Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

71–80 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#71
The incessant stories about Facebook are beyond tedious. I don't even know how to complain about this. I suppose it would be nice if we could somewhere officially label Facebook as dodgy rubbish, and abandon everyone who continues to knowingly use it to suffer the expected consequences, and never have to read another unsurprising article about them ever again.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#72
post #59

Why would anyone just give a site their password to their email account? And to Facebook on top of that?

Convenience. That is, Facebook - and others, like Skype - tells new users that the easiest and quickest way to find your friends is to send them your contacts so they can cross-reference the users.

And that, including me not paying attention, is how all my e-mail contacts got an email from facebook where I invited them to FB. That wasn't the intent!

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#73

FB has said they'll be notifying the people whose contacts they "unintentionally" uploaded. How about notifying those contacts whose private details they illicitly obtained that their privacy has been compromised by Facebook - the innocents who signed up for FB and had their contact-list stolen (let's call it what it is) may or may not feel any moral obligation (more likely, don't even see the issue) to notify their…

That's right. Whenever a computer system is breached, it is the breacher's responsibility to notification the affected people, not the entity entrusted with the information. That's why it's generally agreed that Equifax did nothing wrong when credit data was accessed.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#74

Earlier quoted context omitted.

From the article it sounds like there was a prompt for permission that got removed: > Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases. It doesn't take a…

Facebook is a multi-billion dollar company. This is gross negligence if they didn't spend time to QA this.

Doing QA at large tech companies is never that simple. You have lots of teams that share code. Imagine a scenario where Team A uses code written by Team B which uses code written by Team C. Team C makes a change to their code that breaks Team B's code but only for the way Team A uses it.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#75

Honestly I don't understand why Zuck doesn't sell up at Facebook and use his considerable money and brains to move to philanthropy, like billg. His personal brand is going to continue to dive while he's the face of this bullshit.

Zuckerberg, like billg, has no interest in philanthropy until his mortality and his wife are is staring him the face putting the fear of the afterlife in him.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#76
post #59

Why would anyone just give a site their password to their email account? And to Facebook on top of that?

People who aren't very tech/privacy-savvy, like elderly people, or kids/teenagers.

I remember signing up for facebook when I was in high school, and I probably would've provided my email password if facebook asked for it...as an adult now I wouldn't provide my email password to anyone, of course.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#77
post #68
post #47

Earlier quoted context omitted.

>what is your tipping point? Would you say no to that assignment? When FB stops giving them a check. At least that has been my experience watching programmers at other companies. Unless ethically bound by regulation and law, few people seem to have ethics.

>few people seem to have ethics Or maybe their set of ethics simply differs from yours. It is very subjective after all

> It is very subjective after all

Methinks that was what the OP was asking -- what is the tipping point ? Having differing ethics is fine but one can't just lean on that as a crutch when one has none.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#78
post #65

Earlier quoted context omitted.

From the article it sounds like there was a prompt for permission that got removed: > Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases. It doesn't take a…

its such a coincidence that these accidents keep happening in ways that enable further data gathering...surely there isn't a larger problem with Facebook's attitude towards their users' private data or anything

Well, to be fair we probably don't hear about the accidents that end up causing the opposite situation. Those are just normal bugs.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#79
post #9
post #8

Earlier quoted context omitted.

It requires just one developer and a couple of reviewers to make poor choices. Which begs the question, how do you structure your organisation such that a foolish developer that only barely understands the change that they are making can't write code that makes arbitrary queries to particular data sets in unapproved contexts?

But you actually say it requires negligence on part of multiple people. I find it very hard to apply Hanlon's razor in this case. Anyway, from my experience people do the stupidest/reckless things despite being told not to, just because there is no fear of backlash. Holding people liable for their actions could be a start, but who wants that? Also, don't hire foolish developers in the first place. Policing around peb…

Have you ever worked for an organization? 3 people making mistakes on a project, coupled with bystander effects, is par for the course. Being a million times wealthier isn't a million times smarter. We're still talking about how Boeing accidentally crashed a few jetplanes full of people, which required dozens of people to screw up.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#80
post #63

At some point, some government is going to have to step in and stop Facebook. Five years ago, I would not have believed that I would have supported government action. Now, I’m afraid for the future if there is no intervention.

I don't know if you've followed the news, but multiple governments have investigated, sued and fined Facebook. A quick Google indicates Facebook may end up paying 1.6 billion to the EU. The UK is doing an investigation too, with FB's impact on the Brexit referendum, as well as the whole Cambridge Analytica thing. If you're thinking Facebook is getting away with it, you're wrong. Of course, they're mainly getting fine…

Eventually fines can exceed revenue. There are also laws which allow board members to be directly liable, one of which (I have been told by trade-union-funded free legal aid) is the UK can go after board members who knowingly trade while insolvent — and demand they personally pay the debts.

Another (which is merely me reading the law and therefore probably doesn’t mean what I think it does) is prison time and equipment seizure if a business engages in copyright infringement commercially.

Post reply on HN