|
|
|
|
|
by edouard-harris
2056 days ago
|
|
The point is that CA's data harvesting looked like it was transparent to users at the time they were doing it — which is precisely the appearance you'd expect a malicious app to try to convey. The NYU project is probably on the level, but "they're probably on the level" isn't a very good security model at Facebook's scale. More to the point, the FTC's 2019 Consent Decree [1] makes it fairly clear that FB is responsible for third parties' access to its users' data — and it would be prudent (from FB's point of view) to interpret this responsibility as also covering browser extensions. [1] https://www.ftc.gov/system/files/documents/cases/c4365facebo... |
|
This is in stark contrast to CA. "They're probably on the level" because they have entire systems in place to keep them there.