Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Facebook Android Privacy Technology

Facebook's Android App Is Asking for Superuser Privileges, Users Say (bleepingcomputer.com) 183

Catalin Cimpanu, reporting for BleepingComputer: The Facebook Android app is asking for superuser permissions, and a bunch of users are freaking out about granting the Facebook app full access to their device, an understandable reaction following the fallout from the Cambridge Analytica privacy scandal. "Grants full access to your device," read the prompts while asking users for superuser permissions. These popups originate from the official Facebook Android app (com.facebook.katana) and are started appearing last night [UTC timezone], continuing throughout the day. Panicked users took to social media, Reddit, and Android-themed forums to share screengrabs of these suspicious popups and ask for advice on what's going on.
This discussion has been archived. No new comments can be posted.

Facebook's Android App Is Asking for Superuser Privileges, Users Say

Comments Filter:
  • by DickBreath ( 207180 ) on Friday May 18, 2018 @08:27AM (#56632422) Homepage
    No need to be freak outing. Just grant access for Facebook. Nothing could go wrong.

    The Facebook
    Is Your Friend
    Trust The Facebook
    • Re: (Score:3, Informative)

      by alexhs ( 877055 )

      Funny, I practically had the opposite reaction:

      No need to freak out, just say "hell no", and when their mobile usage drops close to 0, it's FaceBook that will freak out...

      It already dropped dramatically with the #deletefacebook movement, right ? Right ?

    • No need to be freak outing.

      They should all freak themselves out for using Facebook at all in the first place.

      Hey, now they will come out with "Freakbook" . . .

    • For me it is less about not trusting Facebook on my device. But the idea of application running in full privilege mode bothers me. I normally get annoyed when an old windows App require Admin Rights to install, or worse like some old Windows 3.1 and Windows 95 Apps Requires Admin level right to run. Just because they couldn't figure out the safe place to save user data.

      This shows poor judgement either in Facebook, for not coding around normal user permission and for Android for not allowing correct securi

  • by Anonymous Coward on Friday May 18, 2018 @08:28AM (#56632434)

    I don't know if it's algorithmic, or if most of my close friends just hardly use facebook anymore, but it seems like I just rarely see anything anymore in my feed anymore that I care about. It also seems weird that what does appear is generally from people I'm very faint acquaintances with -- if I am curious about one of my actual friends I pretty much have to go straight to their profile.

    Besides that though, I think it just encourages behaviors I don't really enjoy seeing in my friends. I definitely know people who in real-life are totally cool, but their social media presence makes me question why I ever liked them in the first place. Mostly I see a lot of:

    1) very overt attention seeking for pretty lame things (like, pretty girls posting selfies of themselves doing nothing interesting, or dudes with gym photos, that kind of thing) 2) Extremely broad and poorly thought out political rants 3) sharing really vapid motivational quotes 4) people being maybe a little too vulnerable to a very broad audience, to the point where it's awkward. 5) This one is the worst of all. People taking passive aggressive swipes at individuals by posting very vague status updates. I hate stuff like that.

    I don't think of myself as a super judgmental person, but whenever I get on facebook I spend half my time just thinking "really?" and then feeling kind of gross.

  • by Anonymous Coward

    Don't. install. Facebook.

  • Solution (Score:5, Insightful)

    by Anonymous Coward on Friday May 18, 2018 @08:30AM (#56632466)

    #deletefacebook

    Literally. Just remove that shit from your phone already! Then go out and do something more constructive with your life, rather than lazily scrolling through other people's "The best ..." life moments.

    • Re:Solution (Score:5, Funny)

      by Anonymous Coward on Friday May 18, 2018 @08:46AM (#56632592)

      #deletefacebook

      Oh, a "hashtag". Let's start a campaign about how shit one social network is on another shit social network.

    • Facebook can be useful. Very useful to some people. And dropping FB has little or no correlation with "doing something constructive with your life". Even so, you can do without. And the more of you that decide to go without, the easier that choice becomes for the remaining members.
    • Re:Solution (Score:5, Informative)

      by Bob-Bob Hardyoyo ( 4240135 ) on Friday May 18, 2018 @10:44AM (#56633350)

      IIRC my stock ROM on my last phone had facebook installed as an unremovable app. Depending on the phone's bootloader situation that could mean some folks CAN'T remove spywarebook. (Or their manufacturer's homebrewed spyware either)

      • If you have root on your phone, which must be the case for these users, since the app is triggering a root request, then you should have access to remove system apps.
      • You are able to disable apps in the application manager. Even if you can't uninstall.
  • What went wrong is you didn't #deletefacebook.
  • No big deal (Score:5, Funny)

    by DogDude ( 805747 ) on Friday May 18, 2018 @08:33AM (#56632478)
    It's really no big deal. What other data could they possibly collect that they don't have already? They have your location at every second of the day. They have all of your contacts. They have all of your emails and text messages. What else could they get that they don't have, already?
    • by Anonymous Coward

      It's really no big deal. What other data could they possibly collect that they don't have already? They have your location at every second of the day. They have all of your contacts. They have all of your emails and text messages. What else could they get that they don't have, already?

      so you are most clearly a psychopath because you're not even noticing that you have your emotions and facebook doesn't.

