15 ms·
Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098?s=21 https://twitter.com/benedictevans/s
by mobileexpert 6y ago
Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098?s=21 https://twitter.com/benedictevans/status/1320378054150148098...
“Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”
- christkv 6y agoTurns out Cambridge analytics might have been practically useless https://www.wired.co.uk/article/cambridge-analytica-facebook-psychographics https://www.wired.co.uk/article/cambridge-analytica-facebook...
- InitialLastName 6y agoThat's not what the article you posted is arguing. The article is arguing that the data they collected directly through their trojan apps is not particularly useful, NOT that the full connection graphs (including data drawn from connections of users who didn't use their app) they collected and allegedly used to target advertising is useless.
- MAGZine 6y agoComparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.
- mobileexpert 6y agoThe whole point is that a major problem with CA was the scaled friend’s data collection. The NYU app scraping modality could easily do the same thing which violates the present FB consent/sharing model of you control your data going to or not going to third party apps. FB has to fight as hard as possible against such apps. Remember Clearview AI? If we want FB to fight CA and Clearview they must fight here as well.
- andybak 6y ago> If we want FB to fight CA and Clearview they must fight here as well. Or they could partner with NYU, offer technical insight to maintain integrity and privacy (me stifles laughter) and do everything to support researchers who potentially could help build trust in their platform. Going after this group just isn't a good look if you're Facebook. If there are valid concerns then don't start with a Cease and Desist.
- nickff 6y agoThey might be willing to partner if NYU is willing to indemnify Facebook against any and all liabilities which may result. How likely is NYU to take on that risk? Why should we expect Facebook to take on the risk for NYU?
- MAGZine 6y agoSo is your opinion just that facebook just shouldn't be researched?
- nickff 6y agoI don't really have a view on that, but I think researchers and universities should be held fully liable for the harms they cause, that way, they'll be more careful. Some research just isn't worth the risk, but as an outsider, I'm not in a place to make that judgement. NYU could also insure against data breaches; in that case, we might get some good security audits.
- xg15 6y agoHang on. The whole chain of reasoning started with FB protecting users' interests through the permission system, which NYU ostensibly circumvented. How is it in the users' interests to indemnify Facebook?
- nickff 6y agoIf NYU internalizes the cost of all breaches (by indemnifying FB against harm), they will be very careful with the data, and prevent another Cambridge Analytica problem.
- edouard-harris 6y agoThe point is that CA's data harvesting looked like it was transparent to users at the time they were doing it — which is precisely the appearance you'd expect a malicious app to try to convey. The NYU project is probably on the level, but "they're probably on the level" isn't a very good security model at Facebook's scale. More to the point, the FTC's 2019 Consent Decree [1] makes it fairly clear that FB is responsible for third parties' access to its users' data — and it would be prudent (from FB's point of view) to interpret this responsibility as also covering browser extensions. [1] https://www.ftc.gov/system/files/documents/cases/c4365facebookmodifyingorder.pdf https://www.ftc.gov/system/files/documents/cases/c4365facebo...
- libeclipse 6y agoUsers have to install a browser extension in order to participate in the study. That's a way higher barrier than the personality quizzes that Cambridge Analytica used. It also happens at a different layer of abstraction. Cambridge Analytica extracted data through the permissions framework that Facebook itself implemented. Facebook's interest in its users' data doesn't need further explanation after you see that most of their profits derive from their control over it. The same control that allowed the profitable mass political targeting that these researchers are trying to study.
- mFixman 6y agoThe researchers ask people to opt in tracking a restricted amount of data, and then install an extension that has access to their entire Facebook accounts. There is no way for Facebook or anyone else to prove that the current or a future version of the NYU's extension won't scrape more data than people agreed to.
- MAGZine 6y agothe plugins are just javascript, so verifying that is actually a trivial task. You just open the plugin and read the source. NYU could also provide the code, to make it even easier.
- tupputuppu 6y agoSure. So what exactly is the binding rule which Facebook should apply here? Rsearchers can get access to anyone's Facebook data if people enable it? What about the ones in chinese universities? Or just respected universities? Which universities is that? How do we decide? You're missing the point. There needs to be a black and white line, and whatever Facebook allows they're always being demonised, nobody gives them the benefit of the doubt.
- xg15 6y ago> Rsearchers can get access to anyone's Facebook data if people enable it? Yes. Where is the problem?
- tupputuppu 6y agoThis is ironic. Cambridge Analytica was a university with an IRB collecting personal data, then later sold to foe-profits.
- PrinceKropotkin 6y agoThere's no way to see what these third parties actually access of your data. I don't think anything substantial has changed since CA to ameliorate this. The problem is Facebook Ads itself: it's impossible to trust period, let alone with what scraps of information they toss us about how we're actually transacting for services paid with ads.
