Live data from Hacker News

Facebook Secretly Saved Videos Users Deleted

nymag.com

361–370 of 405 posts

Re: Facebook Secretly Saved Videos Users Deleted

#361

Earlier quoted context omitted.

Let's be clear here: I'm not the Facebook user in question. I've never uploaded a video to Facebook and never will. Users didn't sign or agree to anything just because they checked a checkbox next to a link to an ever-changing jumble of legalese to get past a screen. This isn't agreement, it's manufactured consent.

> Users didn't sign or agree to anything just because they checked a checkbox next to a link to an ever-changing jumble of legalese to get past a screen. This isn't agreement, it's manufactured consent. What is the difference? I am thinking if a person really actually cared they would have read the legal agreement before checking the checkbox in question and possibly consulted an attorney of their own. I am thinking…

You can't claim users don't care about their videos not being deleted--the fact that they do care is exactly why this is in the news. They may click past a screen because they think that they don't care, but that's only because they don't understand the implications of doing so. Part of the reason is that a lot of people naively believe that a respectable company like Facebook wouldn't try to screw them over, and would behave with their best interests in mind.

It's unrealistic to expect that users will read AND understand the TOS of every website AND all of the changes to the TOS that occur over time.

Re: Facebook Secretly Saved Videos Users Deleted

#363

Earlier quoted context omitted.

True, but this isn't an excuse. It's slow to delete data because Facebook designed it that way. They could have designed for privacy and real-time deletion of data, but they didn't, because they didn't care.

> "They could have designed for privacy and real-time deletion of data" Actually, they could not. If data is geo-replicated across multiple clusters, spread all over the place, divided into hot and cold storage layers - it's crystal clear you can't perform "real time deletion of data". Instantaneous deletion of all data, leaving no trace behind, can not happen under such complex constraints.

>> > "They could have designed for privacy and real-time deletion of data"

> Actually, they could not. If data is geo-replicated across multiple clusters, spread all over the place, divided into hot and cold storage layers - it's crystal clear you can't perform "real time deletion of data". Instantaneous deletion of all data, leaving no trace behind, can not happen under such complex constraints.

Yes, they could have. Your post is just a description of a design that can't delete data quickly. That doesn't prove that no design exists which can delete data quickly.

If Facebook had been designed with "we need to allow users to delete their data quickly and permanently" as a constraint from the beginning, it wouldn't look like the system you've described.

All you've done is pick all the things that Facebook did and say that if you do those things you can't delete data quickly. Yes, that's true--which is why Facebook would not have done those things if they cared about allowing users to delete their data.

Re: Facebook Secretly Saved Videos Users Deleted

#364

This reminds me of the long conversations that I used to have with family members and friends several years ago. With their continuous requests to create my own Facebook profile so I can keep in contact with them and with their activities as well as to share my whereabouts. I always used the same argument to reject these suggestions — "I don't want Facebook to have too much data about me, more than the data that you…

> I remember the last time I had this conversation with someone, last year (2017) around August. I found a new love partner, and after the long intimate talks on the phone, they requested the usual "intimate pictures", not necessarily sexual but certainly sexy. Why the fuck are these a thing? Couples don't meet in real life much anymore? And how "usual" are they?

Anyone have stats on how widespread this is? My spouse and I avoid being in front of cameras naked even when we're pretty sure the camera isn't enabled. Not that anyone else would really want to see us nude, but why take a chance on accidentally recording material that could be embarrassing?

Re: Facebook Secretly Saved Videos Users Deleted

#365

Earlier quoted context omitted.

> "They could have designed for privacy and real-time deletion of data" Actually, they could not. If data is geo-replicated across multiple clusters, spread all over the place, divided into hot and cold storage layers - it's crystal clear you can't perform "real time deletion of data". Instantaneous deletion of all data, leaving no trace behind, can not happen under such complex constraints.

>> > "They could have designed for privacy and real-time deletion of data" > Actually, they could not. If data is geo-replicated across multiple clusters, spread all over the place, divided into hot and cold storage layers - it's crystal clear you can't perform "real time deletion of data". Instantaneous deletion of all data, leaving no trace behind, can not happen under such complex constraints. Yes, they could have…

[deleted]

Re: Facebook Secretly Saved Videos Users Deleted

#366
post #335

Earlier quoted context omitted.

Instead of having a key that you delete (and also build non trivial infrastructure to support), why not delete the actual data?

Because the key is smaller, it is easier to make sure you deleted every copy of that key than that you deleted every copy of the data. The data also might be part of a larger backup that you would have to take apart and reassemble in order to delete the data, or might be in a place where doing that is costly (e.g. on Amazon Glacier)

It seems precisely as easy to make sure you've deleted every copy of the data as it is to make sure you've encrypted every copy of the data.

Re: Facebook Secretly Saved Videos Users Deleted

#367

Earlier quoted context omitted.

If you truly want privacy and security I would recommend Signal over Telegram -- Telegram has had some controversy with respect to their encryption protocol not being audited, as well as some weird stuff with a very large recent ICO that seems entirely unnecessary except as a money grab and Russian subpoenas for their master private keys.

> and Russian subpoenas for their master private keys. While I cannit defend (or attack, I'm no cryptographer) their crypto they seem to have a solution to this: They say they don't store keys in the same datacenter or even jurisdiction as the customer data they protect. According to them this means getting unencrypted data through a legal process would mean getting a warrant in two or more countries at once.

> They say

> According to them

I find it very hard trusting their word. And we know the company has the ability to read messages. How is telegram better from FB messenger?

Re: Facebook Secretly Saved Videos Users Deleted

#368
post #366

Earlier quoted context omitted.

Because the key is smaller, it is easier to make sure you deleted every copy of that key than that you deleted every copy of the data. The data also might be part of a larger backup that you would have to take apart and reassemble in order to delete the data, or might be in a place where doing that is costly (e.g. on Amazon Glacier)

It seems precisely as easy to make sure you've deleted every copy of the data as it is to make sure you've encrypted every copy of the data.

Edit: apologies, seems I read way too quickly! Thanks for pointing it out.

Re: Facebook Secretly Saved Videos Users Deleted

#369
"I do also think that, you know, Facebook has a responsibility to its users to protect their data and not just to protect it but make sure that people understand what data they're producing and whether they own it, who has access to it and when.

And Facebook has failed them, you know, across the board.

And the question now is not just what - you know, what can be done to ensure the security of that data. It's, how can we use this moment to ensure that we're having a broader cultural conversation about the data that we're all creating on Facebook, Google, Amazon, through our phones, et cetera and make sure that the companies are held accountable for it?"

Source:

Facebook co-founder, Chris Hughes

https://www.npr.org/2018/03/30/598208043/should-facebook-use...

Re: Facebook Secretly Saved Videos Users Deleted

#370
post #366

Earlier quoted context omitted.

It seems precisely as easy to make sure you've deleted every copy of the data as it is to make sure you've encrypted every copy of the data.

Edit: apologies, seems I read way too quickly! Thanks for pointing it out.

You seem to be commenting out of context:

> generate a new encryption key every day for “data deleted today”,

The question is not can we encrypt at storage. We’re now talking about encrypting as a soft-deletion method, which means we need to know everywhere the data is stored at deletion time, whether to delete it or to encrypt it with this new “deletion” key.

Post reply on HN