6 ms·
In the early days, Facebook logged into user's email accounts and stole contact information without users' knowledge or authorization. This was possible because
by interlocutor 7y ago
In the early days, Facebook logged into user's email accounts and stole contact information without users' knowledge or authorization. This was possible because people used the same password for their email and Facebook, a practice common especially back in those days. This is one of their sources for PYMK.
In fact Facebook has used this technique very recently too:
A security researcher noticed the tech giant was prompting some users to type in their email passwords when they opened an account to verify their identity. And after they were caught... Social networking giant Facebook said on Wednesday evening it may have “unintentionally uploaded” the email contacts of up to 1.5 million users on its site, without their permission or knowledge, when they signed up for new accounts since May 2016.
Read more about this: https://www.nbcnews.com/tech/tech-news/facebook-says-it-unintentionally-uploaded-1-5-million-users-email-n995741 https://www.nbcnews.com/tech/tech-news/facebook-says-it-unin...
- uoaei 7y ago"Unintentionally uploaded" Because you just happened to accidentally interact with the API in just the right way and downloaded the information to just the right database and deployed a service to production which just happens to access that data... I don't understand how that statement right there isn't literally incriminating evidence. They admitted to uploading the data explicitly, and "unintentional" is a straight up lie based on how software works.
- presumably 7y ago> "unintentional" is a straight up lie based on how software works This is a very dangerous statement to make. Large systems are not like hackathon projects where you might understand and hold the entire scope and flow in your mind. Software absolutely can and does lead to unintended outcomes, else there would be no bugs.
- not2b 7y agoYes, but in this case it is a highly desirable outcome for Facebook. They didn't just get lucky.
- cameronbrown 7y agoDo you really think Facebook profited from this? I'd bet they took a million dollar PR hit if anything.
- uoaei 7y agoYes, absolutely. It provides a whole new set of connections to improve their view on the IRL social network. It's hard to quantify exactly how much it benefits Facebook but it's not hyperbole to say it contributes positively to everything that makes Facebook money.
- deleted 7y ago[deleted]
- JohnJamesRambo 7y agoDid you read the article?
- bathtub365 7y agoYou’re saying an entire system was added to integrate with user email accounts, download all their contacts, and upload them to a database at Facebook, accidentally?
- presumably 7y agoPlease respond to the actual contents of my post, and not a strawman version of it. I’m saying what I said, nothing more. > Software absolutely can and does lead to unintended outcomes, else there would be no bugs. Edit: also see this: https://news.ycombinator.com/item?id=22429620 https://news.ycombinator.com/item?id=22429620 TFA explains how the system was added, it’s absurd and intellectually dishonest to interpret my post as saying what you wrote.
- bathtub365 7y agoSorry, so they built a system designed to vacuum up even more personal information and accidentally turned off the screen where they tricked people into giving the information up, leading to it being collected by default?
- close04 7y agoHave you noticed how no feature that brings monetary value to the users is ever accidentally added? I never accidentally received money from these companies, extra storage quota, personalized email address, premium account, etc. And certainly never something that you get to keep once they realize the mistake. The fact that they have such weak controls when it comes to protecting you but such strong controls when it comes to protecting themselves can only be a calculated decision. And the number of precedents of such "mistakes" that are always to their advantage is the proof. It's a mistake only the first time. Knowing they get away with it every time and reap the reward is just an incentive to do it again and again. And people finding excuses and justifying this as being acceptable is one reason they get away with it. They rely on advocates for ignorance and defeatism to make such incidents feel like a banality, "oh well, what can you do", "it could happen to anyone", etc. How many situations would you consider excusable where bad things happen to you because someone "accidentally" removed the step where you were informed what's happening and could say no?
- Barrin92 7y ago>Large systems are not like hackathon projects where you might understand and hold the entire scope and flow in your mind. I've seen this argument repeatedly now in a defense of Facebook, recently in a twitter thread where a facebook employee in a discussion about hate speech moderation responded along similar lines of "we are simply too large and don't know what's going on in every corner of the system" I find it funny that this is used as a sort of excuse or defense. We can draw another conclusion. Like Goethe's Sorcerer's Apprentice Facebook has lost control over its own machinations and is simply too large.
- fiblye 7y agoCourts don't know how stuff like this works and congressmen are paid not to know. It's unlikely anybody will have the money, confidence, and time to bring up a case against Facebook, and they'd have a hard time going up against "expert witnesses" whose testimony amounts to "accidents happen." Until fed-up former tech workers get into politics and apply their knowledge to the law, it's basically the word of the normal people vs billions of dollars.
- ikeboy 7y agoI don't understand how people comment without reading the source. It clearly explains what happened - they had a feature in production that was disclosed to the user, and an update inadvertently removed the disclosure without removing the entire feature like they were trying to.
- ryantheleach 7y agoSome junior facebook dev: "Oh look, here's this ancient library for email logins, I can use this to create a way for people to confirm identity" Oh, the library was for 10 years out of fashion, People You May Know? Well craaap.
- giancarlostoro 7y agoThat takes a lot of code and effort moreso necessary for it to ever be accidental. We really need a system where courts can have a jury of relevant people from the relevant industry. Imagine if the jury for Oracle v Google were made up of software developers every single time how much more effective and meaningful that would be...
- nojvek 7y agoMost VC backed apps like Notion, AirTable, Dropbox and a bunch of others do this when using Google Auth to log in. It seems very common tactic (prolly coming from Marketing & Growth). Google makes it very easy to share your contact list. When logging in the permissions are (will see your email and contact list). AirTable makes it very very hard to login with GAuth without giving permissions to your contact list. I feel Google should just disable that permission, it’s abused.
- giancarlostoro 7y ago> I feel Google should just disable that permission, it’s abused. I should have total control over what parts are given to a third party from my email. Much like Android / iOS permission prompts.
- ignoramous 7y agoWe desperately need a Edward Snowden of Facebook to show up with treasure trove of docs at the steps of The Guardian. Surely, it is relatively safer than going up against the NSA? A $500B enterprise that's toying with the very social fabric that they claim to help build is beyond hypocritical and borderline cancerous.
- deleted 7y ago[deleted]
- samplatt 7y ago>Surely, it is relatively safer than going up against the NSA? I mean, call me paranoid but I've always assumed that it's the same thing...
- mehrdadn 7y agoA little off topic but what happened to that other recent security "incident" last year? I forget at this point what even happened, I just remembered they just let it blow over and I haven't heard anything since.
- simonebrunozzi 7y agoI didn't specifically know about this... But it's easy to believe, and it's a terrible thing. Even worse, it hasn't been punished by law enforcement.
- CannisterFlux 7y agoWasn't it was worse than that? I think they used to ask for your email and password explicitly for the contacts. Twitter used to do the same as well as some others. Here is a blog post from 2008 about Yelp doing it, but I can't find anything for Twitter (though I definitely remember it being the case back in the day, a comment on this blog post also mentions it) https://blog.codinghorror.com/please-give-us-your-email-password/ https://blog.codinghorror.com/please-give-us-your-email-pass...