- strawberrypuree 6y agoCambridge Analytica happened with an app hosted on Facebook. This is hosted on your browser. So it’s not exactly how Cambridge Analytica happened because the trust model is completely different.
- refulgentis 6y agoThe legal problem & consequences for Facebook werent because of users who opted in to CA collection, the problem was getting your friend's data, who did not consent.
- beagle3 6y agoThe legal problems for Facebook was mainly because they were an active party to the collection process, which could not have happened without that active participation. This collection can happen manually, within the users’ regular and fully authorized use, without facebooks involvement, and in fact without any ability for them to figure out that it happens. That it happens through a browser extension (which they may or may not be technically able to detect) should not change legality or legitimacy.
- ForHackernews 6y agoI mean, I trust NYU researchers a lot more than I trust Facebook execs. All these big data-harvesting companies (FB, Google, etc.) start with the false premise that well-informed users have affirmatively chosen to trust that company with their private data.
- trhway 6y agos/NYU app/Google Chrome/g and somehow FB is ok with it, so it isn't security model, it is the people and the goals of their actions what ire FB.
- mcguire 6y agoDoesn't NYU have an Institutional Review Board?
- spamizbad 6y agoIt does.
- tupputuppu 6y agoThat's enough? Any university with an IRB can scrape people's personal data?
- refulgentis 6y agoJust in case OP never comes back or you're not aware when you reply later: This was _exactly_ the issue with CA, data for academics with an IRB laundered into a for-profit entity.
- mcguire 6y agoMore or less, yes. The purpose of IRB review is to ensure that personal data collection and use are legally and ethically kosher. Cambridge Analytica and the researchers when they were working for it never claimed to be doing UofC research; if they did, UofC could and should have applied an academic (and possibly legal) baseball bat to their collective face. In fact, when Kosinski did try to use the data as part of his UofC related research, the UofC IRB denied it.
- mFixman 6y agoSo does the University of Cambridge, and that didn't prevent one of their researchers from scraping and selling user data to Cambridge Analytica.
- mcguire 6y agoAs far as I've been able to find out, Kosinski and the others developed their techniques at University of Cambridge (and other universities), then took those techniques to Cambridge Analytica/SCL (something that no one here would have any complaints about); CA/SCL then applied them to Facebook. The UofC IRB has no influence on that. If there is any evidence that CA/SCL/Kosinski said the data collection was affiliated with UofC, I cannot find it. And when Kosinski attempted to use the data in his research, the UofC IRB denied it. In this case the data collection is by the NYU AdObservatory project, meaning the data collection and its use (should) have to go through the IRB.
- thesausageking 6y agoWeak take. All users of the NYU app have to explicitly sign up and grant the researchers access to their data. It has a very clear privacy policy: https://adobserver.org/privacy-policy/ https://adobserver.org/privacy-policy/ And, unlike Facebook which sucks up an ever increasing amount of data on you, this project takes only basic demographic information (age group, gender, ethnicity) and what ads that you're shown. No personal data is retained by NYU.
- bryan_w 6y agoThe user signed up, but the app would have access to that user's friend's data who didn't sign up
- thesausageking 6y agoNope. This isn't a Facebook app. It's a browser plugin.
- beagle3 6y agoIt only has access to what the user is browsing; if a friend hasn’t posted in a year (and doesn’t appear on timeline) and user doesn’t go specifically to their page, then adobserver would be oblivious the the existence of that user (and of the friend relation). This is entirely unlike an FB app like CA’s that had full unadulterated access to anything the user might browse.
- leothecool 6y agoToo bad he didn't cite where in the source code it does any of this stuff.
- xg15 6y agoWell, what exactly should NYU do instead? There is no API with fine-grained permissions that they can use: To get the data they are interested in (ads), they have to resort to scraping - and a scraper will always have access to all data on the page. So there is no way for NYU to not have access to friend data if they want access to ad data.
- propogandist 6y ago>"The supposed scandal around the data analytics supplied to campaign groups by Cambridge Analytica was manufactured by people with a political agenda. >...UK Information Commissioner’s Office has published the findings of its three-year investigation (predating the scandal) into the matter, which concluded there was no illegal electoral interference whatsoever...In other words, the data was commercially available and concerned US voters. The only ‘special sauce’ in CA’s model was the hyperbole of its sales people..." [1] the left has pushed a false narratives and misinformation making Cambridge Analytica, like Russia, the convenient scapegoat for all the things. The same tricks are in play now with Hunter Biden's laptop coverage, which is non-existent from MSM [1] https://telecoms.com/506834/uk-information-commissioner-confirms-cambridge-analytica-was-a-storm-in-a-teacup/ https://telecoms.com/506834/uk-information-commissioner-conf...