45 ms·
50M Facebook profiles harvested for Cambridge Analytica in major data breach
- 734786710934 9y agoThis wasn't a data breach, it was a misuse of data by a third party.
- cryptoz 9y agoYou are nitpicking a small part of an article (incorrectly) and it distracts from the main point: A foreign power is working with American billionaires to subvert democracy and install a dictator. This is a serious issue and one of the biggest news stories of our time. > This wasn't a data breach Yes it was. > it was a misuse of data by a third party. So a bank robber who gets into the vault just misused the locks? Or the security guard misused his eyes? This was a data breach. Your language makes it sound less serious than it is, and you are wrong. This was a data breach. Edit: Less than 30 seconds in, this post is already downvoted. I won't complain about downvotes of course, but it's insane that no conversation is actually allowed to happen on this site without burying one side. I spoke with a neutral tone, didn't do any name calling, I'm not looking for a fight. But downvotes within seconds! You can't silence me HN. I'll keep commenting my opinions and facts no matter how much you don't like what I'm saying. Nitpicking breach or misuse is silly and distracts from the actual substance of the article. It was a breach, by the way.
- hashkb 9y agoYou're downvoted because you're technically not correct. The case is more like the bank manager allowing the robber into the vault, with full knowledge that the robber wants to and could easily make off with all the valuables, then asking the robber to please not do that before heading back to work, leaving the thief unattended in the vault. Edit: it's a breach of contract, maybe; but not a "data breach" which I think everyone understands to be more like the case where the vault is forcibly broken into.
- billiam 9y agoI really don’t get your point. Bikeshedding on what to call it makes it seem like the actions of the company, the Bond villains behind it, and Facebook are just fine. FB’s actions show that they knew CA was not just pushing the envelope of the consumer preference and false identity manipulation that makes them their billions but totes aware it was being done together with a foreign adversary to subvert our democracy.
- hashkb 9y agoWords mean things. Don't assume that because someone nitpicks a technically incorrect use of a word/term that they are shooting down the entire argument. In fact, we're often trying to help; because we do agree with you; but can't get behind what you're saying 100% because part of it is not actually correct. I'm definitely not disputing the fact that FB is an evil entity that only cares about making profits off your personal information. But, they haven't suffered a data breach in the same way as, say, Equifax; and it seems to me that choosing to use the word "breach" here must be in an effort to get more clicks; because "breach in the Equifax sense" is what the author knows most people will assume is meant.
- jpttsn 9y agoBikeshedding what to call a crime can be useful and important. The democracy we are concerned about protecting presupposes rule of law, and precision when discussing laws and crimes.
- cryptoz 9y agoI was completely technically correct. It's a data breach. Plain and simple. > A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.
- sgroppino 9y agoA data breach, yes, but I believe by GSR not FB? It seems like users did authorized FB to share data with GSR?
- UncleEntity 9y ago> A foreign power is working with American billionaires to subvert democracy and install a dictator. Seriously? I'm no fan of any politician (or really of "tyranny of the majority") but I was kind of impressed at how well it all worked out last time. An "unpopular" candidate won and the ruling elite turned over the reigns just like they're supposed to do trusting the checks and balances in the system to work. The quickest way to get a dictatorship is to go against the legal results of an election because the unpopular candidate won based on some metric of "unpopular" like "kids rioting in the streets".
- cryptoz 9y agoThat was not a peaceful transition. Trump said in plain language that he would not accept the results if he lost. He called on gun owners to shoot and kill his political opponents who he has also been trying to jail for the past many years. If you are impressed with the level of functional elections and government in the US since the last election, I'm shocked. It is not a functional system. It is clearly disfunctional.
- UncleEntity 9y ago> That was not a peaceful transition. Indeed, it was the only election since I've been alive that the losing side rioted in the streets calling for the overturning of the election results. > He called on gun owners to shoot and kill his political opponents who he has also been trying to jail for the past many years. Fake news much?
