Hacker News new | ask | show | jobs
by adverbly 1953 days ago
I grant API access to my friend. That is a direct relationship.

I don't grant API access to people that my friend grants API access to.

If one grant allowed for another grant, by that logic you could chain all the way down to any connected node which is clearly not a desirable model.

Data brokers are trying to make it seem like me adding a friend is somehow not a grant so that they can "plus one" on their reach. But it is a grant. It is literally me granting my friend access to my data. Just because the company doesn't call it a grant and doesn't treat it like one on a technical level doesn't change the fact that I have granted my friend access to some data.

1 comments

API access or not is just a technicality. You grant your friend access to this data. Even if API access was restricted, malicious parties would just get your friend to install malware or give out their Facebook credentials directly (thus bypassing the API access restriction).

Either you trust your friend with that data or you don't. Anything else is just playing a game of whack-a-mole which may just give people a false sense of security.