Live data from Hacker News

Facebook won’t let you opt out of its phone number ‘look up’ setting

techcrunch.com

151–160 of 261 posts

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#154
post #146

Earlier quoted context omitted.

> in favor of a transparent society I suggest you read The Transparent Society by Byung-Chul Han. It’s a brutal 50-page indictment of the hypercult of transparency and its effects on the human soul, on the political discourse, and on traditional values like truth and beauty. Might change your view on the costs of transparency.

The three body problem book part 2 also explores a fully transparent society; It's really interesting with all the sides effects (They can't lie, etc.). I recommend anyone to read it !

I read the first and while the ideas explored were interesting, I found the writing itself to be completely off-putting:

- first of all, Three Body seems like the most boring videogame ever developed, not sure how people could actually be believably playing that.

- the characters are pretty much caricatures of stereotypes (the cop), or just plain uninteresting.

- the massive exposure/infodump chapters killed the immersion from me, especially the ones written from the point of view of the other side of the conflict: it really felt like the author was getting towards the end and wanted to Explain All The Things, but couldn't find a subtle way to do so within the narrative, therefore decided to just vomit it all in a single spurt.

I was really looking forward to it but found it disappointing, won't read any more from this author.

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#155
post #82

If you are a Facebook employee, or are close to one, please help me understand. How does it feel to see reports like this being released almost weekly? I realize people are very good at dealing with moral dissonance when their paycheck depends on it, but surely you must be thinking, talking to your colleagues, about what your personal responsibility in this is?

Overall, the vast majority of similar reports are completely irrelevant, partial or non-sensical. Happy to give details but the most common pattern is the same person demanding that Facebook regulate speech in one sentence and being outraged that Facebook feels allowed to regulate speech before that sentence is over. Most journalists who write about Facebook are deemed as “having no idea what they are talking about”. A lot of them are granted some internal access by people who think that it would improve the coverage but rapidly discover that their ignorance isn’t because they lack of access but it is a decision.

This case is a small but clear oversight, one team (Security) set-up a necessary 2FA option; another (Growth) re-using information attached to a profile without context. Both teams have clear objectives but should have clearer lines when edge-cases like these appear. Two remarks on that: 1. clarity in large organisation and 2. prioritisation.

1. Overall, Facebook teams need clearer demarkation but every company in the world has far, far worst practice so as soon as you try to interview, you reek in horror at practices anywhere else — and that’s what they are willing to tell you before you join.

The internal discussion is probably split between many debates; I’ve never been very good at expecting issues around security, but probably a dozen philosophical questions like:

- phone numbers and SMS are not safe from MITM attack, the company should not accept them at all; vs. other options like a device are too selective, demanding, etc. so if people are happy and their threat model doesn’t include MITM SMSs, the company should offer that as an option;

- this is the only piece of information that is “User only” and that visibility option was removed because it used to lead to abuses; vs. we can monitor abusive use of a visibility feature even if that’s extra work, more technical plumbing that could lead to more internal abuse;

- there are no identified threat actually unblocked if there were, our bug bounty would have caught them; vs. we do not have to limit Security to known threats, but “feels” for bad practices should be trusted as a sign there is a threat in there that the company should respect even if we can’t isolate why.

Knowing what to do as an individual contributor when you have gods fighting over your head can be daunting; you want to have a clearer picture that, say “Only me” will be a visibility option for longer and not replaced by “Hide that from anyone, even having access to the account to prevent an access even from escalating into a worse security threat” or that when it’s replaced, this piece of information won’t be missed or excluded.

Anyone who has build large data schemas would be familiar with how tricky changes like that can be when done without coordination. Anyone who follows visibility of information from Facebook has noticed a lack of clear purpose: more nuanced options appear and disappear because there’s a tension between simplification and curating interests.

2. Overall, working for Facebook feels like you are dealing with a fire, an earthquake, a zombie invasion, a revolution and a flood at the same time — and the public only seems to care about electricity shortages. And when you look into internal numbers about who cares about any of the above, the flood seems like a big deal, no one cares about electricity but someone you know that the fire and the zombie invasion are far worst. Facebook is the only place where managers are very clear that the fire will destroy your water pump much faster than the water goes up, and zombies are actually quite slow — and you can not prevent earthquakes, only deal with the aftermaths, so they want you to deal with them in a specific order: #1 Extinguish Fire, #2 Automate the water pumping for the Flood, into the fire-prevention stock, #3 Delegate the dyke-building, #4 Once you have a plan for that, expand dykes to protect from zombies, #5 Schedule a town-hall for after the physical security of everyone is guaranteed because talk is better than a revolution, #6 Imagine what seismographs could be like (network?) and how they could prevent bad things, given how fast earthquakes are. Nothing about electricity because it escapes everyone’s mind at this point.

I once had a task that was about preventing thousands of crimes from happening; it was #3 on my list. That felt wrong, but my manager explained how, if #1 and #2 were not done, I couldn’t do #3. It felt very strange. #2, in particular, was very debatable: I reached out to a friend of mine, a lawyer outside the company and probably one of the top 10 people on deciding if something like #2 was ethical. My friend told me that he had far bigger issues to deal with. So I did #2 reluctantly; I did it first because it made #1 easier. In the mean time, #1 was cancelled without my manager telling me. I had asked someone else to do #3 and he got a massive promotion.

Two years later, the press was up in arms because thinking about #7 was presumably unethical. #7 is about making sure that vulnerable users were even more protected than they were on Facebook (while no other platform did anything for them) and the press really objected to vulnerable users being on Facebook at all. The most widely circulated OpEd on the topic explicitly didn’t care for them being protected: that they were on Facebook at all was the problem. As a former employee, I knew why they really needed to be there: it is their only source of needed social life.

