Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

291–300 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#291
post #276

Earlier quoted context omitted.

Listening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative. HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are no…

> HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data. In order to receive data protected under HIPAA by a covered entity, you have to go through an extraordinarily elaborate and complex legal process. In addition to signing an agreement that (in effect) binds you…

I'll agree with you in characterizing it as a breach of trust. That it is. Operatives in Washington, however, are trying to characterize it as something it is not.

It's not Russians hacking in, it's not part of some effort to destabilize democracy, etc. That characterization and demonization is indicative of the mindset of those people and that may be even pose more danger than the breach of trust by Facebook.

Re: Ex-Facebook insider says covert data harvesting was routine

#292
post #290

Earlier quoted context omitted.

We all know what a data breach is, calling this a data breach is playing fast and loose with the term. https://en.wikipedia.org/wiki/Data_breach Look at all the examples of a data breach in this wiki. The CA/Facebook incident looks nothing like them. CA either paid facebook to collected data through apps or scraped data from public profiles. Maybe the CA/facebook incident will change what we consider "breach" to mean…

The first sentence from your link: "A data breach is the intentional or unintentional release of secure or private/confidential information to an untrusted environment." Sounds like exactly what happened with CA and FB. People came for friends and fun personality tests, their information got into the hands of a propaganda machine. Definitely a breach. As for the examples, do you want me to edit the Wikipedia article…

Based on many of the comments in this thread I don't see how you could say it "sounds like exactly what happened with CA and FB." Debatable maybe. Clear cut, obviously not.

And as for your glib comment on editing the wiki article, you should read more carefully what I said. My argument was that the numerous examples of a breach in that wiki do not fit the CA/FB incident. Adding the incident to the list would do nothing to dispute that point.

Re: Ex-Facebook insider says covert data harvesting was routine

#293

Earlier quoted context omitted.

Well, the reason is that people in general aren't often ethical, when they seek to benefit personally. It's not taught; it's the default setting. I wish a little philosophy and ethics were part of the curriculum. This would not be to inculcate normative values, but to help eng students clarify what they believe, and what the implications are. That said, most engineers I've met who work on sketchy stuff are either nai…

My undergrad Computer Engineering curriculum as far back as the mid 90’s offered a dedicated “social and ethical issues in computing” course, which included not only ethics but the societal issues around hacking, copyright, automation, robots, etc. Do these courses no longer exist? I think tech professionals ought to agree to Do No Harm and be held accountable when they do. Problem is the vague and debatable definiti…

Every ABET accredited degree (CS and/or CE) has a minimum requirement for ethics courses. The software industry just doesn't have a minimum requirement for accredited degrees (or any degrees at all, for that matter).

Re: Ex-Facebook insider says covert data harvesting was routine

#294

Earlier quoted context omitted.

> Who teaches developers that it's okay to work for anyone as long as the tech is cool and the salary is great? Who teaches them otherwise? Absent parental/primary-school-instilled ethics, rather a lot of engineers operate in a bubble of like-minded (and similarly-employed) people, making large amounts of money, and are often insulated (voluntarily, deliberately, or accidentally) from the impact of their work. What c…

Make your new hires watch the multiple camera feeds and lidar of that woman being run over again and again until they really really understand that they're working on life-critical systems.

I mean that is similar to what they make railway workers in the UK do. Nothing like seeing exactly what happens when it goes wrong to focus the mind

Re: Ex-Facebook insider says covert data harvesting was routine

#295
post #32

The cool thing? This "whistleblower" already spoke publicly with an op-ed on the NYT months ago. Again, this is just the top of the newscycle. Let's see what happens in three months from now. My guess: Facebook revenue will go up. This is a PR shitshow, and a great piece of advertising for Facebook's ad department. A lot of marketers right now are thinking "wait, we could do that with all that Facebook data we have?!…

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

No it won't.

> [] I want to see dancing monkeys and for that, I agree to have all my data shared with unnamed third and fourth parties indefinitely.

See? Everyone clicked that :).

