The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. They knew it was illegal but put all the incentives for companies n…
> They knew it was illegal but put all the incentives for companies not to follow the rules. Offtopic but i cant help it. You get what you measure. Which is why economies that only measure profit optimize for nothing but profit. When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit, we should not be surprised that companies like Facebook do…
Zuckerberg on Cambridge Analytica situation
201–210 of 583 posts
Re: Zuckerberg on Cambridge Analytica situation
#202Earlier quoted context omitted.
They could aggressively pursue enforcement and punitive measures. It's not about preventing everything that could possibly go awry, but making it well-known in the developer community that Facebook/Platform has no problem shutting you down if you egregiously break the rules.
I think that's sorta kinda was happening with > we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications. To generalize the issue, if you were in charge of APIs at some company A and some company B (not necessarily located in your jurisdiction and not necessarily subject…
Zuck's announcement seems to have a decent outline -- start with investigating apps with access to large amounts of data, audit apps with strange behavior. But after a year, after the CA (and other) controversies are forgotten, what I was thinking was that FB should be doing regular, random audits/investigations, and publicize the punishment.
I don't mean identifiable shaming, e.g. "Last week, we banned Jane Smith and her Flappy Farm app for misusing the data of 3,000+ users". But maybe weekly/monthly tallies of apps that were shut down or sanctioned, and a breakdown of the reasons why, and users affected, etc. Every once in awhile, an app maker might post a "We Fucked Up" article on HN, which helps even more in reminding people of TOS.
Re: Zuckerberg on Cambridge Analytica situation
#203Anyone else remember Beacon? This was how FB has always designed to work from the beginning. They've just been toying with the PR ways to say it to make people accept it without thinking. The election woke people up. I found this from 2011 when they shut it down as a "mistake." ( https://newsroom.fb.com/news/2011/11/our-commitment-to-the-f... ). Unfortunately, it looks like they removed the launch release - but it wo…
Re: Zuckerberg on Cambridge Analytica situation
#204I remember the old days of the graph API - there was a whole lot you could do with someone's account, and it was common for users, especially non technical users to blindly hit accept on the permissions screens. If I'm not mistaken, you could even make a developer account without a verified phone number at the time.
I don't think banning some of those apps is any kind of consolation really. The API sat like that for years. Anyone with nefarious motives already took what they wanted and ran. What repercussions will they face? The will be banned from Facebook? The apps are probably long gone. There was a time when Facebook apps were at their peak, that fad died off. The data is probably sitting in a database somewhere today. If I'm not mistaken, Facebook Games could still grab the friend list permission until quite recently.
Also what authority does Facebook have to do any kind of audit? How would that audit even work? If someone copies all the data to an external drive and locks it up, what will the audit reveal? "Yep there's no data here, pinky swear!"
The basic premise of Facebook is flawed. If your private thoughts or photos are posted on a platform where you don't control the data, the data is never safe. A good product that serves the user faithfully and takes this into account is probably closer to a decentralized product - maybe something like Mastodon (I haven't looked into it in much detail). Facebook has already acquired the users - if they can figure out a way to make money and switch to a decentralized model at the same time, they can solve this once and for all. They would arguably even gain users who would now have a reason to trust their service.
Re: Zuckerberg on Cambridge Analytica situation
#205[0] https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
Re: Zuckerberg on Cambridge Analytica situation
#206Earlier quoted context omitted.
This feels strange to those of us from technical spheres, but much of the world works without formal verification of facts. There are in theory severe penalties, both implicit and explicit, that ostensibly act as deterrent to bad actors. This is usually only noteworthy when it fails, but by and large it works. The friction involved if we did not generally accept someone's (signed, notarized, appropriately formalized)…
Could smart contracts (maybe in addition to a Trusted Execution Environment) be used to enforce these sorts of guarantees?
You can do some clever things to figure out who it is that leaks stuff, but that's another issue.
Re: Zuckerberg on Cambridge Analytica situation
#207Earlier quoted context omitted.
To really fix this, Facebook will have to stop allowing 3rd party developers direct access to user data. Basically, FB should introduce an App-Engine like platform where the backend of any 3rd-party application that uses FB data has to run on FB-owned servers. Developers of these applications would then ship their code to FB (similar to Heroku) and run in a sandboxed environment where they are not allowed to take dat…
If it were some computation, aggregation or analysis this work, but a lot (I'd guess, most) applications might not fall into this category. How are you gonna present the data in a UI to users, if no data is supposed to leave the server?
Or perhaps their could be a limited capability for developers to log in to their app as another user of it, but those accesses would be logged and periodically audited (just like the as-another-user-logins of regular FB engineers are).
Re: Zuckerberg on Cambridge Analytica situation
#208Earlier quoted context omitted.
How about additionally, 1) providing an "Advanced Feed" providing each user a log of every data field exfiltrated, date/time/who/IP addr,/ etc. 2) requiring every single advert and it's targeting parameters, that runs on the system to be made available in a fully searchable advert pool for anyone to search. This would allow people to see what is being targeted, journalists to figure out what targeting is happening (m…
Plus, a lot of the "news feed" articles started as re-shares of microtargetted ads. There absolutely should have been more transparency on virally reshared things that started as microtargetted ads.
Re: Zuckerberg on Cambridge Analytica situation
#209This is such a well crafted statement not from Zuck's heart but from a PR team that has been working over time. Shame on you FB and Zuck you Suck. If they are so honest or like to be honest going forward why can't they make it easy to see all my pics and posts that are public? Why can't they make it easy to see who can see what I posted? Which app or user is using my data. They have billions of dollars and can't impl…
Further there been plenty of sexual harassment claims under his name. I doubt that he worries too much that he will catch some more dirt for praising Facebook these days.
Re: Zuckerberg on Cambridge Analytica situation
#210Earlier quoted context omitted.
> but refuses to appear before the US Congress and sends the company counsel instead. This strikes me as especially interesting. I mean, I'd personally theoretically have my reservations about this congress over and above the average congress, but FaceMark refusing strikes me as a deeply telling datum about how he's thinking about this.
Basically no CEOs ever want to testify in front of a congressional committee. There is only downside to such a situation for the company. There is zero upside. This is not a deeply telling datum. It is a boring an standard one.
More accurately there is risk in talking to the US congress when the topic sounds more like an inquisition than when congress is asking for opinions.
The matter then is why is it a risk for Facebook to discuss the CA issue? Are they worried about a witch hunt or a public ethics execution?