Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

1–10 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#4
First they ask for email passwords. Then the new users assume Facebook won't comprehensively mine their emails. Then Facebook awkwardly gets caught uploading 1.5 million users' email contacts.

It doesn't make sense for people to trust the service at all unless you assume one of two things:

1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't know how Facebook works or what is done with their data

2 - They don't care about their data privacy. I've heard this claim many times, but the people saying it often change their minds when they read more news stories. I really do think people have trouble assuming the worst about the intentions of others and are inclined to be trusting.

edit: clarification

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#5
post #2

unintentional my foot the code to implement that functionality didn't come from nowhere

Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#6
post #4

First they ask for email passwords. Then the new users assume Facebook won't comprehensively mine their emails. Then Facebook awkwardly gets caught uploading 1.5 million users' email contacts. It doesn't make sense for people to trust the service at all unless you assume one of two things: 1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't kno…

3 - those who know how fb works, assume the worst about its intentions, and still don’t care and keep using it

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#7
post #4

First they ask for email passwords. Then the new users assume Facebook won't comprehensively mine their emails. Then Facebook awkwardly gets caught uploading 1.5 million users' email contacts. It doesn't make sense for people to trust the service at all unless you assume one of two things: 1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't kno…

> "I really do think people have trouble assuming the worst about the intentions of others and are inclined to be trusting."

I think you hit the nail on the head. Even on HN, it's not uncommon to see a few comments on each negative story about facebook accusing the media of a conspiracy against Facebook; claiming that the media is wrongly maligning Facebook who is merely the unfortunate victim of a series of coincidental accidents.

They have trouble accepting that a tech corporation like facebook actually might be rotten.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#8
post #2

unintentional my foot the code to implement that functionality didn't come from nowhere

Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.

It requires just one developer and a couple of reviewers to make poor choices.

Which begs the question, how do you structure your organisation such that a foolish developer that only barely understands the change that they are making can't write code that makes arbitrary queries to particular data sets in unapproved contexts?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#9
post #8

Earlier quoted context omitted.

Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.

It requires just one developer and a couple of reviewers to make poor choices. Which begs the question, how do you structure your organisation such that a foolish developer that only barely understands the change that they are making can't write code that makes arbitrary queries to particular data sets in unapproved contexts?

But you actually say it requires negligence on part of multiple people. I find it very hard to apply Hanlon's razor in this case.

Anyway, from my experience people do the stupidest/reckless things despite being told not to, just because there is no fear of backlash. Holding people liable for their actions could be a start, but who wants that?

Also, don't hire foolish developers in the first place. Policing around pebkac is hard.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#10
post #4

First they ask for email passwords. Then the new users assume Facebook won't comprehensively mine their emails. Then Facebook awkwardly gets caught uploading 1.5 million users' email contacts. It doesn't make sense for people to trust the service at all unless you assume one of two things: 1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't kno…

Group #2 somehow lacks the imagination to see what could go wrong. They will learn when a cause effect of Facebook usage is put in their face. I guess the recent news does not push it in their face enough.

Its like that with skimming, lock picking, server security, infrastructure security, basically everything security related.

Post reply on HN