7 ms·
There's many terrible data brokers involved in many terrible things (especially in the US - they generally get zero headlines because they are b2b and rather se
by ve55 5y ago
There's many terrible data brokers involved in many terrible things (especially in the US - they generally get zero headlines because they are b2b and rather secretive), so it's strange to have this headline be about Facebook, when they're the only company being discussed that doesn't sell your data (even if they do many other things with it that we may not like!). I know it's very fun to use them as the worst possible example in any given category of bad things, but I'd much rather have FB handle data than almost every single US data broker, if I was forced to choose between the two. A GDPR-equivalent would still be nicer either way though too!
- cyounkins 5y agoData can be collected by third parties about your activity on platforms like Facebook without involvement of the platform owner. On TikTok or Instagram a bot can subscribe to you. On Facebook some info may be public to other users (depends on settings) and some interactions are public, like commenting on a public post.
- ve55 5y agoRight, I think a lot of the HN audience understands this often happens with public (or 'public') data on the Internet. I still think the article title is a bit misleading when the article is about data brokers instead of Facebook (even if sometimes data brokers use FB) and would hope for more constructive and better-sourced articles from Mozilla.
- duud 5y agoIncreasing engagement is only evil when Facebook does it.
- nsonha 5y agoyeah what about the streaming industry and the game industry? Of course when we dig into them we'll come to the conclusion that human attention is havested in order to fund a whole range of industries and it's their entire business model we need to kill to stop this. This has always been the case since before the digital age (hollywood, cable, video game, sports, even news). These industries feed on humans paying attention to things that don't matter in their life.
- akomtu 5y agoNot so secretive. Just register a domain, put an official looking website on it with contact details and enjoy sketchy sales pitches. My latest favorite is a blunt offer to buy a database with millions of entries, with all PII imaginable except maybe SSNs. These data brokers aren't much different than drug dealers, it's just PII theft and sale hasn't been outlawed yet.
- wyxuan 5y agoAlso, Facebook and other big tech companies are way less likely to get hacked thanks to more established data handling practices. Breaches still occasionally happen, but you're more likely to see data breaches from these data broker companies because they didn't secure their elasticsearch DBs or something dumb like that.
- LurkingPenguin 5y ago> Also, Facebook and other big tech companies are way less likely to get hacked thanks to more established data handling practices. Well, historically, bad actors haven't needed to "hack" Facebook because it has made it possible for them to access user data without hacking. https://www.npr.org/2021/04/09/986005820/after-data-breach-exposes-530-million-facebook-says-it-will-not-notify-users https://www.npr.org/2021/04/09/986005820/after-data-breach-e... > In response to the reporting, Facebook said in a blog post on Tuesday that "malicious actors" had scraped the data by exploiting a vulnerability in a now-defunct feature on the platform that allowed users to find each other by phone number. It's not a vulnerability, it's a "feature".
- jmspring 5y agoGranted it’s old news, but you mean like the founder and employees stalking profiles of those they were interested in during the early days?
- deleted 5y ago[deleted]
- jrockway 5y agoI think every company has an incident that makes data protection a real concern. When it's two guys with a PHP app in a dorm room, you don't really expect anything serious, but eventually the risk to the company becomes too high and some useful system gets implemented. I think Google's watershed moment was this: https://www.gawker.com/5637234/gcreep-google-engineer-stalked-teens-spied-on-chats https://www.gawker.com/5637234/gcreep-google-engineer-stalke... By the time I got there, it seemed like standard practice for engineers to not be able to read "their own" databases -- every piece of data would be encrypted by a per-user key that only arrives at your application when the user's session is present (or by heavily-audited special exceptions; breakglass, batch jobs, etc.) Much attention was paid to not making data available too widely. (For example, on Google Fiber our hardware knew the MAC addresses of devices that wanted to use WiFi. That's a requirement for 802.11 to work. We modified the Linux kernel, wpa_supplicant, etc. to not log these, explicitly so that someone couldn't collect the logs and do a mapreduce to see who takes their iPhone to their friend's house and intuit a social network. We did that because it was the right thing to do; we only wanted information that was required to operate the service effectively, not to be a dragnet for anything potentially interesting. I'd personally be fascinated to see that information, but it's not the right thing to do.) I have to imagine that any other large tech company has similar access controls and privacy focus -- even Facebook. Where it gets scary are governments and large non-tech companies that just email around spreadsheets with personal information in them. Yesterday there was an article about Missouri exposing teachers' social security numbers in HTML comments. If you tried to write that code with a data storage system like Google's, it simply wouldn't work. Your code wouldn't have the decryption key for those rows, and you wouldn't be able to output them as HTML comments.
- gerdesj 5y ago"so it's strange to have this headline be about Facebook, when they're the only company being discussed that doesn't sell your data" Are we talking about the same Facebook? The mob with some bloke called Zuck are hell bent on selling ads. They absolutely use you.
- renewiltord 5y agoThey don’t sell the data. It’s in the FB walled garden.
- gerdesj 5y agoYou and your mates appear to have invented a new financial system, which involves walls. Please explain 8)
- alexeldeib 5y agoSelling raw data vs. selling targeted advertising based on that data. The difference is maybe not so important to some people, but it's exactly the distinction the comment you originally replied to highlights. "Walled garden" is a fairly common colloquial phrase, often applied to the iOS ecosystem in the context of the app store (genuinely not sure what you meant by your comment otherwise).
- cratering 5y agoFacebook "doesn't sell your data" but I would argue they rent it out to the highest bidder.
- justshowpost 5y ago> Facebook ... the only company ... that doesn't sell your data Was that CNN style reporting where Dr. Zuckerberg sells users' personal data left and right in bulk quantities and seems privacy-friendly at same time? Or just NBC style Let's Go Brandon? > GDPR Also, I blame Dr. Zuckerberg for constantly getting caught brown-handed while selling data to private intelligence firms. His miserable failures to do shady business in shady way resulted in this extremely idiotic legislation which rendered a significant number of US websites inaccessible to, say, Frankfurt VPDN endpoint and polluted the rest with ridiculous cookie police which is even more annoying than popup and animated porn banners.