15 ms·
The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly
by propman 9y ago
The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. They knew it was illegal but put all the incentives for companies not to follow the rules. That's the only hole in his statement.
As for the rest of it, it's progress. It seems like a lot of good changes, but Analytically Facebook execs probabaly summarized that this is the least they had to do to stave off regulations or monopoly anti trust from congress. Any less, regulations would still be placed on them so it's brilliant strategy to do this and frame it in a way that Facebook is concerned about all the damage and we voluntarily do this for you instead of the truth which was we knew about this forever and only are doing it because of threat of regulations.
Overall, an optimal outcome for all parties currently, except for society as a whole down the line
- taurath 9y agoYeah it’s like “oh gosh, they violated our terms of service by pulling 50 million users info! We must send them a sternly worded email with a checkbox to confirm they they won’t do it again!”. It’s inconceivable that there aren’t larger exfiltrations of user data that have taken place - how would they even know?
- chrishas35 9y agoI feel like they really doubled down on that by naming Kogan.... "see, it was just one bad developer"
- netsharc 9y agoI'm guessing teenaged Mark always left a porn site saying "aw shucks, I'm not 18 yet, it tells me here I can't enter.".
- prostoalex 9y agoWhat kind of safeguards would you introduce? At the very start of Facebook platform the API would anonymize the user's email address, the app would get an app-specific hash, e.g. abcdefg-app123456@facebook.net It was a working email address with Facebook handling the forwarding. This proved futile as the very first thing that apps then did was to ask users for their real email address.
- bobthepanda 9y agoThen make "no requests for users email" part of the terms of using the API?
- asah 9y agoWhich they flagrantly violated...
- prostoalex 9y agoBut there are many legitimate use cases of sharing email addresses. Just scratching the surface, * someone used Facebook Connect to login to NYTimes Web site, curious about their Food & Recipes newsletter, wants to sign up * someone logging into e-commerce shop through Facebook Connect, making a purchase and then deciding that yes, they would like to track and manage their order on the retailer's Web site, and they will even sign up for an account with retailer to do that
- bobthepanda 9y agoWhich is fine. But most apps that I remember of this type (back when I used Facebook apps) would ask you for it on landing. Nothing ever has to be black-and-white.
- MertsA 9y agoNeither one of those use cases would necessitate using the user's real email address instead of the forwarding address that Facebook provided.
- 9y ago
- deleted 9y ago[deleted]
- dustingetz 9y ago> They knew it was illegal but put all the incentives for companies not to follow the rules. Offtopic but i cant help it. You get what you measure. Which is why economies that only measure profit optimize for nothing but profit. When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit, we should not be surprised that companies like Facebook do awful things. the GAAP has all but ensured that this happens. You want companies to have values? Then measure values! (alongside profit, not inspite of) https://en.wikipedia.org/wiki/Generally_Accepted_Accounting_Principles_(United_States) https://en.wikipedia.org/wiki/Generally_Accepted_Accounting_...
- JumpCrisscross 9y ago> When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit We don't need accountants to measure legality. That's what we have law enforcement and courts for. Investors care about profits; behaving illegally should hurt profits. Deputising a multi-billion dollar company's thousands of shareholders as its moral police is an absurd proposal.
- adamc 9y agoLaw enforcement and courts aren't funded in a way that makes that effective.
- JumpCrisscross 9y ago> Law enforcement and courts aren't funded in a way that makes that effective In the 1930s, the Congress realized that financial crimes were (a) prevalent, (b) serious and (c) difficult to investigate and prosecute. So it created the SEC [1]. Its specialists, with the budget, focus and mandate to pursue securities-related violations, have been effective (relative to pre-1930s finance). Regulators make rules. They also enforce them. We have no top cop for technology. The costs of that gap are becoming apparent.
- 9y ago
- adrr 9y ago2011 FTC hearings were about the exact same topic. You can't trust the 3rd party app developers. Back then it was social game developers selling user profile data to Rapleaf and other data brokers.
