Live data from Hacker News

Zuckerberg on Cambridge Analytica situation

facebook.com

201–210 of 583 posts

Re: Zuckerberg on Cambridge Analytica situation

#201
post #39

The trusting developers not to sell any data but putting zero safeguards in place to prevent this and extremely punitive repercussions despite being repeatedly told by the public, media, and even high level employees tells me Facebook can't plead ignorance to this and they not only knew this was happening, but they probably intended for it to happen. They knew it was illegal but put all the incentives for companies n…

> They knew it was illegal but put all the incentives for companies not to follow the rules. Offtopic but i cant help it. You get what you measure. Which is why economies that only measure profit optimize for nothing but profit. When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit, we should not be surprised that companies like Facebook do…

[deleted]

Re: Zuckerberg on Cambridge Analytica situation

#202
post #97

Earlier quoted context omitted.

They could aggressively pursue enforcement and punitive measures. It's not about preventing everything that could possibly go awry, but making it well-known in the developer community that Facebook/Platform has no problem shutting you down if you egregiously break the rules.

I think that's sorta kinda was happening with > we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications. To generalize the issue, if you were in charge of APIs at some company A and some company B (not necessarily located in your jurisdiction and not necessarily subject…

In that situation, I guess there's not much power Company A has with regards with Company B, right? Unless Company B is worried that they'll have a future relationship and thus will be willing to submit some kind of audit.

Zuck's announcement seems to have a decent outline -- start with investigating apps with access to large amounts of data, audit apps with strange behavior. But after a year, after the CA (and other) controversies are forgotten, what I was thinking was that FB should be doing regular, random audits/investigations, and publicize the punishment.

I don't mean identifiable shaming, e.g. "Last week, we banned Jane Smith and her Flappy Farm app for misusing the data of 3,000+ users". But maybe weekly/monthly tallies of apps that were shut down or sanctioned, and a breakdown of the reasons why, and users affected, etc. Every once in awhile, an app maker might post a "We Fucked Up" article on HN, which helps even more in reminding people of TOS.

Re: Zuckerberg on Cambridge Analytica situation

#203

Anyone else remember Beacon? This was how FB has always designed to work from the beginning. They've just been toying with the PR ways to say it to make people accept it without thinking. The election woke people up. I found this from 2011 when they shut it down as a "mistake." ( https://newsroom.fb.com/news/2011/11/our-commitment-to-the-f... ). Unfortunately, it looks like they removed the launch release - but it wo…

I basically quit after Beacon.

Re: Zuckerberg on Cambridge Analytica situation

#204
> First, we will investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity. We will ban any developer from our platform that does not agree to a thorough audit.

I remember the old days of the graph API - there was a whole lot you could do with someone's account, and it was common for users, especially non technical users to blindly hit accept on the permissions screens. If I'm not mistaken, you could even make a developer account without a verified phone number at the time.

I don't think banning some of those apps is any kind of consolation really. The API sat like that for years. Anyone with nefarious motives already took what they wanted and ran. What repercussions will they face? The will be banned from Facebook? The apps are probably long gone. There was a time when Facebook apps were at their peak, that fad died off. The data is probably sitting in a database somewhere today. If I'm not mistaken, Facebook Games could still grab the friend list permission until quite recently.

Also what authority does Facebook have to do any kind of audit? How would that audit even work? If someone copies all the data to an external drive and locks it up, what will the audit reveal? "Yep there's no data here, pinky swear!"

The basic premise of Facebook is flawed. If your private thoughts or photos are posted on a platform where you don't control the data, the data is never safe. A good product that serves the user faithfully and takes this into account is probably closer to a decentralized product - maybe something like Mastodon (I haven't looked into it in much detail). Facebook has already acquired the users - if they can figure out a way to make money and switch to a decentralized model at the same time, they can solve this once and for all. They would arguably even gain users who would now have a reason to trust their service.

Re: Zuckerberg on Cambridge Analytica situation

#206
post #159
post #24

Earlier quoted context omitted.

