Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

141–150 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#141
This may be an unpopular opinion, but things like this happen. Someone gets the task to implement a login and either doesn't realize they should be using OAuth or is simply too lazy to do so. Next, someone has the idea to suggest friends, so let's grab some email contacts for that purpose.

That stuff happens all the time at small companies. While it's certainly bad practice, it's often not evil intent, but just lack of technical skills (for the former issue) and missing sense for potential privacy issues (for the latter).

In case of a large company like Facebook, one could expect they'd have processes and education in place to prevent such incidents, but I guess this happened a while back when FB was much smaller than it is now.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#142

Earlier quoted context omitted.

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

That implies that you, as a developer, then hear new stories like this one and simply ignore any role you may or may not have had in the situation. It implies that you simply ignore that your manager or engineering leadership are asking you to do things that are unethical without informing you about how your work will be used. It implies that you continue to work for that leadership knowing that they will lie to you,…

I’m more surprised that people are still being “surprised” that Facebook isn’t a wholesome company out to make the world a better place through algorithmic social manipulation.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#143

Earlier quoted context omitted.

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

If criminal law isn't capable of handling a hacker who hacked 1.5 million victims, criminal law is broken. (If Facebook changed its name to Lulzsec2.0 of course the FBI would be very interested in the situation.) And while the previous commenter quoted the part of the CFAA that mentions fraud, fraud isn't necessary to violate the CFAA. All you need to do is exceed authorized access to any internet-connected computer.…

It's not hacking. It's social engineering. It's no different than some smooth talking "Nigerian" getting your grandmother to cut a check. No systems were hacked here, no technical errors or design loopholes were exploited. People were persuaded into doing things that gave Facebook the access it needed to obtain the contact info.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#145
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

And there will be no oversight or testing of the prompt, the API or the people bringing the two together?

Nobody will test this? No developer in team C will consider what they're doing?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#146
post #65

Earlier quoted context omitted.

From the article it sounds like there was a prompt for permission that got removed: > Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases. It doesn't take a…

its such a coincidence that these accidents keep happening in ways that enable further data gathering...surely there isn't a larger problem with Facebook's attitude towards their users' private data or anything

Just to give them the benefit of the doubt:

When every public-facing thing you build is centered on hoovering up data, you're going to have two broad classes of errors. Hoovering up too little data, which doesn't hit the news, and hoovering up too much, which does.

That said, when your "errors" directly line your pockets, you're not entitled to the benefit of the doubt.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#147

Earlier quoted context omitted.

SOFORT quite explicitly ~scraps~ scrapes the entire available transaction history for „your convenience” (much more is available with access login and password actually). What a satisfaction when they tried to enter Polish market and the Polish finance controlling authorities shut them down before they managed to squeek. The famous German „privacy” it is.

The idea of handing over my banking password to any third party is crazy. Mind you, I'd love an API that I could use to easily pull all of my banking details into my local system. There are a few ways to do this currently, but nothing simple, open, and standard. P.S. As you seem to be a non-native English speaker, the word you wanted to use was "scrapes" not "scraps".

> I'd love an API that I could use to easily pull all of my banking details into my local system.

This is almost non-existend for personal banking. First and only case by now I’ve encountered was in Czechia:

https://www.fio.cz/bank-services/internetbanking-api

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#148
This is like the app version of "sorry honey, I totally didn't mean to stick it your butt but it was dark".

Facebook knew exactly what they were doing but they're playing dumb because it's less insulting to the recipient that way and they feel that will minimize the response.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#149
Related:

WhatsApp on iOS recently updated, and now will only show phone numbers for contacts UNLESS I upload my contacts.

In the UI if I click on a number it will take me to the profile where I can see that users name ~Tom, but wow, waddamove... Have we reached the point where FB can't make any more money until they go deeper or is this just drag-net "data is the new oil"

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#150

This may be an unpopular opinion, but things like this happen. Someone gets the task to implement a login and either doesn't realize they should be using OAuth or is simply too lazy to do so. Next, someone has the idea to suggest friends, so let's grab some email contacts for that purpose. That stuff happens all the time at small companies. While it's certainly bad practice, it's often not evil intent, but just lack…

> This may be an unpopular opinion, but things like this happen.

Yes, and at Facebook in the context of data gathering they seem to happen ALL THE TIME. So if they did actually care about privacy they'd make changes to curb these sort of "mistakes", but taken in aggregate the relentless "bugs" show a pattern of willful malevolence.

Post reply on HN