18 ms·
Ex-Facebook insider says covert data harvesting was routine
- camillomiller 9y agoThe cool thing? This "whistleblower" already spoke publicly with an op-ed on the NYT months ago. Again, this is just the top of the newscycle. Let's see what happens in three months from now. My guess: Facebook revenue will go up. This is a PR shitshow, and a great piece of advertising for Facebook's ad department. A lot of marketers right now are thinking "wait, we could do that with all that Facebook data we have?!"
- Gys 9y agoMy thoughts exactly. People seem to hold on to Facebook whatever the stories are, so there is no real problem. I was even thinking of buying stocks soon (wait one more week to have the market process these 'new' facts).
- spyspy 9y agoIt may not be seen as ethical here, but I also plan on buying some more FB. This is a huge overreaction, and we all know it'll blow over inside of a week.
- rock_hard 9y agoFB is the media’s scapegoat of the season...nothing to see here...keep shopping folks ;) Seriously though, go buy that stock...it’s ridiculously under valued!
- sveme 9y agoGDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.
- Oras 9y agoand how many people are aware of it and will write to companies like FB asking for their data?
- sveme 9y agoThat's not how GDPR works.
- camillomiller 9y agoIt will offer a possibile solution in Europe, where Facebook has already been under heavy scrutiny. It won't change anything in the US, South America, SE Asia and developing countries where Facebook is already dangerously synonimical to the whole online experience of the average user.
- sveme 9y agoThe hope is that Facebook will not have two different data handling strategies for EU and non-EU users and we'll see some sort of regulatory encroachment from the EU to the rest of the world. But obviously GDPR endangers so many of Facebook's shady but lucrative practices that they will have financial incentives to set up two different user silos.
- kazen44 9y agoI wonder if other countries also start making laws like the GDPR? The EU is creating a frameworks which makes it very easy for other countries to "attach" on too. The only danger is not having enough leverage to "prevent" companies from leaving and not adhering to privacy standards, but by cooperating this should be possible?
- Chaebixi 9y ago> The hope is that Facebook will not have two different data handling strategies for EU and non-EU users and we'll see some sort of regulatory encroachment from the EU to the rest of the world. But obviously GDPR endangers so many of Facebook's shady but lucrative practices that they will have financial incentives to set up two different user silos. Facebook might be one of the few organizations with the motivation and ability to set up two different regimes to contain the effects of GDPR on their practices. In that case, I would love to know what their selection criteria is.
- malikNF 9y agoWhat's utterly horrifying about this whole thing is how the media is acting as if this is some sort of surprise. Like what did you think was happening at a company collecting data about billions of people? Especially at a company that has a CEO who is famous for calling its own users dumb fu * * s? A company that experimented on at risk teens. Like come on. --edit--- Or lordy, didn't expect this comment to blow up this much. Do forgive me if it sounded a bit smug, that was not my intention. But the fact of the matter is this was something we were all warned about, we were shown countless examples of exactly this, not just us nerds, everyone, people like Edward Snowden risked their lives telling us about how all this data was being used against all of us. and yet everyone kept giving more and more, you were looked at like a tin foil wearing nutter when you told people not to give away so much information about themselves so easily. At the end of the day, this is not really 100% facebook's fault, this is our fault, the fault of everyone who so readily made their information available without giving much thought to who sees it and what happens to it. And no just because you are not a techie you are not off the hook for not caring enough about your own privacy. I mean what level of technical knowledge is needed to know that once you post something online others can see it? Funny thing is, this would all blow over after a few months, and everyone will go back to the usual habbits.
- fredley 9y agoIt's not a surprise to most readers of HN, but most people are not readers of HN, and take things at face value, where face value is what they see in advertisements and hear from their friends. People still have an expectation of privacy, even when, from an HN perspective they should be extremely skeptical about having such an expectation.
- deleted 9y ago[deleted]
- 1337biz 9y agoFascinating to watch - it shows how much power media has to put a topic on the global agenda if it fits into their preferred narrative.
- scottmf 9y agoOh man this is bad. >the platform operations manager at Facebook responsible for policing data breaches [...] warned senior executives at the company that its lax approach to data protection risked a major breach >One Facebook executive advised him against looking too deeply at how the data was being used, warning him: “Do you really want to see what you’ll find?” >They felt that it was better not to know. I found that utterly shocking and horrifying.