- nickysielicki 9y ago>The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. Why would they intend for it to happen? They didn't make any money off of this exfiltration, CA paid people via Mechanical Turk to install the application so that they could mine their data. Facebook didn't get a dime. In fact, they have a monetary interest in preventing this, because their data is worth something and these guys just got it from free usage of their API. So the insinuation that Facebook wanted this to happen, or looked away because it benefited them, makes zero sense. What kind of safeguards are you imagining? How do you have 3rd parties interface with Facebook without letting those applications reason about the information within a Facebook account? Tinder is valued at over a billion dollars and it's not possible to use it without a Facebook account-- should Facebook shut that down and ban the entire concept of 3rd party Facebook interaction? I do not understand the anger. They did nothing wrong. I can't believe that people are legitimately arguing that users shouldn't have a right to expose their information to apps.
- nugi 9y agoThey sold the data by proxy by knowingly letting the 3rd parties syphon the data. Why else would they be at CA when the cops showed up? Are you being intentionally obtuse?
- nickysielicki 9y agoThey were at CA because it's a multibillion dollar company and that means that they have people who keep tabs on stories that result in millions of dollars of lost stock value. It's not because they were in cahoots with CA, they were covering their bases. Are you honestly suggesting that CA wrote Facebook a check?
- underwater 9y agoThey let third parties access data but where are you getting the idea that they “sold the data by proxy”? There is no evidence they wanted the data to be stolen, or that they willingly allowed it.
- gordon_freeman 9y agoSo FB opened up their platform to 3rd party Devs in 2007 and this CA incident happened in 2013. FB changed their policy of not allowing broad data access to these Devs in 2014. So my question is: Why they admit that they'd audit the pre-2014 apps now when NYT and Guardian/Observer broke the news? And what policy is in place now that makes sure that these 3rd party Devs won't sell whatever info they do collect as per post-2014 policy? I am not satisfied with what Mark said just now. We need more answers.
- d4l3k 9y agoThey probably assumed that if devs couldn't access the data anymore it wouldn't be a problem in the future. > We'll require developers to not only get approval but also sign a contract in order to ask anyone for access to their posts or other private data. Sounds like they'll make the developer agreement legally binding so they can take legal action for violating the ToS.
- cinquemb 9y agoI kind of doubt that this action will stop all of the devs that check in their api keys into public repos everyday that are then used by other parties, but at least it will allow facebook to cover their ass a bit more.
- downandout 9y agoWhy they admit that they'd audit the pre-2014 apps now when NYT and Guardian/Observer broke the news? I don't know, they should have done it when Obama committed even worse Facebook privacy violations back in 2008/2012. I guess when you have Chris Hughes working for your campaign, it's easier to keep things under wraps and spin what does become public as a positive. It was only after Trump won that this kind of use of the data became an issue for the press. The Obama-era articles on this subject actually celebrated the use of these techniques almost universally. And what policy is in place now that makes sure that these 3rd party Devs won't sell whatever info they do collect as per post-2014 policy? You're not understanding what he said. The Facebook platform was completely neutered in 2014. They broke my (and most other developers') apps by disabling access to almost any friend information, even things as mundane as public profile pictures. In fact, these days, more information can be gleaned by scraping publicly available data from Facebook than can be obtained through the API. The post-2014 policy has zero chance of any friend data being sold/abused/whatever, because apps simply don't have access to the data anymore.
- mcintyre1994 9y agoIt's in Facebook's benefit for advertisers to gather all that data, because the only way they can actually use it to make money is by advertising to the users on Facebook. I find it incredibly hard to believe that this thought never crossed anybody's mind.
- shell_oil_101 9y ago"We're sorry!" I agree, I don't think anyone is buying it.
- nappy-doo 9y agoHave you ever looked at FB's ad platform? You don't download everyone's data and target the campaign yourself. You target, "18-25 males in these zip codes who like the yankees". I don't see how you go from that platform (hosted and controlled by facebook) to something else.
- kbenson 9y agoAt least at one point, you could. See the example of the person who pranked his roommate through very specifically targeted facebook ads. [1] It's even mentioned in that article how to get around the fix they put in so you couldn't target a group of less than 20 people. I'm not sure if this particular method still works, but let's take a step back and think before we make claims about what is and is not possible in a complex system with lots features and knobs to twiddle. Whether this was an emergent feature from other features of the system or a specifically desired and designed behavior, at least at one point Facebook allowed very fine grained targeting. 1: http://ghostinfluence.com/the-ultimate-retaliation-pranking-my-roommate-with-targeted-facebook-ads/ http://ghostinfluence.com/the-ultimate-retaliation-pranking-...
- seandougall 9y agoThat still doesn't really sound like the same thing. Highly specific targeting based on PII you already have is a very different prospect than harvesting PII for tens of millions of strangers.
