Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

151–160 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#151

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

"obtaining anything of value" could be satisfied by getting personal data which today is akin to profit, but the "intent to defraud" would be hard to prove in court, save for some very broad and dangerous intepretation of "intent" which could equal sloppiness to malice, a precedent that might ruin the lives of honest people who just happen to be clueless sysadmins or developers. Totally agree though on investigating whether this was really accidental or not; if it was done on purpopse I would expect FB to be hit really hard.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#152
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

From the article it sounds like there was a prompt for permission that got removed: > Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases. It doesn't take a…

Bug or no bug, that doesn't absolve them of liability (or, at least, responsibility) for the outcome of their actions.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#153
post #92
post #78

Earlier quoted context omitted.

Well, to be fair we probably don't hear about the accidents that end up causing the opposite situation. Those are just normal bugs.

"Facebook bug causes all user's sensitive data to not be uploaded in some case" sounds like an Onion headline.

The Onion has quite some insight on Facebook (the headlines practically write themselves):

"Mark Zuckerberg Promises That Misuse Of Facebook User Data Will Happen Again And Again" https://www.theonion.com/mark-zuckerberg-promises-that-misus...

"Facebook Employees Explain Daily Struggle Of Trying To Care About Company's Unethical Practices When Gig So Cushy" https://www.theonion.com/facebook-employees-explain-daily-st...

"Cash-Strapped Zuckerberg Forced To Sell 11 Million Facebook Users" https://www.theonion.com/cash-strapped-zuckerberg-forced-to-...

"New Facebook Feature Allows User To Cancel Account. ... The company later confirmed that account closures would not stop Facebook from continuing to acquire, permanently store, and sell all information about its current and former users until the day they die." https://www.theonion.com/new-facebook-feature-allows-user-to...

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#155

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

The statute says "anything of value." Here the thing of value would be a person's contact list. The attempt to gain this thing of value through deceit (telling the person you are trying to verify their account and using the access they give you to steal their contact list) would be the fraudulent act.

The fact that Facebook put a system in place to obtain these contact lists is evidence on its own of their value, but that value could also be quantified without much difficulty.

The only real question is: was dropping the consent form without removing the feature an honest mistake or was it done because somebody decided it would result in a lower bounce rate and thus more money for Facebook.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#157
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

From the article it sounds like there was a prompt for permission that got removed: > Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases. It doesn't take a…

This reminds me of the Firefox/Google tweet storm. A bunch of "bugs" or "unintentional feature" that get fixed with a seemingly honest apology, only for another "bug" or "unintentional feature" to take its place.

At some point, it goes from "the occasional bug" to negligence at best, and hostility at worst.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#158
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

>For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

I have an open ended question aimed mainly towards founders. Would you have any issues in hiring a candidate with Facebook on their resume?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#159

I'm pretty sure LinkedIn does or used to do the same.

There was a class action lawsuit against them (LinkedIn Lost it, iirc) for what they did. I believe they would try to connect you with any of your email contacts if you logged in with OAuth.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#160
post #158
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

>For the FB employees reading this: what is your tipping point? Would you say no to that assignment? I have an open ended question aimed mainly towards founders. Would you have any issues in hiring a candidate with Facebook on their resume?

Depends on the time range. Any time within the past 3-4 years: yeah, that's a problem.
Post reply on HN