- 1337biz 9y agoIsn't that just part of FB's culture? Didn't the Zuck start out by scraping Harvard's student registry?
- txcwpalpha 9y agoLol, "this is bad"? This is normal. I can give you an entire list of F500 companies I've worked at that have the same mindset. I've sat in meetings with F100 CIOs where they were given the same warning and shrugged it off. I've been asked before to turn off security monitoring systems because executives prefer to not know about vulnerabilities rather than know about them and not be able to fix them. The only thing shocking and horrifying about this whole thing is how naive the American public must be to find any of this shocking and horrifying.
- ggm 9y agoRegulator asleep at the wheel.
- jakelazaroff 9y agoCan we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook, just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify, this is indeed worse than if the data were taken from Facebook without consent. What it means is that not only does Facebook have access to vast troves of personal information, but so does everyone tangentially connected to someone with a Facebook developer account.
- mannykannot 9y agoI hope you are saying that this is worse than a simple breach, not that it is a non-issue.
- jakelazaroff 9y agoGood call. Edited to clarify.
- koboll 9y agoEven "exfiltrated" is not really accurate since it was freely handed over. The problem is that Facebook just made its partners pinky swear to only use the data for research, which is obviously not an adequate data security measure.
- faizshah 9y agoThe real point is that companies like facebook and equifax have such large caches of personal data and have no legal obligation to protect it. This is a point most people outside of tech don't understand. You might not even be a user of facebook but these companies still have data on you that is highly personal and invasive. An academic who has done some great work on this is Evgeny Morozov. Highly recommend his books, articles and lectures.
- jakelazaroff 9y ago
- CptMauli 9y agotell me again why you think the EU General Data Protection Regulation (GDPR) is a bad idea?
- drchiu 9y agoWe’re in the midst of reviewing our GDPR compliance one more time ahead of the May 2018 at my company. As a consumer, this kind of regulation makes sense. On the technical level, with so many service providers involved in running a modern day company, it’s obvious that many things have to be restructured for strict compliance. Eg. ESPs for mail delivery, analytics for business insight analysis In the end, it’s about using data as it’s intended and nothing more.
- IAmEveryone 9y agoI was actually surprised by the generally positive reaction the GDPR got in recent threads here on HN. I guess the suspicion of data hoarding overcame conspiracy theories about government regulation or EU protectionism. BUT it’s important to note that GDPR would probably not have had an effect on the specific situation with Cambridge Analytica. CA is obviously toast if not by law then by the attention alone. Facebook, however, is likely allowed to share data under GDPR as they did with CA: they got the users’ permission initially, and there isn’t much you can do to protect yourself against malicious actors.
- mziel 9y agoRegarding "they got the users’ permission initially" this is true for the users that signed up for it, not anybody in their social graph. GDPR treats data about a user as data belonging to this user. Those people have definitely not consented to having their data mined for this use case. Next (as I understand) the consent was for research purposes, not for the CA targeting. So under GDPR Cambridge Analytica could be fined 4% of global revenue or €20M - whichever is HIGHER [1] [1] https://www.gdpreu.org/compliance/fines-and-penalties/ https://www.gdpreu.org/compliance/fines-and-penalties/
- deleted 9y ago[deleted]
- arkh 9y agoHow the fuck could people be surprised? Open a software job board. 50% of offers are by companies trying to optimize some data harvesting and analysis to better target some ads. Ads, the direct child of propaganda. So to everyone working in those kind of companies: you're not better ethically than people working on missile software. I'd say you're worse because you can argue missiles can be used as deterrent.
- na85 9y agoI up voted because your point is relevant. However, Software development is not a Profession, in the proper use of the term. It is not self-regulating the way Medicine, Engineering, Law, and a few others are. There is no formal standard of ethical conduct in software for practitioners to use as a baseline for their own behaviour.
- 24gttghh 9y agoAhem: http://ethics.acm.org/code-of-ethics/software-engineering-code/ http://ethics.acm.org/code-of-ethics/software-engineering-co... >1.03. Approve software only if they have a well-founded belief that it is safe, meets specifications, passes appropriate tests, and does not diminish quality of life, diminish privacy or harm the environment. The ultimate effect of the work should be to the public good. edit: this version is from 1992. And I should point out my courses at least had a discussion or two regarding programming ethics in college in the mid-2000's.