- goldenkey 9y agoRight. They basically just made an app on FB then had users accept the permissions. The horribly beautiful thing about FB permissions is that almost every single app will request EVERYTHING, and if you deny even a single permission that the app doesn't even seem to need, then the app will break or won't let you use it. So every user is indoctrinated into just clicking accept regardless of the supposed "granular" permissions. They are granular as in granulated sand, falls right through your fingers.
- hashkb 9y agoIt's not a secret that FB's business is profiting off your personal data. You could choose to stop using it.
- samschooler 9y agoHowever in this situation we are talking about 3rd parties having an all or nothing policy on your data. If you don’t let some apps you login with Facebook have access to everything you can’t use their app.
- Erlangolem 9y ago...and have everyone else who knows you stop, and block their widgets and buttons that track you, and block any org that might leak, sell, or just share some of your info with them. I can’t stop a friend or just some rando at a party from uploading a photo of me. I can’t stop friends from using FB and getting me into their system. In 2018, privacy isn’t just about what we choose to do.
- hashkb 9y agoI agree. But you should take that first step, and then start lobbying your friends to stop posting pictures of you. Personally, I also excuse myself at gatherings when the cameras come out, because I know it's all going straight to FB. The shaming has already started to decrease; now I'm usually not alone in popping out of the room.
- thisisit 9y agoI think a better source for this is a related story from Guardian on how all of this worked https://www.theguardian.com/technology/2018/mar/17/facebook-cambridge-analytica-kogan-data-algorithm https://www.theguardian.com/technology/2018/mar/17/facebook-... It was extremely attractive. It could also be deemed illicit, primarily because Kogan did not have permission to collect or use data for commercial purposes. His permission from Facebook to harvest profiles in large quantities was specifically restricted to academic use. And although the company at the time allowed apps to collect friend data, it was only for use in the context of Facebook itself, to encourage interaction. Selling data on, or putting it to other purposes, – including Cambridge Analytica’s political marketing – was strictly barred. It also appears likely the project was breaking British data protection laws, which ban sale or use of personal data without consent. That includes cases where consent is given for one purpose but data is used for another.
- 21 9y agoFacebook? Yeah So I, like, need to collect some data, lol Sorry, can't do that But I'm like, uh, an academic, this is for great science, see my Cambridge page here, lol Ah, ok, just don't share it, k? Yeah, yeah, no prb kthxby
- mrtksn 9y agoDon't you think that it can be a breach in the same sense of a breach by phishing? After all, both of the cases are about people giving their "secrets" for one reason but the info being used for something else. I mean, in the case of traditional phishing the user is tricked to provide the password by impersonating a banking site, getting their funds stolen and in the case in question, the users are tricked to provide personal information by being promised some kind of personality analysis but their data is used for political propaganda that they didn't asked for resulting in life-changing consequences du to politics.
- mch82 9y agoInteresting comparison.
- anonymouz 9y agoTechnically perhaps correct, but for the victims it seems rather irrelevant to me. In a data breach, someone would have used a technical vulnerability or some other (e.g. social engineering) vulnerability of Facebook to get illegitimate access to the data. In this case Facebook simply gave them access to the data and took their word that they won't misuse it. Now maybe the latter situation might not be a data breach in the classical sense, but I don't see how it makes it any better for the victims. If anything it seems worse -- Facebook didn't even try to protect their data.
- jdavis703 9y agoFacebook isn't the victim here, it's voters who may have been specifically targeted at a "physchographic" level and had their opinions unduly influenced. Further, every person who's a member of a democracy that was targeted by Cambridge Anayltica and is now being run by corrupted politicians (or in the case of Brexit by misinformed voters) is a victim.
- dreta 9y agoNobody’s saying FB’s the victim. It’s their fault, if anything. People are „unduly” influenced all the time, and by everybody. Saying CA somehow worse than anybody else just because they worked for people you don’t like is disingenuous. It’s FB that should be held accountable here; they gave away people’s personal data to a third party.