This feels strange to those of us from technical spheres, but much of the world works without formal verification of facts. There are in theory severe penalties, both implicit and explicit, that ostensibly act as deterrent to bad actors. This is usually only noteworthy when it fails, but by and large it works. The friction involved if we did not generally accept someone's (signed, notarized, appropriately formalized)…

Could smart contracts (maybe in addition to a Trusted Execution Environment) be used to enforce these sorts of guarantees?

This begins and ends with the fact that if you can see something, you can record it. The only way to prevent this is through on-site access only with a thorough physical search and no electrical devices allowed.

You can do some clever things to figure out who it is that leaks stuff, but that's another issue.

Re: Zuckerberg on Cambridge Analytica situation

#207
post #192

Earlier quoted context omitted.

To really fix this, Facebook will have to stop allowing 3rd party developers direct access to user data. Basically, FB should introduce an App-Engine like platform where the backend of any 3rd-party application that uses FB data has to run on FB-owned servers. Developers of these applications would then ship their code to FB (similar to Heroku) and run in a sandboxed environment where they are not allowed to take dat…

If it were some computation, aggregation or analysis this work, but a lot (I'd guess, most) applications might not fall into this category. How are you gonna present the data in a UI to users, if no data is supposed to leave the server?

The UI could be a web page, mobile app, etc just like FB.com. But to see any user data you would actually have to be authorized as that specific user. I.E. a developer could test their app by logging in with their own FB account and using their own data but would have no capability to look at the raw DB entries of other users.

Or perhaps their could be a limited capability for developers to log in to their app as another user of it, but those accesses would be logged and periodically audited (just like the as-another-user-logins of regular FB engineers are).

Re: Zuckerberg on Cambridge Analytica situation

#208
post #116

Earlier quoted context omitted.

How about additionally, 1) providing an "Advanced Feed" providing each user a log of every data field exfiltrated, date/time/who/IP addr,/ etc. 2) requiring every single advert and it's targeting parameters, that runs on the system to be made available in a fully searchable advert pool for anyone to search. This would allow people to see what is being targeted, journalists to figure out what targeting is happening (m…

Plus, a lot of the "news feed" articles started as re-shares of microtargetted ads. There absolutely should have been more transparency on virally reshared things that started as microtargetted ads.

Literally everything on Facebook is microtargeted ads. Engagement, including resharing, is just part of the targeting algorithm.

Re: Zuckerberg on Cambridge Analytica situation

#209

This is such a well crafted statement not from Zuck's heart but from a PR team that has been working over time. Shame on you FB and Zuck you Suck. If they are so honest or like to be honest going forward why can't they make it easy to see all my pics and posts that are public? Why can't they make it easy to see who can see what I posted? Which app or user is using my data. They have billions of dollars and can't impl…

Scoble was a fanboy of Rackspace until they stopped paying him and since then he doesn't have a single good thing to say about them.

Further there been plenty of sexual harassment claims under his name. I doubt that he worries too much that he will catch some more dirt for praising Facebook these days.

Re: Zuckerberg on Cambridge Analytica situation

#210
post #100
post #78

Earlier quoted context omitted.

> but refuses to appear before the US Congress and sends the company counsel instead. This strikes me as especially interesting. I mean, I'd personally theoretically have my reservations about this congress over and above the average congress, but FaceMark refusing strikes me as a deeply telling datum about how he's thinking about this.

Basically no CEOs ever want to testify in front of a congressional committee. There is only downside to such a situation for the company. There is zero upside. This is not a deeply telling datum. It is a boring an standard one.

While that may be true for regulations/ethics related appearances, this is not true for things such as funding. For example both Elon Musk and Bruno have gone before congress multiple times to discuss private space programs/ contracts and to justify their cases. Admittedly Elon did send Gwynne Shotwell several times but she is still the COO of the company.

More accurately there is risk in talking to the US congress when the topic sounds more like an inquisition than when congress is asking for opinions.

The matter then is why is it a risk for Facebook to discuss the CA issue? Are they worried about a witch hunt or a public ethics execution?

Post reply on HN