Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

231–240 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#231

Earlier quoted context omitted.

Please don’t downvote me into being the same color as the page background. I’m giving a serious answer to a question that was posed. This has been asked before on HN. The genuine answer is some combination of: * criticisms of FB are wildly exaggerated. This takes many forms, but in this particular case I think it’s the issue of attributing to malice what’s best explained by incompetence. Somebody probably just reused…

Hi FB employee -- I very much disagree with your position. The external reality is far from what you have said. * Criticisms of FB are not exaggerated. In this case, FB stole 1.5 million creds, then used these creds to harvest user data (nobody actually wants to give this data away, it was taken by force). If an individual did this, they would be in prison. FB gets away with it... again.. * People inside FB are a cul…

Please don’t imply that I’m speaking in bad faith and actually just motivated by money. Consider the possibility that I truly believe what I’m saying — anything less is just a horrible way to debate.

I am quite capable of making similar sums outside of Facebook. In fact I plan to leave soon for reasons that have nothing to do with ethics, and I don’t foresee myself changing my opinion once I’m no longer an employee.

Now to answer your specific points:

* Facebook did not steal credentials. They were willingly given.

* “Nobody actually wants to give this data away” how do you know? Do you have polling data on this? My personal belief is that most people don’t care at all.

Also you’re completely ignoring my assertion that it probably was just an accident. Hard to argue that something was “taken by force” by accident.

* Can you give me some examples of Zuckerberg knowingly lying about objective, verifiable facts to Congress?

* Well, your guess is as good as mine whether it’s better or worse on balance. My intuition is that it’s better. You haven’t really argued against this, just given some examples of the worst possible downsides and asking if they’re worth the most trivial upsides (conveniently ignoring the real value of communication tools in people’s lives, which has nothing to do with dog pictures and memes).

In my experience, FB isn’t divisive at all. I use it to talk daily to people who have become very close friends and who live in a different city (my home town). Without that connection, I would be extremely lonely.

* I’ve heard plenty of people in the US tell me great, unjust untruths like they were facts. They saw them on TV or heard them on the radio.

* As for FB being the most destructive force, I think you’d have to give that title to climate change, resource depletion, terrorism, and war.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#232
post #204

Phones need better features to entirely prevent these things - so apps can't trick the user. I want no application to have access, something like Incognito mode for all apps basically. The permission dialogues are typically not very helpful to make a meaningful decision and apps don't function at all without certain permissions. So why not allow to "fake" contacts,storage,location,etc... Majority of apps are just spy…

This could be done previously with on custom Android builds with XPrivacy (an XPosed module).

It worked quite well for a long time, but tended to be quite a burden to maintain through OS updates. Starting with Oreo or so it no longer worked, but there was another similar module that had much of its functionality.

It could even go as far as exposing a subset of your address book to an app. So, for example, when I wanted to use WhatsApp I could just show it the 3 contacts that I wanted it to see.

The operating system should sandbox every app and by default provide it fake data for everything. The user should say what they really want to allow the app to access.

I eventually switched to an iPhone and just don't install many apps.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#233
LinkedIn pulled something similar a few years back. At the time, I was using the same password for both my email and LinkedIn account, and found that people from my email address book were showing up as suggested connections. I can only assume "consent" for this was buried in the T&Cs.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#234
Can't someone file a class action lawsuit against Facebook?

I mean, it's nice that they are deleting the information now, but they clearly did something wrong, and by basic standards, they should be punished. And the deleting the stolen information isn't punishment, and since they probably won't delete any new ad targeting information they gathered as a conclusion from the contacts, they are still profiting from it, so the punishment should be more then just a small fine (that I hope they get).

I'm just sick of them (and other companies) "accidentally" doing something wrong, and barely get a slap on the wrist.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#235
post #199

FB's public comments about these remind me a lot of the "5 Standard Excuses" scene in the '80s BBC sitcom Yes Minister, where a civil servant lists the best CYA mea culpas for politicians to use when something goes wrong. 1. It occurred before certain important facts were known, and couldn’t happen again 2. It was an unfortunate lapse by an individual, which has now been dealt with under internal disciplinary procedu…

For those who haven't seen the clip, [1]. Yes Minister is a brilliant piece of satire (though it does have a somewhat unfortunate Thatcher-esque streak when it comes to discussion of unions -- though it would've been difficult to avoid ridiculing unions in satire from the 1980s).

