Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

171–180 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#171

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

> A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this information without authorized access that is criminal.

I don't understand this. Claiming that something is an accident and not intentional usually isn't much of an excuse where it comes to the criminal acts.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#172

Earlier quoted context omitted.

Sufficiently advanced? I'm pretty sure there are five year olds who have learned the magic phrase "I didn't mean to!"

You're absolutely right. Yet for some reason it seems popular to discount that possibility. Particularly when invoking the thought terminating cliche that is "Hanlon's Razor."

For an entry in a joke book, it has done a surprising amount of damage.

edit - specifically, that mighty tome of great knowledge; 'Murphy's Law Book Two: More Reasons Why Things Go Wrong!', by Arthur Bloch.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#173

Earlier quoted context omitted.

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

Let’s not be ignorant of the idea of one or two senior developers each given a suitcase full of cash. It’s not like learning to program magically gives you unbreakable ethics. Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not. But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fau…

> It’s not like learning to program magically gives you unbreakable ethics.

Indeed.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#174
How is LinkedIn not under more scrutiny right now? They used to ask for my email password all the time along with re-asking for access to contacts at EVERY LOGIN.

I know this isn’t a contest, but I always felt LinkedIn was twice as scummy as fb.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#175

The only way FB will change its ways is if (a) good engineers stop joining them, and (b) good engineers at FB start leaving. This will threaten their entire growth prospectives and finally bring about change. I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore. FB engineers who are on HN: why are you still there? You can make similar…

> You can make similar money at several other companies without sacrificing your soul!

I'm not so sure. Certainly Google, Amazon, et al are just as bad as facebook.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#177

Earlier quoted context omitted.

Convenience. That is, Facebook - and others, like Skype - tells new users that the easiest and quickest way to find your friends is to send them your contacts so they can cross-reference the users. And that, including me not paying attention, is how all my e-mail contacts got an email from facebook where I invited them to FB. That wasn't the intent!

Interestingly, WhatsApp (and Telegram, and Signal) don't even ask and just upload all your contacts' phone numbers (this is before Android had the prompt "Allow this app access to your contacts?). It's very convenient, and also very sad. Also sad is the fact that BlackBerry already had a fine-grained permissions systems pre-iPhone days, but it took iPhone and Android many many versions and years before they built suc…

Signal doesn't upload your contact's details anywhere. It hashes your phone number and sends that to a central service that knows which hashed numbers have Signal. Then it periodically asks that service whether hashes of contact numbers are in the list in order to decide whether to suggest Signal for them instead of unencrypted messages.

It turns out that some people genuinely are forgetful enough that if they told their iPhone Bob's number, email address and shoe size in 2016 and then in 2019 their phone finds out that phone number is registered for Signal, they will conclude that the phone must have learned Bob's details from Signal, which in turn stole them from Bob as part of some nefarious plan.

You can't do anything about this, it's like the Spam problem. If you send ten million very, very useful emails that are genuinely valued by every human recipient, hundreds of them will be flagged "spam" because Humans aren't very good at this sort of thing. They press the wrong button or they've been using "mark as spam" because they thought it's "mark as read" or they meant to mark the one below it, or above it.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#178

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

> A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this information without authorized access that is criminal. I don't understand this. Claiming that something is an accident and not intentional usually isn't much of an excuse where it comes to the criminal acts.

The section he quoted says “knowingly and with intent”.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#179

Earlier quoted context omitted.

If criminal law isn't capable of handling a hacker who hacked 1.5 million victims, criminal law is broken. (If Facebook changed its name to Lulzsec2.0 of course the FBI would be very interested in the situation.) And while the previous commenter quoted the part of the CFAA that mentions fraud, fraud isn't necessary to violate the CFAA. All you need to do is exceed authorized access to any internet-connected computer.…

It's not hacking. It's social engineering. It's no different than some smooth talking "Nigerian" getting your grandmother to cut a check. No systems were hacked here, no technical errors or design loopholes were exploited. People were persuaded into doing things that gave Facebook the access it needed to obtain the contact info.

You are making a distinction that the criminal justice system does not make.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#180

Earlier quoted context omitted.

Not a lawyer, but at least in my jurisdiction, fraud requires a monetary loss by the victim. Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

> There’s got to be a monetary loss here. Our email contacts are valuable.

Why? Nobody lost their contacts, so what’s the $ amount it cost them? Facebook claims they’re deleting them. If that’s true, then Facebook isn’t gaining from the contacts. If users don’t lose anything and if Facebook doesn’t gain anything, what is the monetary loss?

> especially at 150m user scale

Where’s that number coming from? The article talks about 1.5 million users.

> We could have all banded together and sold them, had Facebook not stolen them.

So while it’s entirely true that contacts should never be copied without consent, and that’s exactly what happened, I guess don’t forget that these users consciously gave Facebook their passwords. No matter how much I trust what someone says they’ll do, my email account password gives access to everything in my email account, I’ve always thought it was a terrible terrible idea to ever do it when connecting services together, for this very reason. I’m saying it’s partly the users responsibility, and the outcome here is predictable, because it has been predicted before by many people.

BTW, nothing stopping you from banding together and selling email addresses now, if you think it’s a good idea... the blip with Facebook is not in any way preventing that from happening.

Post reply on HN