27 ms·
Facebook Is Giving Advertisers Access To Your Shadow Contact Information
- tomlock 8y agoI'm surprised people didn't know this... this has been happening for at least 4 years through custom audiences. An advertiser can upload a list of mobile numbers or email addresses to target people.
- lmedinas 8y agoActually this should be an act of "good faith" where you are adding a layer of security to your account and not about making even more harm to your account.
- senectus1 8y agohttps://www.gizmodo.com.au/2018/09/facebook-is-giving-advertisers-access-to-your-shadow-contact-information/ https://www.gizmodo.com.au/2018/09/facebook-is-giving-advert...
- hnzix 8y agoThe reason I never give fb my mobile is if you use a pseudonym account, it will suggest your profile as a friend to anyone who has your mobile in their phone contact list (eg ex-partners, stalkers, employers, drug dealers). Found that one out the hard way. I know Zuck wants me to preemptively upload my nudes, but still.
- black_puppydog 8y agoLucky you already have your account. These days you can sign up for one without a phone number, but then you flat-out can't sign in without giving one.
- lysp 8y agoYou can even do a search by mobile number, by typing a mobile number into the search without pressing enter. Depending on the owner's security settings, Facebook will often suggest the profile of the person in the type-aheaded search results.
- muglug 8y agoI believe they removed this feature a couple of months ago.
- rickdg 8y agoFB's terms of service do not allow pseudonym accounts.
- paulie_a 8y agoDo people honestly give a shit about terms of service?
- jkaplowitz 8y agoYes. Especially ones with broad arbitration clauses, and double especially ones where your access to the courts is determined by whether you opt out within a short time period after agreeing to them. These are frighteningly common, typically enforceable in the US even for consumers, and typically enforceable in most countries for even small business customers (though rarely for consumers in much of Canada and Europe if the vendor has enough ties to the area for local consumer protection law to apply and you win the race to the courthouse).
- ageitgey 8y agoThis is basically how FBI Director Comey's secret Instagram account (and thus Twitter account) was unmasked. But it was even worse - you are suggested to 3rd party people who just follow the people who know you: https://gizmodo.com/this-is-almost-certainly-james-comey-s-twitter-account-1793843641 https://gizmodo.com/this-is-almost-certainly-james-comey-s-t...
- ninit3 8y agoYep, something similar I discovered recently that if you sign up to Instagram with somebody's email that they use on Facebook then within a day or two you'll start to see all of their friends from Facebook whom are also on Instagram in your recommended follows. All of this happens without email verification..
- dvfjsdhgfv 8y ago> All of this happens without email verification This has very interesting consequences...
- baybal2 8y agoWhoa... so it was around in the open since around 2013, and still not fixed? 0_0
- pishpash 8y agoAlmost every shop does this, no verification before use. ffs, at least provide a "report not mine" function.
- jkaplowitz 8y agoI've only ever seen a "report not mine" function from Google. Where else have you seen it? I am not on FB/LinkedIn/most similar ones, so I may be missing examples.
- 8y ago
- denzil_correa 8y ago> The reason I never give fb my mobile Here's the issue with it. You might not give it but your friends would. Therefore, this strategy is pretty useless as network effects kick in.
- tumetab1 8y agoTIP which I discovered by accident: create a bogus account with your phone number. Facebook will remove the phone number from your account when you do that. You can also use that to check who are your friend who gave FB your phone number.
- denzil_correa 8y ago> You can also use that to check who are your friend who gave FB your phone number. Can you explain further how this will work?
- ashwinikd 8y agoProbably by suggesting users who have your number as friends.
- deleted 8y ago[deleted]
- 0x262d 8y agothis is an interesting idea but probably one already-implemented feature from being circumvented
- unquietcode 8y agoFacebook gonna Facebook. It's long past time to consider regulation of an ethically bankrupt corporation.
- Symbiote 8y ago"four months ago" they stopped requiring it for 2FA, that's the time GDPR came in. I wonder if Facebook acts differently for European users?
- everdev 8y agoWhy have costly government regulation when users can just quit? Plenty of other online and offline ways to connect with the people in your life.
- lumberjack 8y agoUsers cannot "just quit". Facebook probably has a profile for my grandma who never touched a PC in her whole life.
- everdev 8y agoMany people can't quit because they are addicted, but there is an option to permanently delete your account and it takes about 5min. I'm not aware of Facebook creating profiles for people that haven't signed up for their service. If so, that should definitely be illegal. The government should have bigger fish to fry than trying to regulate the distribution of information that you have and continue to willingly provide to a company. If you don't like it, sure government could jump in and make Facebook just how you like it, or you could delete the info you don't want them to have. The later sounds easier on everyone.
- epicide 8y agoWhy have costly government regulation when people can just not breathe polluted air? There are some things users/people did not sign up for and cannot (reasonably) opt out of that still harm them. This is what regulations are for.
- jarfil 8y agoPhone numbers were not a secure 2FA anyway, and I've been using the TOTP alternative since it's been available... but I don't really see a problem with them using whatever to show "more relevant ads", if you don't want ads just use an ad blocker.
- cecja 8y agoCan you link me the Ad Blocker for text messages?
- hjek 8y agoIf you're running android, it has a word-based spam-filter[0]. But it does look like phone number blocking is a more common solution. [0]: https://www.quora.com/Which-is-the-best-app-in-Android-for-blocking-text-messages?share=1 https://www.quora.com/Which-is-the-best-app-in-Android-for-b...
- xg15 8y agoWhat if the more relevant ads are robocalls like in this case?
- lozaning 8y agoWho is still answering phone calls on their cell from numbers not in their contact book? If you call me and you're not in my phone my phones just dumps you direct to voicemail. Not excuse this behavior in the least, but robo calls in general are a solved problem for me.
- Broken_Hippo 8y agoThe answer is many folks depending on lifestyle. But more importantly, increased robocalls seriously means more life interruptions. Work nights? Sleeping while sick? That phone still rings, and there are many reasons to leave the sound on. Direct to voicemail simply doesn't really solve all the issues.
- anonytrary 8y ago"Give me as much service as you can while keeping me as far off the grid as possible" is a skill that is sorely lacking in this market. I don't have this problem with weed dealers, but I have this problem with information dealers. Internet companies could seriously learn a thing or two from the black market on how you treat your customers.
- tanto 8y agoDoes your weed dealer provide the service for free? If you want to be treated as a $$$ paying customer start paying. Problem with social networks and $$$ is that network effects will not come into effect as not everyone will be willing to pay. There are actually ethical information dealers but they require you to pay them as you are paying your weed dealer.
- tokyodude 8y agoI'm probably wrong but I feel like there's a market for an ethical advertiser that does no tracking and placed ads by content only. is that impossible? it was reality until the 90s
- Insanity 8y agoI think (but might be wrong) that duckduckgo works like that. They show ads based on search the content rather than via tracking.
- Isn0gud 8y agoI mean, if you give a $$$ option instead of giving up data than you removed the intended targets of most ads out of your advertising pool.
- fouric 8y agoThe ultimate goal is to make money, not serve ads.
- anilakar 8y agoThis is exactly the kind of abuse that GDPR is designed to curtail.
- rikkus 8y agoYes using information for a purpose other than it was collected for. Hopefully this means in Europe we won’t see this spam.
- afandian 8y agoHopefully? Hopefully this means we will see facebook employees faceing criminal charges!
