running on the device, not just the "app store". Also, they define "app store" as any website or software that people can download and install software from, which is VERY broad.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 4 months ago (1 child)

    And everything else, including via the little Facebook button on various pages.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 18 points 4 months ago (1 child)

    Or take the blame. Either way, I was expecting Palantir.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 19 points 4 months ago (1 child)

    Zuck is on board with destroying democracy as much as Theil, otherwise Zuck wouldn't have personally hired Joel Kaplan back in 2009.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 4 months ago* (1 child)

    Well of course he is. Billionaires believe they are special little kings who deserve far more than democracy can ever offer them. One vote? Are you kidding? Just one vote each? Not for them. They deserve more. And so, they’re intent on destroying it for millions.

    Petty, ambitious tyrants, down to the stunted emotional growth of past rulers. Grow up with everyone telling you you’re a king vs growing into incredible money before you’ve finished developing into a full adult.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 4 months ago (1 child)

    They don't want to deal with the costs, just get the data. At least that's what I got from the text, as a reason why they were pushing to make social networks extempt and keep it on app/OS level.

    Fuckers.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 4 months ago (1 child)

    But they're not getting the data. The data is going to Google, MS and Apple. All they're getting is an age bracket.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 months ago

    For now... But they are pushing laws that require the infrastructure for data harvesting be built into the OS level and then broadcast the data to any program that asks for it without question...

  • source
  • parent
  • [–] 1 point 4 months ago

    Inside scoop having talked to the company meta uses. Since they use face identification to check age, my belief is that it burdens them with biometric data that the federal government wants rights to. That puts them in a precarious situation if they don't want to share said data, or can't make enough off it for the risk, just like problem Discord had. Much safer to have ad-focused data.

  • source
  • parent
  • [–] -5 points 4 months ago (1 child)

    I recall reading an article a few days ago saying it was Meta behind it. I feel like tons of research wasn't needed when the answer key was already known.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 30 points 4 months ago (2 children)

    Independently verifying it is still worthwhile.

  • source
  • parent
  • hideshow 4 child comments