Live data from Hacker News

Facebook Doesn’t Tell Users Everything It Really Knows About Them

propublica.org

251–260 of 275 posts

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#251
post #204
post #191

Earlier quoted context omitted.

> open source everything Sure. Like they open sourced their Blu-Ray cold storage system. Oh, wait, if they do that, people will realize they should be sued for using the word "delete", since you can't remove data from Blu-Ray.

The standard way to do this is to store the data encrypted, and store the key in something modifiable. Then when there's a delete you scramble the key.

So who is auditing Facebook, making sure they actually do that?

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#252
post #248

Earlier quoted context omitted.

If the ability to enumerate targets for holocaust is our concern, then tech companies are a bizarre place to start caring. The institutions we should be attacking are the DMV, voter registration, and the Social Security Administration

Why that? The data collection you're talking about is relatively constrained and transparent - all those institutions have a well-defined range of data they are allowed to collect, using well-known procedures. On the other hand, the data private organisations collect is not restricted - neither what data is collected, nor how or from who. If voter registration started to ask for skin color, there would be immediate p…

Why does the subject knowing about it make it any less useful for genocidal purposes?

You pretty much need a state ID or drivers license, which lists your skin color. Political contributions are a matter of public record for anticurruption purposes. Vital records offices are more than sufficient for tracing ancestry. Welfare offices know who is poor and medically needy. Telecoms and the post office knew who you communicated with.

There was more than enough information to mount a holocaust on any of those axes long before the current crop of tech companies.

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#253
post #249

Earlier quoted context omitted.

It's easy to forget on HN, but there is far from universal buy-in for the notion that having or collecting data on people is unethical. Some may even consider it noble to optimize and perfect the world and its institutions (including commerce, via efficient advertising) using large-scale personal data. The impulse to make something better by applying a database engine that you might feel for business processes, can j…

> Some may even consider it noble to optimize and perfect the world and its institutions (including commerce, via efficient advertising) using large-scale personal data. Data they don't own. So I suppose, "noble" in the Robin Hood kind of way. Also, "efficient" in what way? What metric do they optimize that lets advertising benefit society?

[deleted]

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#254
post #245

Earlier quoted context omitted.

Not everyone agrees with your ethics. I have no financial stake in Facebook (don't work there), but really don't see many moral problems with what it does. And I think their mission of connecting the world in a single easily discoverable network is absolutely world-changing and noteworthy. It's changed my world for sure.

I think a lot of fear is rightly grounded in history: it's clear that this much power in very few hands turns to shit at some point. Facebook may well be humanity's biggest concentration of power (knowledge being power). How do you keep an advantage when the other side knows >> than you could ever know? There's also the disparity in availability of AI, since large applications need powerful and thus expensive hardwar…

To be clear, I don't think Facebook is flawless. All the issues you bring up are definitely true.

I just think it's unfair to assume that these issues automatically make Facebook evil and that there's no good they do.

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#255

I cant speak for other countries, but why do American people seem to trust companies more than they do the government? I mean, it is completely known that companies are here to make money, and publicly traded companies are here to please their investors so they will do whatever it takes to do that. They study us, classify us, categorize us, manipulate us. They spend billions in research so they can make that 'perfect…

I think the reason is that government is vastly more powerful than any single company.

Yeah that's definitely true, and it is what makes me question a lot of why they do what they do and distrust it generally. But would it be better if a company was vastly more powerful than the government?

Actually, I think some companies kind of are in some aspects. They may not have the military, but some definitely have a hand on the reigns.

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#256
post #239
post #139

Earlier quoted context omitted.

That seems particularly absurd (which isn't to doubt you, but as much as I like the EU, they have some absurd policies). If you take a very narrow view of data as just bits on a hard drive somewhere, then this seems reasonable. But if the ownership right to your data is centered on the information itself, and not the company part, that raises issues. I can't simply destroy the memory of reading the message you wrote…

It's simple: you don't get to store data unless there's a technical requirement to keep that data stored to provide whatever service a user signed up for. If a user didn't agree to their data to be stored in the first place, you don't get to retain it at all. Whether you can discard data about a user "against their wishes" is likely covered by your terms of service. If you're a commercial hosting provider, there's pr…

Well, the cookie notice also only is ridiculous if taken out of context.

You literally have the cookie notice in your post, too, as the law simply states:

If you collect any tracking data about a user that's not technically required, you have to let them opt in.

This obviously means tracking cookies have to be opt in, and that's how the cookie notice came to be.

Technical cookies, such as login cookies, are exempt, obviously, but other tracking methods, such as storing in localStorage are included.

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#257

Earlier quoted context omitted.