- type0 8y agoIf it's a corporate decision they won't be liable. "Similarly, individual employees, managers, and directors are liable for their own malfeasance or lawbreaking while acting on behalf of the corporation, but are not generally liable for the corporation's actions." from https://en.wikipedia.org/wiki/Corporate_personhood#Case_law_in_the_United_States https://en.wikipedia.org/wiki/Corporate_personhood#Case_law_... I don't think GDPR has any tooth in this.
- afandian 8y agoMaybe not. But you can hope about the future. Laws are created because of malfeasance. And they can change.
- baq 8y agoi'll be ok-ish with a $5B fine or whatever makes sense. it'll be cheaper then to hold the employees liable.
- pimmen 8y agoIt's a corporate decision made way above the heads of the developers, for sure. But, there has been very notable occasions in history when the US and Europe wasn't content with "I was just following orders" as a defense. And, during at least one of those periods in history, the US was not content with superiors claiming ignorance of any wrong doing either.
- ummonk 8y agoAs a security engineer, I cannot overstate just how horrible this is. Phone numbers might not be an ideal 2nd factor for authentication, but to punish users for setting up 2FA by using the provided phone number for ad targetting is incredibly unethical.
- qrbLPHiKpiux 8y agoI never heard of this company when I did a monitor.firefox.com search of my work address. Exactis Breach date:June 1, 2018 Compromised accounts:131,577,763
- tumetab1 8y agohttps://haveibeenpwned.com/PwnedWebsites https://haveibeenpwned.com/PwnedWebsites > Compromised data: Credit status information, Dates of birth, Education levels, Email addresses, Ethnicities, Family structure, Financial investments, Genders, Home ownership statuses, Income levels, IP addresses, Marital statuses, Names, Net worths, Occupations, Personal interests, Phone numbers, Physical addresses, Religions, Spoken languages
- cmroanirgo 8y agoI agree with your sentiment. But, as someone who understands that not all people and companies use the same moral set as myself, this is why I've never set up 2fa using a phone. Why should I give some company my phone number? Increasingly it's become a single point of metadata to uniquely describe myself (just as my email addresses have).
- otachack 8y agoYou don't have to but it's the most user-friendly, although flawed, method of enabling 2FA. They could have easily used a software token but that requires non-tech savvy users to download a 3rd party authentication app, as well as understand the basic usage. Why do that when users can simply get a text sent on a method they most likely have?
- jsjohnst 8y ago
- magicalhippo 8y agoIt's also entirely what I expected, hence why I haven't given Facebook my number. Not sure why anyone is surprised by this to be honest.
- josho 8y agoIf I recall correctly creating a Facebook account today requires a phone number. So, consider yourself lucky that you have the option to protect that bit of yourself.
- asaph 8y agoFacebook probably knows your phone number anyway because your friends have likely shared their phone's contacts with Facebook.
- ddeck 8y agoOr if you use Whatsapp. Their privacy policy makes this pretty clear: As part of the Facebook family of companies, WhatsApp receives information from, and shares information with, this family of companies. We may use the information we receive from them, and they may use the information we share with them, to help operate, provide, improve, understand, customize, support, and market our Services and their offerings. This includes helping improve infrastructure and delivery systems, understanding how our Services or theirs are used, securing systems, and fighting spam, abuse, or infringement activities. Facebook and the other companies in the Facebook family also may use information from us to improve your experiences within their services such as making product suggestions (for example, of friends or connections, or of interesting content) and showing relevant offers and ads. Bizarrely, whilst general everywhere else, the policy specifically calls out banner ads to make it clear that they won't use them until they do, at which point they'll stop saying they don't: No Third-Party Banner Ads. We do not allow third-party banner ads on WhatsApp. We have no intention to introduce them, but if we ever do, we will update this policy. https://www.whatsapp.com/legal/#privacy-policy-affiliated-companies https://www.whatsapp.com/legal/#privacy-policy-affiliated-co...
- 8y ago
- mojuba 8y agoAnother personal observation. I have an Instagram account that I thought was fully incognito. I never connected it to any other social account, I used a separate email for authentication etc. Just days after the Instagram founders left Facebook I started receiving friend suggestion on my IG that were very very relevant. Those were people I knew in real life and mostly connected via Facebook but not only. I shouldn't be surprized as being connected to the Internet by itself is an end to your privacy but still, this was probably the spookiest invasion into my privacy so far. Bye-bye Instagram.
- oedmarap 8y agoWhen I was in another country on a business trip I bought a temporary local SIM, originally valid for two weeks but I've kept it active as I travel there often. I used that foreign number to create my Instagram account and I've gotten the benefit of only being shown suggested accounts from locals from that country (zero people I know). Same goes for ads as well. Currently I keep it on roaming and actually use it to verify other online services that may stubbornly require SMS. Might be worth a try for those of you looking to pseudo-opt-out of phone number tracking & recommendations on social media services that do this, if you can get your hands on one.
- bilbo0s 8y agoJust as a warning to anyone who might try this, it won't work. (At least not without a massive amount of opsec effort expended on your side.) I'll give you an example of why it might not work. Since your phone has roaming, you happen to have it with you at work, or at a party, or at the library, or anywhere really. If even a single acquaintance of yours is "nearby", the information is leaked. If acquaintances seem to always be "nearby", children, wives, husbands, siblings, your info is DEFINITELY leaked. If anyone is going to try to use this strategy for anything which might result in the loss of your livelihood, (eg - porn), please realize there are many, many, many more precautions you will have to take than are listed in oedfmarap's comment. If you just do what you see in that comment, you could find yourself without a job somewhere down the line.
- 8y ago
- kerng 8y agoAgain? Weren't they called out on this about half a year ago already? Did they continue doing this? How irresponsible and total lack of any ethical standard. Its horrible but mostly just sad that users are just a commodity to make profit. So let's trick them to sign up for 2FA to pretend they have more security and then we can send them nice little ads. What a bad company this has become.
- usrusr 8y agoThe other really stupid thing, besides generally hurting the adoption of 2FA forever, is that they probably did it for hardly more than scraps, compared to their conventional add targeting capabilities. Maybe I am completely wrong about this, but I'm pretty convinced that almost all of the ad spending for that feature would have reached Facebook's coffers anyways had it not been available.
- neotek 8y agoAt Facebook's scale even the scraps can be worth millions. And the sad truth is that the vast majority of people will not be deterred by, be aware of, or even understand the fact that Facebook is abusing their phone number in this way, so as far as Facebook is concerned it's a small bump in the long road to increased profitability.
- usrusr 8y ago> At Facebook's scale even the scraps can be worth millions. Sure, but the same is true about negative headlines, the effect is just more difficult to quantify. Maybe it's a general world view problem within Facebook, but usually these things are the result of one overly ambitious person or group optimizing the singular bonus metric of their own little fiefdom at the cost of corporation-wide commons. Big organizations need to be extremely vigilant in their defense against internal foes who won't blink an eye costing the company billions for a gain of millions add long as the latter will be attributed to them while the former won't.