Re: Ex-Facebook insider says covert data harvesting was routine

#296

Earlier quoted context omitted.

I don't work for facebook. I don't have a facebook. I don't like facebook. What I do like is honesty. https://en.wikipedia.org/wiki/Data_breach Look at this very robust list of data breaches and tell me how the CA/Facebook incident this week looks anything like any of them.

2006 - AOL search data scandal [1] >The release was intentional and intended for research purposes; Sounds pretty damn close to this event with Facebook [1]: https://en.wikipedia.org/wiki/AOL_search_data_leak

An analogous example would be if the CA/FB breach had access to private facebook messages or information that was never intended for public consumption.

In the CA/FB case the information was either public (and could be scraped as such) or was collected in the form of facebook apps.

Re: Ex-Facebook insider says covert data harvesting was routine

#297

Earlier quoted context omitted.

That's just your perspective. I live in the Germany where we have very strong data protection laws. Is it natural for people to assume that these laws are broken at such a large scale? And that abuse goes completely unchallenged for years?

Data protection laws are so strong in Germany that they let registration offices sell your data if you don't explicitly opt out. Most people don't even know whats going on and that they have to opt out to avoid that. Or German credit scoring institutions, who are allowed collect data about you even if you don't have any mutual agreement with them.

This registration office law has finally been changed to opt-in just this year.

Re: Ex-Facebook insider says covert data harvesting was routine

#298
post #223

Earlier quoted context omitted.

Ahem: http://ethics.acm.org/code-of-ethics/software-engineering-co... >1.03. Approve software only if they have a well-founded belief that it is safe, meets specifications, passes appropriate tests, and does not diminish quality of life, diminish privacy or harm the environment. The ultimate effect of the work should be to the public good. edit: this version is from 1992 . And I should point out my courses at least h…

How is this enforced? What is software development as a field doing to regulate itself and ensure members follow this guide?

The ACM has certainly tried to keep software development a profession, but yes the industry mostly ignores the ACM and still revels in a cult of amateur programming.

Re: Ex-Facebook insider says covert data harvesting was routine

#299

Earlier quoted context omitted.

You don't even need a developer account. You could just scrape Facebook which is probably what CA did in the first place. They used the app to identify US users and from there on just scrape the pages using a headless browser and multiple proxies.

Unless I’m doing something wrong, a developer account makes this sort of thing harder: you can’t just access anyone’s data, you have to convince them to authorize your app first. . . Which is probably why there’s all these “find which star wars character you are!” quizzes that make the rounds on FB.

It's a little easier than getting everyone to sign up, back at the time this app was circulating if you gave it access to your data the app would also gain access to all of your friends' data. That's why a relatively small number of installs allowed it to hoover up huge amounts of data. So even if you were militant about not granting access, but your grandma clicked a button... Whoops!

Re: Ex-Facebook insider says covert data harvesting was routine

#300
post #26

Earlier quoted context omitted.

Not at all. Just media's desperate hunger for any story that paints Trump in a bad light. The recent video evidence on Cambridge Analytica shows that they were at least shady in their operations. But their approach to targeting voters and scraping Facebook userdata would have been described as brilliant data wizzardry if it were done for the other side.

You can perform brilliant data wizardry without deceiving people. Micro-targeting has been around since the 60s. There is a huge gulf between finding people receptive to an ad whose content you publicly endorse and creating astroturf sites and fake news content to manipulate people's world view. I keep seeing comments which equating cheating and cleverness. If I win a chess game by moving making illegal moves this is…

The Obama campaign literally did the exact same thing as CA.

See this thread: https://twitter.com/cld276/status/975564499297226752

Here's Time describing exactly the same tactic of friend-mining and using the data for targeting, and praising it as a game-changer: http://swampland.time.com/2012/11/20/friended-how-the-obama-... ctrl+f privacy -> no results

When we do it it's awesome, when they do it it's a data breach, it's a privacy violation, it's a breach of trust, and it requires government regulation.

Post reply on HN