Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

381–390 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#381

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

Was this a security breach in the sense that the company with the data got “hacked”? No. Was this a breach in trust to Facebook users? I think undoubtedly yes. And was there a breach of a the Terms of Service by companies taking all this data and using it for non-academic purposes? Yes there was. So the type of breach seems to be a worthwhile distinction to make.

> Was this a breach in trust to Facebook users? I think undoubtedly yes.

What's interesting about this is the fact that the same data is shared with many third-parties, with proper "consent", and users not understanding what's really happening. Calling this a "breach" has the slight unintended side-effect in the public by promoting the idea that this company received a different dataset than other partners, which is not the case.

Re: Ex-Facebook insider says covert data harvesting was routine

#382
post #32

Earlier quoted context omitted.

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

It will offer a possibile solution in Europe, where Facebook has already been under heavy scrutiny. It won't change anything in the US, South America, SE Asia and developing countries where Facebook is already dangerously synonimical to the whole online experience of the average user.

> developing countries where Facebook is already dangerously synonimical to the whole online experience of the average user.

Was that not the case with AOL in the US in decades past?

Re: Ex-Facebook insider says covert data harvesting was routine

#383
post #291

Earlier quoted context omitted.

> HIPAA data is accessed by researchers, sometimes anonymized, but not in all cases. These are not considered breaches. In addition, as others indicate, FB posts are not, at least at this time, protected data. In order to receive data protected under HIPAA by a covered entity, you have to go through an extraordinarily elaborate and complex legal process. In addition to signing an agreement that (in effect) binds you…

I'll agree with you in characterizing it as a breach of trust. That it is. Operatives in Washington, however, are trying to characterize it as something it is not. It's not Russians hacking in, it's not part of some effort to destabilize democracy, etc. That characterization and demonization is indicative of the mindset of those people and that may be even pose more danger than the breach of trust by Facebook.

> It's not Russians hacking in

True! Mostly it was information about users and their social graph collected by people voluntarily. It's distressing that people were not informed, "We're going to use this to target political propaganda at you when you" when they took personality quizzes/etc, but all the data was shared by users. FB's security isn't breached, merely their users' trust.

> it's not part of some effort to destabilize democracy, etc

I'm not sure we all agree on that. ;) The whole point was that one can use the intelligence gleaned from these users' social graphs to target memes/advertising/messaging to specific subgroups whose political responses you are hoping to influence.

Re: Ex-Facebook insider says covert data harvesting was routine

#384
post #49

Is there any reason to believe that the situation isn't the same in, say, the Android ecosystem? In my experience many 3rd party apps require ridiculous amounts of permissions (contact list etc...) for something that's not core functionality. Surely all these free-to-play crapware games on the Android market have siphoned all the data they could and sold them to the highest bidder? Does Google do a better job of moni…

Wait until you see the video of these guys: https://www.sentiance.com/ (via https://news.ycombinator.com/item?id=16626752 )

There is an increasing need for a container app that will feed whatever sensor data you want to the apps within the container. Also there would need to be some preconfigured sensor data profiles, like "Occasionally cheating husband living in city X" or "Really rich housewife living in city Y" or maybe "piss-poor guy living in a rural developing country"

Re: Ex-Facebook insider says covert data harvesting was routine

#385

How long before it comes out that Google does the same thing with search history, Amazon with product browsing, Apple with phone usage, and Microsoft with Windows 10 usage?

Can you show me how psychographers have been using Google or Amazon in the same way as Facebook?

I believe you are making a false equivalency.

Re: Ex-Facebook insider says covert data harvesting was routine

#386

I still don’t understand the breach part. It just seems like Facebook app developers used Facebook exactly as it was set up, and then resold the data.

Imagine a clinic has a policy that allows patient data to be released to non-patients but a court decides that the use violates HIPPA. There would be no technical breach of security, but rather a breach of responsibility.

Re: Ex-Facebook insider says covert data harvesting was routine

#387

I see a lot of Facebook sympathizers here. Is this what devs do at Facebook? Browse HN and defend the reputation of Facebook at any cost? Yes we all knew what we were in for when we signed up for Facebook and Instagram. Yes, they can sell our data to show us ads about what coals to buy for July 4th bbq party and we are OK with that. But not to turn blind eye to foreign entities which in return use it against us and j…

I don't work for facebook. I don't have a facebook. I don't like facebook. What I do like is honesty. https://en.wikipedia.org/wiki/Data_breach Look at this very robust list of data breaches and tell me how the CA/Facebook incident this week looks anything like any of them.

You're right, it looks worse.

Re: Ex-Facebook insider says covert data harvesting was routine

#388
post #9

Earlier quoted context omitted.

Isn't that just part of FB's culture? Didn't the Zuck start out by scraping Harvard's student registry?

And the website's original purpose was for upperclassmen to rate the hotness of incoming female freshmen.

Male actually but that’s a longer story.

Re: Ex-Facebook insider says covert data harvesting was routine

#389

Earlier quoted context omitted.

2006 - AOL search data scandal [1] >The release was intentional and intended for research purposes; Sounds pretty damn close to this event with Facebook [1]: https://en.wikipedia.org/wiki/AOL_search_data_leak

An analogous example would be if the CA/FB breach had access to private facebook messages or information that was never intended for public consumption. In the CA/FB case the information was either public (and could be scraped as such) or was collected in the form of facebook apps.

This is not true. The old Facebook API gave access to all data the user had access to. This included information (posts, photos…) by “friends” which was not public.

Re: Ex-Facebook insider says covert data harvesting was routine

#390

Earlier quoted context omitted.

No, this is not a breach. Words still mean things.

"Words still mean things" is not an argument. This can be a 'breach' by many of these definitions.[0][1][2] You're basically saying, "Words only mean the things that I want them to mean, and if you try to use them a different way than I approve, then I will use this meme to try to shut you down." Words fluctuate in meaning all the time. This may very well be the beginning of a new definition for breach, i.e., a socia…

> Any of these old definitions contains sufficient meaningfulness to make "Facebook loses control of data to unauthorized breach" perfectly intelligble.

Sure, but the point being made by the "it's not a breach" people is that Facebook didn't lose control of data to an unauthorized breach. They gave up data according to their own documented and expected procedures to people who were supposed to have it. "Facebook voluntarily and purposefully gives away data in an authorized breach" is not so intelligible.

The fact that "Facebook loses control of data to unauthorized breach" would be a sensible, understandable sentence isn't really relevant when nothing of the kind has happened. Who'd be using that sentence?

Post reply on HN