- na85 9y agoHow is this enforced? What is software development as a field doing to regulate itself and ensure members follow this guide?
- 24gttghh 9y agoI think ethical guidelines by definition are not enforced per se. They're just that, guidelines. However, as mentioned by GP there are boards of ethics at universities and medical/engineering organizations and such that might be able to dole out a modicum of justice. For instance, not following those guidelines would conceivably end one's membership of the ACM, and many companies have their own ethical guidelines (I would argue there is not much difference between professions for what is truly considered "ethical") which when breached would result in disciplinary action. Theoretically? Perhaps not in the case of FB...
- tmalsburg2 9y agoIt's important to realize that Facebook's lax attitude to data harvesting was most likely one key to their success. If they had closely guarded user data, there would soon have been stiff competition, but this way everyone could benefit from Facebook's data treasure trove and Facebook's success was in many other companies best interest. The current state of affairs should therefore be seen not as the result of negligence but a desired outcome of Facebook's core business strategy.
- KasianFranks 9y agoWe knew it facebook was going to be the next friendster+AOL+myspace but I never suspected it would disintegrate to these levels. Expect employees to start jumping ship left and right.
- drpgq 9y agoI suppose stock option values will plummet, but I guess most get stock grants now.
- Invictus0 9y agoEthics can't be a side hustle. https://deardesignstudent.com/ethics-cant-be-a-side-hustle-b9e78c090aee https://deardesignstudent.com/ethics-cant-be-a-side-hustle-b...
- synchronist 9y agoI made a Facebook web scraper which opens 20 headless browsers. You provide a list of unlimited usernames & proxies (you can buy them at https://buyaccs.com/en/ https://buyaccs.com/en/). It will scrape every ounce of public information available. I acquired a few million users worth. The data is too easy to get.
- AcheyLegs 9y agoLisa, I'd like to buy your rock.
- hanspeter 9y agoEveryone who ever googled a name should realise that.
- aylmao 9y agoWhich kinda throws me off. It's no secret Facebook, Twitter, your phone (if you give permission to a 3rd party app) etc, are all harvestable. All CA is in regards to a story that broke a couple months ago. Why is it catching fire now?
- orthecreedence 9y agoSomething something Trump
- kelvin0 9y agoOf course, nothing is going to change since everyone has known this for years, and still use FB. In the upcoming weeks users will be more 'careful' but since they have 'nothing to hide' it's 'Okay' to use FB in a 'responsible' way. 'Everyone' is shocked but no one feels threatened individually, so the circus and clown show can continue.
- nkkollaw 9y agoCan someone do an ELI5? I have no idea what's going on... EDIT: I guess not.
- zitterbewegung 9y agoSo the greatest achievement of big data and ML right now is the manipulation of elections a true shock and awe. And yes, everyone on HN and RMS will say “why is everyone surprised ?” Well it’s because normal people don’t have that perspective and think Facebook is the internet for them. Data is the new oil but now everyone knows this except just us on HN.
- ams6110 9y ago> Asked what kind of control Facebook had over the data given to outside developers, he replied: “Zero. Absolutely none. Once the data left Facebook servers there was not any control, and there was no insight into what was going on.” Um, well yeah. This is the case any time you give data to a third party. They now have a copy, and you can't control what they do with it.
- d_theorist 9y agoExactly. What kind of controls could there possibly be? Even doing an audit wouldn't necessarily reveal anything. If somebody has data that they want to hide I'm not sure how much can really be done to force them to reveal it.
- checkyoursudo 9y agoThe controls are agreements that make getting caught doing the unauthorized act painful enough that it might be enough to deter the act in the first place. If the price is high enough, bad actors will be willing to breach NDAs/CDAs/licensing agreements/etc, but at least then you can be seen as having done more than zero. Might have been prudent here.
- checkyoursudo 9y agoWell, NDAs/CDAs/licensing agreements/etc can make disclosure to non-authorized 3rd parties very painful for your customers/partners/etc to contravene your requirements for what they do with data, intellectual property, customer lists, etc. This doesn't stop external attacks, of course, but it can reduce internal risks. Facebook could have had more than zero control, if it had wanted.