    • Re: (Score:3, Insightful)

      by Ecuador ( 740021 )

      Well, I guess full access would also allow them to either edit your stuff (here are some new contacts, yay!) or delete them?
      I admit I use facebook since it is the only way to keep contact with certain people, but I only have messanger installed - the app takes over 200MB on a phone which is a suspiciously large size for an app that does part of the things that a badly designed website does...

    • They have all of your contacts. They have all of your emails and text messages.

      ...and if you ever want to see them again, you'll buy $10,000 of the newly announced "Facecoin!"

    • I heard a hilarious German advert today involving a phone assistant that went feral. Among other things it threatened to send the owner's dick picks to their parents.

      Stupid thing about that advert was I can't remember what it was for other than many a philosophical commentary on modern life.

    • Yeah, as always there's an XKCD for this...

      https://xkcd.com/1200/ [xkcd.com]

  • Why do they care? (Score:2, Informative)

    by Anonymous Coward

    Facebook users have already granted Facebook access to their life [techcrunch.com], and even parts of the lives of people around who are trying to stay out of its clutches, to boot. There is very little Facebook does not collect about you.

      Why the crocodile tears when Facebook users are the ones who have voted in surveillance clusterfuck?

  • Shocked I tell you (Score:5, Informative)

    by Urinal Pube ( 4508429 ) on Friday May 18, 2018 @08:36AM (#56632500)
    I'm most surprised that someone with enough technical merit to root their phone, would install the FB app to begin with.
    • I'm most surprised that someone with enough technical merit to root their phone, would install the FB app to begin with.

      Why not? What does technical have to do with using a service? Being technical doesn't mean you go all tinfoil hat private. Being non-technical doesn't mean you share every breathing second of your life on a Facebook post either.

      We can flip this on its head. Having a rooted phone that provides you the fine grained controls to fake your data may be the only way to safely use Facebook.

      Disclosure: Have rooted phone, have Facebook. Though have not seen a superuser request from it.

  • by ArchieBunker ( 132337 ) on Friday May 18, 2018 @08:37AM (#56632506)

    The app already asks for every single permission available.

    • Re:No big deal (Score:5, Interesting)

      by Thelasko ( 1196535 ) on Friday May 18, 2018 @09:16AM (#56632764) Journal

      The app already asks for every single permission available.

      The purpose of the Facebook app is:

      1. harvest as much data as possible
      1. bypass as many protections/ad blockers as possible

      If you absolutely must use Facebook on your phone, do it using a web browser that is well secured. You won't really miss out on anything, but Facebook will.

      • by jrumney ( 197329 )
        I figured they must be up to some new shenanigans this week with their app when the web interface got bumped into a new level of unusable. It's quite painful to watch a company commit slow suicide like this. If I was inclined to launch a new social networking site, I might just pick now as the timing to do it.
    • If you read the Android manifest, the perms Facebook ask for is almost like a novel. I wouldn't be surprised if ACCESS_SUPERUSER was in there.

      I miss XPrivacy. If a generic fleshlight app asks for every permission under the sun, it can have them... except it will fetch random strings for contacts, the location would be at the same spot all the time, the microphone and camera would give static. XPrivacy Lua should be its replacement, but it has a ways to go.

      Barring that, I wish phone makers would allow fo

      • If a generic fleshlight app asks for every permission under the sun,

        There can't be a fleshlight app any more, not after they removed the headphone jack anyway.

  • This app has access to: Contacts read your contacts Location approximate location (network-based) precise location (GPS and network-based) Photos/Media/Files read the contents of your USB storage modify or delete the contents of your USB storage Storage read the contents of your USB storage modify or delete the contents of your USB storage Wi-Fi connection information view Wi-Fi connections Other receive data from Internet view network connections allow
    • by AvitarX ( 172628 )

      That's seems about right, I don't know ow the game though.

      Contacts = invite friends
      Location = ads (the only one that seems questionable
      USB = get character avatar
      Wi-fi = warn when doing a large update not on WiFi
      Network = ads
      Run at start up. = Notifications = ads (another questionable one for a random game.