- philipodonnell 8y ago"Millions" is still scraps to a company with the scale of Facebook
- blake_himself 8y ago> An ever increasing craving for an ever diminishing pleasure is the formula. It is more certain; and it's better style. To get the man's soul and give him nothing in return -that is what really gladdens our Father's(0) heart. - C.S. Lewis, senior demon to a junior, 'Screwtape Letters'. (0) Satan
- tajen 8y agoI didn’t give facebook my phone, my email has timed out (and facebook knows it, it deactivated my email) and I forgot my password, more or less intentionally. So the only thing tying me to Facebook is my browser cookie. I have to say, I’m surprised I’ve been able to keep this account open for years in this state, it’s almost as if they really wanted me to stay. But it’s possible to keep a facebook account alive with no accurate contact information.
- a_imho 8y agoWhen people suggested phone 2fa was a data collection scheme they were hushed and called tinfoils.
- Freak_NL 8y agoPeople still do that when you point out that using a phone number as a required identifier (WhatsApp, Signal, etc.) gives every 'free' service a near perfect unique identifier that's the same for all services used by that person. Ideal for cross-service collation. Who wants a social security number when you've got someone's phone number?
- baarkerlounger 8y agoExcept that a phone number is as quickly and easily disposable and changeable as an email address or any other identifier?
- probably_wrong 8y agoWhile I share the sentiment, I think I should be fair to HN: according to a quick search I've just performed, I brought up the topic 4 times in comments over 3 years, and those comments have scores of 7, -4, 16, and 3 [1][2][3][4]. So saying that I was "hushed and called tinfoil" would not be fair to HN. [1] https://news.ycombinator.com/item?id=17515029 https://news.ycombinator.com/item?id=17515029 [2] https://news.ycombinator.com/item?id=14105696 https://news.ycombinator.com/item?id=14105696 [3] https://news.ycombinator.com/item?id=12782158 https://news.ycombinator.com/item?id=12782158 [4] https://news.ycombinator.com/item?id=9804876 https://news.ycombinator.com/item?id=9804876
- Spearchucker 8y agoAll my personal details on Facebook are (and have always been) false. My phone number is the number of a hotel in Monte Carlo. When Facebook nagged me to give them my mobile number for 2fa I ignored them. My friends thought I was crazy. I know it's not exactly gracious of me but feeling very self righteous right about now.
- FilterSweep 8y agoYour friends also gave Facebook your actual phone number too.... Facebook app abuses your phones internal Contacts API. Effectively, you are linked and your main Facebook account is known to be a pseudonym already
- Loughla 8y agoSo you're stuffing it full of false data, but still connected to people who aren't stuffing it full of false data? That seems like a lot of effort for no real payoff.
- epicide 8y agoThis is basically the only reason I don't "delete" my Facebook account. I have so many family members and friends that I cannot realistically prevent putting pictures and the like about me on Facebook. At least I can see some of what Facebook has about me instead of none.
- happybuy 8y agoThis should have been obvious for anyone who is paying attention. When data collection and advertising companies such as Facebook (and Google) push a feature actually beneficial to users so aggressively – such as 2FA – during the sign-up process; you'd have to be naive to think it's for your benefit. It's not 2007 any more... tech savvy users should know better than to trust such organisations with any scrap of additional personal information than absolutely necessary.
- type0 8y agoTech savvy or not, really there's no way any current fb user would be concerned with it nowdays and they will continue to rat you out to the fb apparatus. You know how they say "ignorance is a bliss".
- deleted 8y ago[deleted]
- anoplus 8y agoSadly, I believe Facebook will truly respect their users in the face of backlash.
- yesenadam 8y agoLately FB says when I go on there "Add a profile pic so people know who you are". Huh? I've always one.
- pndy 8y agoHa! I'm being constantly nagged whenever I visit fb (to see if those who can't live anymore without it, didn't want something etc.) to update my details - which I removed long ago; among that, they sometimes "suggest" updating new profile pic, which I haven't change since end of 2014 - when I stopped wasting time there
- denzil_correa 8y agoThe worst part about these updates is that you have two options - "Yes" and "Not Now". The "No" option doesn't exist in their dictionary.
- ddebernardy 8y agoThe url should point to the Gizmodo article; not the sensationalizing tweet. https://gizmodo.com/facebook-is-giving-advertisers-access-to-your-shadow-co-1828476051 https://gizmodo.com/facebook-is-giving-advertisers-access-to... The actual story is FB enriching your profile with shadow contact information about you when you or third parties provide it with details it wasn't aware about yet. For instance when a friend of yours has your landline number in their address book and gives FB access to the latter; or when an advertiser provides FB with the same as part of targeting an ad campaign.
- B-Con 8y agoIs this any surprise? Just a few hours ago the Acton article on the front page[0] talked about them doing this in WhatsApp: > Later he learned that elsewhere in Facebook, there were “plans and technologies to blend data.” Specifically, Facebook could use the 128-bit string of numbers assigned to each phone as a kind of bridge between accounts. The other method was phone-number matching, or pinpointing Facebook accounts with phone numbers and matching them to WhatsApp accounts with the same phone number. > Within 18 months, a new WhatsApp terms of service linked the accounts and made Acton look like a liar. Companies like this, and Facebook in particular, are desperate to connect identities. Phone numbers are an incredibly useful way to do so. Most people only have a couple of them, their re-use rate is slow, they get entered into forms all over the place, and they're usually valid (because they were provided as a primary method of contact). In this case advertisers have an identity (and phone number), Facebook wants to match on that value. They're going to do it any way they can. It may not be ethical, but the carrot is right there and it's naive to think you can give them your identifying number and they're going to turn a blind eye to it. [0] https://news.ycombinator.com/item?id=18074690 https://news.ycombinator.com/item?id=18074690
- close04 8y agoWasn't one of the conditions to get the deal approved by EU regulators to NOT share any data between services? [0] Did they just restart it because they found reprieve or simply decided to ignore the regulation? Edit. Also this [1]. Does GDPR suddenly open the door for sharing this data "legitimately"? [0] https://www.ft.com/content/951d650e-abf5-11e6-9cb3-bb8207902122 https://www.ft.com/content/951d650e-abf5-11e6-9cb3-bb8207902... [1] https://www.theguardian.com/technology/2018/mar/14/whatsapp-sharing-user-data-facebook-illegal-ico-gdpr https://www.theguardian.com/technology/2018/mar/14/whatsapp-...
- macpete 8y agoThat‘s what happens when you give a dog a bone
- vezycash 8y agoOn android, if messenger handles SMS, FB knows how much you have in the bank and your transactions.
- saiya-jin 8y agohaving any FB-developed app on your phone is a serious mistake in the first place
- CalRobert 8y agoIt's a mistake many people make just by buying a phone. I had an HTC M8 and liked it except that they made it absolutely impossible to remove FB until I flashed Lineage on to it.
- icebraining 8y agoHow so? Do you get your transactions by SMS??
- gruez 8y agomaybe not by default, but if you have transaction notifications delivered through SMS, it's possible
- tjoff 8y agoI guess EU users should be fine? GDPR is a masterpiece. I actually assume that they violate GDPR, but GDPR gives users a sliver of chance to fight back.
- newscracker 8y agoThe situation is such that this is what's expected of Facebook. It would be a shocker if Facebook didn't do this. Actually, it's quite surprising that it took so long to do this. Bottom line, Facebook will devalue you as a human and invade your privacy in any manner possible for as long as it can withstand legal pressures and get away with paltry fines. Obviously, all these measures are to provide users with a better experience. That's Facebook's DNA.
- anfilt 8y agoHonestly, I hate how many 2FA systems want you to use a phone number. There are other ways that are much better.