- rtx 9y agoWhy are you calling it Target by CA? Its such a great advancement in technology.
- anonymouz 9y agoYes, sorry, if that wasn't clear. By victims I mean the people whose data was harvested of course.
- cryptoz 9y agoEvery single definition I find classifies this as a data breach. > A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.
- sgroppino 9y agoPossibly, but remember it starts with the user authorizing a company (FB) to release his/her data to a third-party. If the user doesn't trust the third-party then it shouldn't authorize the data sharing. The question I guess is that FB then agrees to share the data under certain conditions (that the third party only uses the data for an agreed purpose), and if this agreement between FB and the third party isn't honoured, shouldn't FB then sue for damages on behalf of the user?
- UncleEntity 9y agoYes indeed, we need to redefine "data breach" to include "against terms of service" to make it easier to go after all the future Aaron Swartz's. If you redefine a concept and use it against your political enemies don't be all that surprised when they turn around and use it against your political allies.
- deleted 9y ago[deleted]
- DangerousPie 9y agoBut they were authorized to access the data, weren't they? The problem wasn't that they accessed it, it was that they used it for things they weren't allowed to.
- rhizome 9y agoEverybody with an FB app key is "authorized to access [the] data," but the API TOU says you can't save anything. I'm imagining the crux of the CA issue is that they saved stuff.
- nemothekid 9y agoIt’s a data breach in the same way “social engineering” can still be considered hacking
- auntienomen 9y agoI.e., prosecutors aren't really interested in the distinction.
- sambe 9y agoYes, per https://mobile.twitter.com/alexstamos/status/975044091393187848 https://mobile.twitter.com/alexstamos/status/975044091393187... this (headline) seems like quite a sensationalisation. Nonetheless good to repeatedly raise people’s awareness of what they agreed/are agreeing to.
- johnchristopher 9y agoIf that third party wasn't sanctioned or authorized by the contract binding it with facebook then it's a breach. (not sure if you meant /s)
- gaius 9y agoFacebook: "no-one herds our sheep but us, mmmkay?"
- ceejayoz 9y agoI wonder how many of the "see what you'll look like when you're 80" and "find out how you'll die" quiz apps are doing this behind the scenes.
- thisisit 9y agoIf I am reading the paper which started all of this correctly, you don't even need the quiz apps if you have the correct permissions: http://www.pnas.org/content/110/15/5802 http://www.pnas.org/content/110/15/5802
- ceejayoz 9y agoThe quiz apps are how you get the permissions. Require the user to "connect with Facebook" to see their result. Give them the result, but quietly siphon off every bit of data you can with the access token.
- fjsolwmv 9y agoAll of them. That's the only reason the apps exist.
- yeldarb 9y agoThat’s a ridiculous statement. I still run several games on Facebook platform. It’s much easier to acquire and retain users than on mobile and it’s much more profitable because there seems to be a higher propensity for users to pay.
- kmfrk 9y agoI once told a sales rep from my ISP to stop trying to sell me on a phone subscription to which he replied that "I probably signed up for a Facebook competition or something" as if that justified it. (I don't have a Facebook account.) One of the worst things Facebook did was to just destroy any expectation of privacy.
- fjsolwmv 9y ago> Facebook denies that the harvesting of tens of millions of profiles by GSR and Cambridge Analytica was a data breach. It said in a statement that Kogan “gained access to this information in a legitimate way and through the proper channels” but “did not subsequently abide by our rules” because he passed the information on to third parties. This is exactly how Facebook was designed. You get a stupid quiz or photo frame in exchange for a copy of your friends list. It's always worked that way, and it's why Facebook OAuth was more popular than Google+ and other Oauth since 5+ years ago -- because app devs can make more money from Facebook OAuth since it comes with a copy of your friends list, so they prefer to integrate Facebook.
- yeldarb 9y agoAs of ~4 years ago when graph api 2.0 was released that’s not true. The /friends endpoint only returns friends of the user who have also already installed your application.
