![]() |
@dylanmckaynz | |||||
Downloaded my facebook data as a ZIP file
Somehow it has my entire call history with my partner's mum pic.twitter.com/CIRUguf4vD
|
||||||
|
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 21 |
a historical record of every single contact on my phone, including ones I no longer have pic.twitter.com/XfiRX6qgHl
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 21 |
metadata about every text message I've ever received or sent
spoiler: I don't use messenger for SMS pic.twitter.com/ehWXhpnrrV
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 21 |
and the metadata of every cellular call I've ever made, including time and duration 😬😬 pic.twitter.com/Ykr3o0gZFu
|
||
![]() ![]() ![]() |
![]() |
Ben Vidulich
@zl4bv
|
Mar 21 |
Which mobile OS would this data have been pulled from?
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 21 |
Android 5.1 - I've both Facebook and Messenger installed
|
||
![]() ![]() ![]() |
![]() |
Andras Zoltan
@RealLordZoltan
|
Mar 22 |
Isn't that what we agree to when Android pops up with a prompt saying 'access to your call history' etc?
I mean, yes: it's scary AF - but are we surprised they *can* do it, or the fact that they *actually* do it after we give them permission?
|
||
![]() ![]() ![]() |
![]() |
Ændrew Rininsland
@aendrew
|
Mar 22 |
This is interesting — I just did the same and none of that info is in there, and I've been using Facebook on my Android phone for years. I wonder if it's because the UK/EU has different personal data disclosure rules? What section of the zip was that all in?
|
||
![]() ![]() ![]() |
![]() |
Carl Brusell
@carlbrusell
|
Mar 22 |
Facebook calls?
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 22 |
nope, regular cellular calls with the stock 'Phone' android app
I used facebook's integrated SMS+cell call functionality for about a week at one point, but disabled it quickly after and went back to the stock app
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 22 |
The 'Contact Info' tab, inside 'html/contact_info.htm'
the only other interesting page I found was the 'Ads' page, which shows all the keywords that are used for you in targeting
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 22 |
Inside 'html/account_info.htm'. There's an 'index.htm' that serves as a homepage to all of the photos+ads+messages+videos+pokes pages in that folder too IIRC
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 22 |
I'm in New Zealand for what it's worth
privacy.org.nz/the-privacy-ac…
|
||
![]() ![]() ![]() |
![]() |
Kamen Naydenov
@pau4o
|
Mar 22 |
how big is it?
|
||
![]() ![]() ![]() |
![]() |
Dylan McKay
@dylanmckaynz
|
Mar 22 |
my ZIP file was ~250mb, but if you have more photos and videos it'll be much larger because it has every photo and video across every album and PM
|
||
![]() ![]() ![]() |
![]() |
Braden Golub
@BSG617
|
Mar 22 |
Can we assume that the Droid is the root of some of this data leakage? Haven't seen anything this substantial on iOS yet...
|
||
![]() ![]() ![]() |
![]() |
Luciano Carvalho
@lscarval
|
Mar 22 |
It's not Android or iOS, it's the permissions you give the Facebook app. If you allow you to access phone records, contacts and location, you be damn sure it will access them.
|
||
![]() ![]() ![]() |
![]() |
Luciano Carvalho
@lscarval
|
Mar 22 |
That's the beef I have with most of these apps. They come with a innocent "invite your friends, but first give us access to your contacts so we can list the people and you can pick". That naive permission setting will give the app access to all your contact data.
|
||
![]() ![]() ![]() |
![]() |
Viljami Kuosmanen
@anttiviljami
|
Mar 22 |
Android or iOS user?
|
||
![]() ![]() ![]() |
![]() |
Luciano Carvalho
@lscarval
|
Mar 22 |
A good example is this app I'm using right now (sic). Why does it need permissions to my Phone records, text messages and contacts? pic.twitter.com/y99uDLj7EL
|
||
![]() ![]() ![]() |