- snarfy 8y agoEverybody punts security issues from identification to the next guy. Eventually the only safeguard left between you and the bad guys is a minimum wage salesman working at the t-mobile counter. It's sad to know that all of your primary email addresses, with links to online shopping accounts with credit cards, bank accounts, etc, can all be accessed by spoofing your phone number.
- anfilt 8y agoI honestly wish sites would use client side certs or auth via a private key.
- tialaramex 8y agoClient side certs mean now every user has a verifiable identity. Maybe you're OK with Facebook knowing your full ID, but is it also OK to tell Grindr, Redtube and Amazon? Security Keys are better here. The security key can prove to a site that its the same one as before. "Before what?" Well that's up to the site. In most cases it's going to register one or more keys when you sign up to the site, and then check you still have one when logging in. This is completely useless for everything except the one thing it's intended for, a Second Factor during login.
- anfilt 8y agoYou can always generate a new key pair though. I don't necessarily mean a cert signed by a CA. More akin to use a key pair for SSH.
- qwerty456127 8y agoWait? Did somebody ever doubt this? I always believed collecting phone numbers for their marketing needs is exactly the reason why do any of the social networks ever introduce SMS auth.
- type0 8y agoOrwells final warning is chilling and beautiful, in a some kind of perverse metaphorical sense it's strangely relevant to the future of the Brave new world that we are "faced with": https://www.youtube.com/watch?v=SIoAX5bI6S0 https://www.youtube.com/watch?v=SIoAX5bI6S0 edit: typo
- subbz 8y agoFacebook (probably) using everything possible for ad targeting
- boraturant 8y agoAs an FB Marketing API developer, this has been available for several years . The way it works, advertisers can send their phone list to FB for ad targeting. However, phone hashes are sent, not clear ones. Personally, as long as the user has an opt-out and opt-in options, I don’t think ad targeting is necessarily an unethical pattern, the blurring lines of ads and recommendations would be actually a pattern that users might like. Would you rather use Netflix or Spotify without recommendation engine?
- oneeyedpigeon 8y agoSpeaking as someone who hasn't used facebook in years, I think it's awkward trying to compare it with netflix/spotify. The latter are narrowly-focussed, with a clear target for recommendvertising - i.e. I am viewing a film or listening to music, the case for suggesting another is pretty good, and useful. That's very different from, for example, recommending a product to me when I'm viewing my friends' photos.
- FabHK 8y agoAlso, one pays for Netflix, and there are no ads. They try to give you, the user/customer, a better experience, so that more users/customers sign up and pay. Needless to say, Facebook's goals and incentives are very different.
- whoknowsnobody 8y agoAnd you use Netflix to watch videos and Spotify to listen to Music, no problem in being offered other, personalised, videos and music. But on Facebook people go for socialising, and not to get personalised ads.
- hjek 8y agoI disagree. Blurring the lines between ads and recommendations is super creepy[0]. Anyway, I still upvoted your comment, because it's interesting to read what someone working at FB has to say on this. [0]: https://readwrite.com/2012/12/11/why-are-dead-people-liking-stuff-on-facebook/ https://readwrite.com/2012/12/11/why-are-dead-people-liking-... EDIT: Images seem to be missing from the original link, so here is an archived version: https://web.archive.org/web/https://readwrite.com/2012/12/11/why-are-dead-people-liking-stuff-on-facebook/ https://web.archive.org/web/https://readwrite.com/2012/12/11...
- psykus 8y agoYou'll notice whenever you get the banner to add a phone number for 2FA, it says "add your phone number for additional security and more"
- daemin 8y agoI also hate how all the social media apps want to grab your address book to "see who else you know on here". They all do it.
- uptown 8y agoAnd even if you don't do it ... chances are a friend of your already has so your contact info is already burned.
- JetSpiegel 8y agoAt least on recent Android you can deny it. The UI doesn't support it and you need to resort to hacks such as https://whatsappwithoutcontact.com/ https://whatsappwithoutcontact.com/
- daemin 8y agoFor WhatsApp in its initial incarnation I did not mind allowing it access to my contacts since the phone number was the way it identified people and since it was universal. With these upcoming incarnations I'm not sure I want to use it, and I'll be looking for a simple IM application which just charges a simple fee for service.
- EZ-E 8y agoDoes this affects Facebook's "Account Kit"? (toolkit that provides login/register by SMS to third party apps)
- _Microft 8y agoI had my mobile phone-number appear pre-filled in an add-your-number-to-your-account prompt on Facebook's mobile website while I never provided it in any way to Facebook myself (in the meaning of: neither added it to my account nor mentioned it ever on the website; I never used their apps at all either) . They had farmed it from one of my contacts adressbook obviously. Not surprising that they'd do that but still a disconcerting feeling to actually see it happen.
- philipodonnell 8y agoTBF that might ave been your browser doing the pre-filling.
- akerro 8y agoI'm in a wired situation, I opened my facebook account with a phone number, not email, my username is phone number I had ~5 years ago. I lost the sim card ~4.5 years ago, so since then I still use the same login. Every time I login facebook asks me to update my phone number because it's no longer valid, so they probably know it's been recycled and someone else owns the number. Another thing... a year ago, I got a new sim card with new phone number again (I change my number every 1-2 years), and since that time I can't use this phone number to setup 2FA because... someone else on Facebook has this number in their profile!
- batuhanicoz 8y agoIt's admittedly off topic but if you don't mind me asking, what are the reasons for you to change your number every 1-2 years? Doesn't that complicate things with past clients, old friends and maybe even with family? I changed my number 3 years ago but I still keep my old number active because it occasionally gets calls or text from past contacts.
- akerro 8y agoI don't use phones for communication, I much more relay on emails. My friend and family know how to contact me and they know that my phone number might stop working any time. I don't give phone numbers to clients, as I don't want to be disturbed when they want something, instead I respond to emails when I have time.
- tempodox 8y agoIs anybody still surprised that everything FB touches ends up being an unethical swamp?
- throwaway122378 8y agoOne would think they’ve learned and will stop. On the other hand, they’ve been getting away with this type of behaviour so WHY STOP
- pard68 8y agoI work in sysops. Our user base is larger 40+ year olds. It has taken us nearly two years to convince our users to use a phone or email for password resets. We are now moving to 2fa and this sort of stuff only hurts the industry.
- pilif 8y agoDidn't we have this discussion already earlier this year and they told us it was an unfortunate bug and that it has been fixed? Yes. Yes. We did: https://www.theverge.com/2018/2/16/17022162/facebook-two-factor-authentication-sms-notifications-security-bug https://www.theverge.com/2018/2/16/17022162/facebook-two-fac...
- darthoctopus 8y agonot relevant
- throwawaymanbot 8y agoYes.. yes it is relevant, its shows how Facebook morally and ethically operates. Who are you to tell anyone what is or what is not relevant in a public forum. I hope you are not this overbearing in real life?
- pilif 8y agoI think it is relevant: back in february they made us believe that them using 2FA phone numbers for marketing purposes was a bug and today we learn that them using 2FA phone numbers for marketing purposes is a feature. So either they lied in February or they have changed their minds. Either way, I think there is value to bring this very similar discussion back to our minds.