- chatmasta 9y agoAs of April 2016 wasn't it limited to 50 "close friends"? IIRC it was also possible to abuse iOS webview and the FB library by modifying some private methods and injecting some JS to get the info of more than 50 friends. I don't remember the details, but I saw it in the wild in a high growth top 10 iOS app (reverse engineered to see how they were getting so many users so quickly).
- shiftfocustime 9y agoI think it is much more important to focus on an investigation to make clear to the public how this data was used. That i think will lead into a much more interesting story. No one seems to want to go there and i don't understand why. Maybe because a lot of its clients are political parties/political individuals around the world and they do not want to be ousted for using "public opinion manipulation technology" on a wide scale.
- mistermann 9y agoAny investigation would be about as thorough as the Russian bots "investigation".
- patja 9y agoI was curious how the figure leaped from the 270k cited in the Facebook press release to this 50M figure. It sounds like they never had full access to the Facebook profiles beyond the 270k who installed the app, but just harvested the friend lists of those 270k. This doesn't give the app developer full access to the friends' profile data, but I guess once you have the network of friend connections you can use other public data sources to fill in or infer the gaps. And of course some of those 50M will have FB profiles that are fully public open books ready for anyone to harvest. I will say as someone who has developed Facebook apps, the whole ecosystem is pretty much on the honor system for protecting user data. There are some seemingly random and capricious (and often erroneous) abuse detection algorithms, but once an app has access to user data who knows what they do with it and whether it was kept secure -- surely Facebook has no idea unless they perform invasive manual physical audits.
- tobilg 9y agoYou could get access to the full friends‘ user profile data in Graph API earlier than v2.0. If you had 500 friends, and granted friends_* OAuth permissions to an app, the app had access to 501 user profiles.
- 616c 9y agoYou know where you read this?
- Xorlev 9y agoAt $dayjob-1 we relied on this to pull in your Facebook friends as contacts. Eventually FB limited the scope of this to friends who also had the app.
- tobilg 9y agoThis was post-v2.0 afaik.
- SubiculumCode 9y ago
- ENOTTY 9y agoOne thing other commenters haven't mentioned is that Facebook asked the other parties to delete the data and promise never to use it again and the other parties even certified that they had done so, but the whistleblower is alleging they lied to Facebook. Maybe that's legally actionable.
- myth_buster 9y ago50M doesn't strike much in FB scale, that's until... At the time, more than 50 million profiles represented around a third of active North American Facebook users, and nearly a quarter of potential US voters.
- myth_buster 9y agoSorry for the crappy formatting, can't edit now, so here's pprint version: At the time, more than 50 million profiles represented around a third of active North American Facebook users, and nearly a quarter of potential US voters.
- dawhizkid 9y agoThink about all those apps where you connect your bank account via your online banking creds that have full access to everything you buy.
- urlwolf 9y agoOK, this feels like it will bring about the end. Of something. Facebook? Massive use of data for political campaigns? Anything? If we keep consuming news like this, and do nothing, it's going to scalate massively. Same way as when Snowden told people they were spyed on and they collectively shrugged and continued with their lives as if nothing had happened. We, people in tech, have a massive moral burden to educate 'normals' on the meaning of news like this!
- John_KZ 9y agoThe problem is that regular people no longer have a place to communicate. It used to be that the workplace, church, neighborhood or union meetings were the place to socialize and discuss these issues and take collective action. Now we have nowhere to turn to. Modern nomadic culture alongside temporary jobs, low trust and personalized news all make sure that we cannot take collective action on anything. We need to find a new way to communicate before this cancer becomes so widespread that the last bastillions are lost.
- krapp 9y ago> It used to be that the workplace, church, neighborhood or union meetings were the place to socialize and discuss these issues and take collective action People still socialize and discuss issues in the real world. Having a Facebook group for a church or neighborhood doesn't preclude anyone from going to church or physically interacting with their neighbors. People also still take collective action in the real world - Antifa, BLM and the Tea Party are three modern examples, but there are countless others which simply don't get media attention. And, all else aside, social media is still perfectly adequate for enabling communication between most people. I'm sorry, but your comment seems more rooted in hyperbole than reality.
