Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

181–190 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#181

tell me again why you think the EU General Data Protection Regulation (GDPR) is a bad idea?

I was actually surprised by the generally positive reaction the GDPR got in recent threads here on HN. I guess the suspicion of data hoarding overcame conspiracy theories about government regulation or EU protectionism. BUT it’s important to note that GDPR would probably not have had an effect on the specific situation with Cambridge Analytica. CA is obviously toast if not by law then by the attention alone. Facebook…

>they got the users’ permission initially, and there isn’t much you can do to protect yourself against malicious actors.

The EU is clearly moving against that blatant circumvention. I don't know exactly what they are going to do, but the whole, "just sign all your rights to privacy way with one click" is something they want to change.

I think the mostly likely situation will be one where each specific instance of use of your data would need explicit approval. Moreover the prompt cannot be disingenuous legalese. It needs to be clear and concise. I fear it might just become another Cookie's Law. But it might still be useful. For example, imagine if you get something like:

"Facebook discovered that you have Chronic Illness 1. Facebook requests permission to share this information with Insurance Company in your State. Do you approve?"

I think people would suddenly care about that.

Re: Ex-Facebook insider says covert data harvesting was routine

#182
post #26

Earlier quoted context omitted.

Not at all. Just media's desperate hunger for any story that paints Trump in a bad light. The recent video evidence on Cambridge Analytica shows that they were at least shady in their operations. But their approach to targeting voters and scraping Facebook userdata would have been described as brilliant data wizzardry if it were done for the other side.

... or not http://www.washingtonpost.com/wp-dyn/content/article/2006/03...

Did you actually even read your own link? I don't think it says what you think it says. That story you linked is about how democrats in 2006 wanted to do more data collection but couldn't agree on whether it should be the DNC or a private firm that did the data collection. The one thing they could agree on was that data collection was something they should be doing.

Re: Ex-Facebook insider says covert data harvesting was routine

#183

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

Let's please do better than HIPAA. It was the first such law that I know of, and there are a lot of kinks to it. Many subsequent laws were able to learn from its mistakes.

One of the big weaknesses of HIPAA is that the privacy requirements technically apply to the data custodians, not the data. That allows for some loopholes through which private information can fall out of HIPAA protection, and also creates some unnecessary hassles for health care providers.

Ontario's PHIPA is one example of a better model for patient privacy.

Re: Ex-Facebook insider says covert data harvesting was routine

#184
post #132
post #90

Earlier quoted context omitted.

Why do we censor words? Aren't we all adults here? Does HN have a policy about this?

We're adults here but that doesn't mean we should pursue a higher level of discourse. If you want cursing or other low content, there's always Reddit.

Self-censoring is in no way 'a higher level of discourse'. Not using curse words is one thing, but in some situation (esp. like this where a direct quote is used) there is no real reason to censor swear words in an adult conversation.

Re: Ex-Facebook insider says covert data harvesting was routine

#185

Earlier quoted context omitted.

Lol, "this is bad"? This is normal. I can give you an entire list of F500 companies I've worked at that have the same mindset. I've sat in meetings with F100 CIOs where they were given the same warning and shrugged it off. I've been asked before to turn off security monitoring systems because executives prefer to not know about vulnerabilities rather than know about them and not be able to fix them. The only thing sh…

"Better to ask forgiveness after than ask permission before."

You've clearly never tried helping yourself to someone else's chips at pub closing-time in Glasgow.

Re: Ex-Facebook insider says covert data harvesting was routine

#186

Earlier quoted context omitted.

I agree with you that not everything is perfect in Germany with respect to data protection. Not even close. However, our data protection laws are uncontroversially stronger than elsewhere (specifically compared to the US), and I'm almost certain that the courts will find that Facebook violated them.

Maybe, but what sucks about Germany and the EU is the arbitrary nature of many laws, enabling them to selectively punish those who don't play their game. By not being able to define clear boundaries, you give them the power to rule over who can succeed and who not. Data is what fuels businesses in the end.

> but what sucks about Germany and the EU is the arbitrary nature of many laws,

In what way is the law used arbitrarily? I would like some sources for this claim.

Re: Ex-Facebook insider says covert data harvesting was routine

#187
post #3

What's utterly horrifying about this whole thing is how the media is acting as if this is some sort of surprise. Like what did you think was happening at a company collecting data about billions of people? Especially at a company that has a CEO who is famous for calling its own users dumb fu * * s? A company that experimented on at risk teens. Like come on. --edit--- Or lordy, didn't expect this comment to blow up th…

> Like what did you think was happening at a company collecting data about billions of people?

"A more productive answer to someone saying something you agree with is “I agree”, not mistakenly berating them for not agreeing sooner." (https://news.ycombinator.com/item?id=16627766)

It's not like huge numbers of people didn't know about global warming before society started caring about fixing it.

Re: Ex-Facebook insider says covert data harvesting was routine

#188

Earlier quoted context omitted.

Sounds like a breach to me. The only difference is that instead of the baddies having to sneak in carefully at night to nick stuff, Facebook said 'welcome, come on in, help yourself – here's a sack'. The end result – millions of people having their personal data used against them without their knowledge or consent - is the same.

"Breach" specifically implies that defenses were penetrated. But as you said, Facebook is not trying to protect our data. This is far worse than if the data were taken from them unwillingly, because it vastly increases the number of entities with unfettered access to it.

> ”Breach" specifically implies that defenses were penetrated

It’s time to update the definition. “Breach” means you lost my shit. I thought I gave it you in confidence and then you lost it. Facebook arguing “this isn’t technically a breach” comes across as their yet again talking down to users to slip problems under the rug.

Re: Ex-Facebook insider says covert data harvesting was routine

#189
post #76

Earlier quoted context omitted.

> and surprising for most users of Facebook Yeah, but let's be honest, they're dumb fu * * s.

No, they're not. Look, I'm a developer, I'm somewhat privacy-conscious, and I quit Facebook years ago because they're slimy. But "doesn't keep up with technology and privacy news" is not the same as "dumb". For any product as big as Facebook, there are people of all kinds using it, including many who are brilliant. Is it wise to trust Facebook with your data? No. But not having come to that conclusion doesn't make so…

Parent comment is making a sarcastic reference to Zuckerberg's comments about facebook users.

http://www.businessinsider.com/embarrassing-and-damaging-zuc...

Re: Ex-Facebook insider says covert data harvesting was routine

#190

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

It's definately a breach, just not breach into Facebook's technical infrastructure.

As I wrote previously, don't you think that it can be a breach in the same sense of a breach by phishing? After all, both of the cases are about people giving their "secrets" for one reason but the info being used for something else. I mean, in the case of traditional phishing the user is tricked to provide the password by impersonating a banking site, getting their funds stolen and in the case in question, the users are tricked to provide personal information by being promised some kind of personality analysis but their data is used for political propaganda that they didn't asked for resulting in life-changing consequences du to politics.

Post reply on HN