Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

241–250 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#241

I still don’t understand the breach part. It just seems like Facebook app developers used Facebook exactly as it was set up, and then resold the data.

It is more of misuse than a breach. The data was provided to a guy for academic research, but the guy sold it to a third party. That is where the 'breach happened.

Re: Ex-Facebook insider says covert data harvesting was routine

#242

Delete your Facebook/Instagram/Whatsapp accounts.

I say wipe them. I have been deleting data for the last couple of days, I don't need old comments and likes - even pictures as I have them myself.

This was I can slowly phase it out, this has been my plan all along, but I need some time to make all logins work without facebook ect.

My intent is to delete it eventually. Until then no new content, and wiping the old content.

Re: Ex-Facebook insider says covert data harvesting was routine

#243
post #223

Earlier quoted context omitted.

Ahem: http://ethics.acm.org/code-of-ethics/software-engineering-co... >1.03. Approve software only if they have a well-founded belief that it is safe, meets specifications, passes appropriate tests, and does not diminish quality of life, diminish privacy or harm the environment. The ultimate effect of the work should be to the public good. edit: this version is from 1992 . And I should point out my courses at least h…

How is this enforced? What is software development as a field doing to regulate itself and ensure members follow this guide?

I think ethical guidelines by definition are not enforced per se. They're just that, guidelines. However, as mentioned by GP there are boards of ethics at universities and medical/engineering organizations and such that might be able to dole out a modicum of justice.

For instance, not following those guidelines would conceivably end one's membership of the ACM, and many companies have their own ethical guidelines (I would argue there is not much difference between professions for what is truly considered "ethical") which when breached would result in disciplinary action. Theoretically?

Perhaps not in the case of FB...

Re: Ex-Facebook insider says covert data harvesting was routine

#244

Earlier quoted context omitted.

Lol, "this is bad"? This is normal. I can give you an entire list of F500 companies I've worked at that have the same mindset. I've sat in meetings with F100 CIOs where they were given the same warning and shrugged it off. I've been asked before to turn off security monitoring systems because executives prefer to not know about vulnerabilities rather than know about them and not be able to fix them. The only thing sh…

People love to pretend to be horrified by things they've assumed to be true. "What? A politician is corrupt? Outrage!!" "What? They're tracking me to build profiles on my use of all their advertising driven free services? Outrage!!" I'm sure there's a word for it in German.

The applicable German-language meme would be this (from a French movie btw!) https://youtu.be/w4aLThuU008

"Shocking" fact is revealed. "No!" "Yes!" "Whoa!"

It's a sarcastic way to say "what else is new?".

Re: Ex-Facebook insider says covert data harvesting was routine

#246
post #238

Earlier quoted context omitted.

Was this a security breach in the sense that the company with the data got “hacked”? No. Was this a breach in trust to Facebook users? I think undoubtedly yes. And was there a breach of a the Terms of Service by companies taking all this data and using it for non-academic purposes? Yes there was. So the type of breach seems to be a worthwhile distinction to make.

>Was this a breach in trust to Facebook users? I think undoubtedly yes. How naive is the average person? The purpose of facebook is to gather this information, hence why its offered as a "free service". Frankly, I don't understand why the stock is going down, facebook is fulfilling its core mission: Get private information on millions of people and package that information for sale to its clients. If anything CA situ…

The average person is incredibly naive with regards to what the cost of a "free service" like Facebook is. It's not until you start looking at people who are in related fields that you start seeing people who truly understand the costs.

The public waking up to this breach and the costs being exposed are probably a huge part of why the stock is dropping. Facebook's continued profitability and success is dependent on its users not understanding how their data is being used. And now "everyone" knows, so the secret is out and hopefully Facebook can't get away with this going forward.

Re: Ex-Facebook insider says covert data harvesting was routine

#247

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

>protected data

What data was being protected? The data was created when the user chose to engage with the facebook apps. CA pays facebook to put something in front of users faces and then CA gets back information on user engagement. How is that different than any other kind of advertising on the web?

We can argue that there needs to be more transparency on facebook but a breach? That's torturing the word.

Re: Ex-Facebook insider says covert data harvesting was routine

#248

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

Sounds like a breach to me. The only difference is that instead of the baddies having to sneak in carefully at night to nick stuff, Facebook said 'welcome, come on in, help yourself – here's a sack'. The end result – millions of people having their personal data used against them without their knowledge or consent - is the same.

To me, calling it a breach is Facebook's attempt at passing the buck. Getting breached alleviates some responsibility for what happened. Maybe not in reality, but in how it's portrayed in the media and how it's understood by laymen it absolutely does.

Re: Ex-Facebook insider says covert data harvesting was routine

#249
post #24

Earlier quoted context omitted.

It reminds me of the Snowden leaks about mass surveillance programs like PRISM. I think most technical people expected something like that to exist ever since the internet became mainstream. Still, if it's just an "educated rumor" without hard evidence there's not much for the media to talk about. Up until now you could only say "it seems pretty likely that Facebook is doing something like that, but we don't know for…

I think the trust is a new thing though, new to the social media age. I remember growing up with computers in the 90's and people I knew wouldn't even consider entering a credit card number on a website. Now we give them freely. People used anonymous handles on AIM. At some point this changed and people decided they could be themselves on the internet, which is a fine idea, but the trust just went too far.

This was visible when using credit cards in stores, too.

1990s: your signature needs to match exactly so we know it's really you!

2000s: you must enter a PIN that hopefully only you know?

2010s: fuck it just tap the card near the reader

Re: Ex-Facebook insider says covert data harvesting was routine

#250
post #24

Earlier quoted context omitted.

It reminds me of the Snowden leaks about mass surveillance programs like PRISM. I think most technical people expected something like that to exist ever since the internet became mainstream. Still, if it's just an "educated rumor" without hard evidence there's not much for the media to talk about. Up until now you could only say "it seems pretty likely that Facebook is doing something like that, but we don't know for…

Another educated rumor: As soon as Al Franken suggests regulating Facebook under Net Neutrality, pictures surface that destroy his political career.

This doesn't even strike me as crazy or "out there" anymore, which is so sad.
Post reply on HN