Well, the go-to example is usually the Netherlands (they had a central registry of all Jews, so the Nazis invaded, and managed to eradicate almost all in mere weeks), but yes. And the StaSi, with constant surveillance of everyone in East Germany, also is still in collective memory, and another reason why no one wants that much surveillance (although acceptance for surveillance went up since the Berlin attacks, quite…

I went to the Stasi Museum recently. And I remember thinking if you traded the physical surveillance(a man in a van) for the now near ubiquitous security cameras, both the US and the UK are on par with the surveillance state that was the former East Germany. Albeit a much more technologically advanced one. It's a sad irony. What is the evidence that acceptance of being surveilled went up since the attacks? Opinion po…

Opinion polls show that after a few days of searching for the attacker unsuccessfully, which could ahve easily been solved if we knew what he looked like (surveillance), the support for more surveillance went up.

And no, I don't know much about why the Netherlands had such a registry — just that they did.

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#258

Earlier quoted context omitted.

It's easy to forget on HN, but there is far from universal buy-in for the notion that having or collecting data on people is unethical. Some may even consider it noble to optimize and perfect the world and its institutions (including commerce, via efficient advertising) using large-scale personal data. The impulse to make something better by applying a database engine that you might feel for business processes, can j…

The problem I have with it is that Facebook decides what "improve" means -- it tries to groom me like cattle rather than ask me how I want to experience it or who I want to be "optimized" in to being. And that's okay, so far as they're open about it. But I don't think they are, especially the sophistication of their psychology research (and experimentation).

I appreciate that, but most people don't know how they want to experience it. E.g. people will say they want to see everything in their feed, but if they do get everything, they complain about how much crap there is

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#259
post #239

Earlier quoted context omitted.

It's simple: you don't get to store data unless there's a technical requirement to keep that data stored to provide whatever service a user signed up for. If a user didn't agree to their data to be stored in the first place, you don't get to retain it at all. Whether you can discard data about a user "against their wishes" is likely covered by your terms of service. If you're a commercial hosting provider, there's pr…

Well, the cookie notice also only is ridiculous if taken out of context. You literally have the cookie notice in your post, too, as the law simply states: If you collect any tracking data about a user that's not technically required, you have to let them opt in. This obviously means tracking cookies have to be opt in, and that's how the cookie notice came to be. Technical cookies, such as login cookies, are exempt, o…

True, but I would argue that the idea of cookie notices is good but the execution is poor.

This is one of the few situations where a technical solution would have been better, e.g. having each cookie come with a specified purpose and letting the browser prompt per issuer and displaying the purpose to the user:

* 3 cookies from ads.google.com: "Personalizing the advertisements you see on this page" [Allow] [Deny]

* 1 cookie from share.facebook.com: "Social media integration" [Allow] [Deny]

* 1 cookie from analytics.example.com: "Anonymized site analytics. For more information see http://example.com/privacy. We value your privacy." [Allow] [Deny]

* 1 cookie from www.example.com: "Keeping you logged in as kuschku on www.example.com" [Allow] [Deny]

But this would require passing an actual web standard and getting browser vendors on board (and Chrome has a conflict of interest making them unlikely to support it without sufficient pressure).

This would have satisfied the legal requirement without creating the obnoxious obligatory "Please click 'okay' or we'll keep showing this message on every page" experience we have now. It would also be less error-prone because the failure state would be "users might deny unjustified cookies" rather than "site will send cookies regardless" when not implemented correctly.

Besides, browsers already ask for permissions for things like desktop notifications or geolocation.

EDIT: I'm not saying this shouldn't have been passed into law. I'm saying the EU should have involved browser vendors and investigated a technical solution before making the notices mandatory. Compliance would have then be easier ("just add these headers") and adoption would have been faster ("it's easy to fix and it's the law").

EDIT2: Unlike the old Semantic Web problem of websites being liars I don't think deceptive purpose statements for cookies would have been a noteworthy issue because it would be literally against the law in the EU to deceive users. It would also have imposed the burden on the actual cookie issuers and created incentives for EU websites to hold their advertising providers accountable to comply with EU laws (rather than build a kludge around them to make their scripts opt-in).

Re: Facebook Doesn’t Tell Users Everything It Really Knows About Them

#260
> One Facebook broker, Acxiom, requires people to send the last four digits of their social security number to obtain their data.

This is just one of the many WTFs that Facebook apparently actively supports.

In what world, what possible explanation was this ever a good idea? Or a reasonable idea? Either the US SSN is like a password (it's not) then how did Acxiom get their hands on it, or it isn't (correct) and it doesn't serve the purpose for identification.

Letting this sort of crap run wild also affects what is considered "normal" or common privacy in other parts of the world, like the EU, it slides the window. Continuously pushing the boundaries against people watching helplessly as layer upon layer of foundations of surveillance are built. Authorities don't do much until adoption is way beyond the curve of network effect, or they do it weirdly. And by then people think it's normal or acceptable.

Already now, on countless popular sites, advertising transgresses heavily on not only guidelines but also law. Medical claims, product placement, child advertising, you name it.

What can we do to not make the lowest common denominator decide what's normal?

Post reply on HN