Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

21–30 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#22
post #16
post #4

First they ask for email passwords. Then the new users assume Facebook won't comprehensively mine their emails. Then Facebook awkwardly gets caught uploading 1.5 million users' email contacts. It doesn't make sense for people to trust the service at all unless you assume one of two things: 1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't kno…

Don't attribute to stupidity what can be attributed to malice. No, I didn't get that backwards.

Sufficiently advanced malice disguises itself as incompetence.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#23
post #2

unintentional my foot the code to implement that functionality didn't come from nowhere

Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.

That's not exactly true, it depends on the architecture in use. For instance if using a Publish/Subscribe model, you could have had a service that listens to your email being connected, and since the only reason to connect your email was to upload contacts, it would upload contacts automatically.

Later when login with email was added, the same event was sent but whomever added the event didn't know it would case the upload of contacts.

That doesn't mean it wasn't shoddy craftsmanship, bad architecture, bad QA and probably bad communication later on, but it could have been by mistake (at least at first).

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#24
post #16

Earlier quoted context omitted.

Don't attribute to stupidity what can be attributed to malice. No, I didn't get that backwards.

Sufficiently advanced malice disguises itself as incompetence.

Sufficiently advanced?

I'm pretty sure there are five year olds who have learned the magic phrase "I didn't mean to!"

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#25
post #19
post #17

Can someone use a throwaway e-mail address to sign up for Facebook? Once the e-mail address is validated, is there any further need for a valid e-mail address to continue using FB? Historical fact: Going back to the days when a university address was required, if the user created her Facebook account while at university and her e-mail address later expired when she graduated, FB did not disable the account. Unless on…

Just use a throwaway email account AND keep it? At some point they might decide to lock you out if you log in from a different place, I think it's better if you keep the email account safe.

Has been over ten years since email address no longer valid; still waiting to be "locked out".

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#26

Earlier quoted context omitted.

Sufficiently advanced malice disguises itself as incompetence.

Sufficiently advanced? I'm pretty sure there are five year olds who have learned the magic phrase "I didn't mean to!"

You're absolutely right. Yet for some reason it seems popular to discount that possibility. Particularly when invoking the thought terminating cliche that is "Hanlon's Razor."

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#27

Earlier quoted context omitted.

Sufficiently advanced? I'm pretty sure there are five year olds who have learned the magic phrase "I didn't mean to!"

You're absolutely right. Yet for some reason it seems popular to discount that possibility. Particularly when invoking the thought terminating cliche that is "Hanlon's Razor."

[deleted]

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#28
post #2

unintentional my foot the code to implement that functionality didn't come from nowhere

Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.

If the feature was using the fact that the user supplied the email password, parsing the emails for contacts or logging in with the password and getting the contact list, how on earth could that have been a part of an earlier import contact feature? Did they already ask users for their email password for that? If not this is a feature that needed special code, impossible to be an accident.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#29

Earlier quoted context omitted.

"Start by keeping the primary copy of the user's data on the user's own device" It's an organizational policy, procedural, ethics and legal question - not a technical one. They should have feature reviews before the code reviews. The feature review panel puts bounds on what the code can do.

I don't think you need a board to stop this specific case. It's pretty obvious that what they were doing is unacceptable. The problem must have been a pervasive culture of lack of respect for privacy at Facebook, not a single engineer who somehow just didn't know any better.

Situations can get complicated. There might have been some side show reason to do this or that. Without oversight, some things will fall through the cracks.

A review board would a) give clear direction b) catch problems and c) put accountability where it belongs.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#30
Not for one second I believe this was unintentionally. After all data scandals where Facebook didn't actively care or even empowered the problem by not acting towards privacy.

I think this company is inherently bad from the top and everyone working there is enabling them. Sure, it pays well.

Problem is, most bigger companies do bad things. See VW and the emission scandal and I hope Winterkorn and other top managers goes to jail for that. Also I'm biased, for me Facebook and Instagram are pretty useless, the only useful product they have is Whatsapp...

Post reply on HN