- mellow-lake-day 8y agoThis is not a "Bug" but a "Feature" Some things don't change: Zuck: Yeah so if you ever need info about anyone at Harvard Zuck: Just ask. Zuck: I have over 4,000 emails, pictures, addresses, SNS [Redacted Friend's Name]: What? How'd you manage that one? Zuck: People just submitted it. Zuck: I don't know why. Zuck: They "trust me" Zuck: Dumb fucks.
- mtgx 8y agoGoogle has been pushing SMS 2FA a little more aggressively over the past couple of years, too. And I think Apple made it "easier to use SMS 2FA" in iOS 12 for the same reason. I also said before that this is exactly why Facebook wanted to "verify people's faces for security purposes", too. It just seemed so obvious to me that Facebook would use security as an excuse to get people to put their own 100% accurate face scans into Facebook. It's also because Facebook used the same excuse with the shadow tracking (it's for your own good!), which is as ridiculous as Google claiming Analytics is for website visitors' own good.
- matwood 8y ago> And I think Apple made it "easier to use SMS 2FA" in iOS 12 for the same reason. Wait. You think Apple is selling your phone number to advertisers?
- jeromegv 8y agoThat person is confusing different things. Apple is making it easier to use SMS 2FA in iOS 12 (automated copy paste) However Apple itself doesn’t use SMS for 2FA. As for Apple they had your phone number since the launch of the iPhone (!). Never needed 2FA to know it. And no, Apple isn’t selling your phone number.
- MrEfficiency 8y ago>Apple isn’t selling your phone number. Until they have bad iphone sales. Given Apple's less than stellar track record toward developers, employees, and customers, Apple will do things for Apple.
- arcticbull 8y agoNo dude, Apple has an excellent track record for privacy of customer data. They don't share anything with anyone else, intentionally. It's a walled-in garden. They have always, and continue to, view themselves as a hardware company. They make money on hardware sales. I mean look at their margins. Any such activity, if called out, may lower their hardware sales.
- spr1ted 8y agoPeople of multiple platforms dislike me for discrediting facebook. Simply talking about facts and what they could expect. They think they know it all. Some corps are good some are evil. People tend to forget that an evil person could also be your most trusted and reliable one. I work as a cyber security engineer and the things i have see flying by are crazy. The fact that information is sold without you4 knowledge is real. Its a dark world out there in disguise.
- da02 8y agoWhat are some crazy things you've seen?
- krageon 8y agoYou don't need his crazy stories, really. All you need to do is accept that Facebook isn't behaving exceptionally poorly, this is industry standard. Lo and behold - the entire sector is suddenly a cesspool of disrespect and money grabbing at the cost of your data, your privacy, anything they will be able to get away with. And they can get away with a lot, because you are not allowed to talk when you work anywhere. On pain of basically having your life ruined.
- inetknght 8y ago@da02 asked @spr1ted for some examples and you come in saying he's crazy and deny that examples are needed?
- da02 8y agoHe wasn't calling anyone crazy. The remark about "his crazy stories" was meant to be: "his stories on crazy (ie evil, corrupt) practices."
- ddeck 8y agoThey didn't call the gp crazy. They labelled the stories crazy, which is precisely how the poster described them: >things i have see flying by are crazy
- dangrover 8y agoInaccurate headline. Being targetable is different than them "giving access" to the information. The actual information is not shared with anyone.
- megous 8y agoThough you can probably gat at least an IP address, and if you create a nice looking fake e-shop with something your target may want, ... they may give you the rest. Phishing ads on FB may be less obvious than sending them a phishing link over e-mail.
- pishpash 8y agoCorrelation is information. People are slowly beginning to learn that basic information theoretic fact.
- WA 8y agoNo surprise. But what can one do? Btw this is definitely not GDPR-compliant, because consent isn’t given for using the phone number this way. I feel helpless, even though GDPR is in place.
- d--b 8y ago"Why did you never join facebook?" they used to ask me.
- ravenstine 8y agoI talked with the lead engineers from a company back in 2014, that shall remain nameless, that bought private profile data from Facebook, ran it through a bunch of algorithmic mumbo jumbo, and sold the aggregated data to marketing firms. They acted like this was really cool and awesome, much like the wide-eyed cultists. It was very creepy, and I backed away slowly even though this place was looking for more engineers. This kind of thing has been going on forever, and I've told people this. 99% of people don't actually care, though.
- avivo 8y agoAre you sure the "private profile data" wasn't aggregated before it was sold? Either way, selling private data is not something Facebook is actually known to do much (outside of misunderstandings by confused activists/journalists). If you contact me (info in profile) I'm very curious to understand more.
- pimmen 8y agoMaybe they bought it from someone violating the terms of setting up a Facebook app? I can't stress that this shit's illegal but I also can't stress how the Cambridge Analytica scandal showed that Facebook had almost no way of regulating this.
- tambourine_man 8y agoAt what point are people going to stop being surprised by news like this? That’s their business model, it’s what they do. If you use it, treat all data as public. Otherwise, don’t.
- css 8y ago> A spokesman also told us that users can opt out of this ad-based repurposing of their security digits by not using phone number based 2FA. That's one way to encourage people to use 2FA App, I guess.
- jandrese 8y agoNote however that to enable any other type of 2FA you first have to give them your phone number. You can delete your phone number afterward, but it's too late, they have seen everything.
- css 8y agoInteresting, thanks for letting me know. I don't have an account. I understand _why_ they require you to verify a phone number though, for the exact reason this article explains.
- jandrese 8y agoThe phone number isn't for your protection (it's actually really terrible for 2FA), it's for Facebook's protection. It's an anti-bot mechanism to require a unique phone number for each account, or no more than 5 accounts per number or so. They also refuse VoIP numbers for authentication.
- Mankrik 8y agoWell it won't matter once you change your number, but nobody should have to consciously think about doing that because the company you gave it to is using it for non-user account security purposes.
- dwighttk 8y agocan you actually "opt out" of that number being used or is the spokesperson just saying "we don't get your number via this method if you never give it to us via this method" I.e. if you switch from using a 2FA phone number to using the app do they stop using that phone number in your facebook profile? And your shadow profile?
- bigtyy 8y agoI believe that for us to wait for our governments to have to make regulations around our privacy and data is overly optimistic. Since companies like Google and FB exist on a global market the only way to truly bring about any real changes is to take away the very thing that they're looking for, and that's our use of said services. As someone that works daily with the general public trying to educate them on the safety and use of their technology, I often ask what their feelings are on the subject of companies like FB and Google selling their data to anyone willing to pay for it. The response I get the vast majority of the time is that they aren't doing anything illegal so why would they care? My response to that is "Would you let strangers walk into your house and dig through your personal items?". Every time i get the same response. "Of course not!" Well in my mind this is no different. I've read a lot of suggestions on what we feel government should do to regulate these things but we need face facts here. Society is addicted to many of these services. The simple solution would be to just STOP USING THEIR SERVICES. There are alternatives to both of those services. We now know that the data being collected and sold has the potential of revealing information that could be used maliciously against us, and we complain about what's going on. But then many people turn right around and continue to use the free service. I truly feel that this isn't totally an issue with government regulation as much as it an issue with the vast majority of its users being completely addicted to it. If we want to truly make any kind of impact we need to take personal responsibility for these things. And not only that, but as people that are knowledgeable on these topics we need to educate those non-technical people around us just what it is they're giving up when they click Accept on their EULA's and privacy agreements. As much as I dislike what FB and Google are doing at the end of the day they are counting on the fact that the general public won't spend even 30 seconds reading these agreements. If users care so little about the fact that they're making a legally binding agreement why would FB and Google? Most are so concerned with getting access to whatever service they're attempting to gain access to that they just click the accept button with little or no thought about what it is they're agreeing to. Government can't be expected to do our thinking for us.