- thrownaway954 9y agothe platform was designed to entice and integrate into every aspect of people's lives and then ENCOURAGED you to get your friends to participate by inviting them to the platform. it was a data harvesting, advertising mongrel from the start and everyone KNEW it, but no one cared. like all things in life... people cry foul when things come back to bite them in ass. like i said yesterday in a comment... delete ALL forms of social media cause this goes on with ALL platforms out there, it isn't just limited to FB.
- CaptSpify 9y agoWould you not consider HN Social Media? I personally don't think it's the same as FB, but there are some strong similarities. Maybe "Social News" is a better term? Where do you draw the line for Social Media?
- thrownaway954 9y agono... it's a glorified comment chain. no different then posting a comment on an open wordpress blog where everyone can submit a post.
- avoutthere 9y agoHow long before it comes out that Google does the same thing with search history, Amazon with product browsing, Apple with phone usage, and Microsoft with Windows 10 usage?
- amrx101 9y agoThey are already doing it mate.
- kimdcmason 9y agoCitation needed.
- tzakrajs 9y agoCan you show me how psychographers have been using Google or Amazon in the same way as Facebook? I believe you are making a false equivalency.
- deleted 9y ago[deleted]
- simias 9y agoIs there any reason to believe that the situation isn't the same in, say, the Android ecosystem? In my experience many 3rd party apps require ridiculous amounts of permissions (contact list etc...) for something that's not core functionality. Surely all these free-to-play crapware games on the Android market have siphoned all the data they could and sold them to the highest bidder? Does Google do a better job of monitoring these apps?
- TeMPOraL 9y agoWait until you see the video of these guys: https://www.sentiance.com/ https://www.sentiance.com/ (via https://news.ycombinator.com/item?id=16626752 https://news.ycombinator.com/item?id=16626752)
- simias 9y agoYeah that's exactly the type of things I'm worried about. Smartphone apps have potential access to an incredible amount of sensitive data and I always found Android's permission system to be woefully inadequate.
- beefield 9y agoThere is an increasing need for a container app that will feed whatever sensor data you want to the apps within the container. Also there would need to be some preconfigured sensor data profiles, like "Occasionally cheating husband living in city X" or "Really rich housewife living in city Y" or maybe "piss-poor guy living in a rural developing country"
- aylmao 9y agoI don't know which one I'm more worried about. On the one side Facebook can track preferences and something akin to feelings closely, but on the other Google can track day-to-day activities much better. If you've ever seen your Google activity log; that's very scary. The accuracy with which your phone can track your movement and where you are at every point in time is unprecedented. I'm very careful with what I allow 3rd parties to access but I can see a lot of users blindly accepting (like they did for this personality quiz that leaked all this Facebook info in the first place).
- peterwwillis 9y agoThis has literally been de rigeur at any company that does advertising for a decade. Even sports websites have been doing this since forever. Excuse me if I'm not really horrified by political groups using personal data to craft strategies.
- jypepin 9y agoI've been thinking more and more recently of deleting my facebook profile. 1. I barely add stuff on it 2. 99% of my news feed is irrelevant and I really don't care (there maybe 1 post/day from a friend that is interesting to me) 3. Starting to be more and more concerned about all this data But I'm scared for multiple reasons: 1. connections needed from a lot of friends, family etc. that I would not keep contact with otherwise 2. It does a great job at keeping my contact list updated (no later than yesterday I searched for friends/coworker to make sure I don't forget anyone on my farewell email) 3. Messenger. I use it a lot (almost as much as iMessage) and again, a lot of people I talk to on facebook I don't have their info for telegram/whatsapp/etc.
- swyx 9y agoyou dont have to delete it, you can just not be an MAU
- orthecreedence 9y agoYeah exactly. My Facebook is pretty much read-only at this point, except for a few "likes" to show support for friends or if I get invited to a personal event or something.
- Chaebixi 9y ago> I've been thinking more and more recently of deleting my facebook profile. > But I'm scared for multiple reasons: I went through that a similar thought process. I decided to keep my profile active, but unlike everything and delete all my posts. I also changed my profile pic to make it clear I wouldn't be using Facebook anymore. That way I can still get event invites, etc. but not be too burdened by the whole thing. Eventually I'll delete my profile, but not until Facebook becomes far less ubiquitous (and I do what small things I can to hasten its decline).
