Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

301–310 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#301
post #276

Earlier quoted context omitted.

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

Listening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative. HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are no…

> you'd think the systems were actually compromised

We're seeing a divide between the technical and popular interpretations of the term "breach". When an industry drops the ball and responds pedantically, that's a strong sign that further regulation is needed. If only to force a common language.

Facebook insists they were not "breached" because many states require notification in the event of "security breaches of information involving personally identifiable information" [1]. Each body of law defines "breach" differently. Most do not limit it to technical security malfunctions.

[1] http://www.ncsl.org/research/telecommunications-and-informat...

Re: Ex-Facebook insider says covert data harvesting was routine

#302
post #132

Earlier quoted context omitted.

We're adults here but that doesn't mean we should pursue a higher level of discourse. If you want cursing or other low content, there's always Reddit.

Self-censoring is in no way 'a higher level of discourse'. Not using curse words is one thing, but in some situation (esp. like this where a direct quote is used) there is no real reason to censor swear words in an adult conversation.

Exactly. It's not that you are not using the word if you put several asterisks instead of the actual letters.

Re: Ex-Facebook insider says covert data harvesting was routine

#303
post #291

Earlier quoted context omitted.

> HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data. In order to receive data protected under HIPAA by a covered entity, you have to go through an extraordinarily elaborate and complex legal process. In addition to signing an agreement that (in effect) binds you…

I'll agree with you in characterizing it as a breach of trust. That it is. Operatives in Washington, however, are trying to characterize it as something it is not. It's not Russians hacking in, it's not part of some effort to destabilize democracy, etc. That characterization and demonization is indicative of the mindset of those people and that may be even pose more danger than the breach of trust by Facebook.

> It's not Russians hacking in, it's not part of some effort to destabilize democracy, etc.

I'll avoid the word "hacking" since it's used to mean a lot of different things to different people, but it absolutely could be part of an effort to destabilize or undermine (US) democracy.

What we've seen is definitely a breach of responsibility and a breach of trust. It's also probably a breach of the law, since the data Facebook collects is still subject to some protections (and it's hard to imagine how Facebook could have done all this while adhering to those). And while we don't yet know the motivation or intentions of the people involved in these actions, it could very well be motivated by an effort to destabilize or undermine US democracy. I don't see why you think those are mutually exclusive.

Re: Ex-Facebook insider says covert data harvesting was routine

#304
post #32

Earlier quoted context omitted.

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

No it won't. > [] I want to see dancing monkeys and for that, I agree to have all my data shared with unnamed third and fourth parties indefinitely. See? Everyone clicked that :).

Under GDPR you cannot mix these two things. They cannot force you to accept conditions that are not relevant to the requested item - if you do not accept the opt-in, they are still not allowed to refuse your access to the monkey video, as there is no meaningful connection between said video and all of your data.

It would be different if you had to pay for something, in which case you would have to agree to share your name, credit card etc. However, they still would not be allowed to share it with unrelated (!) third parties.

Re: Ex-Facebook insider says covert data harvesting was routine

#305

Earlier quoted context omitted.

> There is no formal standard of ethical conduct in software for practitioners to use as a baseline for their own behaviour. Such a baseline standard _must_ exist, and _must_ be created. Every applied technology has started out with dreams to "change the world", only to have those dreams shattered by those obsessed with power. Biology? Biological weapons, nerve agents. Chemistry? Mustard gas, TNT. Physics? Nuclear we…

Assuming it _must_ exist, how can we enforce it given that anyone with an internet connection can teach themselves how to make software? There is no centralized accrediting board for programmers, and it’s not very feasible to me when there are so many self-taught programmers today.

In some states anyone can take the Bar Exam to be a lawyer. [1] They all still require time in provable apprenticeship/study in exchange.

Michigan doesn't have a degree requirement for the Fundamentals of Engineering exam to work toward being a licensed Professional Engineer. In general, in the past, the NCEES, which runs the FE and PE exams has made degree exceptions for people with appropriate work experience.

It's absolutely feasible to have accrediting standards and bootstrap in all/most of the self-taught programmers today.

The flip side is admitting defeat and proclaiming software development truly is the new blue collar and has no hopes of truly being a profession.

[1] http://www.slate.com/blogs/business_insider/2014/08/02/state...

Re: Ex-Facebook insider says covert data harvesting was routine

#306
post #276

Earlier quoted context omitted.

Listening to politicos, you'd think the systems were actually compromised, and, in the same breath, boogeypeople from Russia are mentioned in order to conflate things in the mind of the audience. This willful conflation is a tactic to drive a narrative. HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are no…

> you'd think the systems were actually compromised We're seeing a divide between the technical and popular interpretations of the term "breach". When an industry drops the ball and responds pedantically, that's a strong sign that further regulation is needed. If only to force a common language. Facebook insists they were not "breached" because many states require notification in the event of "security breaches of in…

> When an industry drops the ball and responds pedantically, that's a strong sign that further regulation is needed. If only to force a common language.

We already have plenty of regulation here that Facebook is unambiguously subject to; the question is whether the relevant authorities will actually follow through on that.

For what it's worth, it's been two days, and we're already seeing an FTC investigation and a Congressional investigation, so it's a little premature to conclude that existing regulation is insufficient.

Re: Ex-Facebook insider says covert data harvesting was routine

#307

Earlier quoted context omitted.

Even if they complied with your erasure request and deleted everything from all their servers and their backups (spanning the world over a decade), think of all the non-EU third-parties who have your FB data already

I wonder if GDPR could be applied to companies I don't have a relationship with but have my data (i.e. CA-type data collection companies)?

Sure. That's already possible in Germany, where any company has to provide you with the details of their knowledge about you once a year for free: https://selbstauskunft.net/

Re: Ex-Facebook insider says covert data harvesting was routine

#308
Wow. “react only when the press or regulators make something an issue, and avoid any changes that would hurt the business of collecting and selling data.”

From:

https://mobile.nytimes.com/2017/11/19/opinion/facebook-regul...

The scary part is the cat is already out of the bag if you authorised any app. They could have a wealth of your data that is being sold.

Re: Ex-Facebook insider says covert data harvesting was routine

#309
post #145

Earlier quoted context omitted.

German credit scoring institutions collect data on behalf of banks, insurances, etc., and you need to consent that they send data to the credit scoring company. So you are actually consenting. If you never give consent to any such party, the scoring company must not store data about you (and most probably won't, they are tightly observed by data protection agencies). It will become interesting with GDPR, when custome…

I guess he wants to hint you to the fact that the "Einwohnermeldeamt" is allowed to sell your data to a "Addresshändler", see https://www.teltarif.de/datenweitergabe-adresse-einwohnermel...

Yes, that is a legitimate complaint.

I was only referring to the remark about credit scoring companies which I believe to be wrong

Re: Ex-Facebook insider says covert data harvesting was routine

#310

Earlier quoted context omitted.

Another educated rumor: As soon as Al Franken suggests regulating Facebook under Net Neutrality, pictures surface that destroy his political career.

What exactly would Net Neutrality do to Facebook?

Basically the same effect supporters were asking from NN for telecoms:

http://thehill.com/policy/technology/359499-franken-condemns...

“No one company should have the power to pick and choose which content reaches consumers and which doesn’t,” said Franken. “And Facebook, Google and Amazon, like ISPs, should be neutral in their treatment of the flow of lawful information and commerce on their platform.”

And then one week later, his political career was suddenly over. Politicians got the message loud and clear; Don't F* with Facebook.

Post reply on HN