- CaptSpify 9y ago> The problem is that regular people no longer have a place to communicate. Have email, chat, forums, physical letters, meetings, etc gone away for some reason?
- mch82 9y ago
- olivermarks 9y agoMy problem with this 'outing' of CA is that Facebook explicitly commercially exists to harvest user data for Procter & Gamble, Johnson & Johnson, Fidelity etc etc so they can profile us. A million dollars is chump change in the crazy US election game. This all seems overly selective - it's ok for some people to profile but not for others. I'm not in favor of any of it to be clear but there is a definite political bias going on here. Let's not forget FB itself has a formal political unit that exists to push propaganda in foreign elections, 'stifling opposition and stoking extremism' https://www.bloomberg.com/news/features/2017-12-21/inside-the-facebook-team-helping-regimes-that-reach-out-and-crack-down https://www.bloomberg.com/news/features/2017-12-21/inside-th...
- rtx 9y agoIn recent years America seems to be very eager to compromise. First it did for security after 9/11 and now for right thought after Trump.
- eecks 9y ago> Facebook explicitly commercially exists to harvest user data for Procter & Gamble, Johnson & Johnson, Fidelity etc etc Sources on this?
- olivermarks 9y agohttps://www.wsj.com/articles/p-g-to-scale-back-targeted-facebook-ads-1470760949 https://www.wsj.com/articles/p-g-to-scale-back-targeted-face... Not hard to find information, although it is typically couched as brand reach and advertising spots. The big data sales side of FB and other sites is more sensitive and less overt https://www.facebook.com/help/494750870625830?helpref=uf_permalink https://www.facebook.com/help/494750870625830?helpref=uf_per...
- deleted 9y ago[deleted]
- IAmEveryone 9y agoYour links do not support the idea of “harvest[ing] user data”. They describe the usual Facebook ad platform, where you can set criteria to target users. But nowhere does it mention data on individual users flowing from Facebook to advertisers.
- dreta 9y agoWhy bother protecting any data, if you can put a footnote in your ToS.
- allthenews 9y agoLet's be realistic here. This headline is nothing but partisanship. The only reason this is exaggerated as a "data breech" is because of the connection to the Trump campaign. The real scandal is that such data is so easily harvested and freely available. I'd be interested in seeing how much of facebook's data repository was used in targeted political ads by all parties. Including Russian agitators who have been shown playing both sides.
- forapurpose 9y agoIt's essential to hold the President publicly accountable for his actions, especially when illicit actions pervert the foundation of the United States, the democratic process. That's not partisan; that's normal, healthy democracy; that's the primary public good provided by journalism.
- allthenews 9y agoSure. But it is unethical to exaggerate and hold only part of the political system accountable for shady or illegal practices. This is part of a consistent pattern. Our media has become as hopelessly partisan as our unfortunate two party system, and unethical behavior on one front does not justify the same on another in response.
- Thorncorona 9y agoCan you explain why it's unethical to hold people accountable for their actions or actions others took on their behalf?
- allthenews 9y agoFrom my post, again: >But it is unethical to exaggerate and hold only part of the political system accountable Please consider what I wrote in sum. Partisanship and exaggeration are antithetical to trust.
- 9y ago
- deleted 9y ago[deleted]
- hux_ 9y agoCan't wait for Sheryl Sandberg to write a new book now on garden soil or something.
- matt4077 9y agoAny reason to attack the one woman among the Facebook leadership and not, say, Mark Zuckerberg?
- avoidit 9y agoBecause the others among the Facebook leadership are not going around writing and promoting books? Also, do you genuinely not find it disconcerting that Facebook leadership go to great lengths to avoid discussing the privacy implications of their service? And the only person in that group who puts herself "out there", so to speak, is instead writing "success literature"?
