Live data from Hacker News

Why We Disagree with The New York Times

newsroom.fb.com

301–310 of 325 posts

Re: Why We Disagree with The New York Times

#301

I'm no huge Facebook fan - hardly use it these days, but... These apps are just alternative Facebook clients. Don't we _want_ a system where you can use different clients to access your own data? If the problem is not trusting the client, well, that'll be a problem for any such system, even some utopian fully open, distributed and federated social network - until you build an open source client yourself.

It seems that FB gave to those clients an API to access more data than the user allowed. The Blackberry used by the Times got data about the friends of the journalist even if those friends didn't consent to that. One thing is allowing the official FB client to see those data (FB has those data anyway), another thing is to let third parties see them and possibly store them on their servers and not only on our devices.…

I'm not sure this is a fair reading.

> The Blackberry used by the Times got data about the friends of the journalist even if those friends didn't consent to that.

They did consent to that - by becoming your friends! Are you saying that every time you open your friends' Facebook pages, a notification should be sent to those friends requiring consent?

I think perhaps you meant something else - the Blackberry got data about the friends even though the user did not consent to that:

> The Hub also requested — and received — data that Facebook’s policy appears to prohibit. Since 2015, Facebook has said that apps can request only the names of friends using the same app. But the BlackBerry app had access to all of the reporter’s Facebook friends and, for most of them, returned information such as user ID, birthday, work and education history and whether they were currently online.

This is also questionable. Would you say that Chrome requests and receives prohibited data, when you use it to browse your friends list? We are talking about the distinction between client(full access) and third-party app(limited access). The cases described in the NYT article seem to be clients.

Further on your point:

> This is different from email and email clients. First, the expectations are different: if I send you an email I expect that you can forward it to your friends or anybody else unless I explicitly ask you not to.

You seem to be making an argument against your claim here. The parallel would be, if I accept your friend request, I expect that you can see my data and use it(i.e. by browsing your friends list on the Facebook site, or the Blackberry client).

> Second, local clients don't send mail to their authors, same for address books.

Perhaps, but doesn't that hinge on the definition of "local clients"? For example, my Outlook definitely shares information with a cloud server. Was "The Hub" an unknown/unexpected feature of the Blackberry client?

> Third, we know that Google and others can see most of our mails anyway, because most people use only webmail and messages are stored on the servers of those companies.

Are device manufacturers not included in those "others"?

The email client parallel with Google is even more in Facebook's favour. For example, is Mozilla stealing data about my friends when I use Thunderbird to access my gmail account? What if I explicitly ask it to store my emails in a "hub" of sorts, so I could sync them between PCs?

> Finally, FB didn't tell us about this API and what it can do.

I think this is the strongest point, but it's important to note that we are judging Facebook's old decisions by our new increased focus on privacy and user-focused control. As one user gave an example, we used to give our passwords to sites back in the day, so they could integrate with other services(actually, this still happens in some apps..)

> My suggestion for a social network of the future is to have a single API, used also by the official client. The servers must not trust any client, which is the usual thing we do in web development, and give all them the same level of access. It's up to the user to decide if they want to use the official client or one of any third party.

But isn't this literally what is happening here? The "secret" API does not have access to any data the "official" one(used by the site) doesn't(at least, the NYT does not present any evidence to that effect). You also seem to access it by giving your credentials to the "third party client", i.e. no "special access".

Re: Why We Disagree with The New York Times

#302
post #50

Facebook’s response seems perfectly reasonable to me. - Obviously in order to integrate FB functionality into a Mobile OS UI requires an API to render the data being displayed. - If your phone has a home screen widget which shows friend data, obviously that friend data came from a Facebook API call. - If you type your Facebook username and password into a settings dialog in order to enable that home screen widget to…

My email client has full access to the contents of my email but the author of said client has none. Although my client has credentials these are stored locally and like my email never communicated to the creator of my client. If the device makers applications merely fetched data on behalf of users and displayed it on their machine it would be no more of a problem than my email client. In the first place it looks the…

> "Facebook acknowledged that some partners did store users’ data — including friends’ data — on their own servers."

