Live data from Hacker News

Facebook's tentacles reach further than people think

bbc.co.uk

191–200 of 302 posts

Re: Facebook's tentacles reach further than people think

#191
post #4

The bigger problem for me is how facebook tracks and identifies even people who do not have a facebook account. They simply infer such a person exists from photograps, contacts and other one sided activity and can start to track that person, tie all this information together and then target them with ads even though they never signed up for Facebook. Such shadow profiles are a much larger problem to me than people wh…

Where will they post these ads if I don't visit facebook?

Re: Facebook's tentacles reach further than people think

#192
post #137

Earlier quoted context omitted.

An easy disarm is "You are confusing privacy with secrecy. It is no secret what happens in the bathroom. It doesn't mean we are going to remove the doors because people still want privacy"

No, that's not an easy disarm. They just say "you're welcome to watch me poop".

That's why you only bring this up with attractive individuals.

Re: Facebook's tentacles reach further than people think

#193
post #123

In computer security, every time machines become fast enough to breach the limits of an algorithm we invent something new so that “hard” problems remain “hard” and therefore encryption is still secure. There has been no corresponding increase in the difficulty of invading privacy. 30 years ago, even though you probably “could” observe somebody for a long time and eventually connect some dots about them, it would not…

I would love if someone made a Chrome extension that encrypted all the posts and messages you put on Facebook. That is, any post you made would be made as a ciphertext, the extension would swap keys with all your friends in the background, and would decrypt their posts when displaying them to you. Sure Marky Mark still sees when you post, who you send messages to, etc. but it's a much better situation than what's goi…

If you have out-of-band connections with all your friends and you have friends who are willing to jump through weird, nerdy, technical hoops, what do you need Facebook for?

Re: Facebook's tentacles reach further than people think

#194
post #123

In computer security, every time machines become fast enough to breach the limits of an algorithm we invent something new so that “hard” problems remain “hard” and therefore encryption is still secure. There has been no corresponding increase in the difficulty of invading privacy. 30 years ago, even though you probably “could” observe somebody for a long time and eventually connect some dots about them, it would not…

I would love if someone made a Chrome extension that encrypted all the posts and messages you put on Facebook. That is, any post you made would be made as a ciphertext, the extension would swap keys with all your friends in the background, and would decrypt their posts when displaying them to you. Sure Marky Mark still sees when you post, who you send messages to, etc. but it's a much better situation than what's goi…

At this point you are bootstrapping a parallel social network, with all the pitfalls this entails.

Re: Facebook's tentacles reach further than people think

#195
post #22

Earlier quoted context omitted.

Nothing will change until the law cracks down on this. The people who work on these systems are smart enough to comprehend the wider consequences, but they do it anyway because money. Without significant external pressure, there will always be a long line of engineers willing to dial their cognitive dissonance up to 11 and build software that is clearly unethical in exchange for a fat paycheck.

In the EU the law just did crack down on this with the new EU Data Protection Directive[1]. The DPD covers not only EU based companies, but also any company that provides services for EU citizens in the EU (so, Facebook, LinkedIn etc. are covered by this..but also e.g. your little weather app). The new DPD is strict compared to previous regulation, but there are two parts of the directive that a particularly interest…

> The Data Portability concept: A company covered by the DPD is required to deliver to the user all data the company has on the user, in a standardised format. That means Facebook now has to hand out all your data (information, pics, likes, posts,...) for you to use freely - also in other services. I think this in effect means you own your data. I'm excited to see the effect of this one.

The problem here is that those companies use fingerprinting to collect data. This means that in theory they are not 100% sure who is the person they are collecting data from, but in practice they could be 99.99% sure. Still, this makes it impossible to hand out all this data, because there is still a 0.01% chance that the data does not belong to the person who requested it.

Re: Facebook's tentacles reach further than people think

#196
post #172
post #149

Earlier quoted context omitted.