- IAmEveryone 9y agoIs there some specific evilness to writing books? Because I don’t see how her writing books is reason to single her out for criticism. > Also, do you genuinely not find it disconcerting that Facebook leadership go to great lengths to avoid discussing the privacy implications of their service? And the only person in that group who puts herself "out there", so to speak, is instead writing "success literature"? So you’re angry because they don’t talk about privacy. And you’re especially angry at her because ...she doesn’t talk about privacy? That argument also doesn’t make much sense when comparing her to Zuckerberg explicitly, who’s at least as “out there” as she is. Didn’t he go on a “50 states listening tour” last year?
- watwut 9y agoI guess she likes money and success literature earns more then privacy literature. If there would be someone in Facebook leadership that writes about privacy and political implications for it, it would absolutely make sense to single out that person. Success literature is irrelevant to topic. But, I think she was single out, because she is only name besides Zuckenberg the parent knows. Never underestimate ignorance on discussion forum.
- auntienomen 9y agoSo... If I were in Cambridge Analytica's position, employed to influence the US election, one of the first things I'd do is match this data with any data I could find on voting patterns. Which reminds me, didn't some of the Russian APTs hack into state voter databases?
- oh_sigh 9y agoYou don't need to hack into voter databases - most people register for the party they vote for and that is public information(along with their home address, phone number, and whether they voted in past elections).
- beager 9y agoYou may not even need to cross-reference it, Facebook asks you what your political affiliation is and displays it on your profile (or did, at one point)
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- MechEStudent 9y agoChina has more. They have enough that this is a drop in the bucket. While they might be as blatant and ineffective as Russia by interfering with an election, they want a low profile and to maximize capture of revenue, so they are more about making money than trying to put feces on the face of the American political process. You people should pick your battles. It would help if you knew the battlefield first.
- mistermann 9y agoHow about this idea: what if the Russian bots aren't actually Russian? How has no one considered this possibility?
- threeseed 9y agoYes they have considered it. And they have identified they are Russian. You really think governments wouldn't have checked this ?
- mistermann 9y agoI thought the public might be a bit more skeptical. How did they identify with certainty that they are Russian? Is there any way for someone without top secret clearance to verify this?
- stevenwoo 9y agoHow - the special counsel Mueller has subpoena authority. First link from indictments in list form. The one I saw on TV was that guy with Hillary in a cage in parades - he was paid by Russians to make it. I also remember reading about the pro and anti gun rallies at that Texas state park - the Russians made the Facebook page for both sides in that little incident. https://mashable.com/2018/02/16/indictment-russian-trolls-interference-election/#SD5UuJloE5ql https://mashable.com/2018/02/16/indictment-russian-trolls-in... Presumably Mueller used that subpoena on Facebook and internet providers and the Russians didn't try to hide very hard and used mostly Russian ip addresses. There's also the fact Facebook admitted it sold ads and post promotion to Russian agencies and told Congress the reach of those ads and posts. Recently Facebook revealed to all users in North America whether or not they had interacted with those ads/posts. Several news organizations have independently found the data from other sources including actual interviews with the people working in Russia. One technique the Russians used was to impersonate Americans of some extreme view to stow discord and inflame the other side of some debate. https://www.thedailybeast.com/exclusive-russians-impersonated-real-american-muslims-to-stir-chaos-on-facebook-and-instagram https://www.thedailybeast.com/exclusive-russians-impersonate... There was also several different Facebook campaigns where they got Africans with pidgin English to pretend to be Americans and try to inflame white nationalists and latent racists fears.
- inetknght 9y ago1) Facebook collects and builds a profile about you 2) Facebook allows third parties to target advertisements based on the profile 3) Advertisements are tracked 4) Browsing habits and advertisement tracking reconstructs who was targeted
- aetherspawn 9y agoI hadn’t thought of it like this before, but from a political POV everyone’s vote, whether they are a dole bludger or a quantum physiscist, are worth the same. So really, to win an election .. take that as you will. Identifying these people is a very profitable area. Interesting side note .. in Australia we assign school funding based on the highest education received or wage class of the parent (classes A, B ... E or such).
