Live data from Hacker News

Facebook denies 'listening' to conversations

bbc.com

211–220 of 415 posts

Re: Facebook denies 'listening' to conversations

#212

Earlier quoted context omitted.

Well, I'm (marginally) more comfortable with a company like Facebook having this data compared to... Equifax

Why? FB has agency to actually do something, probably horrible with it. Equifax would just get hacked.

Don't forget the sell out when they finally jump the shark.

Re: Facebook denies 'listening' to conversations

#213

Earlier quoted context omitted.

Right, like the example from Target. It is possible that facebook has access to a stream of Target purchases or credit card purchase information. I'd be 0% surprised if there was a data sharing agreement with credit rating companies. Even if they just knew the price of the purchase, combined with the job (burn risk) and location data (traveled from work to nearest store with pharmacy during the day), it's possible th…

I'm sure Facebook would like to do what you're saying, but I think that they're a long way from having those capabilities. They have billions of users, billions of ads, and trillions of pieces of metadata. Sifting through that to produce a guess like "User 1234 burned themselves and would be interested in product 5678" would be an amazing and scary piece of AI. Not to mention that Facebook are limited by the ads they…

Last year there were 29,000 categories that could be targeted. If an ad sales rep wanted to close a deal, how difficult would it be to add one more for recent burn victims, or people who recently bought a specific product?

From the links that m_ke posted, facebook already has ties to loyalty card information, so it's very possible that they didn't need to do any inference, they just had the data directly.

In any case, the main point is that facebook doesn't need to listen to what people are saying, it has a ton of other data streams that could explain the stories in the link.

Re: Facebook denies 'listening' to conversations

#214
post #208

Earlier quoted context omitted.

> The way I would do this is by issuing a certificate for facebook.com that I mark as trusted on the device. Half the entire point is "mark it as trusted" doesn't work when the application has already pinned the certificate it's expecting. Have you actually done this yourself at all? > But you can probably do this directly on the device: just look for where the encryption is taking place, and intercept it. "Just" int…

I've done all of these things since it's my job. I haven't tried Facebook, because I don't have any confidence in the surveillance hypothesis, but my first guess being inapplicable doesn't change the fact that root access would allow people to prove this is happening, and that hasn't happened. Furthermore, this could be proven with some fair reliability using correlation only. Is more encrypted data sent when you're…

> I've done all of these things since it's my job.

It's weird that this is your day job and yet you tell me that I should mark a certificate as "trusted" when we both explicitly acknowledged that the problem was with certificate pinning. You didn't answer this part: how long does it take you to manage to intercept Android HTTPS traffic for a brand-new, never-before-seen application that uses certificate pinning on your day job?

> I haven't tried Facebook, because I don't have any confidence in the surveillance hypothesis

Well then try it with Facebook. If this kind of thing is really your day job then it shouldn't take long, and you'd do everyone a favor by (a) showing that nothing is going on, and (b) teaching people how to do it themselves so that the myth doesn't keep spreading. People would appreciate it.

> Furthermore, this could be proven with some fair reliability using correlation only.

No, it can't. They don't need to be sending raw audio. They could just do some rudimentary speech recognition and send it along with some other routine data.

> Does the app access the microphone while sleeping? Nobody has presented anything _close_ to evidence.

I've personally logged it accessing the microphone when I've been scrolling on my news feed. Though I don't see why you'd believe me anyway.

Re: Facebook denies 'listening' to conversations

#215
post #185

Earlier quoted context omitted.

This is called the "Frequency Illusion" (also often called / a similar thing is called the "Baader-Meinhof Phenomenon").

I would disagree with that phenomenon. In direct contrast, my awareness of these ads kicked into overdrive after seeing them for the first time, so I was hyper aware and looking out for them afterwards, which is why I noticed they disappeared a day or two after popping up. Since then, my feed has been a bland sea of adverts for mattresses, knives etc. that almost all of my friends complain about seeing. I don't use a…

It would be weird if that sort of coincidence never happened. Two incidents of this happening to you ever doesn’t sound like much. Maybe even a bit low.

If they really are using audio for ad targeting like they do with search history, then it should be easy enough to prove it by experiment.

Re: Facebook denies 'listening' to conversations

#216

Earlier quoted context omitted.

Right, like the example from Target. It is possible that facebook has access to a stream of Target purchases or credit card purchase information. I'd be 0% surprised if there was a data sharing agreement with credit rating companies. Even if they just knew the price of the purchase, combined with the job (burn risk) and location data (traveled from work to nearest store with pharmacy during the day), it's possible th…

My suspicion on this is that stores offer "reward cards" so they can get you to sign something that allows them to gather and sell your data.

Rewards cards / loyalty card are designed to incentivize you to spend more with the stores. Ostensibly reselling data is a lot less valuable than directly trying to convince you to shop more at their establishments

Re: Facebook denies 'listening' to conversations

#217

Earlier quoted context omitted.

There was a backdoor that let the Uber iPhone app record the screen invisibly from the background that went unnoticed for years.

Well no, Apple (in an unprecedented move), granted the Uber app the com.apple.private.allow-explicit-graphics-priority entitlement. "Apple gave us this permission because early versions of Apple Watch were unable to adequately handle the level of map rendering in the Uber app," an Uber representative, Melanie Ensign, told Business Insider. "Subsequent updates to Apple Watch and our app removed this dependency, and we…

What is the meaningful difference, in the context of tedunangst's post, between an entitlement that allows surreptitious recording of video and a backdoor that allows surreptitious recording of audio?

Re: Facebook denies 'listening' to conversations

#218

They're listening, but not to your voice or with a microphone. Facebook is listening to your data--to all of our data, all at once. They have locations, searches, clicks, messaging, photos, hashtags, and any other form of browsing patterns for everyone in your country, everyone in your neighboorhood, everyone in the same room as you. They have enough data with such advanced analysis that on occasion they can get real…

Right, like the example from Target. It is possible that facebook has access to a stream of Target purchases or credit card purchase information. I'd be 0% surprised if there was a data sharing agreement with credit rating companies. Even if they just knew the price of the purchase, combined with the job (burn risk) and location data (traveled from work to nearest store with pharmacy during the day), it's possible th…

"It is possible that facebook has access to a stream of Target purchases" ...

It's not possible, it's simply true. In fact, this feature of the facebook ad platform is available to any advertiser on Facebook/Instagram/etc, whether you have $100 to spend or $100M.

You simply upload your customer's purchases to Facebook with data such as zip code, email, etc etc which Facebook then uses to optimize your advertising budget and find more customers similar to the ones you already have (the feature is called look-alike audiences).

Re: Facebook denies 'listening' to conversations

#219
What can we do to prevent this? Use another service? Make it more difficult to link information together with use of per-website generated emails, burner phones, etc? Just seems there is room for something to come along and change the game, just not too sure what that thing is.

Re: Facebook denies 'listening' to conversations

#220
A fairly reliable and simple test is this: leave your phone around content for several hours of a different language and see if ads related to that language show up.

It's surprising to me that people here are still debating this. I believe it's been going on since the original iPhone came out after a friend told me a very specific product appeared for her on Facebook immediately after she spoke about it and went to go look it up on her phone.

I don't think Facebook would stop at any measure to get all the data they can from you if they can get away with it and frankly anyone who does is extremely naive. It's right there available to them. There has never been and may never again be a time when companies (particularly Facebook and Google) to obtain as much sensitive data as is available to them from us without our knowledge, without external oversight, and without repercussions due to the lack of legislation.

Post reply on HN