Live data from Hacker News

Zuckerberg on Cambridge Analytica situation

facebook.com

191–200 of 583 posts

Re: Zuckerberg on Cambridge Analytica situation

#191
post #153

Earlier quoted context omitted.

> When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit We don't need accountants to measure legality. That's what we have law enforcement and courts for. Investors care about profits; behaving illegally should hurt profits. Deputising a multi-billion dollar company's thousands of shareholders as its moral police is an absurd proposal.

Law enforcement and courts aren't funded in a way that makes that effective.

> Law enforcement and courts aren't funded in a way that makes that effective

In the 1930s, the Congress realized that financial crimes were (a) prevalent, (b) serious and (c) difficult to investigate and prosecute. So it created the SEC [1]. Its specialists, with the budget, focus and mandate to pursue securities-related violations, have been effective (relative to pre-1930s finance).

Regulators make rules. They also enforce them. We have no top cop for technology. The costs of that gap are becoming apparent.

Re: Zuckerberg on Cambridge Analytica situation

#192

Earlier quoted context omitted.

What kind of safeguards would you introduce? At the very start of Facebook platform the API would anonymize the user's email address, the app would get an app-specific hash, e.g. abcdefg-app123456@facebook.net It was a working email address with Facebook handling the forwarding. This proved futile as the very first thing that apps then did was to ask users for their real email address.

To really fix this, Facebook will have to stop allowing 3rd party developers direct access to user data. Basically, FB should introduce an App-Engine like platform where the backend of any 3rd-party application that uses FB data has to run on FB-owned servers. Developers of these applications would then ship their code to FB (similar to Heroku) and run in a sandboxed environment where they are not allowed to take dat…

If it were some computation, aggregation or analysis this work, but a lot (I'd guess, most) applications might not fall into this category. How are you gonna present the data in a UI to users, if no data is supposed to leave the server?

Re: Zuckerberg on Cambridge Analytica situation

#193
Standard operating procedure for Facebook. Let violations go on unless and until seriously threatened by PR damage or legal action. Deny knowledge, claim "mistakes were made", claim "We're so sorry. We will make sure it can't happen again", repeat.

Data exfiltrations of roughly this kind has been going on at least since 2009. Handled according to the formula above. I just posted links to two writeups from back then:

http://theharmonyguy.com/oldsite/2009/05/28/about-that-verif...

https://www.lightbluetouchpaper.org/2009/06/09/how-privacy-f...

Re: Zuckerberg on Cambridge Analytica situation

#194
post #38

Heh. I couldn't read it when logged in, then I remember I have Zuck blocked.

But you still have a Facebook account, so Zuck wins.

This is spot on. I would get rid of it as the only thing I really use it for is social logins, but there's the other issue of wanting access to the Facebook Developer stuff. I guess I could just make an account only for that?

Re: Zuckerberg on Cambridge Analytica situation

#195

Earlier quoted context omitted.

> the backend of any 3rd-party application that uses FB data has to run on FB-owned servers Would that work for mobile apps?

The backend of the mobile app would run on FB servers.

Most apps that do "Login with Facebook" also support "Login with Google" and sometimes "Login with LinkedIn". The backend ownership issue becomes a bit more complicated.

This is even before we get into trust issues most developers would have with Facebook having access to their user data.

Re: Zuckerberg on Cambridge Analytica situation

#196
post #39

The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. They knew it was illegal but put all the incentives for companies n…

It's in Facebook's benefit for advertisers to gather all that data, because the only way they can actually use it to make money is by advertising to the users on Facebook. I find it incredibly hard to believe that this thought never crossed anybody's mind.

Have you ever looked at FB's ad platform? You don't download everyone's data and target the campaign yourself. You target, "18-25 males in these zip codes who like the yankees". I don't see how you go from that platform (hosted and controlled by facebook) to something else.

Re: Zuckerberg on Cambridge Analytica situation

#197
post #159
post #24

Earlier quoted context omitted.

This feels strange to those of us from technical spheres, but much of the world works without formal verification of facts. There are in theory severe penalties, both implicit and explicit, that ostensibly act as deterrent to bad actors. This is usually only noteworthy when it fails, but by and large it works. The friction involved if we did not generally accept someone's (signed, notarized, appropriately formalized)…

Could smart contracts (maybe in addition to a Trusted Execution Environment) be used to enforce these sorts of guarantees?

How would you enforce a smart contract guaranteeing that data was deleted and not copied?

Re: Zuckerberg on Cambridge Analytica situation

#198

The main problem is that users can't control their data. FB should: - Allow its users to delete their accounts as if they never existed - Show users which person and or service has accessed their data (also FB internally) - Use backend permission management instead of frontend permission management

On point 1: Facebook are going to be forced into this by law. The EU is introducing a major piece of regulation, entering into effect in late May. The 'right to be forgotten' is an important part of this[1]. It's possible this will become the de facto standard worldwide as a result. The penalties for non compliance: "In the case of non-compliance with key provisions of the GDPR, regulators have the authority to levy a fine in an amount that is up to the GREATER of €20 million or 4% of global annual turnover in the prior year."

[1] https://gdpr-info.eu/art-17-gdpr/

[2] https://www.imperva.com/blog/2017/03/gdpr-series-part-4-pena...

Re: Zuckerberg on Cambridge Analytica situation

#200
I have to wonder if Facebook was even competently exploiting people's data for money. It sounds like they essentially gave away nearly all of their users' profiles for free to any app developer who could get a user to sign up. Facebook didn't even charge app developers for access to the Platform.

This would allow app developers to create a copy of the data and re-sell that. And Facebook wouldn't see a dime. If their crown jewel is people's data, why would Facebook give away a copy of their crown jewels?

Post reply on HN