- chadash 8y agoI'm not sure I understand what's going on here and the article doesn't really explain. What does it mean that they are "using your 2FA phone number"? It doesn't seem like they are texting ads to people. Are they just using the area code to determine where you live?
- NiekvdMaas 8y agoNo, they are using the phone number for "custom audience" targeting, where advertisers upload lists of phone numbers of users to target.
- idunno246 8y agoMultiple devices and linking them to a single person is an active area of development. Say your phone you’ve never signed into Facebook on safari, so Facebook won’t know what account it is. But you sign into some other service that you give it your phone. Since phone is pretty uniquely identifying, the two companies share info and thus Facebook knows that safari browser is you and can track everything you do to your account.
- p49k 8y agoAdvertisers can upload lists of phone numbers that represent people they want to see their ads. Facebook matches those up with your 2FA phone number to show you those ads.
- adpirz 8y agoWhat's facebook's boiling point? My guess is they'll respond, they'll no longer use 2FA #'s for ads, the damage will have been done, and 99% of the population won't know any of it occurred. We'll repeat this cycle when a fresh revelation occurs months from now, as facebook continues to test how much they can leverage for more ad revenue. But none of it is actually slowing FB down. Its biggest dip in value came from decelerating growth and spending to make FB more user-friendly, so there's a clear disconnect between shareholder incentives and those of the general populace. On top of that, most people remain unaware that FB owns both WhatsApp and IG, and while the departures of their top brass have made waves in these circles, it's not a concern for most. I don't see FB's dominance relenting any time soon, though I wish it would.
- secfirstmd 8y agoAs someone who has occasionally runs experiments with FB adverts for various types of business. I feel it's boiling point will be when people and organisations advertising on the platform really start to look deeply into the value for money they are getting on it. I can't tell you the amount of times I've seen organisations throw money at it in return for dubious clicks from markets they never targeted, bot like users and poor really ROI after advertising with it.
- gcb0 8y agofrom that egoistically lawless point of view, they will do better on each privacy violation that gets reported as it signal better return for the investment of advertisers.
- NiekvdMaas 8y agoAre you hinting that FB advertisers are throwing 50 billion (expected 2018 revenue) at ads that are poorly performing? Obviously that is not correct, the result of all this detailed targeting is campaigns that are performing very well for experienced marketeers.
- Eric_WVGG 8y ago
- ozim 8y agoI really liked it when people downvoted me when I wrote that Google pushing for 2FA phone numbers is doing it to get your phone number. (they don't use it for ads but lately I don't trust them, also 6mo ago I removed my FB) In the end I gave Goog even 2 of my numbers because I am scared as hell to lose access to my account. I got my Gmail account when it was in 'innvite only' so it is my main account for long time. Have to move out of it soon.
- megaman8 8y agoI think it's much worse when HTC places ads on your phone via bloatware apps that can't be uninstalled. That's absolutely vicious and hardly ever gets any press time. But, oh, facebook makes a minor little slip up and they even FIX the problem and everyone looses their heads over it.
- darpa_escapee 8y agoOne of the bloatware apps that I can't remove from my phone is Facebook :) Thanks, Sprint!
- saagarjha 8y agoCan't both things be bad?
- puppetmaster 8y agoIt should be already well understood that free services aren't free. To me the moral issue of the story is how Facebook isn't upfront about "the cost" of the services they provide. You want to use facebook to get in touch with friends? We all now know that you will be targeted by ads customized with every piece of information that you reveal (and some bits that you are not even aware you are revealing...) Assume that an extra layer of security is also costing you some privacy. Interesting dilemma...
- sincerely 8y agoAlso, it's one thing to willingly give up your own data in exchange for using Facebook etc for free, but often the data they collect could reasonably considered other people's - for instance uploading your contact book to "find friends" tells Facebook what names to associate with phone numbers and helps them build "shadow profiles" (or whatever the term they use is) for users who haven't given them anything.
- puppetmaster 8y agoThis is particularly an issue when minors are present in the photo, videos, comments, etc... Dad/Mom/Uncle/Grandma shares a photo of a young family member, and without a doubt a new individual has been added to Facebook's records. Will our kids resent our posts?
- ben_w 8y agoIt is not well understood that they are a service. To many people it is more like a place, and places are free. Sure, technically you can buy a place and own it and charge for access, and technically somebody owns almost all places you might care to go to, but mostly we think of them as free. The fact that it costs nothing, monetarily, to access… that very thing often makes something seem like it has no cost.
- gdrift 8y agoI don't understand why people think these services cost nothing monetarily. All ads are not free, all advertised products already include the cost of advertising in their price. So everybody are paying for those "free" services whether they use them or not.
- wmeredith 8y agoIt’s a cycle. Facebook has been doing nasty shit and apologizing for it since 2003. I’m starting to think they aren’t actually sorry. https://www.wired.com/story/why-zuckerberg-15-year-apology-tour-hasnt-fixed-facebook/ https://www.wired.com/story/why-zuckerberg-15-year-apology-t...
- MaxBarraclough 8y agoRight, because Move fast and break stuff is their mantra. I'm surprised that articles doesn't even mention it. Perhaps Move fast and hurt people would be more honest. I think it's rather catchy.
- beaconstudios 8y agoI think that's already taken by Uber's self-driving car division.
- zethraeus 8y agoNot remotely funny.
- marnett 8y agoUnderstanding HN is not a place for jokes and quips, I understand your sentiment. But it is pretty humorous.
- dhimes 8y agoI took it as a pun on remote-control.
- deleted 8y ago[deleted]
- pathseeker 8y ago
- prolepunk 8y agoI had a feeling that facebook does it and remove my phone number from facebook a few years ago. I'm fine living with the cost that if someone hacks into my facebook I'll just have to finally delete it. Maybe using app like Google authenticaticator would solve the problem, but then I'd have to think of all of the nefarious ways facebook will leverage that against me. Right now I'm trying to get into a habit of checking out facebook only from (the same) my home desktop computer once a week.
- kevmo 8y agoI am becoming anxious to see some action out of the DOJ Anti-Trust division against Google, Facebook, and Amazon, etc. These tech behemoths effectively own most of the consumer internet and they use their muscle to either acquire or force out the majority of other players. More regulation is not going to cut it (or else it would have already). In America (and most places), law normally lags quite a bit behind the events of the day. Standard Oil destroyed markets unchecked for several decades in the 1800s. No individual or company could withstand their market power. Then the government divided it into dozens of vertically integrated companies, which allowed for a wave of new market entrants, better deals for consumers, and higher standards of living for more people. We are obviously at that breaking point now with the tech behemoths and their sprawling, impregnable market power. It is time for antitrust action against Facebook and the gang.
- trendia 8y agoI think we need proper privacy measures, since the misuse of data is not necessarily an "antitrust issue". For instance, would breaking up Facebook really mean that the newly formed constituents respected privacy? And would antitrust enforcement against Google or Facebook reduce privacy exploitation by smaller entities? I'd argue that it would not -- 1,000 small Facebooks could still violate privacy. Creating privacy legislation is the only real way to achieve proper privacy guarantees.
