Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

271–280 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#271

Earlier quoted context omitted.

>> ...but that protected data was accessed by folks who shouldn't have had it. Facebook handed over the data. They need to understand that they don't have control over it once it leaves Facebook. Is a violation of ToS a data breach? Do we really want to conflate those things?

I understand why Facebook doesn't want to call it a breach. But it seems equally reasonable to me that users see it as one. From the user perspective, private data is suddenly in the hands of unknown, suspicious actors who may use it against them. That Facebook would rather not call that a breach so much as "business as usual" is all the more reason legislators may be inclined to define "breach" the way that voters d…

My intention was to contrast the mundane connotation of "business as usual" with the visceral negative reaction most of us seem to have with our data being used this way.

The point I'm trying to make is that there's a difference between an isolated attack (e.g. Equifax) and what Facebook has going on here. To the person who reads about a "data breach at Facebook", it does sound like this was an abberant event that happened suddenly — rather than systemically, by a machine built on doing this every day.

Cambridge Analytica's actions may illuminate how far this can go, but we should treat it as the norm — and regulate accordingly.

Re: Ex-Facebook insider says covert data harvesting was routine

#272

I see a lot of Facebook sympathizers here. Is this what devs do at Facebook? Browse HN and defend the reputation of Facebook at any cost? Yes we all knew what we were in for when we signed up for Facebook and Instagram. Yes, they can sell our data to show us ads about what coals to buy for July 4th bbq party and we are OK with that. But not to turn blind eye to foreign entities which in return use it against us and j…

I don't work for facebook. I don't have a facebook. I don't like facebook.

What I do like is honesty.

https://en.wikipedia.org/wiki/Data_breach

Look at this very robust list of data breaches and tell me how the CA/Facebook incident this week looks anything like any of them.

Re: Ex-Facebook insider says covert data harvesting was routine

#273
post #32

Earlier quoted context omitted.

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

Even if they complied with your erasure request and deleted everything from all their servers and their backups (spanning the world over a decade), think of all the non-EU third-parties who have your FB data already

GDPR isn't only about data deletion, but also about the transparency of data handling strategies. There was a "nightmare GDPR" letter HN post a couple of days ago that illustrates some of those responsibilities.

Re: Ex-Facebook insider says covert data harvesting was routine

#274

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

You don't even need a developer account. You could just scrape Facebook which is probably what CA did in the first place. They used the app to identify US users and from there on just scrape the pages using a headless browser and multiple proxies.

Re: Ex-Facebook insider says covert data harvesting was routine

#275
post #233

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

All this lawyering over the definition of 'breach' is failing to see the forest for the trees. It is a breach of trust, even if not a breach of technical security controls.

I think there's a meaningful, non-definition difference - and in some ways it makes Facebook look worse.

Metaphorically, somebody had a gun, and someone else took that gun and used it to rob a bank. Equifax left the gun sitting visible in an unlocked car, and people are angry about the predictable results. Facebook was running a "borrow my gun" program for strangers, but had a clause saying "no using my gun for crimes, no lending my gun to any third parties". One of those strangers lent the gun to the robber, and Facebook is saying this isn't their problem because they said not to do that.

So yes, they're both bad outcomes. But "breach" usually means "this was stolen without our knowledge", and that's a very misleading impression to create here.

Re: Ex-Facebook insider says covert data harvesting was routine

#276

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

Listening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative.

HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data.

So, while illustrative, the analogy is not apt.

Re: Ex-Facebook insider says covert data harvesting was routine

#277
post #32

Earlier quoted context omitted.

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

Even if they complied with your erasure request and deleted everything from all their servers and their backups (spanning the world over a decade), think of all the non-EU third-parties who have your FB data already

I wonder if GDPR could be applied to companies I don't have a relationship with but have my data (i.e. CA-type data collection companies)?

Re: Ex-Facebook insider says covert data harvesting was routine

#279

Earlier quoted context omitted.

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

>protected data What data was being protected? The data was created when the user chose to engage with the facebook apps. CA pays facebook to put something in front of users faces and then CA gets back information on user engagement. How is that different than any other kind of advertising on the web? We can argue that there needs to be more transparency on facebook but a breach? That's torturing the word.

CA state that the data was collected by a third party as "academic research" and they didn't know that when it was given to them - so they violated the terms of service in good faith.

Whether you believe them is another matter.

Re: Ex-Facebook insider says covert data harvesting was routine

#280

Earlier quoted context omitted.

>protected data What data was being protected? The data was created when the user chose to engage with the facebook apps. CA pays facebook to put something in front of users faces and then CA gets back information on user engagement. How is that different than any other kind of advertising on the web? We can argue that there needs to be more transparency on facebook but a breach? That's torturing the word.

"protected data" was part of the HIPAA analogy. > This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was accessed by folks who shouldn't have had it. Protected data, in the context of HIPAA, would refer to Personal Health Information (PHI)

Why would the HIPAA standard of a breach apply here? Scraping public data to create a political profile is on par with getting access to private health data?
Post reply on HN