Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

121–130 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#121
post #113

Earlier quoted context omitted.

> that isn't harsh enough punishment then I don't know what to do next, Split the business into smaller, independent ones. We've seen this before. There's enough services hiding inside FB that treating them like a monopoly is not a terrible idea.

What, exactly, does Facebook have a monopoly on? It's not social media, chat, photo sharing, events, ads, or news.

They don't. I meant the similar approach of splitting them up would make both the regulation easier and self-regulation more incentivise - the same reason monopolies are split.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#122

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#123
post #97

Why are companies even asking users to provide passwords for unrelated services? For example, when I added an external account on Etrade, they gave me the option of same day verification of that account if I provided them my online banking account credentials. This practice opens up a significant potential for abuse and should be illegal.

Is this question rhetorical?

Your online banking is known to be verified, therefore another company can piggyback on that verification.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#124
post #84

Earlier quoted context omitted.

Still does. The apparently popular German payment system Sofortüberweisung (now run by Klarna) even requests the password of your bank account.

SOFORT quite explicitly ~scraps~ scrapes the entire available transaction history for „your convenience” (much more is available with access login and password actually). What a satisfaction when they tried to enter Polish market and the Polish finance controlling authorities shut them down before they managed to squeek. The famous German „privacy” it is.

They claim it's to see that the customer is liquid enough, so more for the convenience of the seller.

It's incredible that the banks tolerated this service even though they told their customers to not to give their credentials to a 3rd party. Or not just banks, how about the German Federal Office for Information Security.

I wish the bank would just block accounts who they detect used the service with an error like "We think your credentials have been compromised" (then again the stupid customer will think it's the bank who got breached). Or give them a fine of e.g. 100 Euro for breaching their user agreement. Then again, this would lose them so many pissed-off customers.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#125

Honestly I don't understand why Zuck doesn't sell up at Facebook and use his considerable money and brains to move to philanthropy, like billg. His personal brand is going to continue to dive while he's the face of this bullshit.

Presumably he enjoys running a powerful business built on privacy violation more than he thinks he'd enjoy philanthropy.

The BS you refer to is his creation, not some accidental thing that happened to occur in his company without his intention.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#126

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

Yeah, 18 USC 1030 (a)(2)(C) might be a better fit:

> Whoever ... intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer ... shall be punished as provided in subsection (c) of this section.

(The definition of "protected computer" encompasses any computer that is "used in or affecting interstate or foreign commerce or communication".)

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#127

Earlier quoted context omitted.

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

“150m user scale” is an expression speaking to Facebook’s gain, not to any users’ loss.

What’s needed is serious privacy legislation, not creative reinterpretation.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#128

Earlier quoted context omitted.

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

I think 'monetary loss' has a bit more of a meaning of actual money or assets lost, not potential to earn money that you weren't really planning on using being lost. Not saying I think it's not an issue! But I don't think the term 'monetary loss' is applicable.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#129

Earlier quoted context omitted.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

I think 'monetary loss' has a bit more of a meaning of actual money or assets lost, not potential to earn money that you weren't really planning on using being lost. Not saying I think it's not an issue! But I don't think the term 'monetary loss' is applicable.

Yeah you are probably right. For shame. Also, thanks for Graal!

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#130

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

If criminal law isn't capable of handling a hacker who hacked 1.5 million victims, criminal law is broken.

(If Facebook changed its name to Lulzsec2.0 of course the FBI would be very interested in the situation.)

And while the previous commenter quoted the part of the CFAA that mentions fraud, fraud isn't necessary to violate the CFAA. All you need to do is exceed authorized access to any internet-connected computer. Is there any doubt that Facebook has admitted to doing that?

Post reply on HN