Hacker News new | ask | show | jobs
by ubernostrum 2743 days ago
Facebook appears to have designed their system in such a way that permissions were not granular enough to do things like "Spotify can only post certain types of messages". Instead it had to be "Spotify has full read/write access to all private messages".

Given Facebook's history it's hard to believe that the lack of granularity, and resulting incentivizing of users to grant as much access to personal data as possible, was an accidental oversight.

2 comments

Looking at the Spotify sign-in image from 2013 that jahlove found above, Spotify didn't even ask for that auth permission.

The full messaging access seemed to be a hidden bonus for their larger partners.

Seems to me that it was more of a "who cares" oversight than an accidental one.