Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

261–270 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#263

So, when is the FTC going to actually bring down the hammer on FB for violating the consent agreement? There's no way this was "unintentional." At $40,000 per user per day [1], even at just one day of violation, that's a $60 billion fine FB should be liable for. "Under the settlement, Facebook agreed to get consent from users before sharing their data with third parties," so this seems to be EXACTLY in violation of t…

Also Let’s see a list of the various FTC settlements with FB. And a list of FTC employees who worked on those settlements now working for big tech.

I know one FTC employee who worked on the 2011 FTC/FB settlement (which required FB to obtain independent 3rd party audits certifying their privacy program for 20 years...never mind the subsequent violations and settlements) is now “head of privacy” for a certain social networking company.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#264

So, when is the FTC going to actually bring down the hammer on FB for violating the consent agreement? There's no way this was "unintentional." At $40,000 per user per day [1], even at just one day of violation, that's a $60 billion fine FB should be liable for. "Under the settlement, Facebook agreed to get consent from users before sharing their data with third parties," so this seems to be EXACTLY in violation of t…

Maybe I'm just ignorant, but I do not really see how this violates the FTC agreement, because it covers Facebook sharing user data (stored/tracked/gathered by Facebook) with third parties.

However, what Facebook did is far worse than violating that agreement. Facebook gained accessed to user data on third party systems, to which they should never have had access. They gained this (unauthorized) access (at best without clear consent) on a false pretense (disguising as security related requirement). Then they imported user data, with no relationship to their stated goal/requirement, into their platform.

Associative contact information is a highly valuable commodity to any company involved in marketing and social media. I've seen a lot of people argue how this could have been the result of a laps of oversight, but that sounds like arguing how a gem stone trader might have "accidentally" stolen a large quantity of rough gem stones, while claiming to not have known their value. Even if theoretically possible, it's extremely unlikely that nobody within Facebook knew/realized the value of this data.

Either way, Facebook gained access to highly valuable assets. Even in the unlikely event of sincere lack of oversight, it would demonstrate a level of incompetence that warrants them to still be held criminally liable.

Moreover, Facebook might actually have outright violated the Computer Fraud and Abuse Act (CFAA), in particular the "access in excess of authorization" part, but I'm not sure.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#265
post #235
post #199

FB's public comments about these remind me a lot of the "5 Standard Excuses" scene in the '80s BBC sitcom Yes Minister, where a civil servant lists the best CYA mea culpas for politicians to use when something goes wrong. 1. It occurred before certain important facts were known, and couldn’t happen again 2. It was an unfortunate lapse by an individual, which has now been dealt with under internal disciplinary procedu…

For those who haven't seen the clip, [1]. Yes Minister is a brilliant piece of satire (though it does have a somewhat unfortunate Thatcher-esque streak when it comes to discussion of unions -- though it would've been difficult to avoid ridiculing unions in satire from the 1980s). [1]: https://www.youtube.com/watch?v=6Y4PEqvk0Jg

Why do think ridiculing unions is bad?

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#267
Am I wrong in thinking "unintentionally" is only there because they claimed it was accidental? Accidental possibly in the same way that a woman is accidentally washing her hair so she doesn't have to answer the door. There is a question of how accidental accidental really is.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#268

18 USC 1030 (a)(4) (4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value https://www.law.cornell.edu/uscode/text/18/1030 A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this…

> A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this information without authorized access that is criminal. I don't understand this. Claiming that something is an accident and not intentional usually isn't much of an excuse where it comes to the criminal acts.

Literally begins with

>knowingly and with intent

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#269
post #42

Saying "unintentionally" here is like saying you unintentionally stole someone's TV when they gave you their key to walk their dog. It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it. For the FB employees reading this: what is your tipping point? Would you say no to that assignment?

In The Fine Article, it says that the feature was built on purpose, and previously asked for permission. The accident is that it wasn't completely removed.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#270

So, when is the FTC going to actually bring down the hammer on FB for violating the consent agreement? There's no way this was "unintentional." At $40,000 per user per day [1], even at just one day of violation, that's a $60 billion fine FB should be liable for. "Under the settlement, Facebook agreed to get consent from users before sharing their data with third parties," so this seems to be EXACTLY in violation of t…

Maybe I'm just ignorant, but I do not really see how this violates the FTC agreement, because it covers Facebook sharing user data (stored/tracked/gathered by Facebook) with third parties. However, what Facebook did is far worse than violating that agreement. Facebook gained accessed to user data on third party systems, to which they should never have had access. They gained this (unauthorized) access (at best withou…

Just stop using Facebook, Instagram and WhatsApp. I did, years ago, and absolutely nothing of value was lost.
Post reply on HN