[1]: https://www.youtube.com/watch?v=6Y4PEqvk0Jg

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#236

The only way FB will change its ways is if (a) good engineers stop joining them, and (b) good engineers at FB start leaving. This will threaten their entire growth prospectives and finally bring about change. I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore. FB engineers who are on HN: why are you still there? You can make similar…

I would assume that FB has gotten pretty good at hiring devs that match their culture. FB devs aren't reading HN articles about how bad FB is. FB devs are at FB because of the "prestige" of having been selected from the 10's of thousands of candidates. They're there for the money. They're there because they enjoy the projects. They're not there because they have some moral obligation to change FB.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#237
post #204

Phones need better features to entirely prevent these things - so apps can't trick the user. I want no application to have access, something like Incognito mode for all apps basically. The permission dialogues are typically not very helpful to make a meaningful decision and apps don't function at all without certain permissions. So why not allow to "fake" contacts,storage,location,etc... Majority of apps are just spy…

iOS has a prompt before your address book/contacts are shared with any app and apps will always work without it (required by dev guidelines).

However note that this article is not referring to the Facebook mobile app accessing the mobile contacts -- this is about their service logging into a person's email service (like GMail) and downloading their email contacts.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#238

The only way FB will change its ways is if (a) good engineers stop joining them, and (b) good engineers at FB start leaving. This will threaten their entire growth prospectives and finally bring about change. I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore. FB engineers who are on HN: why are you still there? You can make similar…

I would assume that FB has gotten pretty good at hiring devs that match their culture. FB devs aren't reading HN articles about how bad FB is. FB devs are at FB because of the "prestige" of having been selected from the 10's of thousands of candidates. They're there for the money. They're there because they enjoy the projects. They're not there because they have some moral obligation to change FB.

This just isn’t true. Plenty of people at FB read HN, everyone is acutely aware of the company’s reputation, and there is robust internal discussion and debate about all of these topics (and more)

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#239

Earlier quoted context omitted.

Hi FB employee -- I very much disagree with your position. The external reality is far from what you have said. * Criticisms of FB are not exaggerated. In this case, FB stole 1.5 million creds, then used these creds to harvest user data (nobody actually wants to give this data away, it was taken by force). If an individual did this, they would be in prison. FB gets away with it... again.. * People inside FB are a cul…

Please don’t imply that I’m speaking in bad faith and actually just motivated by money. Consider the possibility that I truly believe what I’m saying — anything less is just a horrible way to debate. I am quite capable of making similar sums outside of Facebook. In fact I plan to leave soon for reasons that have nothing to do with ethics, and I don’t foresee myself changing my opinion once I’m no longer an employee.…

I accept that you believe it, but I wish to challenge your beliefs. I hear the same talking points from most FB employees. I suspect its the local memes reinforcing cognitive dissonance.

* "Wallet inspector". I don't think the authorities would let you off if you claimed to socially engineer (steal) someones wallet. People wanted their FB supplied dopamine hit, and handing over email creds was the only thing in their way. It is coercion.

* Another FB meme -- 'people dont care so we can do what we like'. People lack the specific understanding of what they give up. It is coersive to take advantage of people like this. We talk of informed consent. FB existence is reliant on action without informed consent. https://news.gallup.com/poll/232343/worries-personal-data-to... recent poll showed 55% of users are concerned about FB selling there data. That's a majority. I think society is growing wiser in time. My hope is the social climate matures to understand what the individual gives up by using these services.

* MZ lies to congress: "we don't sell data to anyone." Mental gymnastics to make this true. Its the entire business model of FB, selling user data to advertisers -- sure, its not the raw bytes the user uploaded (however, they provided lots of record data to 3rd parties). The social graph is data, user data, and it is sold to advertisers, integration providers, hardware vendors, etc etc. How is MZ not a liar about privacy, again and again?

* I am ignoring your assertion it was an accident. Stealing credentials isnt an accident. Full take logging (capturing creds) on your HTTP gateways is an accident (kinda). Deploying credential stealing walls is no accident. Deploying code that uses these credentials to harvest address books is no accident. Its a chain of malicious actions. Cannot be an accident.

* We have legislative and industry standards for Radio and TV (aka legacy media) to ensure that untruths don't get very far. FB, not so much. Yes, all media can be a source for misinformation, but FB really is king here.

* I dont use facebook and am extremely lonely.

* Point taken, there are worse things in this world. But to me, this is the most visible, and most actionable, today.

Thanks for engaging. I don't really know why I decided to write all of this, but Im feeling mad over this credential harvesting. Its yet another strike.

Best of luck with your career outside FB!

Post reply on HN