- nappy-doo 9y agoWRT to FB's knowledge of this happening: Your assuming bad intent is no worse than FB's assuming good intent. Otherwise, one of the more reasonable FB comments on HN.
- asfhakjfhakjfh1 9y agowith respect to to
- downandout 9y agoThey knew it was illegal What, exactly, are you claiming about this that was “illegal”? When you singup for Facebook, you agree that anything you post might be shared with others on the platform. The Facebook developer platform became so limited in 2014 that most developers (including me) left. There was no point in developing apps for the social graph that had no ability to be use the social graph. But even prior to that, the sharing of this information with apps, even those authorized by a friend, wasn’t “illegal”. You agreed to it when you signed up for Facebook and voluntarily handed them your information. Even the idea that developers were supposed to delete the information they had before was just a civil agreement between the company and themselves - it wasn't illegal. Facebook can certainly sue them over it, but there are no violations of the law occurring here. So what about this whole situation is "illegal"?
- Symbiote 9y agoIt's not clear to me how much, if any, of the work was done in the United Kingdom or by British companies. If the are companies in the UK, or people working in the UK, the sharing or retention of data may have been illegal under British law. https://en.wikipedia.org/wiki/Data_Protection_Act_1998 https://en.wikipedia.org/wiki/Data_Protection_Act_1998
- branchless 9y agoThe UK won't do much: http://www.bellacaledonia.org.uk/2018/03/20/scl-a-very-british-coup/ http://www.bellacaledonia.org.uk/2018/03/20/scl-a-very-briti...
- makmanalp 9y ago> Even the idea that developers were supposed to delete the information they had before was just a civil agreement between the company and themselves - it wasn't illegal. Facebook can certainly sue them over it, but there are no violations of the law occurring here Perhaps not in the US, but I'd like to point out that it's not the same way everywhere: I think the EU is moving towards another direction. There's a whole thing around whether a company has a responsibility to do due diligence around preserving the personal information of its users. Just because you gave them your data doesn't always mean that they can now do whatever they want with it (e.g. give access to detailed information in large amounts to third parties). Even if you sign an agreement, in many jurisdictions there are certain rights a company can't just make you sign away.
- pelario 9y ago> That's the only hole in his statement. What about the punishment to Christopher Wylie, by closing/suspending his accounts in facebook, whatsapp, etc ?
- SolarNet 9y ago> Last week, we learned from The Guardian, The New York Times and Channel 4 that Cambridge Analytica may not have deleted the data as they had certified. We immediately banned them from using any of our services. He was part of Cambridge Analytica at the time. So they suspended his account along with the rest of them I suppose.
- dragonwriter 9y ago> What about the punishment to Christopher Wylie, by closing/suspending his accounts in facebook, whatsapp, etc ? The Christopher Wylie that, by his own account, was a knowing, active, and key participant in the things they punished CA for, and in fact claims to be the one who came up with the concept for it? What about it?
- IncRnd 9y agoOne of the key points of the Z post is that for an app to be able to request permissions from users, the app creator will need to sign a contract and be subject to an audit. This appears to solve the issue of having wide permissions, but it does not do so. In reality, this is an attempt at transferring facebook's risk to shady app developers, while the overall lifecycle for the app won't change. In essence, this is a do-nothing from the standpoint of app developers who have requested additional permissions. Any app developer who is told they need to undergo an audit, due to transcribing the entire social network, can simply say no and get their account banned. It will likely have no effect, as the account will almost certainly have already been suspended in such a spot.
- sunir 9y agoFacebook did not intend for this to happen. That is such nonsense. They intended for cool apps to go viral across their social graph so Facebook could be a “social utility” and the operating system of human relationships and other airy fantasies they spouted in 2012, 2013, 2014 when they built the app platform. Their hopes of a beautiful future of joy and freedom were dashed when they discovered humans are capable of garbage behaviour. Ironically they believed the walled garden of Facebook would clean up the cesspool of blog comments. Oops.
- Jayakumark 9y agoWhy can’t they hold on the data inside Facebook and ask developers to come in a VPN to a VM or Remote Desktop (which gets recorded always ) and then use analytical tools installed on it , to work on it with no internet access in a DMZ . By this way they can record everything the developer is doing with data and the worst case he can do is take screenshot. By this way no data goes out of their hands
- darepublic 9y agoSo are you cheering for more regulations