5 ms·
I'm going to echo another comment I saw here yesterday: if Mark cared he would put his money where his mouth is and back off datamining IM conversations and ena
by intslack 13y ago
I'm going to echo another comment I saw here yesterday: if Mark cared he would put his money where his mouth is and back off datamining IM conversations and enable OTR by default.
Mark only cares because the IC is, in a way, damaging his brand by plainly revealing the dangers of centralized services.
The hypocrisy is Facebook's repeatedly sneaky approach to "permissive" marketing. While Facebook will never have a gitmo or "enhanced interrogation program," that doesn't excuse their complete disdain for user's privacy such as actively tracking the movement of users across the web, for example, data they most definitely didn't volunteer.
- declan 13y ago>back off datamining IM conversations and enable OTR by default. Do you have more info on Facebook "datamining IM conversations?" We learned last year that Microsoft does this: http://www.h-online.com/security/news/item/Skype-with-care-Microsoft-is-reading-everything-you-write-1862870.html http://www.h-online.com/security/news/item/Skype-with-care-M... But I don't recall any evidence that Facebook does. Of course I may be misremembering, and I did write a piece for CNET (before leaving to found http://recent.io http://recent.io) titled "Facebook's outmoded Web crypto opens door to NSA spying": http://news.cnet.com/8301-13578_3-57591560-38/facebooks-outmoded-web-crypto-opens-door-to-nsa-spying/ http://news.cnet.com/8301-13578_3-57591560-38/facebooks-outm...
- MichaelGG 13y agoWe did not learn that Microsoft "datamines IM conversations". All we know is that Skype (like other IM services) has a URL checking service. It's possible that only the URL is sent to Microsoft outside of whatever normal encryption Skype uses. There may be some technical questions we might like answers to (why do HTTP URLs apparently not get scanned; why does it only do a HEAD request), but the most obvious answer is that it's some detail of MS's anti-spam/phishing system.
- ta_fbp 13y agoI remember skype being known for making it possible to spy on user conversations, text and audio/video, way before microsoft bought it. With microsoft moving skype back from p2p to centralized server architecture doesn't hints at making spying on users more difficult.
- MichaelGG 13y agoThat's a separate issue. Obviously Skype could have MiTM connections since forever. They probably were legally required to do so, too. But decoding messages isn't the same as "datamining" them. And it's disingenuous, in context of IMs being datamined for advertising, to call an antispam service datamining, even if it's possibly technically true.
- declan 13y agoThis turns on the definition of "datamining." Surely scanning ostensibly private messages to update a database, even one built for innocuous purposes, especially without clear and conspicuous notice to users, is one form of it. From the H-Online.com article: A spokesman for the company confirmed that it scans messages to filter out spam and phishing websites. This explanation does not appear to fit the facts, however. Spam and phishing sites are not usually found on HTTPS pages. By contrast, Skype leaves the more commonly affected HTTP URLs, containing no information on ownership, untouched. Skype also sends head requests which merely fetches administrative information relating to the server. To check a site for spam or phishing, Skype would need to examine its content.
- intslack 13y ago>Do you have more info on Facebook "datamining IM conversations?" Sure, the post I am echoing is in reference to Facebook "scanning" messages and relationships for criminal activity[1], as well as the suit filed at the end of last year[2] alleging that Facebook datamines messages for URLs to use as part of its ad targeting data. We'll have to wait and see if these allegations are true and whether it implicates the company's constant decree with the FTC[3], but Facebook has already confirmed that it does in fact scan private messages for "anti-spam" purposes[4], even blocking links to thepiratebay iirc. [1] http://www.reuters.com/article/2012/07/12/us-usa-internet-predators-idUSBRE86B05G20120712 http://www.reuters.com/article/2012/07/12/us-usa-internet-pr... [2] http://dockets.justia.com/docket/california/candce/5:2013cv05996/273216 http://dockets.justia.com/docket/california/candce/5:2013cv0... [3] http://www.ftc.gov/news-events/press-releases/2011/11/facebook-settles-ftc-charges-it-deceived-consumers-failing-keep http://www.ftc.gov/news-events/press-releases/2011/11/facebo... [4] http://nakedsecurity.sophos.com/2012/10/08/facebook-scans-private-messages-like-counter/ http://nakedsecurity.sophos.com/2012/10/08/facebook-scans-pr...
- declan 13y agoThanks. I'd say that [2] is an unsupported, so far, allegation. But [1] and [4] do qualify as evidence of FB datamining: examining messsages for TOS violations, and scanning private chats to see what URLs are being shared. Yet another reason to not use Facebook for chat or messages.