Live data from Hacker News

Zuckerberg on Cambridge Analytica situation

facebook.com

131–140 of 583 posts

Re: Zuckerberg on Cambridge Analytica situation

#131

"... we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications." How is it at all possible to certify that data has been deleted and no copies were taken..?

The definition of certify here is to "attest or confirm in a formal statement." So, Cambridge Analytica could be sued if they lied in such a statement.

This may be possible, however it is going to be interesting to see how Facebook gets standing to sue CA. From what I understood from Zuckerberg's statement, the agreement was between Facebook and Kogan. If CA got the data from Kogan, it seems like Facebook wouldn't have standing to go after CA directly. I haven't seen the specific agreements made by each party in this case, so I can't say for sure, but traditionally I think Facebook could only go after Kogan, who then may be able to go after CA depending on the specifics of their agreement.

Re: Zuckerberg on Cambridge Analytica situation

#132
post #122

Earlier quoted context omitted.

>The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. Why would they intend for it to happen? They didn't make any money…

They sold the data by proxy by knowingly letting the 3rd parties syphon the data. Why else would they be at CA when the cops showed up? Are you being intentionally obtuse?

They were at CA because it's a multibillion dollar company and that means that they have people who keep tabs on stories that result in millions of dollars of lost stock value. It's not because they were in cahoots with CA, they were covering their bases.

Are you honestly suggesting that CA wrote Facebook a check?

Re: Zuckerberg on Cambridge Analytica situation

#134

"... we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications." How is it at all possible to certify that data has been deleted and no copies were taken..?

Along those lines, how is it possible for Facebook to demand that CA deleted the data, when CA is a third party and never had any kind of agreement with facebook(at least, relating to the information Kogan shared)?

If someone leaks facebook data to a journalist, can FB demand that they delete it as well?

Re: Zuckerberg on Cambridge Analytica situation

#135

> I'm serious about doing what it takes to protect our community. While this specific issue involving Cambridge Analytica should no longer happen with new apps today, that doesn't change what happened in the past. We will learn from this experience to secure our platform further and make our community safer for everyone going forward. It's good that Facebook took steps to secure the platform against third parties cra…

Great point. We already know from the 2012 election and from the 2015 Podesta e-mails that Facebook doesn't exactly have a great record of political neutrality.

Re: Zuckerberg on Cambridge Analytica situation

#136

Earlier quoted context omitted.

What kind of safeguards would you introduce? At the very start of Facebook platform the API would anonymize the user's email address, the app would get an app-specific hash, e.g. abcdefg-app123456@facebook.net It was a working email address with Facebook handling the forwarding. This proved futile as the very first thing that apps then did was to ask users for their real email address.

Then make "no requests for users email" part of the terms of using the API?

But there are many legitimate use cases of sharing email addresses. Just scratching the surface,

* someone used Facebook Connect to login to NYTimes Web site, curious about their Food & Recipes newsletter, wants to sign up

* someone logging into e-commerce shop through Facebook Connect, making a purchase and then deciding that yes, they would like to track and manage their order on the retailer's Web site, and they will even sign up for an account with retailer to do that

Re: Zuckerberg on Cambridge Analytica situation

#137
"We have a responsibility to protect your data, and if we can't then we don't deserve to serve you," so Zuck says.

"Protect" is the keyword. He means protect while letting Facebook be profitable. Facebook's business will not let him do that without losing a large chunk of its profits.

I expect a lot of talk but little effect on how they sell their data. The problem is that "free to user" = "sell my data". The model fundamentally works against the everyday user.

The only fix is for people to guard their data. It's your data! Facebook is not your friend so don't act as if it is.

Re: Zuckerberg on Cambridge Analytica situation

#138
Why does Facebook need to give up any of this information to developers in the first place? Presumably these apps are part of the reason Facebook has the engagement it has? Or part of the reason for the user growth it has seen in the past?

Perhaps this will prompt Facebook to start cutting out third party developers and build more home grown social apps, leveraging the data it already has on what eye balls engage with. Maybe they'll only grant API access to large companies, eg. TripAdvisor, who they can hold accountable and would be worth investing the time to audit. Perhaps they will start their own internal Cambridge Analytica where no data sharing is even necessary, assuming they haven't already.

Re: Zuckerberg on Cambridge Analytica situation

#139
post #39

The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. They knew it was illegal but put all the incentives for companies n…

What kind of safeguards would you introduce? At the very start of Facebook platform the API would anonymize the user's email address, the app would get an app-specific hash, e.g. abcdefg-app123456@facebook.net It was a working email address with Facebook handling the forwarding. This proved futile as the very first thing that apps then did was to ask users for their real email address.

To really fix this, Facebook will have to stop allowing 3rd party developers direct access to user data.

Basically, FB should introduce an App-Engine like platform where the backend of any 3rd-party application that uses FB data has to run on FB-owned servers. Developers of these applications would then ship their code to FB (similar to Heroku) and run in a sandboxed environment where they are not allowed to take data out at all.

That way FB can audit how the data is being used at anytime and kick out people who are out of compliance with their terms. If a user deletes their FB account, now all their data could be deleted from any 3rd party applications automatically. This is basically similar to the way the government handles classified data.

Post reply on HN