Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

131–140 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#131
post #113

Earlier quoted context omitted.

> that isn't harsh enough punishment then I don't know what to do next, Split the business into smaller, independent ones. We've seen this before. There's enough services hiding inside FB that treating them like a monopoly is not a terrible idea.

What, exactly, does Facebook have a monopoly on? It's not social media, chat, photo sharing, events, ads, or news.

Two points:

1.) The US FTC really needs to update its working definition of a monopoly. “Consumer welfare” is normally shown via price and since free services are always free, it’s a tough thing to argue.

2.) Facebook owns about 70% of the social networking space, and Google and Facebook have a virtual lock on online advertising. Moreover, through its share buttons, Facebook has created a web full of data gathering - the sheer amount of information they have makes them very hard to compete against. Add in some regulatory issues in the Instagram and Whatsapp regulations and there’s an image of a company that’s just about impossible to compete against and that has used its clout to bring net harm to consumers.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#132

Earlier quoted context omitted.

Convenience. That is, Facebook - and others, like Skype - tells new users that the easiest and quickest way to find your friends is to send them your contacts so they can cross-reference the users. And that, including me not paying attention, is how all my e-mail contacts got an email from facebook where I invited them to FB. That wasn't the intent!

Interestingly, WhatsApp (and Telegram, and Signal) don't even ask and just upload all your contacts' phone numbers (this is before Android had the prompt "Allow this app access to your contacts?). It's very convenient, and also very sad. Also sad is the fact that BlackBerry already had a fine-grained permissions systems pre-iPhone days, but it took iPhone and Android many many versions and years before they built suc…

Permissions to read text messages is another one that gets me. I know not many people use SMS as their primary communication but how can you be so astonishingly blasé about your data to save typing in a code?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#133

Earlier quoted context omitted.

Apparently Facebook is claiming that the functionality came from a separate "import contacts" feature that used to exist. But I agree; the idea that the import logic could have slipped into the login process accidentally is ludicrous. Or at least it indicates an outrageous lack of care on Facebook's part.

That's not exactly true, it depends on the architecture in use. For instance if using a Publish/Subscribe model, you could have had a service that listens to your email being connected, and since the only reason to connect your email was to upload contacts, it would upload contacts automatically. Later when login with email was added, the same event was sent but whomever added the event didn't know it would case the…

[deleted]

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#134

> Facebook says that it didn't mean to upload these contacts How can you not mean to? It's one thing to say that, were it something tangible, like paper, "Sorry, mate. These pages snuck in with the others. Sorry about that. We'll pull it out. No worries." Pulling contacts and uploading them is not a passive action but takes active action. > and is now in the process of deleting them. So, the question must then be ask…

> Pulling contacts and uploading them is not a passive action but takes active action. Action such as "accidentally" asking for email passwords. It is quite remarkable how these accidents line up just so. Grammar-checking programs should be flagging any use of "accident", "accidentally", "unintended" and "unintentionally" whenever they appear in the same sentence as "Facebook" and are not within quotes.

[deleted]

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#135
post #89

Earlier quoted context omitted.

Well yeah, I’m sure they do, but at what cost? The same data collection that government loves so much has been misused to throw elections and genuinely cast doubt upon the democratic process. Ultimately, creating this big giant drag nets has only empowered companies to demonstrate a complete lack of regard for humanity. If that’s security, I no longer want to be secure.

> The same data collection that government loves so much has been misused to throw elections If this is done in favor of the current government, then they probably won't mind.

I am sad by how incredibly accurate this statement is. Great comment, but geez, let me put my head back in the sand...:)

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#137

Earlier quoted context omitted.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

“150m user scale” is an expression speaking to Facebook’s gain , not to any users’ loss. What’s needed is serious privacy legislation, not creative reinterpretation.

Unfortunately not a lawyer so even my creative reinterpretation is moot but I was thinking along the lines of class action. Why can’t that group of people form a class? Is there really no damage here?

Of course we need actual fundamental privacy protection.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#138
post #84

Earlier quoted context omitted.

Still does. The apparently popular German payment system Sofortüberweisung (now run by Klarna) even requests the password of your bank account.

SOFORT quite explicitly ~scraps~ scrapes the entire available transaction history for „your convenience” (much more is available with access login and password actually). What a satisfaction when they tried to enter Polish market and the Polish finance controlling authorities shut them down before they managed to squeek. The famous German „privacy” it is.

The idea of handing over my banking password to any third party is crazy. Mind you, I'd love an API that I could use to easily pull all of my banking details into my local system. There are a few ways to do this currently, but nothing simple, open, and standard.

P.S. As you seem to be a non-native English speaker, the word you wanted to use was "scrapes" not "scraps".

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#139
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

Let’s not be ignorant of the idea of one or two senior developers each given a suitcase full of cash. It’s not like learning to program magically gives you unbreakable ethics.

Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not.

But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fault”. That isn’t a bad plan.

Post reply on HN