- danShumway 8y agoYou can personally decide not to use Facebook, which is good. But you can't convince everybody to do that. So if you or your family members do use Facebook, at least install an ad blocker for all of them. Not for privacy, but to deny them revenue. I block Google ads on every single site I visit, period. I don't care if the advertising is non-obtrusive. If it's being run through Google, part of that revenue is going to fuel Google's tracking. I support creators directly instead. And if creators refuse to give me a way to support them, that's not an excuse to expect me to contribute to Google's bottom line. Huge props to the people who are working on blocking trackers and protecting privacy. I'm very glad they exist, and I don't think their efforts are worthless. But, it is currently a losing battle to fight these companies on the privacy front, because the tracking model is so profitable that they will always be pushing more resources into it than we are. Collectively, the people fighting for privacy don't have enough resources to win. But there's an easy, completely legal solution to that problem; the one thing companies haven't figured out how to get around is ad blocking. And a good ad blocker will block even native ads. For a company like Facebook, all of this boils down to getting you to click on ads. If enough people target that chokepoint, then the advertisers will start pulling out of the system, and there'll be less financial incentive for these companies to undermine people's security and privacy. And we have evidence that this works. Even Google, which is the powerhouse for getting their ads to actually show up, is starting to devote more resources into trying to figure out how to stop mainstream people from installing adblockers. That's where all the autoplay stuff came from, that's where the acceptable ads initiative came from. They desperately want your roommate to say, "I'm not going to mess around with these weird Chrome extensions or whatever, that's too complicated. Chrome blocks this stuff itself, anyway." Install adblock on every browser you get access to, tell ordinary people who aren't on HN to use it, and let the advertising industry kill itself. Make it very obvious to companies that buying ads on Facebook is a complete waste of time because even non-technical users just won't see them.
- gcb0 8y agoyou gave an idea for a weekend project. posting here in case I change my mind and slack on something else. instead of deleting facebook (or not having it), create a shell profile, just enough for you family to pointlessly add. then subscribe the account with a service (aka The Idea) that simply post a once a month post on how to install ad blockers and such.
- adam12 8y agoThis should not be a surprise to anyone. Facebook is all about making money with your info.
- ricokatayama 8y agocambridge, whatsapp founders, instagram founders, 2FA exploit and so on. What's next for Mark? And actually what would be the trigger for people to flee away?
- justtopost 8y agoSlow boiling the frog. Those who can notice at this point already left.
- oxymoran 8y agoI was purging my life of all things Google(Facebook went first), so I was changing my email addresses under all my various accounts. An odd thing happened when I was changing my info for my Microsoft account: they texted my as a security precaution. The only problem is that I NEVER gave Microsoft my phone number. I do not have 2FA set up. In my contact details, there is a blank for my phone number. WTF Microsoft.
- cecja 8y agoAt some point you gave it to them. Could be Skype, office, Xbox or an old windows phone. You just forgot.
- joering2 8y agoWhat kind of cooperation level did YOU expect from a $240MM check? http://www.nbcnews.com/id/21458486/ns/business-us_business/t/microsoft-invests-million-facebook/ http://www.nbcnews.com/id/21458486/ns/business-us_business/t...
- marssaxman 8y agoI always imagined they would probably end up doing this, and that's why I've never accepted 2FA anywhere a site has tried to push it on me. They can't spam me if they don't know my number...
- JoshTriplett 8y agoGood 2FA does not involve phone numbers. I use 2FA on sites that support TOTP.
- makecheck 8y agoI only use Facebook like every month now but it always asks about my phone number. It also asks me to enable a log-in short-cut every time. This last time, they crossed a line: they pre-filled the field (I do NOT have this set up in the browser), meaning they already figured out my number (probably by scrubbing some friend’s phone) and just want it confirmed. To hell with that. I would not be surprised if every spam call in existence can be traced to Facebook.
- tombert 8y agoIt upsets me that the "normal" way to keep in touch with people now seems to be to use some kind of big-brother-esque system. I try and evangelize Signal over WhatsApp and most of my friends won't budge. I deleted my Facebook four years ago, and as a result I have lost contact with a lot of friends.
- Brockenstein 8y agoBefore this sort of technology keeping in contact with friends wasn't trivial. Both parties had to want to keep it up. And if they didn't, or you didn't, you just lost contact with a lot of people as a normal matter of course. Everyone moved on with their lives, you met new people, and so on. That there is this artificial world where people can arbitrarily keep in contact doesn't make that sort of non-interaction of occasionally commenting on or liking posts normal or better. It certainly is easy though to search for someone you knew ages ago, add a friend, have the five minute conversation of what's been going on the last five, ten, twenty years and then never really talk again. In this regard facebook isn't the problem, and your preferred platform isn't a solution. The problem is people.
- justtopost 8y agoAs someone who still makes phone calls and writes letters, it seems like a step backward. Most people have nothing to even discuss once they 'get together' as they have shouted everything remotely interesting about themselves and their lives into the void already. I have letters I treasure and will keep to my death. Emails? Not so much. The impression, the personal touch is missing. We as humans notice that sort of thing even when we pretend its all the same.
- paul7986 8y agoSo, Google is not doing this too? How many of us use 2FA on our Google accounts?
- ergothus 8y agorecently interviewed at Facebook (didn't pass the in-person) and one thing I was looking for was a job that WASN'T based on ads. I didn't want to come across negative so I was circumspect in my asking ("Tell me about the positions at Facebook that I as an outsider don't know about - I know ads, messaging, and events"). I wasn't really excited by the answers I got - ads seemed worked into everything they brought up, but the answers weren't super-nefarious either. This was the Seattle office, which apparently has a strong ads-basis. Because they hire people and then (allegedly) let them pick from available team openings (after a "bootcamp" to do onboarding), I simultaneously felt like I'd have a chance to avoid the worst but also couldn't be sure of what I was committing to. I didn't pass the interview and the few weeks since have tried very hard to make me not regret that by raising issues like this one, despite my natural tendency to give FB the benefit of the doubt and to recognize the difficulty of moderating speech sanely. I've never had such uncertainty about what a job would involve before - the "you find your match" sounded good initially, but in retrospect I'm wondering if I dodged a bullet - so hard to know.
- mav3rick 8y agoThere's Oculus and Building 8. Also, backend infra stuff.
- sweezyjeezy 8y agoI find it interesting that you would absolve yourself for working for Facebook just because you wouldn't be working directly on ads. Facebook is an ad company with services attached (a fairly reprehensible one in my opinion). If you work for them, you are helping them achieve their goals, which ultimately is about serving people ads, it doesn't matter what particular role you are doing there.
- ergothus 8y ago"absolve" is not the correct term (I think) - I don't find ads particularly offensive, I just don't ENJOY them, and I was looking for a job I'd enjoy and enjoy telling people about. I'm perfectly fine with ads existing, though I'm supportive of being able to buy my way out of them. (You can raise issues about ads being inherently deceptive and manipulative, and I wouldn't say you're wrong, but I've not taken a position against them...yet) That facebook is doing bad things because ads are their only real source of income is a problem because of the bad things, not the ads. At the time the primary concern was "what should facebook be doing about de facto empowering hate speech and (actual) fake news?" and that's a tricky problem that I don't think has a resolved answer, and I sympathize with those that empower communication and only later realize people have more desire to trash things than apply rational caution. Since then much more has come out about some FB practices (and Google), and the question of whether ads-as-your-primary-revenue-source is too much incentive to be "evil" is being implicitly raised, but is likewise not yet resolved. That said, I do think there are lines to draw and lines not worth drawing. There's very few jobs that don't end up supporting bad things. I don't think it's right to pretend that if you aren't doing it directly that you AREN'T supporting such things...but I also think it's sometimes unrealistic to make your situation worse to deny an indirect support. Deciding where that line lives is an individual decision, and one I have to regularly re-evaluate. To expand my point in the previous post, the news coming out about FB practices definitely made me feel like I'd have been uncomfortable even if I wasn't working directly in ads.