- heckanoobs 9y agoI used to make fb apps, any app gets full access to fb's user graph as long as they request the relevant permissions. Users don't comprehend what permissions they are giving to apps they run. A quiz site getting full access is not surprising. Once an app has any amount of access the only thing stopping them from harvesting their own clone of your data is an agreement in the ToS that you won't store PII for more than x hours. These rules are like the bare minimum to stop good actors. If you're a bad actor fb does not do a single thing to protect users from you. As evident in this report fb is also not above blaming the users for the hostile environment fb created and placed them in. There must be countless copies of harvested fb data out there. My employer at the time once realized we were accidentally storing some PII permanently in a derived field. If good actors can't even keep above the law what do you think the ecosystem looks like in the shadows? IMO we aren't having the right conversation with fb over how they mistreat our PII and we should loosen the definition of that term when companies like the one in the article can infer our political preferences from the innocuous bits of our lives we tag on facebook. We should be asking why even an authorized API that can't stop you from copying the data doesn't count as a systemetized data breach.
- traek 9y ago> We should be asking why even an authorized API that can't stop you from copying the data doesn't count as a systemetized data breach. Is your argument that no company should offer any developer APIs at all? It's impossible to stop apps from storing data that they have access to, given malicious intent. This is like saying that the existence of the Google Calendar API is a "systemetized data breach" because an app could copy data from it once authorized by a user.
- heckanoobs 9y agoI'm not sure how we draw the line. But it should at least feel ethically itchy if ppl can use data you collected to statistically infer things normally considered private information. This puts Google on the wrong side of the line, wherever it is, next to other big offenders - fb, twitter, linkedin. To waffle less, I would absolutely be very cautious with who you give access to your gcal. You can tell a lot about a person knowing their schedule, who they meet with, where they meet, when they fly, etc. Lots on a calendar
- loxias 9y agoMinor point of confusion -- this article refers multiple times to a "data breach". ("...one of the largest-ever breaches of Facebook data...", "At the time of the data breach...", "...first reported the breach...") As far as I can tell, there is no data breach, right? It sounds like CA got facebook data through an app they wrote, thisisyourdigitallife, which did some shady things. Also, "The New York Times is reporting that copies of the data harvested for Cambridge Analytica could still be found online". The link is: https://www.nytimes.com/2018/03/17/us/politics/cambridge-analytica-trump-campaign.html https://www.nytimes.com/2018/03/17/us/politics/cambridge-ana... Anyone know what they're talking about? I haven't heard of any 50-million-profile data dump, and I really like collecting corpora...
- gscott 9y agoExactly it's confusing how they're using the word data breach like something wrong happened.
- frankzinger 9y agoIt wasn't a breach as we know it. Basically FB gave the data away. Apps have access to the data but they're not allowed to give/sell it to third parties. In this case the rules were ignored. Probably many other companies with API access have also ignored the rules. In this case FB didn't make much of an effort at all to prevent it from happening so it's reasonable to assume the practice is rampant. There's likely many copies of large parts of FB data out there (left on laptops on trains or on unprotected FTP/HTTP servers, etc.). It's a 'breach' from the users' perspective.
- svbill 9y agoNothing new about Campaign Data companies. In fact knew of a South San Francisco company called 'Campaign Data' in the '90s that ran a SAS on DECUnix. They collected voter registrar data from counties for targeted voting campaigns. Usually for passing more restrictive laws or raising taxes. Like raise property taxes for schools; send flyers to renters with kids and send nothing to homeowners with no kids. It was always in a way, unfair and evil.
- matchagaucho 9y agoThis is hardly news... Facebook ads cannot target specific users, they only target audience segments. It's actually far easier to create ads targeted at segments with likely political beliefs, and Marketers have access to aggregate numbers of niche segments today. There's no need to scrape people's profiles or get down to the individual level.
