Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…
It's an alleged legal breach of Data Protection principles. That language is used historically by the ICO in the UK to describe exactly this type of situation. Facebook's responsibilities and Cambridge Analytica's responsibilities towards data protection have been breached . There's no other useful word for that. It might not be a hack and it might not be a security vulnerability, but it is surely a breach.
> A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
Most of the breaches I'm familiar with are accidental - people putting their research on thumb drives and losing them, etc etc.
Whether the fox gets into the chicken shed, or you let the chicken out of the safety of the shed, it's a breach of the chicken's security.