This statement from the article is meaningless, as many legit things might mean "third party storing data" as: 1.) Storing and editing contact imports, if user wants. This is technically friends data, but it's my contact list. 2.) Proxy-ing and caching: we are talking about shitty phones mostly before android and ios were mainstream, so "store on their servers" could be as simple as an artefact of implementation of non-html facebook client app on that shitty phone. Example of such artefacts: custom notifications channels, caching, downscaling of images. I think that blackberry did proxy all of their communications through their servers (not 100% sure), so if Facebook was available, they probably also had to store something on their servers.

The journalist didn't even attempted to distinguish between "my device is calling this api" and "company is doing requests" and resort to conflating those two and ambiguous "some partners did store users". This is example of journalist trying to create a story instead of getting to truth. If they would dig deeper, and try to figure out which companies stored data, what type of data (was it contact import, caching, or did they download full graph?), and what was purpose, it would be valuable article.

Re: Why We Disagree with The New York Times

#303
post #269

Earlier quoted context omitted.

ads (if I'm reading about gardening then show me an ad for potting soil or gloves) That’s what genuinely baffles me. If I were a manager of a gardening company and I wanted to do targeted advertising I would just buy space in gardening themed publications. The idea of showing people my ads while they’re on other websites and not in a gardening mood anyway makes literally no sense. All this tracking and profiling ads…

Because it does add value. Brand awareness/clout. A reminder that you need or want that thing.

You can do that kind of advertising without collecting this much data and creating psychological profiles on every user (think: Coca-Cola).

And even if I like something seeing it repeatedly online just annoys me more than it inspires me to buy their stuff. I think they'd get more bang for their buck by having social media personalities that align with their target market push their product (think: Nike).

If people are likely to be consumers of those things then they'll probably digest media related to those things or other media in the same demographic. This is classic marketing and it doesn't require the level of privacy abuse that Facebook has been trying to justify.

Re: Why We Disagree with The New York Times

#304

Earlier quoted context omitted.

> You broke your promise. Then you face the legal consequences for doing so. Thats what prevents people from breaking them in first place. Unless you are arguing that all legal contracts are useless because they can be broken. I am not asking about the logistics of leaking. Yes ofcourse its physically possible, I am asking why the consequences of breaking a contract don't matter in this specific case.

How do you prove that Bob leaked the information? How do you prove that Abe told Bob? How do you prove that FB was the source of information to Abe? How do you demonstrate that FB, Abe, and Bob did not take all good faith efforts to keep the information secure? How do you show any actual damages?

> How do you show any actual damages?

All that presumably is figured out before signing a agreement. Thats the whole point of an agreement vs pinky promise.

Re: Why We Disagree with The New York Times

#305

Earlier quoted context omitted.

>It was obvious to anyone since the beginning that FB was a clearinghouse for private data trading. How else could the model remotely work? This is just hindsight talking. It was hardly obvious from the beginning because it was hardly obvious how big the market for granular private data was going to be. Facebook, in the beginning, was functionally just a stripped down personal page with a status update feature analog…

Dude that’s BS. The day FB was announced was the day I said “this is a bad idea.” I and many others on HN have NEVER made a FB account, and my life seems to generally have been better for it. But it was obvious then, and it is obvious now. Matter of fact it frankly looks even worse today, since there really seems to be no solution, and the granularity of tools and regulation is too coarse to deal with this scenario.…

>The day FB was announced was the day I said “this is a bad idea.”

The "day FB was announced" it was exclusive to Harvard students and was just a cleaner version of MySpace and Friendster. It's unlikely you would have had strong opinions about Facebook, in particular, that you didn't also extend to those two, as well as AOL and sites like Digg.

Re: Why We Disagree with The New York Times

#306

Earlier quoted context omitted.

I run websites that get traffic from Amazon Silk browsers. I've never signed a data sharing agreement with Amazon. There's more going on in this story than a simple browsing proxy.

