Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If Facebook is to make its encrypted chat services interoperable with third parties, it must reserve the right to aggressively fix bugs and patch vulnerabilities. Sometimes, this will make it difficult for competitors to keep up, but protocol security is not something we can afford to sacrifice.

This looks like a barn door, not a loophole. What would stop major players from updating their proprietary protocol on a daily basis? The overhead of staying on top of a dozen big social media sites' protocols would be absurd.

I agree with the need for security, and I see that the industry has failed to update email; but I see that more as a consequence of the industry continually trying to "disrupt" email through the creation of walled gardens.



As pointed out, in section 4 of S.2658 this is explicitly prohibited:

C) PROHIBITED CHANGES TO INTERFACES.—A change to an interoperability interface or terms of use made with the purpose, or substantial effect, of unreasonably denying access or undermining interoperability for competing communications services shall be considered a violation of the duty under subparagraph (A) to facilitate and maintain interoperability based on fair, reasonable, and nondiscriminatory terms.


I'm sure that clause will come in handy after a mind-reading device is invented. The SEC already has a tough time proving "market manipulation".


Fun fact: Within Facebook’s task-tracking system there is/was a “wishlist”-priority task with planned details for how to change Messenger’s MQTT protocol to break third-party clients if need be. As far as I know this was never acted upon because Pidgin-like third-party clients never became popular for Messenger MQTT like they were for the old now-deprecated XMPP Messenger gateway.


Wait, FB Messenger has a semi-standard API now?


No it doesn't, you need to impersonate an user and login with your password in order to relay messages outside of FB messenger. That said, it has been done: https://github.com/tulir/mautrix-facebook


No, it used to support XMPP, but that support was eventually removed: https://news.ycombinator.com/item?id=9266769


I knew about that: the talk of MQTT made me think that there was some improvement in the situation.



It is based on MQTT+extensions.


As I’m reading S4c2c it looks like this would be prohibited.

https://www.congress.gov/bill/116th-congress/senate-bill/265...


That's certainly the intent, but as it's written, (by my lay-reading) it appears that the burden of proof would rest upon a single change, and not a sequence of changes -- any one may be innocuous, but their sum may not be. And where a single actor may not run afoul, I can imagine a conspiracy of big players making changes which collectively burden smaller players. I would greatly prefer a consortium or better, an independent standards body.


Having professional standards bodies for interfaces has actually been proposed - in another bill! S.1084 - DETOUR Act, introduced 2019-04-09.

Full text (only 1800 words!): https://www.congress.gov/bill/116th-congress/senate-bill/108...

It was written to get rid of dark patterns and deceptive interfaces. The official summary says: "To prohibit the usage of exploitative and deceptive practices by large online operators and to promote consumer welfare in the use of behavioral research by such providers."

In my reading, the DETOUR act says that large online operators (defined as services with more than 100M monthly active users anywhere, not just in the US) may not use misleading interfaces or unclear wording to mislead the user. It also says that they can only conduct behavioral experiments (e.g. A/B testing) if they have an independent review board registered with the FTC and have informed consent from the users as well as routine disclosure to the public of experiments being done. Finally it says that online large operators may form professional standards bodies, and that those bodies should develop on a continuing basis guidances and bright line rules for developing their technology products in a way that does not impair user autonomy or induce compulsive behavior in children.


From what I understood from the content of the bill, it seems that there is a clause that prevents companies from aggressively modifying their API to prevent interoperability.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: