Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

191–200 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#191
post #65

Earlier quoted context omitted.

its such a coincidence that these accidents keep happening in ways that enable further data gathering...surely there isn't a larger problem with Facebook's attitude towards their users' private data or anything

Just to give them the benefit of the doubt: When every public-facing thing you build is centered on hoovering up data, you're going to have two broad classes of errors. Hoovering up too little data, which doesn't hit the news, and hoovering up too much, which does. That said, when your "errors" directly line your pockets, you're not entitled to the benefit of the doubt.

1. Give us the login info to your personal email.

That’s the initial asshole maneuver. There’s no excuse for Facebook to need that. Period.

2. CollectUserContacts(email, username, password);

It’s pretty hard for me to imagine that there’s some other function that just happens to coincide with accessing different email servers and collect past emails to collect the email addresses.

It was deliberate because of the work involved. The only investigators that think it’s accidental probably believe the internet is a small black box guarded by the “Internet wizards”.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#192
post #97

Why are companies even asking users to provide passwords for unrelated services? For example, when I added an external account on Etrade, they gave me the option of same day verification of that account if I provided them my online banking account credentials. This practice opens up a significant potential for abuse and should be illegal.

Is this question rhetorical? Your online banking is known to be verified, therefore another company can piggyback on that verification.

Yes, but that doesn't mean that someone else needs my credentials to verify it. They should have their own independent method of verification. Do I need to give you my online banking's user name and password in order for you to send me money?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#193

The only way FB will change its ways is if (a) good engineers stop joining them, and (b) good engineers at FB start leaving. This will threaten their entire growth prospectives and finally bring about change. I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore. FB engineers who are on HN: why are you still there? You can make similar…

Regulation is much more realistic, IMO. The tech industry worships money and those who make it, and there are plenty of engineers who'd take the FB compensation package in a heartbeat, regardless of FB's public image problem. This idea that the public will act together morally to stop corporate malfeasance while sacrificing their good fortunes isn't that realistic. Look at the FB shareholder situation. Lots of shareh…

> while sacrificing their good fortunes isn't that realistic.

... this does not need to happen. Plenty of other companies in the Bay Area pay as well as FB, but without the heartache.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#194
I hate it when I accidentally write some code to crawl email accounts for data and accidentally upload that data. Accidentally deploy that code to production, hide the opt-out button, and forget to post a disclaimer. Gosh darn it!

I'm just a mess without my morning coffee. If I don't get a good cup of joe in the AM I could do something reckless and random... like violate the privacy of millions of people! OOPS!

You know what I'm talking about! Right! ... right? ...

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#195
post #180

Earlier quoted context omitted.

There’s got to be a monetary loss here. If there isn’t precedent for calculating that loss, such precedent should be established. Our email contacts are valuable, especially at 150m user scale. We could have all banded together and sold them, had Facebook not stolen them. These users should be compensated.

> There’s got to be a monetary loss here. Our email contacts are valuable. Why? Nobody lost their contacts, so what’s the $ amount it cost them? Facebook claims they’re deleting them. If that’s true, then Facebook isn’t gaining from the contacts. If users don’t lose anything and if Facebook doesn’t gain anything, what is the monetary loss? > especially at 150m user scale Where’s that number coming from? The article t…

>don’t forget that these users consciously gave Facebook their passwords.

There is a lot of legal precedence about social engineering and how to prosecute it, this would completely fall under fraud. If I ask someone for their password to perform some service and they then I copy all of their data, that is a crime regardless of how stupid they are.

This really doesn't matter at all in a case of fraud if you gave the password willingly, it is under false pretense. If someone asks me to give them something so that they can provide a service or take those things as an investment. I willingly give them those things yes, but we have a written, verbal, or implied contract that they will do and will not do certain things with that information. Failure to follow our agreement and instead robbing me is a crime.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#196
post #189

Earlier quoted context omitted.

Let’s not be ignorant of the idea of one or two senior developers each given a suitcase full of cash. It’s not like learning to program magically gives you unbreakable ethics. Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not. But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fau…

I’m not one of them, but let me play the devil’s advocate... You’re getting paid 2x market salary (“market” here being non-Facebook and non-Google, which isn’t any better) and delivering services to people who voluntarily sign up ro them... I mean there are worse jobs in the world.

“I have an idea”

“That’s a really dick of an idea and I’m pretty sure it’s illegal. Exactly how illegal, I’m not sure. But I know illegal to some degree.”

“You live in a shit apartment because housing prices are stupid and makes your salary meaningless in this town. Here’s a wheelbarrow full of hundreds and we all agree it was an accident.”

“When do you need it by?”

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#197

> Facebook says that it didn't mean to upload these contacts How can you not mean to? It's one thing to say that, were it something tangible, like paper, "Sorry, mate. These pages snuck in with the others. Sorry about that. We'll pull it out. No worries." Pulling contacts and uploading them is not a passive action but takes active action. > and is now in the process of deleting them. So, the question must then be ask…

So Facebook has no QA or Facebook has QA no one listens to? I imagine the latter.

Probably no qa. Lots of tech companies put qa on the developer

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#198

Earlier quoted context omitted.

It's not hacking. It's social engineering. It's no different than some smooth talking "Nigerian" getting your grandmother to cut a check. No systems were hacked here, no technical errors or design loopholes were exploited. People were persuaded into doing things that gave Facebook the access it needed to obtain the contact info.

You are making a distinction that the criminal justice system does not make.

There's no law that makes "hacking" a criminal offense. This particular case is just manipulation/social engineering so you probably shouldn't be calling it "hacking" on a message board that's mostly populated by software professionals to whom "hacking" has a meaning that does not include what is basically a con-man trick (though I see you have already edited the parent comment to reflect this).

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#199
FB's public comments about these remind me a lot of the "5 Standard Excuses" scene in the '80s BBC sitcom Yes Minister, where a civil servant lists the best CYA mea culpas for politicians to use when something goes wrong.

1. It occurred before certain important facts were known, and couldn’t happen again

2. It was an unfortunate lapse by an individual, which has now been dealt with under internal disciplinary procedures.

3. There is a perfectly satisfactory explanation for everything, but security forbids its disclosure.

4. It has only gone wrong because of heavy cuts in staff and budget which have stretched supervisory resources beyond their limits.

5. it was a worthwhile experiment, now abandoned, but not before it had provided much valuable data and considerable employment.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#200

> Facebook says that it didn't mean to upload these contacts How can you not mean to? It's one thing to say that, were it something tangible, like paper, "Sorry, mate. These pages snuck in with the others. Sorry about that. We'll pull it out. No worries." Pulling contacts and uploading them is not a passive action but takes active action. > and is now in the process of deleting them. So, the question must then be ask…

This seems like 'growth hacking' gone wrong. Facebook's growth has been loosing momentum for several year's now and it seems to me they are trying to make up for it by using every trick they have up their sleeves.

They might want to overthink their motto 'Move fast and break things'.

Post reply on HN