      Basically permissions are worthless, since everything wants access to your photos for some stupid reason, and everything needs network and location to advertise.

      I do like that the apps ask when they use in

  • by Anonymous Coward

    I got rid of any app that basically just mimics going to a website.

    While I still use facebook (though at a limited capacity). I was tired of the app draining my battery, but also was very wary of all the stuff it was trying to get access to.

    But in general I don't understand installing an app for a service that's offered via a website.

  • Facebook (Score:5, Insightful)

    by ledow ( 319597 ) on Friday May 18, 2018 @08:42AM (#56632562) Homepage

    Hey Facebook.

    Make one app. That has messenger in it. With a bunch of options of what I want it to do (run all the time for messenger, read my photos, etc.).

    Try and not make it an app that literally sucks up all my storage just browsing (my gf filled her phone up twice to the brim, when we looked it was all data stored in the Facebook app - removed the app, reinstalled, all was fine again)

    Then, maybe, just maybe, I'll consider installing it. But JUST that. Nothing else. No other apps to do the same thing. And, no, you really don't require (or will ever get) one percent of the permissions your current apps demand.

    To be honest, the fact that you DELIBERATELY break the Facebook mobile website to remove messenger (when "View as Desktop Site" shows it perfectly well but in a not-nice format) pisses me off more than anything. You are literally trying to force me to use the apps and I have no interest in that.

    You know what happens when you try to force people to use products/services they have no interest in? They go elsewhere.

    Another 5 years and Facebook will be like MySpace is now.

    • You know what happens when you try to force people to use products/services they have no interest in?

      Judging by past behavior, what they actually do is keep using the more broken thing because it's what they know and all their friends use.

      They go elsewhere.

      The problem is, in the case of Facebook (and Twitter), there is no "elsewhere" to go to. Seriously, go to what?

      Nor is there any sign of an elsewhere anytime soon, what nascent systems could work to replace either of these companies even if you could conv

    • by Anonymous Coward

      Why are you still using Facebook anyway?

      Just delete it already.

    • ... will be like MySpace is now. ...

      What is a "MySpace?"

    • by jrumney ( 197329 )
      Better yet, put the messaging back into the mobile website and let everyone use their web browser instead of a handful of apps.
      • by tepples ( 727027 )

        Better yet, put the messaging back into the mobile website and let everyone use their web browser instead of a handful of apps.

        "Everyone" except for the anti-JavaScript hardliners here on Slashdot, who prefer OS-specific installable native executables to OS-independent zero-install script-in-the-browser.

    • You know what happens when you try to force people to use products/services they have no interest in? They go elsewhere. ... Another 5 years

      In another 5 years you may well be saying in another 5 years just like cold fusion. If Facebook has shown one thing it's that you can force an incredible amount of shit down your user's throats and they'll say please sir can I have another! Myspace was a relatively small platform that got replaced by a huge alternative. People have predicted the death of Facebook and the Next Big Thing (tm) social network for the past 10 years now. It hasn't happened.

      Side note: Never heard of your Facebook storage issue. 9

    • (when "View as Desktop Site" shows it perfectly well but in a not-nice format)

      Thanks for the work around! Someone should make a plugin for that.

  • by niittyniemi ( 740307 ) on Friday May 18, 2018 @08:52AM (#56632626) Homepage

    Apparently, Facebook are now saying that the message is clearly a bug. It was meant to say:

    "Do you want to continue to be anally raped by a multi-billion spying operation run by a dwarf with no moral compass?{Y/n]"

    For those with a room temperature IQ (in celsius) you want to hit "Yes". Everybody else wants to hit "No".

    • Apparently, Facebook are now saying that the message is clearly a bug.

      It was either a bug or active warfare against the tinfoil hatters. It doesn't make sense for it to be a general hoovering of data as per normal since this permission would only affect the 0.001% of phones that are actually rooted, ... most of which are rooted because people distrust the likes of Facebook in the first place.

  • Comment removed (Score:5, Informative)

    by account_deleted ( 4530225 ) on Friday May 18, 2018 @09:05AM (#56632680)
    Comment removed based on user account deletion
  • There is worse (Score:5, Informative)

    by volodymyrbiryuk ( 4780959 ) on Friday May 18, 2018 @09:06AM (#56632684)
    The fact that the shitty FB app is preinstalled on many android devices (and cannot be removet without root) is far worse.
    • The fact that the shitty FB app is preinstalled on many android devices (and cannot be removet without root) is far worse.

      That is a giant "meh". Just disable the app. A disabled app in Android literally can't do anything. It can't even be updated let alone run in the background sucking up data.

