Live data from Hacker News

Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

nytimes.com

291–300 of 331 posts

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#291

Earlier quoted context omitted.

The political think tank that promulgated the term "whataboutism" has created a bane on humanity.

Whataboutism (also known as whataboutery) is a variant of the tu quoque logical fallacy... The term "whataboutery" has been used in Britain and Ireland since the period of the Troubles (conflict) in Northern Ireland.[10][11][12] Lexicographers date the first appearance of the variant whataboutism to the 1990s[1][10] or 1970s... https://en.wikipedia.org/wiki/Whataboutism https://books.google.com/ngrams/graph?content=t…

The problem with the term "whataboutism" is that its users wield it to prevent discussion about anything that doesn't fit their agenda. In particular, its main use has been to amplify the Russiagate conspiracy which was never backed by any evidence and yet was the forefront of public attention for almost three years. If you pointed out actual evidence-based foreign influence such as that put forward by the Saudis, you were accused of "whataboutism". This was almost certainly a tactic dreamed up in a politically motivated D.C. think tank or PR firm, and has prevented fruitful discussion of countless real issues for an extended period of time.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#292

This is pocket change for them. Reminds me of how they fine oil companies $50,000 and another $450,000 for violations. When they are making billions off of violating user privacy and will continue to keep using that user data for future business, this fine is nothing to them. It's like I manipulatively steal $10 from a million people and only lose a few bucks. They still profited.

$5,000,000,000 reminds you of $50,000? A fine of 1% of Facebook's value seems a bit more than pocket change.

It is 5 billion but that's nothing considering they make 15 billion and more in future using the unethical practices. It's like me stealing your car and only being fined for the wheel and I still get to keep the car.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#293

Earlier quoted context omitted.

Right. That's like saying there's not a difference in involuntary manslaughter and murder. There is. Intent is very important. That's WHY so many people focus on the intention.

A logical reason to care about intent is that malicious people will likely do it again and can not be trusted in the future where as people who make a mistake will avoid doing it again

For a corporation, "avoiding doing it again" means dedicating resources to preventing a repeat of that type of "mistake": audits, privacy reviews, etc.

The choice not to dedicate those resources up front was an intentional one.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#294

Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…

I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.

>Never attribute to malice that which is adequately explained by stupidity

I find that the people who use that quote are most often both.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#295
post #38

Seems like they should add another 0 to the fine after the recent hat trick: 1) Prompting users to give Facebook their email passwords.[0] 2) Using that email access to "inadvertently" upload the information of their email contacts.[1] 3) Storing said passwords and others in plaintext. [2] It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no mo…

> 3) Storing said passwords and others in plaintext. [2] in logs.

So, it's not in plaintext if it is in logs? Storing passwords in logs is even worse than on a database since access more likely is less restrictive. Every programmer worth its salt knows about this problem (I surely wrote code to prevent this).

Sorry, but it is like saying "there is no SQL injection, only bad input validation".

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#296

Earlier quoted context omitted.

I'm ashamed to say that up until now, when I saw Facebook (or similar) acting evil I thought about the quote, "Never attribute to malice that which is adequately explained by stupidity". Well, fuck that and fuck me, those people are not idiots, they're criminals.

Not to contradict your overall sentiment, but people often focus on intention with these issues. I think that's wrong. Like, if someone treads dog poo into my house on their shoes, it doesn't really matter if they did it by mistake, or spent ages walking around town trying to find some dog poo to step in before coming to my house; the effect is that there is now dog poo on my carpet. We need to be more dispassionate…

Isn't the presence of motive one of the cornerstones of a criminal investigation.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#298

Earlier quoted context omitted.

There definitely is a difference between someone accidentally tracking dog poo into your house vs someone doing it intentionally; in the first case, you all them to clean it up, and in the second case you break the friendship and/or seek criminal prosection. Likewise for big companies. If a company is acting badly, you need to figure out if it was intentional. In both cases you seek damages, but your approach to maki…

> There definitely is a difference between someone accidentally tracking dog poo into your house vs someone doing it intentionally; in the first case, you all them to clean it up, and in the second case you break the friendship and/or seek criminal prosection. But the point is that this assumes you're able to tell the difference between the two cases- intent is often a really hard thing to prove. And often discussion…

> hard thing to prove

It is and yet the legal system is busy with these sorts of proves all the time. e.g. if you have a professional insurance and caused some damage by mistake - that's covered, if you cause damage deliberately - it's not.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#299
post #130

> Every insider I've spoken to said any FTC fine on Facebook under $10 billion would be seen as a massive win, showing firm won't face serious consequences for privacy violations. Wall St. seems to agree in response to news of $3-$5b settlement [$FB up 4% after hours] https://twitter.com/lhfang/status/1121148735818358784

In other words, market rewards Facebook for being fined only $5 billion by increasing their market cap $20 billion. Unreal.

We should never read too much into such numbers, but, technically, expectations of a $25bn fine could explain exactly what you describe.

Re: Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues

#300

Earlier quoted context omitted.

I don't think they can make money off plain text passwords? They can only lose money from that, if it's discovered and they are fined and lose some users. They can make money from contact lists, but IIUC the article said they didn't use the contact lists. Also, given that it only affected a couple million users (like 0.1% of their user base), the damage to their reputation would far outweigh any benefits of actually…

how about extracting a user's contacts with their plaintext passwords that would usually be hashed into a database (at least in my professional experience) and thus unusable by facebook?

You can do many evil things with passwords. But, according to the articles, that's not what happened. They did download contact lists, even though they never used the plaintext passwords they stored in the logs. The users involved in the two incidents were different.
Post reply on HN