Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

181–190 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#181
post #59

Why would anyone just give a site their password to their email account? And to Facebook on top of that?

It's a pretty easy mistake to make when you're new to the web, or simply don't care all that much how it works. I made the mistake of giving someone my contacts once when I was new to this stuff, and had many apology emails to send when my friends were spammed as a result. It was a harsh lesson in the web's fundamental hostility.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#182

This may be an unpopular opinion, but things like this happen. Someone gets the task to implement a login and either doesn't realize they should be using OAuth or is simply too lazy to do so. Next, someone has the idea to suggest friends, so let's grab some email contacts for that purpose. That stuff happens all the time at small companies. While it's certainly bad practice, it's often not evil intent, but just lack…

They broke the law. They should pay. "Accidentally" is irrelevant here, even if you believe them.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#183

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

I think the "intent to defraud" (scienter) requirement's going to present a proof hurdle. Not necessarily insurmountable but it's still there.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#184

Earlier quoted context omitted.

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

That looks too compilcated. Will you also use several different QA engineers and several product managers for this?

Yes, work at large organizations with a lot of different features and products, often having complicated interactions, is not trivial.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#185

The only way FB will change its ways is if (a) good engineers stop joining them, and (b) good engineers at FB start leaving. This will threaten their entire growth prospectives and finally bring about change. I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore. FB engineers who are on HN: why are you still there? You can make similar…

Regulation is much more realistic, IMO.

The tech industry worships money and those who make it, and there are plenty of engineers who'd take the FB compensation package in a heartbeat, regardless of FB's public image problem.

This idea that the public will act together morally to stop corporate malfeasance while sacrificing their good fortunes isn't that realistic. Look at the FB shareholder situation. Lots of shareholders are angry at Zuck but can't do anything about it. None of them seem particularly interested in selling their shares because they don't want to have to pay for his bad behavior.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#186

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

> A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this information without authorized access that is criminal. I don't understand this. Claiming that something is an accident and not intentional usually isn't much of an excuse where it comes to the criminal acts.

Really? Mens rea is a necessary component of the statutes for many crimes.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#187

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

"obtaining anything of value" could be satisfied by getting personal data which today is akin to profit, but the "intent to defraud" would be hard to prove in court, save for some very broad and dangerous intepretation of "intent" which could equal sloppiness to malice, a precedent that might ruin the lives of honest people who just happen to be clueless sysadmins or developers. Totally agree though on investigating…

It wouldn't be that hard if the court orders a search of internal memos, emails, and chats to see if this was ever mentioned internally.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#188

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

> A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this information without authorized access that is criminal. I don't understand this. Claiming that something is an accident and not intentional usually isn't much of an excuse where it comes to the criminal acts.

[deleted]

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#189

Earlier quoted context omitted.

A common practice is to keep developers unaware of the real objective of their work (like Uber, in another comment on HN, https://news.ycombinator.com/item?id=13786384 ): - developer A is tasked to create the prompt to ask for username and password of the email account - developer B is tasked to call some API to upload contacts from email account - developer C is tasked to bind two functionalities. Now replace develo…

Let’s not be ignorant of the idea of one or two senior developers each given a suitcase full of cash. It’s not like learning to program magically gives you unbreakable ethics. Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not. But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fau…

I’m not one of them, but let me play the devil’s advocate...

You’re getting paid 2x market salary (“market” here being non-Facebook and non-Google, which isn’t any better) and delivering services to people who voluntarily sign up ro them... I mean there are worse jobs in the world.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#190

I don't recall ever hearing that Facebook made a mistake which decreased the amount of data they collected or their usage thereof. Can anyone provide an example?

I get what you’re getting at here, but I don’t think it would be reported in the general media as it’s not a privacy violation.
Post reply on HN