Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

281–290 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#282

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

It's an alleged legal breach of Data Protection principles. That language is used historically by the ICO in the UK to describe exactly this type of situation.

Facebook's responsibilities and Cambridge Analytica's responsibilities towards data protection have been breached.

There's no other useful word for that. It might not be a hack and it might not be a security vulnerability, but it is surely a breach.

Re: Ex-Facebook insider says covert data harvesting was routine

#283
post #204

Earlier quoted context omitted.

> Some of my friends willingly opt into streaming their position in real time continuously through their smartphones How do you avoid this? I have a GPS in my car with stored routing information, but if I need to navigate for someone else or get walking/biking directions, I am forced to do this. Printing out directions beforehand is something I did only a few years ago, but these days I don't always have a chance to…

On Android, you can open your Google account settings and disable their always-on location tracking "service". Of course, you have to take Google's word for it, and that doesn't stop GPS from working for apps like Maps when you request it. I usually leave Location services off. I'll enable them for 5-10 seconds, get the directions from Maps, then disable the Location service again. Of course, they can still estimate…

you can can disable your access to it and its background upload to google. If you read the fine print the "anonymized" gps/cell-tower/wifi data is still used periodically by google to refine their maps etc. Same for apple, same for the GPS in your internet connected car.

Re: Ex-Facebook insider says covert data harvesting was routine

#284

Well of course this was routine. Facebook prides itself on it's data collection and ad targeting. I'm not discounting The Guardian's reporting, but I thought this was known. I mean you can download your data here and see what endpoints/interests you can be targeted on: https://www.facebook.com/help/302796099745838 Sadly, the world will continue to use Facebook and users will continue to be exploited.

That URL doesn't tell me what I really want to know -- what parties used the graph API to download data from me.

Re: Ex-Facebook insider says covert data harvesting was routine

#285

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

You don't even need a developer account. You could just scrape Facebook which is probably what CA did in the first place. They used the app to identify US users and from there on just scrape the pages using a headless browser and multiple proxies.

Unless I’m doing something wrong, a developer account makes this sort of thing harder: you can’t just access anyone’s data, you have to convince them to authorize your app first. . . Which is probably why there’s all these “find which star wars character you are!” quizzes that make the rounds on FB.

Re: Ex-Facebook insider says covert data harvesting was routine

#286

I made a Facebook web scraper which opens 20 headless browsers. You provide a list of unlimited usernames & proxies (you can buy them at https://buyaccs.com/en/ ). It will scrape every ounce of public information available. I acquired a few million users worth. The data is too easy to get.

Everyone who ever googled a name should realise that.

Re: Ex-Facebook insider says covert data harvesting was routine

#287
post #276

Earlier quoted context omitted.

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

Listening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative. HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are no…

> HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data.

In order to receive data protected under HIPAA by a covered entity, you have to go through an extraordinarily elaborate and complex legal process. In addition to signing an agreement that (in effect) binds you to all of the same restrictions on the data that the original covered entity (e.g. hospital/insurer) was, if you're accessing the data for research purposes, you'll have to go through an institutional review of your intended purpose and methods for the research.

Facebook does none of these, which is why they have been (rightfully) criticized for conducting unbelivably unethical studies[0] without either user consent or institutional approval, even though both of those are typically required by all reputable universities and publishers for research.

Facebook posts are not protected under HIPAA, but they're not entirely unprotected either, and it's totally valid to refer to that breach of responsibility and trust as a breach.

[0] e.g. https://www.washingtonpost.com/news/morning-mix/wp/2014/07/0...

Re: Ex-Facebook insider says covert data harvesting was routine

#288

I see a lot of Facebook sympathizers here. Is this what devs do at Facebook? Browse HN and defend the reputation of Facebook at any cost? Yes we all knew what we were in for when we signed up for Facebook and Instagram. Yes, they can sell our data to show us ads about what coals to buy for July 4th bbq party and we are OK with that. But not to turn blind eye to foreign entities which in return use it against us and j…

I don't work for facebook. I don't have a facebook. I don't like facebook. What I do like is honesty. https://en.wikipedia.org/wiki/Data_breach Look at this very robust list of data breaches and tell me how the CA/Facebook incident this week looks anything like any of them.

2006 - AOL search data scandal [1]

>The release was intentional and intended for research purposes;

Sounds pretty damn close to this event with Facebook

[1]: https://en.wikipedia.org/wiki/AOL_search_data_leak

Re: Ex-Facebook insider says covert data harvesting was routine

#290
post #235

Earlier quoted context omitted.

Breach doesn't imply a mistake. Anyway, the idea here is that CA breached Facebook users personal data by methods quite similar to phishing and FB look the other way. Not necessarily by design but maybe by a desire to exploit the platform as much as possible so that did not get in the way of people who were doing interesting things.

We all know what a data breach is, calling this a data breach is playing fast and loose with the term. https://en.wikipedia.org/wiki/Data_breach Look at all the examples of a data breach in this wiki. The CA/Facebook incident looks nothing like them. CA either paid facebook to collected data through apps or scraped data from public profiles. Maybe the CA/facebook incident will change what we consider "breach" to mean…

The first sentence from your link: "A data breach is the intentional or unintentional release of secure or private/confidential information to an untrusted environment."

Sounds like exactly what happened with CA and FB. People came for friends and fun personality tests, their information got into the hands of a propaganda machine. Definitely a breach.

As for the examples, do you want me to edit the Wikipedia article and add the CA/FB incident?

Post reply on HN