- mannykannot 9y agoAll the self-serving memes are out on parade here: "This not news", "what did you expect?", "anyone paying attention should have known", "it is the new normal", "it could not be any other way", "everyone benefits"... Actually, as of posting, the "Apple/Google/Microsoft are just as bad" version has not yet put in an appearance.
- freeone3000 9y agoOne could argue that Apple and Microsoft are not as bad, because Apple and Microsoft sell products, not advertisements.
- Applejinx 9y agoApple wants to be a walled garden. Can't be a walled garden without walls: their self-interest and marketing direction lies elsewhere. Also, in the case of the iPhone, hardware is the product, and in the case of the app store, the devs and apps are the product (some of the time, anyway).
- jjulius 9y agoYeah, it makes me think of how people often say that SV is disconnected from the rest of society. Sure, those of us on HN know to expect this from data-mining companies, but spend an extended amount of time with people who don't work in tech and you'll quickly learn that, yes, they know that FB uses your data, but most people have almost zero idea around just how much of your data is captured and sold/harvested/whatnot, nor what is done with the data after that point.
- belorn 9y agoIt would be interesting to see someone analyze if the relationship between government and Facebook got more news coverage this time than it did when Snowden reported the exact same thing in 2013 or when other people reported it back in 2012. In particular it would be interesting to see which new sites write articles about it and if possible how negative they are. For example we have CNN article in 2013: https://www.cnn.com/2013/09/30/us/nsa-social-networks/ https://www.cnn.com/2013/09/30/us/nsa-social-networks/ vs now in 2018: http://money.cnn.com/2018/03/19/technology/facebook-data-scandal-explainer/index.html?iid=EL http://money.cnn.com/2018/03/19/technology/facebook-data-sca... Maybe that would explain why we see so many that got surprised by this while others has seen it for a long time and just got used to everyone not caring.
- breakpointalpha 9y agoWater is wet.
- api 9y agoAre we really that ahead of the curve here? Did the general public not realize that a free service that collects tons of information from you might be gasp using that information to make money? I know some people who work in SEO and marketing and the stuff CA was doing was a more sophisticated version of what every free Facebook game or 'survey' vendor is doing. This is literally the business model of the free/popular Internet. Of course it's going to be used for political campaigns-- why not? It's used for every other kind of marketing. I'm not saying it's good. I think it's terrible. It's a plague. I'm just shocked that people are shocked by what's been happening in the open now for years.
- intended 9y agoDoes anyone else have the wild speculation that Rupert Murdoch is opening a bottle of champagne today? The interest in FB and privacy, while gratifying, also seems focused through a particularly yellow lens. People on HN have also pointed out that it’s very likely that CA’a analytical prowess may well be overstated as part of submarine marketing efforts. I suppose many people are just surprised that this is taking off now, without any truly new or novel fuel driving it - when the same articles and worse, had no effect earlier.
- cryptoz 9y agoThere is new fuel. Did you miss the video of the CEO of Cambridge Analytica bragging about how his company stole 200 elections around the world by lying and cheating and deceiving the public? With illegal methods abound? Lots of new fuel.
- aylmao 9y agoBut specifically the way Facebook is being dragged to the center of the fire, even though there isn't really any new fuel on Facebook's side. There's good reason for the media to be tense against Facebook right now, since Facebook has changed the news feed algorithm: "traffic in the news category, which includes major news publishers The New York Times, Washington Post, CNN and BuzzFeed, was down 14 percent after a sharper drop in the months prior" I do think Facebook should audit its 3rd party developers more closely and that this leak of data is terrible. Yet, imagine CA instead had built an app for a personality quiz and asked for a ton of permissions from your phone to track your location, harvest your contacts, etc. What else could Google/Apple have done? [1]: https://digiday.com/media/promised-facebook-traffic-news-publishers-declines-post-news-free-change/ https://digiday.com/media/promised-facebook-traffic-news-pub...
- mollusc 9y agoWhat kind of data are we talking about here? I'm sure there are all kinds of metrics and analytics available but I'm interested: What are the "rawest" forms of user interaction that Facebook makes available to these companies? I'm not in the business of using this data and neither I suspect are most of the Guardian readership so it would be nice to see this elucidated.