Well, your moral principles are very different from mine. I don't feel like I (or the state) should have a say about what goes on inside of Facebook's servers, they can do whatever they want with the information they have as long as the don't use coercion (to me, freedom is the lack of coercion). That said, I do believe that there's a practical problem, but it's us that must try to solve it, we must educate people, w…

The state is our collective will, on a national level. People like to refer to them and us but the government is us.

The state is the collective will of a relatively small group of people with money and power. Most people have no influence at all. That's how it always has been. I think the only way to maximize freedom is to support small, local governments.

Re: Facebook's tentacles reach further than people think

#197

It annoys me how much I want to leave Facebook (if only to stop them gathering MORE data on me - I can't erase what they have) but don't because of the convenience of getting in touch with or finding out more about whoever I meet in meatspace. The fact that they try to force me to install their messenger app by making messaging through a mobile browser difficult is particularly infuriating and reveals how much they h…

> The fact that they try to force me to install their messenger app Treat it as asynchronous communication, using a client like Swipe for Facebook (for Android, don't know about iOS alternatives) to look at messages when you feel like doing it. Use another app for synchronous purposes. Facebook's own WhatsApp is a lot more secure, for starters.

If you have the option, hosting your own bitlbee instance with bitlbee-facebook plugin [1] could be even better, since you can access it with any irc client you like. The additional benefit of always being logged in (and messages being marked read as soon as the come) is that facebook has no way to monitor your passive usage of their chat service.

[1] https://github.com/bitlbee/bitlbee-facebook

Re: Facebook's tentacles reach further than people think

#198

Earlier quoted context omitted.

You're so close to what I am currently building that I feel like I have to chime in. I left Apple's security team a few months ago to go solo and build an app that is similar to Facebook/Instagram and Snapchat in terms of functionality and UX but uses the Olm protocol (similar to Signal) to protect all content. So, fear not - something is being done, and I'm sure I'm not the only one working in this problem space. I…

I'm skeptical as to how worthwhile your effort is as long as the outcome is just another alternative to FB. We've seen countless examples of how these alt-social nets failed. But I do see a lot of value in the tech you might be developing, and if in some way we could embed it into existing social nets, that would be amazing. Fingers crossed!

How easy would it be for Zuck to just update the TOS to say "encrypted content is against our TOS" and ban you?

Zuck can't add any encrypted content to your personal profile, which means he doesn't make any money off you. And Zuck can do pretty much whatever he wants in his castle, I'd say.

Re: Facebook's tentacles reach further than people think

#199
post #122

Earlier quoted context omitted.

Security breaches are bad for one party's capital, good for another party's capital. It's interesting to contemplate WHY is there a difference between the two. Security and Private both nasciently have something to do with "info I'd like to keep to myself", but I'm not sure I can come up with a hard delineation between the two, at least when you try to go above "A/S/L" and below "user/pass".

A security breach allows to use the victim's resources: from CPU and bandwidth to money directly on your bank account. A privacy breach allows... what? Where's a direct threat? A privacy breach can be a first step to a security breach, though. Social engineering is all about it. Social networks can be, too.

>A privacy breach allows... what? Where's a direct threat?

A privacy breach could mean that your job application is rejected, that you pay higher interest on a loan or higher insurance premiums.

It could mean that your health insurance refuses cover for some treatment because some data points towards a pre-existing condition.

You could be rejected as a tenant based on the scoring done by a referencing agency or you could get searched every time you cross a border.

In a more unlikely event could even become the victim of a miscarriage of justice or get blackmailed by a corrupt government official.

Re: Facebook's tentacles reach further than people think

#200
post #123

Earlier quoted context omitted.

I would love if someone made a Chrome extension that encrypted all the posts and messages you put on Facebook. That is, any post you made would be made as a ciphertext, the extension would swap keys with all your friends in the background, and would decrypt their posts when displaying them to you. Sure Marky Mark still sees when you post, who you send messages to, etc. but it's a much better situation than what's goi…

Eh, your head is in the right place, but honestly if you have all the meta data, the message content almost isn't needed.

Exactly. I also think that encrypting data is a smokescreen to gain brownie points. Yes, it is more secure than not encrypting messages but the effect of message encryption on your privacy is very low.
Post reply on HN