> I run websites that get traffic from Amazon Silk browsers. I've never signed a data sharing agreement with Amazon. Of course not. Because the fact that a user agent like this has widespread access to the data that the user has access to is expected. The OS itself also has at least that same level of access (as it has control over the behavior of the user agent). We just all seem to assume that we can trust those en…

> We just all seem to assume that we can trust those entities to not misuse the data

I don't need to trust that entities will not misuse my data; I have legal documents on my websites that set out how entities may use the data that they download from my sites. The terms apply to my users and to any intermediary technology providers.

For the Silk browser, I don't need a data sharing agreement with Amazon because my terms say that service providers like Amazon may not copy and store data from my website for their own purposes. Amazon Silk can access my site only for the purpose of helping the end user visit my site. I expressly exclude data sharing from my relationship with service providers and users.

This is a standard part of website terms and conditions; here's an example from Facebook's terms of service:

> You may not access or collect data from our Products using automated means (without our prior permission) or attempt to access data you do not have permission to access.

And from their platform policy:

> Data Collection and Use: If you are a Tech Provider for an entity, comply with the following:

> a. Only use an entity's data on behalf of the entity (i.e., only to provide services to that entity and not for your own business purposes or another entity's purposes).

Data sharing agreements are only necessary when another entity (i.e. Amazon the company) wants to store and use data separate from, and in addition to, the service they provide to end users.

The existence of a "data sharing agreement" is proof that device manufacturers were collecting and storing user data, not just facilitating user access to Facebook. That's what "data sharing agreement" means. Further proof is that Facebook explicitly said that some companies collected and stored FB user data.

Re: Why We Disagree with The New York Times

#308

Earlier quoted context omitted.

All sensible choices last only till antagnositc action occurs. In the case of legal documents - 1) the base scenario itself is terrible - attempts to make credit card terms easier to read have resulted in a huge increase in the amount of text required to read it. 2) leaving the base case aside - the moment a company or individual decides that they can get away with preying on customers, sensible options no longer wor…

you have to evaluate this position in the context of comparing it to the alternatives. Do you propose government regulating every moderately complex activity because people can't understand it? First of all, people are smarter than you give them credit for and secondly, Soviet Union tried this. It just doesn't work.

The Soviet Union didn’t live in the modern era - and the country which is comparable today is China - and they’re doing very well. I’ve heard many credible claims that the Chinese state will fail, but it hasn’t till date.

So that point may need to be re-thought.

Re: Why We Disagree with The New York Times

#309

Earlier quoted context omitted.

Dude that’s BS. The day FB was announced was the day I said “this is a bad idea.” I and many others on HN have NEVER made a FB account, and my life seems to generally have been better for it. But it was obvious then, and it is obvious now. Matter of fact it frankly looks even worse today, since there really seems to be no solution, and the granularity of tools and regulation is too coarse to deal with this scenario.…

>The day FB was announced was the day I said “this is a bad idea.” The "day FB was announced" it was exclusive to Harvard students and was just a cleaner version of MySpace and Friendster. It's unlikely you would have had strong opinions about Facebook, in particular, that you didn't also extend to those two, as well as AOL and sites like Digg.

To ding me for using the term announced is to find issue in semantics. My position is the same - I had the chance to be part of FB at some of the earliest stages and thought it was a bad idea as did many others.

And people clearly saw and pointed out the issues with privacy back then.

I had few issues with Aol, but it was still a simple service play - and had/has little at all in common with Facebook.

DIGG was never at the same scale or range - and from what I know it never depended on your real life profile as I recall.

Re: Why We Disagree with The New York Times

#310

Earlier quoted context omitted.

I think that's an insane stretch of what's really happening.

Sure. It was a reply to a (dismissive) question asking what's the worst a regulator could do... it wasn't necessarily meant to be a reflection of what's really happening.

The harm of (captured-)regulated monopolies is real, but we ought to save this argument for important targets like the Daughters Bell. I offered an admittedly far-fetched example of a possible harm from regulating FB, in the hopes that you could come up with a more plausible one. No such luck!
Post reply on HN