- mstade 9y agoFrom the article: > He said one Facebook executive advised him against looking too deeply at how the data was being used, warning him: “Do you really want to see what you’ll find?” Parakilas said he interpreted the comment to mean that “Facebook was in a stronger legal position if it didn’t know about the abuse that was happening”. If this is true – would this constitute willful blindness, and is that not illegal?
- d_theorist 9y agoOne thing I can't quite find a straight answer to: is there any suggestion that either FB or CA broke the law here? Note that I'm not saying that any of this is ok just because there was no illegality.
- IshKebab 9y agoUnlikely, I've managed to work out what was happening (the news never really explains it - just a "data breach"). In the past if you gave it permission, a Facebook app could access information about your friends, e.g. their photos, name, gender, etc. I'm not sure exactly how much data. Some sketchy apps harvested this data (which was against Facebook's terms and conditions for those apps). So the apps may have broken the law. I guess there is the question "should Facebook have protected the data better" but I doubt they broke the law exactly. Anyway the stupid thing about this is that it was obvious that's what all these sketchy apps were doing at the time. Facebook app developers knew they could get this data, and the only thing stopping its exploitation was Facebook's app T&C's - i.e. "please don't do bad things". There was even a setting to prevent third party apps accessing your data when given permission by friends. That's how obvious this issue was. (I doubt anyone used this option). https://nakedsecurity.sophos.com/2013/04/03/how-to-stop-your-friends-facebook-apps-from-accessing-your-private-information/ https://nakedsecurity.sophos.com/2013/04/03/how-to-stop-your... Facebook removed the friends API in 2014 so this is all about historical data "breaches".
- lumberjack 9y agoStallman is right once again. The response that we used to get is, "but Facebook/Google would never give away their data, they will just use it for targeted advertisement, the data is too valuable to just sell it wholesale to other entities".
- bbarn 9y agoAttention everyone's smart friend or family member: Now is not the time to scream "DUH!" or "I told you so!" to people who in the past have not grasped just what they were agreeing to. Now is the time to help your less tech-savvy friends understand the impact their data has in aggregate (like swaying elections!), and how they have been used by this system. Take advantage of all this bad press and help people you care about stop contributing to this machine. If ever you were going to get someone to stop using these services, these are the moments you capitalize on.
- jjulius 9y agoThank you! I'm going to be using this thread as a perfect example when people think I'm crazy for saying that SV often exists in its own bubble. The disconnect here, and the failure of so many people to realize something so obvious, is appalling.
- YCode 9y agoI take this to mean anything private or sensitive said on Facebook Messenger should be considered breached?
- deleted 9y ago[deleted]
- CaptSpify 9y agoThose were never actually private in the first place.
- smpetrey 9y agoWell of course this was routine. Facebook prides itself on it's data collection and ad targeting. I'm not discounting The Guardian's reporting, but I thought this was known. I mean you can download your data here and see what endpoints/interests you can be targeted on: https://www.facebook.com/help/302796099745838 https://www.facebook.com/help/302796099745838 Sadly, the world will continue to use Facebook and users will continue to be exploited.
- robterrell 9y agoThat URL doesn't tell me what I really want to know -- what parties used the graph API to download data from me.
- 4684499 9y agoI'm OK with data harvesting, but, it has to be transparent and ask for permissions every time they want to use my data, allow me to delete the data I generated. It should always be opt-in. I use google maps a lot. I search a place, it provides me lots of useful information. Yes, I find it helpful, but also terrifying, especially with the "Popular times" section, which is "based on visits to this place." Where are the eyes? :/
- deleted 9y ago[deleted]
- mroll 9y ago> ...terms and conditions people did not read or understand. The article acts like this is unprecedented. No one reads terms and conditions. It's not as if people fork over intimate details of their personal lives to Facebook with the defense that "oh the terms and conditions say they can't use this in a way I don't like" People fork over intimate details of their personal life to companies like fb because they haven't thought about it very hard
- dwighttk 9y agoA Tangent: What is the deal with those videos in news stories these days that are just moving* pull quotes with music and maybe some pictures? It's like a really short article in video form. *I mean literally, not emotionally
- whiddershins 9y agoI still don’t understand the breach part. It just seems like Facebook app developers used Facebook exactly as it was set up, and then resold the data.