- matchagaucho 9y agoEDIT: As more is revealed about Cambridge Analytica, this clearly is "news" that requires more investigation. My original comment was more in response to user vs segment level targeting.
- gfodor 9y agoI remember when the Obama campaign hired data scientists and used targeted social networking tools to pursuade voters who were on the fence and it was heralded as brilliant and the future of politics. I worked for a company crawling Facebook data by creating viral apps the year the original API came out. By now I am sure this is done by many companies. Why is any of this news? My understanding is that companies harvesting social networking data via viral apps and then reselling it to perform targeted voter advertising is literally a 10 year old concept. Were any laws broken here? Were there any techniques used here that were novel or done by one political party and not the other? Why are we talking about this one firm and not the many others that surely exist that are trying to do the same thing for <insert political candidate of choice>
- clay_the_ripper 9y agoIsn’t harvesting data prohibited by Facebook TOS? (Not to say that people don’t still do it). Also, could you elaborate on what kind of data you get access to by doing this data harvesting versus just using Facebook targeting data that Facebook explicitly gives advertisers access to? I’m curious because fb gives a lot of targeting criteria, so I’m wondering what kinds of things this harvesting unlocks. Sentiment analysis on post language or something?
- cloakandswagger 9y ago> Isn’t harvesting data prohibited by Facebook TOS? This should be the main takeaway from this article--that Facebook relies on the honor system for protecting user data. Breaking a company's TOS isn't a crime in and of itself, and social media data has been used for political targeting for years now. Insinuating that Trump won because of a nefarious brain control operation fueled by data from a "data breach" is irresponsible.
- frankzinger 9y ago> Isn’t harvesting data prohibited by Facebook TOS? Facebook gives companies access to the data (e.g., "for research") but they're not allowed to sell or provide that data to third parties (which is what these people did).
- trhway 9y agoFor example, "Weev" got 3 years for downloading ATT user data. I wonder whether Bannon&Co would get anything ... So far it doesn't look like FB makes any push for CFAA case here. I wonder what would FB do if instead of Bannon it were a nobody like the above mentioned "weev".
- megous 9y agoWhistleblower's account suspended. https://twitter.com/chrisinsilico/status/975335430043389952 https://twitter.com/chrisinsilico/status/975335430043389952
- whiddershins 9y agoI don’t understand the use of the word “breach” in this headline.
- GenYCubeJockey 9y agoLoloophole
- andy_ppp 9y agoThis kind of work combining propaganda and disinformation with AI models and feedback into them to get a progressive change of belief is fascinating. I think of this as the first of many wars democracy will fight against AI and we are currently loosing. This comment is from the “Duped” article that has a different headline and more detail.
- mcintyre1994 9y agoI think I finally understand what the point of Facebook apps is and why they've always felt in some way dodgy. It's been clear for years that Facebook apps can get your user data, and that of your friends, and that Facebook designed them that way and were aware of that. The Guardian article even mentions that one of the apps used by GSR to gather data for Cambridge Analytica triggered Facebook security protocols trying to pull too much data. What I didn't understand is why Facebook would grant this - maybe at some point they needed viral apps on the platform and giving user data away encouraged people to make them - but why did it still work a few years ago? But this article made it click: all you can really do to monetise or use millions of profiles of Facebook users is target them with ads, and Facebook is the only place you can target those ads effectively given Facebook user data, and the more data you have the more effective those ads are, the more you pay Facebook. Facebook don't sell user data, they've long said that - and it's true. They sell the ability to target advertising to their users, and you can do that a whole lot better if you have their user data. So they don't sell it, they give an API for their users to freely give it away, knowing that once you've done all your analysis on it you'll conclude that you should spend money paying Facebook to actually deliver your messages to those users.
- muddi900 9y agoITT: people who did not read the link Astrotrufing and conservative martyrs bleeding all over the site.