Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

161–170 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#161
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

Mushroom management: feed them shit and keep 'em in the dark.

Unfortunately, this ha-ha-only-serious joke is least several decades old.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#162

This may be an unpopular opinion, but things like this happen. Someone gets the task to implement a login and either doesn't realize they should be using OAuth or is simply too lazy to do so. Next, someone has the idea to suggest friends, so let's grab some email contacts for that purpose. That stuff happens all the time at small companies. While it's certainly bad practice, it's often not evil intent, but just lack…

"Next, someone has the idea to suggest friends, so let's grab some email contacts for that purpose."

You're joking right?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#163

I'm pretty sure LinkedIn does or used to do the same.

LinkedIn was pretty bad, but Facebook was saying that your login information was only going to get used to verify your email. smt88 has a good analogy up there

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#164
The only way FB will change its ways is if (a) good engineers stop joining them, and (b) good engineers at FB start leaving. This will threaten their entire growth prospectives and finally bring about change.

I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore.

FB engineers who are on HN: why are you still there? You can make similar money at several other companies without sacrificing your soul!

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#165

Earlier quoted context omitted.

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

Of course. If the email contacts were of no value, Facebook wouldn't be taking them from accounts. People tend not to to steal worthless assets. Unfortunately, monetary loss for the user may be tougher to prove than monetary gain for the thief.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#166
post #145

Earlier quoted context omitted.

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

And there will be no oversight or testing of the prompt, the API or the people bringing the two together? Nobody will test this? No developer in team C will consider what they're doing?

Of course there’s testing. It amounts to:

return true;

Return true is tested to still work.

But seriously. There’s no accident in what happened. This is Facebook. Anyone who thinks Facebook isn’t morally corrupt probably also says “What do you mean Stalin wasn’t a pacifist?”

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#167
post #116

Earlier quoted context omitted.

That looks too compilcated. Will you also use several different QA engineers and several product managers for this?

.. isn't that how larger scale projects are done?

I’m dead serious when I say that no two large scale projects are done the same way. I have seen many and can tell you the possibilities are infinite how it gets approached

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#168
post #153
post #92

Earlier quoted context omitted.

"Facebook bug causes all user's sensitive data to not be uploaded in some case" sounds like an Onion headline.

The Onion has quite some insight on Facebook (the headlines practically write themselves): "Mark Zuckerberg Promises That Misuse Of Facebook User Data Will Happen Again And Again" https://www.theonion.com/mark-zuckerberg-promises-that-misus... "Facebook Employees Explain Daily Struggle Of Trying To Care About Company's Unethical Practices When Gig So Cushy" https://www.theonion.com/facebook-employees-explain-daily-st…

You probably could just say CNN instead of the Onion and people wouldn’t bat an eye. Which is sad.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#169
post #63

At some point, some government is going to have to step in and stop Facebook. Five years ago, I would not have believed that I would have supported government action. Now, I’m afraid for the future if there is no intervention.

I don't know if you've followed the news, but multiple governments have investigated, sued and fined Facebook. A quick Google indicates Facebook may end up paying 1.6 billion to the EU. The UK is doing an investigation too, with FB's impact on the Brexit referendum, as well as the whole Cambridge Analytica thing. If you're thinking Facebook is getting away with it, you're wrong. Of course, they're mainly getting fine…

I don't think personal liability for white collar crime would be "dangerous." Someone either signed off on this, or negligently let it happen, and they should own it. Unfortunately, we'll probably just keep fining the company, and occasionally dragging Zuck in front of Congress for a bit of scolding and boilerplate apologizing.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#170

Earlier quoted context omitted.

From the article it sounds like there was a prompt for permission that got removed: > Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases. It doesn't take a…

Facebook is a multi-billion dollar company. This is gross negligence if they didn't spend time to QA this.

Gross negligence?

It is difficult to get a man to understand something, when his salary depends on his not understanding it.

-- Upton Sinclair

Post reply on HN