- xtracto 9y agoIt is more of misuse than a breach. The data was provided to a guy for academic research, but the guy sold it to a third party. That is where the 'breach happened.
- tzakrajs 9y agoImagine a clinic has a policy that allows patient data to be released to non-patients but a court decides that the use violates HIPPA. There would be no technical breach of security, but rather a breach of responsibility.
- squozzer 9y agoI have a feeling this is less about what was done and more about who was doing it. https://www.investors.com/politics/editorials/facebook-data-scandal-trump-election-obama-2012/ https://www.investors.com/politics/editorials/facebook-data-...
- matte_black 9y agoWhat’s the worst that could really happen from any of this? You’re shown a highly targeted ad that you don’t even look at anyway? Give me a break. Manipulating elections? Elections already have tons of opportunities for manipulation across all mediums.
- skc 9y agoI still think FB is a useful tool, but it puts things into perspective when people try and argue that Microsoft of the 90's is/was evil.
- bogomipz 9y ago>"Academic research from 2010, based on an analysis of 1,800 Facebooks apps, concluded that around 11% of third-party developers requested data belonging to friends of users. If those figures were extrapolated, tens of thousands of apps, if not more, were likely to have systematically culled “private and personally identifiable” data belonging to hundreds of millions of users, Parakilas said." So it's quite possible that there are more than a few third parties holders of FB user data who have now been alerted to the potential profitability of their old "research data."
- deevolution 9y agoIm honestly not surprised by this news at all.
- Mc_Big_G 9y agoDelete your Facebook/Instagram/Whatsapp accounts.
- SaturateDK 9y agoI say wipe them. I have been deleting data for the last couple of days, I don't need old comments and likes - even pictures as I have them myself. This was I can slowly phase it out, this has been my plan all along, but I need some time to make all logins work without facebook ect. My intent is to delete it eventually. Until then no new content, and wiping the old content.
- discordance 9y agoSo the Cambridge Analytica stuff had been public for a while, as has Facebook's responsibilty in the matter. The cynicist in me wonders if this is all lighting up intentionally before GDPR is enacted to reduce potential financial liability. Too conspiratorial?
- ahmetkun 9y ago>Parakilas, 38, who now works as a product manager for Uber a company known for their respect of privacy and exemplary business ethics. good that he left facebook.
- CodeSheikh 9y agoI see a lot of Facebook sympathizers here. Is this what devs do at Facebook? Browse HN and defend the reputation of Facebook at any cost? Yes we all knew what we were in for when we signed up for Facebook and Instagram. Yes, they can sell our data to show us ads about what coals to buy for July 4th bbq party and we are OK with that. But not to turn blind eye to foreign entities which in return use it against us and jeopardize the American democracy and social fabric.
- verylittlemeat 9y agoI don't work for facebook. I don't have a facebook. I don't like facebook. What I do like is honesty. https://en.wikipedia.org/wiki/Data_breach https://en.wikipedia.org/wiki/Data_breach Look at this very robust list of data breaches and tell me how the CA/Facebook incident this week looks anything like any of them.
- lightbyte 9y ago2006 - AOL search data scandal [1] >The release was intentional and intended for research purposes; Sounds pretty damn close to this event with Facebook [1]: https://en.wikipedia.org/wiki/AOL_search_data_leak https://en.wikipedia.org/wiki/AOL_search_data_leak
- verylittlemeat 9y agoAn analogous example would be if the CA/FB breach had access to private facebook messages or information that was never intended for public consumption. In the CA/FB case the information was either public (and could be scraped as such) or was collected in the form of facebook apps.
- ahakki 9y agoThis is not true. The old Facebook API gave access to all data the user had access to. This included information (posts, photos…) by “friends” which was not public.
- antr 9y ago"Move fast and break things." Sigh...
- deleted 9y ago[deleted]
- yread 9y agoI'm starting to feel like all this is just a PR campaign for GDPR cause I'm sure looking forward to it
- paulie_a 9y agoIsn't that their business model?
- KevanM 9y agoRemember folks, if you've got nothing to hide, you don't have anything to worry about.
- pcarolan 9y agoAre there any liability laws that hold those in the chain of custody accountable for third party misuse? Seems like it is an obvious burden of responsibility.
