6 ms·
> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed.
by generalk 9y ago
> Can we not let this become framed as a "breach"? No
> systems were compromised. Nothing of Facebook's was
> accessed that wasn't supposed to be accessed. This was
> data intentionally exposed by Facebook, just exfiltrated
> and given to an entity whom Facebook hadn't authorized.
This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was accessed by folks who shouldn't have had it. In this context, framing it as a breach is perfectly accurate.
As an aside, a HIPAA-style law that protects and enforces portability for this type of personal data might be a good first step to reforming our industry here, which is currently completely unregulated in this regard.
- bunderbunder 9y agoLet's please do better than HIPAA. It was the first such law that I know of, and there are a lot of kinks to it. Many subsequent laws were able to learn from its mistakes. One of the big weaknesses of HIPAA is that the privacy requirements technically apply to the data custodians, not the data. That allows for some loopholes through which private information can fall out of HIPAA protection, and also creates some unnecessary hassles for health care providers. Ontario's PHIPA is one example of a better model for patient privacy.
- phkahler 9y ago>> ...but that protected data was accessed by folks who shouldn't have had it. Facebook handed over the data. They need to understand that they don't have control over it once it leaves Facebook. Is a violation of ToS a data breach? Do we really want to conflate those things?
- wpietri 9y agoI understand why Facebook doesn't want to call it a breach. But it seems equally reasonable to me that users see it as one. From the user perspective, private data is suddenly in the hands of unknown, suspicious actors who may use it against them. That Facebook would rather not call that a breach so much as "business as usual" is all the more reason legislators may be inclined to define "breach" the way that voters do.
- radicalbyte 9y agoFacebook DO want to frame it as a breach. Because then it's a f*-up, not expected behaviour.
- jakelazaroff 9y agoMy intention was to contrast the mundane connotation of "business as usual" with the visceral negative reaction most of us seem to have with our data being used this way. The point I'm trying to make is that there's a difference between an isolated attack (e.g. Equifax) and what Facebook has going on here. To the person who reads about a "data breach at Facebook", it does sound like this was an abberant event that happened suddenly — rather than systemically, by a machine built on doing this every day. Cambridge Analytica's actions may illuminate how far this can go, but we should treat it as the norm — and regulate accordingly.
- deleted 9y ago[deleted]
- cyphar 9y agoA much better example would be GDPR, which comes into force EU-wide in about two months.
- tremon 9y agoActually, the regulation itself already is in force, and has been since the day it was ratified. There's just a moratorium on enforcement in the first two years of this EU directive, so that business (and society) has time to adjust to the new reality. The distinction may be very subtle, but it's important to know that following the 25th of May, businesses can no longer claim to be "in the process" of implementing it -- they have already had two years to prepare.
- closeparen 9y agoAmerican businesses did not need to prepare until Safe Harbor fell through much more recently.
- tremon 9y agoSafe Harbour was overturned in October 2015 (so half a year before the GDPR was ratified), according to https://en.wikipedia.org/wiki/International_Safe_Harbor_Privacy_Principles https://en.wikipedia.org/wiki/International_Safe_Harbor_Priv...
- verylittlemeat 9y ago>protected data What data was being protected? The data was created when the user chose to engage with the facebook apps. CA pays facebook to put something in front of users faces and then CA gets back information on user engagement. How is that different than any other kind of advertising on the web? We can argue that there needs to be more transparency on facebook but a breach? That's torturing the word.
- ncallaway 9y ago"protected data" was part of the HIPAA analogy. > This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was accessed by folks who shouldn't have had it. Protected data, in the context of HIPAA, would refer to Personal Health Information (PHI)
- verylittlemeat 9y agoWhy would the HIPAA standard of a breach apply here? Scraping public data to create a political profile is on par with getting access to private health data?
- rahoulb 9y agoCA state that the data was collected by a third party as "academic research" and they didn't know that when it was given to them - so they violated the terms of service in good faith. Whether you believe them is another matter.
- JumpCrisscross 9y ago> What data was being protected? Personally-identifiable information [1]. Many states require notification in the event this data is found to have been accessed improperly. The definition of a "breach" is not limited to technical malfunctions. [1] http://www.ncsl.org/research/telecommunications-and-information-technology/security-breach-notification-laws.aspx http://www.ncsl.org/research/telecommunications-and-informat...
- 9y ago
- mc32 9y agoListening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative. HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data. So, while illustrative, the analogy is not apt.
- chimeracoder 9y ago> HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data. In order to receive data protected under HIPAA by a covered entity, you have to go through an extraordinarily elaborate and complex legal process. In addition to signing an agreement that (in effect) binds you to all of the same restrictions on the data that the original covered entity (e.g. hospital/insurer) was, if you're accessing the data for research purposes, you'll have to go through an institutional review of your intended purpose and methods for the research. Facebook does none of these, which is why they have been (rightfully) criticized for conducting unbelivably unethical studies[0] without either user consent or institutional approval, even though both of those are typically required by all reputable universities and publishers for research. Facebook posts are not protected under HIPAA, but they're not entirely unprotected either, and it's totally valid to refer to that breach of responsibility and trust as a breach. [0] e.g. https://www.washingtonpost.com/news/morning-mix/wp/2014/07/01/facebooks-emotional-manipulation-study-was-even-worse-than-you-thought https://www.washingtonpost.com/news/morning-mix/wp/2014/07/0...
- mc32 9y agoI'll agree with you in characterizing it as a breach of trust. That it is. Operatives in Washington, however, are trying to characterize it as something it is not. It's not Russians hacking in, it's not part of some effort to destabilize democracy, etc. That characterization and demonization is indicative of the mindset of those people and that may be even pose more danger than the breach of trust by Facebook.
- FLUX-YOU 9y ago>This is similar to a HIPAA "breach" It's not, at all. The FB API was designed to give out this information before it was changed. That means the friend data was not need-to-know like healthcare data.
- CiPHPerCoder 9y ago> This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was accessed by folks who shouldn't have had it. In this context, framing it as a breach is perfectly accurate. Data breach is a compound noun with a very specific meaning in information security. It means that the data was protected, and a malicious entity defeated the protections. Breach of contract, breach of trust, physical breaching of the hull of a ship, etc. are all different usages of the word breach, but it's not a data breach unless someone accessed a protected system without or exceeding authorization as defined by the CFAA.
- deleted 9y ago[deleted]