- Bhilai 8y agoThe only justification I could come up is that Facebook has grown so big that "one hand does not know what the other hand is doing." The security and privacy folks at Facebook agreed to this kind of abuse is somewhat hard to believe and the most likely explanation is that these features never got fully reviewed and vetted. Either way its a big failure.
- yumraj 8y agoWe know that social networks are here to stay, and even if people disagree the writing is on the wall for Facebook to have Myspace moment, as soon as an alternate is available. What will it take for some prominent VCs/Investors to just come together and create a fund to fund FB replacement? If done right, they will make a killing (from a returns perspective).
- Aunche 8y agoDon't get me wrong, this is absolutely a scummy thing to do since it's deceptive. That said, I don't understand why everyone thinks this is such a big deal. They already have your phone number from 2FA anyways, and they already show advertisements. What difference does it make that they let advertisers target people based on their number?
- bogomipz 8y agoAnd yet in April Mark Zuckerberg told the US Congress that he wasn't "familiar" with shadow profiles[1]: Lujan: Facebook has detailed profiles on people who have never signed up for Facebook, yes or no? Zuckerberg: Congressman, in general we collect data on people who have not signed up for Facebook for security purposes to prevent the kind of scraping you were just referring to [reverse searches based on public info like phone numbers]. Lujan: So these are called shadow profiles, is that what they’ve been referred to by some? Zuckerberg: Congressman, I’m not, I’m not familiar with that. [1] https://techcrunch.com/2018/04/11/facebook-shadow-profiles-hearing-lujan-zuckerberg/ https://techcrunch.com/2018/04/11/facebook-shadow-profiles-h...
- igravious 8y agoQuelle surprise. I bet plausible deniability is that they call them by a different name internally. Information brokers are so sketchy – it makes me so sad that the coolest tech companies are also some of the sketchiest. Do you remember back when the internet and web were all so full of promise? Instead we got tech behemoths that would put Standard Oil and AT&T in their day to shame.
- bogomipz 8y agoI wouldn't count FB to be among the "coolest" tech companies. Maybe 10 years ago they had some cachet but today it's just Mega Corp.
- abalone 8y ago> They found that when a user gives Facebook a phone number for two-factor authentication or in order to receive alerts about new log-ins to a user’s account, that phone number became targetable by an advertiser within a couple of weeks. I have always been suspicious of the aggressive "give us your phone number to secure your account" campaigns that so many sites/apps are running. And I think this is a HUGE disservice to users. At first I was like, cool, companies are being responsible and encouraging good security practices, good on them. But there was something a touch too.. aggressive and "marketing-y" about it. It raised my spidey sense. Maybe the form and frequency and placement of them just was too familiar to previous campaigns to grab your email for "opt in" spam. All of these companies should be shamed to high hell. Getting people to adopt 2FA is so important and here they are shamelessly exploiting it to market to you for undisclosed purposes.. well, buried in the privacy policy, but you know how that goes. The prompt is 100% about securing your account and nothing mentioned there about using it for targeting. Seriously F these companies for breaking user trust. ALSO: Did Zuckerberg lie to Congress?[1] [1] https://techcrunch.com/2018/04/11/facebook-shadow-profiles-hearing-lujan-zuckerberg/ https://techcrunch.com/2018/04/11/facebook-shadow-profiles-h...
- njarboe 8y agoThe article states that you can give Facebook a list of phone numbers or email addresses and it will put your ad in front of only those people. Does anyone know how small a list you can target? List of one? List of one plus N number of dead email addresses? Therefore a list of one, but more expensive?
- TheKarateKid 8y agoThis is probably the reason Jan Koum left Facebook. He knew the betrayal of privacy promised of Whatsapp was completed by Facebook by doing exactly this. This doesn’t surprise me at all. Facebook has been bothering me for YEARS to enter my mobile number for “account recovery” purposes. My email is fine for that. Now Facebook is recommending pages and friends to me who I only am connected with on Instagram. Not to mention Facebook notifications are now integrated into IG. I wouldn’t be surprised if these were the final nails that made Kevin Systrom leave.
- benchplz 8y agoWhat people forget is that Facebook doesn't just give them to advertisers, they give them to everyone. Click "Advertising" on the bottom of the site and try it yourself. Anyone can be an advertiser. The fact that it's equal for everyone makes it seem fair to me.
- sandov 8y ago>The researchers also found that if User A, whom we’ll call Anna, shares her contacts with Facebook, including a previously unknown phone number for User B, whom we’ll call Ben. Why didn't the author use Alice and Bob?
- joesb 8y agoUmm, based on the content of the article, no, Facebook did NOT advertiser access to your shadow contact information. Advertisers can specifically say that they want to advertise to a phone number THAT THEY ALREADY HAVE, (READ: THE ADVERTISER ALREADY KNOW WHO YOU ARE). And Facebook will display that ads to the Facebook account that use that phone number in their shadow contact info. At no point does advertiser have access to which Facebook account that is.
- deleted 8y ago[deleted]
- tomhoward 8y agoFrom the guidelines: > Please don't use uppercase for emphasis. If you want to emphasize a word or phrase, put asterisks around it and it will get italicized. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- FrostyBear 8y agoThe big picture here seems to be alluding people. Let's not get bogged down with Symantec's and logistics. It boils down to self preservation, people need to understand who/ what that " self" is.
- pure-awesome 8y agoEluding, not alluding, and semantics, not Symantec's. (I'm sorry, not trying to be needlessly pedantic - I had to re-read to understand your meaning.)
- pure-awesome 8y agoWhat do you mean by "people need to understand who/what the 'self' is"? Can you elaborate?
- FrostyBear 8y agoI did mean indirect referencing and Linguistics.
- FrostyBear 8y agoPlease try to stay focused on the forest, not the tree's. With each generation my hope grows stronger.
- Number8 8y agoWell Frosty, I for one am glad to see the scrambling and gasping for oxygen. As for hope in each generation, I believe #3 is getting stronger each day. We are living in a truly glorious time.
- Number8 8y agoWell Frosty, I for one am glad to see the struggle and gasping for oxygen. As for hope in each generation, I honestly believe #3 is growing stronger each day. We are alive in a great moment in time.
- makecheck 8y agoThis is the kind of thing that is stupidly hard to fight now. Even if you block Facebook’s 80,000 domains at your router, your friend’s address book dump gives lots of goodies to Facebook and 3rd parties and you can’t touch it. Every new thing they try becomes illegal in 2 years “but not yet” so they do it until they can’t. Sometimes it seems like the “Default deny” security concept needs to apply to Internet companies. Instead of having years to screw with data and the Internet until told “no”, how about every idea they have is illegal until it can be proven through thorough review that it might be valuable?