- ismail 9y agoWow. “react only when the press or regulators make something an issue, and avoid any changes that would hurt the business of collecting and selling data.” From: https://mobile.nytimes.com/2017/11/19/opinion/facebook-regulation-incentive.html?referer=https://www.theguardian.com/news/2018/mar/20/facebook-data-cambridge-analytica-sandy-parakilas https://mobile.nytimes.com/2017/11/19/opinion/facebook-regul... The scary part is the cat is already out of the bag if you authorised any app. They could have a wealth of your data that is being sold.
- Applejinx 9y agoYou are assuming these same people, with everything to gain through just this behavior, have been utterly and scrupulously well-behaved this entire time all while nobody really questioned them. 'If you authorized any app'? I'm sure there are workarounds for that. If you touch them or pages where their invisible Facebook gif is present, they've probably got all your data that's gettable.
- sol_remmy 9y agoOngoing discussion at: https://news.ycombinator.com/item?id=16626318 https://news.ycombinator.com/item?id=16626318
- panchicore3 9y agoSorry for this stupid question: how does Facebook to prevent kamikazes developers/sysadmins data dump and run away? It's there some framework to manage data loss prevention in this way?
- arkona3 9y ago> utterly horrifying This has been common knowledge for years. Is the general population not aware of Facebook’s business model?
- petilon 9y agoFrom the story: > They seemed to be entirely focused on limiting their liability and exposure rather than helping the country address a national security issue. This is a national security issue. That seems like the most pertinent issue, and yet there is no mention of it in the discussions here. Facebook has amassed huge amounts of data about all citizens, and adversary nations are leveraging this data to manipulate the nation, including by helping elect a president who will be friendlier towards them. Facebook is Russia's biggest cyberweapon. Just as private companies would not be allowed to stockpile WMDs, private companies should not be allowed to stockpile so much digital information either. This is a national security issue.
- mithoon 9y agoThis was 6 years ago, and we wonder they would be no where 6 years down the line ?
- username223 9y agoThis article sums it up for me. FB makes the short-sighted decision to allow apps to scrape friend-of-friend info, because it would encourage more app developers, from which they get a 30% cut. When this guy asks a question about scraping, his boss replies "better not to know." The company continues not to give a shit about distributing PII until they realize that someone might use that data to create a rival social network. Then they shut it down and treat the fallout as a PR exercise. Utter scum.
- Khaine 9y agoI'm glad that a light is finally being shined on the sliminess of facebook's business model and that the public are starting to understand what an ugly company facebook is. I am dismayed at the state of journalism that it took until there was a trump connection until they seriously reported on this
- xixi77 9y agoDo we actually know what data has been leaked/illegitimately retained/whatever you call it? A lot of the discussion revolves around friends data -- was all friends data accessible regardless of the friends' own privacy setting (this would be deeply troubling), or was it the data that friends shared with the app users (a bit less troubling, but still very questionable), or was it friends' data that was openly available on their public profiles open to any internet user?
- Mmunzali 9y agoI was really careful on who to hire when it comes to getting an ethical hacker to help me hack into my fiance's phone after reading a lot about series of hackers i decided to give CYBERMESSIAH a try. From the very first day of getting to talk to him as they say "FIRST IMPRESSION LAST LONGER" I gave him a benefit of doubt i followed all instructions given and he did an incredible work. I was given a cloned phone that gives me free access to my fiance's phone apps and all her phone messages and calls all without trace. He advised on how to get my wife back and I can tell you we are very good friend now. All thanks to cybermessiah (dot) hack (at) gmail (dot) com for helping get back my partner. Y'all shouldn't hesitate to contact via text or email cybermessiah (dot) hack (at) gmail (dot) com (910) 420-5887if you have any hack issues. Trust me he will definitely make you smile. Blank ATM Here is our price list for ATM cards: BALANCE PRICE $2,500----------------$150 $5,000----------------$300 $10,000 ------------- $650 $20,000 ------------- $1,200 $35,000 --------------$1,900 $50,000 ------------- $2,700 $100,000------------- $5,200 Bank Account Hack Credit Score Upgrade Phone hack Company Server hack Email Instagram Twitter Facebook University Grade Upgrade Contact CYBERMESSIAH (dot) HACK (at) GMAIL (dot) COM