      • It might sound ridiculous to you but it is still using space on the phone's internal memory. And some people just don't want crappy bloatware on their phones.
        • It might sound ridiculous to you

          Yes complaining about a few 10s of MB of the default image being used does sound ridiculous to me.

          • It's 450MB for Facebook. With the latest AAndroid update (to oreo) they also added the shitty Linkedin app.
            • It's 450MB for Facebook.

              It's not 450MB for my current version, updated 6 times over including the data portion and the cache portion from the last 9 months of usage. If your install is that big then you've done goofed son.

              Also apps shipped with the image do not sit on your data partition so they fundamentally sit unchanging, unedited. If you're worried about free space, then look up how much free space you get with your phone when you first purchase it. Complaining about the bundled apps is stupid in the face of the inefficiencies

  • No big deal (Score:5, Informative)

    by WindBourne ( 631190 ) on Friday May 18, 2018 @09:08AM (#56632704) Journal
    Say no and uninstall it.
  • by ctilsie242 ( 4841247 ) on Friday May 18, 2018 @09:09AM (#56632716)

    The good su apps on Android will not, by default, allow a program to present a su dialog unless the app manifest in the Google Play Store has ACCESS_SUPERUSER declared.

    What bothers me is that this is something that has to be explicitly coded. Why would an app -ever- request this by accident, is beyond me.

    • ...Why would an app -ever- request this by accident, is beyond me....

      My thoughts exactly. It was an accident only because they got caught.

    • What bothers me is that this is something that has to be explicitly coded. Why would an app -ever- request this by accident, is beyond me.

      Apps do a lot of things when developers are working on it, and it wouldn't be the first time a wrong version has been pushed out to publish. To be honest it sounds like an oversight given what this is capable of: accessing additional permissions on a rounding error of a percentage of phones out there that actually have superuser capability enabled.

      The alternative to an accident is quite bad. If this was done on purpose then someone decided to target a group of people specifically likely to NOT want anything

  • I'm planning to make a nice-big write up about what it means to browse Facebook on a traditional browser while using a mobile phone, using screen-shots for reference. The amount of begging, strong-arming, and general "feature isolation" they pull when you use a mobile browser (that worked five years ago) is astounding. "Request Desktop Site" sometimes gets you around some of that, sometimes it causes other weird things to happen.

    Facebook is evil. I want to jettison it outright and just move to Minds and Steemit. Unfortunately Facebook is where the people are, especially family. I make my family posts there and my general posts elsewhere. I really want to move the family away.....

  • Firefox for android works fine for when I choose to brows Facebook from my phone. -- you can no longer send messages without the separate massager app (so, I don't use them). I've just told my friends not to use that method to get a hold of me and Presto! ... I know that any message showing there is from somebody who doesn't know me.
  • You are already granting full access to Google by the grace of Android... Where is the panic?


  • Fuck facebook.

    Tell it to go & fuck itself in various creative forms, then get angry and really mean it.

    Once Facebook has fucked off to a sufficient, edge-of-the-continent distance beat it into an intercontinental fuck off until it cannot possibly fuck of any more.

    Once at the very edge of the the last millimetre of Earth make Facebook dream the impossible dream into recording break outer-space fuck off to be set adrift forever.

    Fuck Mark "we don't spy on you but do record audio when recording vide
  • The solution is simple enough; don't install the Facebook app. And don't use Facebook. Facebook's entire business model depends on making money by giving advertisers your personal information. They're selling access to your eyes.

  • I don't have Facebook but can you purchase items, media, etc through the app? I know when I installed the DirecTV app on my phone it was checking for root as a way to disallow rooted devices from using their streaming app. I had to use the magisk hide module to get around this.

  • It's time to leave.
  • In a traditional permission system where you tell your OS what you will and won't allow, you could still run the Facebook app and notice when it fails to work normally—or when the OS terminates it outright.

    But that's not what we have. Imagine a town where everyone feels socially obligated to leave a house key under the door matt for the town priest, who basically just sleeps wherever he wants.

    Why Zuckerberg's 14-Year Apology Tour Hasn't Fixed Facebook [wired.com] — 6 April 2018

    Concert dates: 2006, 2007, 200

    • by HiThere ( 15173 )

      Well, I consider the Nook e-book reader a worse purchase than the phone, and there was some notebook device I bought a few years earlier that was still worse. I actually have uses for my phone, but it sure isn't as good as my previous non-smart phone.

      OTOH, I've never been tempted to download any apps. Perhaps if I did I'd consider the smart-phone a worse purchase. (My fingers are too large to consider the phone an acceptable keyboard, even for a a short note...or perhaps it's that I learned touch typing.

If you do something right once, someone will ask you to do it again.

Working...