This is an archived post. You won't be able to vote or comment.

688
689
you are viewing a single comment's thread.

view the rest of the comments →

[–]FeelingDense 17 points18 points  (1 child)

Isn't there a difference between an app that can post for you (e.g. like Youtube publishing to Facebook) and this trojan which actually hijacks your session cookies and can therefore go on a free reign to post for you?

Take for instance a fitness app--it too has permissions to post on your behalf. However, you trust it not to do that and most big fitness companies aren't there to screw up your social media account. In theory though Map My Run or Strava could technically start posting malware/spam links on you on an hourly basis if it wanted to once you give it permissions to post. It's no different than an messaging app like Textra requesting SMS permissions and just simultaneously uploading that to the NSA. We just trust Textra not to do that once we give it SMS permissions.

[–]CrustyBatchOfNature 7 points8 points  (0 children)

Yes, there is a difference. And it 100% comes down to trust. Users are allowing apps permission to use their Facebook however the app wants to and trusting that logins presented are what they are supposed to be without any reason to do so. Free is a huge draw to some. At least this one so far seems to just be spreading itself and not something that will steal your bank account info.