My experience was a little extreme, but it’s quite representative.

Take the recent appeal to have more community monitoring:

- Facebook notices, years before anyone, external agents using social media to spread inflammatory messages; they understand that they won’t be able to prevent the gutter-press from spreading it, so they appeal to institutions because they carry editorial authority and local understanding that Facebook can’t have.

- That is dismissed as interference, and Facebook is mocked for knowing nothing about the free press. As a reaction, Facebook publishes articles on polarisation and clearly point at external sources; they asks researchers to measure how much the News Feed bridges that gap and helps moderate the worst messages. The article is summarised clearly with graphs by internal comms. The article is summarised in the press as: Facebook is pouring gas on the political fire.

- Facebook anticipates that astroturfing will get worst, at an exponential rate, and decides to enforce strict “authentic identity” rules to cut most of it; also starts efforts in identifying “fake news”. Explicitly connects the efforts to political manipulation. Both efforts are openly disparaged by people who spread false information and openly ignore that Facebook has a clear handling process for people who don’t want to be found for legitimate reasons. Political parties gladly finance negative attack ads that are the main source of inauthentic, false coverage.

- Facebook gets signal that human censoring is not scaling; details become increasingly worrying. Facebook ramps up their AI research program to identify increasingly relative inauthentic users, messages; the program is ignored, or only presented as an Orwellian effort by “the Borg”. Mentions of issues in human reporting are completely overlooked by the press.

- Facebook realise that scaling its community enforcement won’t work because they don’t know how to manage those and the third-party company are treating them like lab rats at best. Asks for improvement on work conditions; nothing, or rather systematic executive-level Me-Too scandals. Facebook fires said companies out of desperation. Instant backlash because ‘Facebook fired journalists’. Facepalm, partial decision reversal. Silence from the press, which honestly is a relief at this point.

- Major progress on the front of automated community enforcement. Facebook is the first to identify several threats to democracy (Cambridge Analytica is banned in 2014; everyone finds Trump funny when he asked for Russia’s help, while Facebook Security reveals to the FBI suspicious behaviour). Unsurprisingly, Facebook is blamed for acting as a Good Samaritan; internal debate on whether to come clean publicly, or only tell law enforcement. Law enforcement is clearly dependent on electoral results, so coming clean publicly proves important… but extremely costly for the company brand. Should the company sacrifice the little goodwill it has left among the press now, to prevent current threats, or keep it for a worse crisis?

- No surprise: political parties don’t like being targetted as being bad actors and defend themselves by empowering lunatics and doubling down on a constant barrage of incendiary news. Community enforcement is completely overwhelmed by its own scale and size and catastrophic situations emerges. No one raises that Facebook has offered several solutions, from institutional standards, automated detection, visibility control and just blames the company for its subsidiaries. The company is just the enemy of everyone at this point. Facebook has two options: not having any community enforcement, or trusting suppliers that have repeatedly lied to them. The third one is what many employees are working on: automation.

Your question is: why wouldn’t they leave? Answer: many do. Drama is hurtful no matter how you understand the whole story. Whether those who stay are more confident, or less reliable in their ethical stand is debatable.

If you care more for technical problems, I’m happy to explain why facebook.com/ads/preferences is the best implementation at the moment of user-control over dark data brokers. It’s insufficient, but helping people identify threats and we can implement reporting from there that no other company will let you have, not without the transparency of Facebook.

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#156
post #54
post #51

Earlier quoted context omitted.

well - I did that .... and changed the email address to a dummy account .... and still they send me almost weekly spam to the old address - "Why aren't you using FaceBook? here's a single link you can use to log on without a password" ... these bozos have no concept of security

Or rather I should say "these bozos have no concept of their customer's security" .... but I guess we all knew that already

But at least they can solve graphing problems!

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#157

They own WhatsApp, which is integral to having a social life in Germany. So they already have my phone number.

You don't need WhatsApp to have a social life anywhere, even in Germany.

There's something seriously wrong with society if an app owned by a malicious tech company is considered fundamental to the human experience.

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#158

This will make keeping your social media private during recruiting much much harder because rather than trying to search for your name on FB or your email, an interviewer can just search your listed contact number. Names are often not unique but phone numbers are. This matters because creating a new email account for recruiting is trivial, yet creating a new phone number for recruiting is not. Most phones are not dua…

I honestly do not get what problem are you trying to solve here. If you have content which you think should be hidden from someone, just do not make it public.

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#159

Earlier quoted context omitted.

They do in GDPR jurisdictions or they’re fucked.

Define fucked in this context. They'll pay a fine, perhaps, but it's not like Mark Zuckerberg will be laying in a gutter pissing blood. Regardless, you can't put the cat back in the bag. Bad actors will still have scrapped your number, or way too much personal identifying information, anyway.

GDPR fines can be pretty significant. Google was hit with a €50 million fine in January.

Re: Facebook won’t let you opt out of its phone number ‘look up’ setting

#160
post #21

Earlier quoted context omitted.

I believe GDPR specifies right of erasure, and if Facebook doesn't delete the phone number you "deleted", Facebook will face much larger problems.

My comment was fairly US-centric, as we don't have GDPR. In the EU that'd be much more useful, as the cost of phone numbers in Europe and calling rates vary wildly, and can be quite exorbitant in some countries.

Facebook still operates as a business in the EU and can therefore be fined there. As a similar example, Google was fined €50 million earlier this year as a result of a GDPR violation.
Post reply on HN