Live data from Hacker News

Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

bloomberg.com

41–50 of 105 posts

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#41

I'm glad the attorney general is getting involved. We need to start charging Facebook execs for these flagrant privacy violations. They're being fined 3 billion dollars for legal expenses relating to an FTC inquiry… and their stock price went up by 8% [1]. The market just does not care; it's time regulators and law enforcement started to. [1] https://www.barrons.com/articles/facebook-stock-is-up-becaus...

Not just execs, I hope. The engineers who wrote the code and managers who told them to do it should also face justice.

Have you never committed a bug before?

> A Facebook spokesperson said before May 2016, it offered an option to verify a user's account using their email password and voluntarily upload their contacts at the same time. However, they said, the company changed the feature, and the text informing users that their contacts would be uploaded was deleted — but the underlying functionality was not.

I doubt it was an engineer who deliberately removed the text but kept the contact import functionality.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#42
post #5

I'm glad the attorney general is getting involved. We need to start charging Facebook execs for these flagrant privacy violations. They're being fined 3 billion dollars for legal expenses relating to an FTC inquiry… and their stock price went up by 8% [1]. The market just does not care; it's time regulators and law enforcement started to. [1] https://www.barrons.com/articles/facebook-stock-is-up-becaus...

The market cares. It had already priced in a fine, possibly one larger than 3B. The reduction in uncertainty -- knowing the magnitude of the fine -- also positively affects the stock price. If the fine were cancelled tomorrow, you can be sure that, all else equal, Facebook's market cap would jump by 3B. The fines need to be bigger.

Yes. The fine needs to take into account how much Facebook would stand to lose if the case went to trial and they were found guilty, setting a precedent for future actions against them. That seems like it could result in near-unlimited liability for Facebook. The fine for avoiding an admission of wrongdoing should be set equal to the expected value of all that liability, based on an estimate of the probability of winning the case.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#43
post #41

Earlier quoted context omitted.

Not just execs, I hope. The engineers who wrote the code and managers who told them to do it should also face justice.

Have you never committed a bug before? > A Facebook spokesperson said before May 2016, it offered an option to verify a user's account using their email password and voluntarily upload their contacts at the same time. However, they said, the company changed the feature, and the text informing users that their contacts would be uploaded was deleted — but the underlying functionality was not. I doubt it was an engineer…

> Have you never committed a bug before?

Engineers who make mistakes that harm people are still responsible for the mistakes they made. You cannot just claim "it was a bug" and get off scot free if your code harms someone or otherwise breaks the law. Also there's no need for this sarcastic tone, "have you never..?"

> I doubt it was an engineer who deliberately removed the text but kept the contact import functionality.

Why would you doubt that? I personally think that situation sounds quite likely. But either way we're just speculating.

Also, don't ignore the part of the parent comment that discusses the manager's (and implied other decision markers) that result in the decision being made to make an illegal change to the code.

Engineer, or manager, or QA assistant - someone or some group of people will have made the change. And "oops that was a bug" doesn't count. Corporations and their employees must be held to the same laws and standards to which the rest of us are held. "Ooops I didn't mean to do that" doesn't fly as an excuse to break the law.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#44

So this relates to their practice of ransacking all your email contacts without your consent, engaging in data theft as they upload them and analyze them for subsequent actions. And of course Linked In is also notorious for engaging in this criminal vile privacy raping practice. I remember maybe 8 years ago it was here on HN that a company was found to be doing this and it was shocking to some. But an executive of th…

LinkedIn is notorious for this. The app still asks for contact access all the time.

Saying that the app asks is not accurate. It's not presented as a choice and it's not clear what will happen when you continue.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#45
post #10
post #4

Did anything happen regarding LinkedIn's email harvesting from before when Microsoft bought it? I feel like that was far worse than Facebook's.

They settled a class action lawsuite I think, but if I remember there was some form of consent involved that emails will be leveraged (probably not obvious either, and shouldn't be done). In Facebook's case it has clearly been misleading, possibly intentionally multiple times now (email, phone numbers,...).

I didn't like it (which is why they didn't get my damned password), but they were pretty open about what they planned to do with your credentials.

The problem isn't how open they are, it's that most people don't understand what the harvesting means. Facebook could have asked for the sacrifice of the firstborn and people would have snapped it up on the prospect of a few likes on their fake online alterego. It's human nature and the HN echo chamber exists far outside that normalcy. Most people don't "get it" (through no fault of their own) and that's why it's dangerous [edit] and effective.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#46
Are there screenshots or something of this "asking for email password" thing the article talks about? I feel like anyone who sees a facebook page asking for their email password should already feel a bit warned and skeptical. I had personally never seen such a thing until 3 years ago when I deactivated my account. Is this a new thing?

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#47

Are there screenshots or something of this "asking for email password" thing the article talks about? I feel like anyone who sees a facebook page asking for their email password should already feel a bit warned and skeptical. I had personally never seen such a thing until 3 years ago when I deactivated my account. Is this a new thing?

The Business Insider article has this: https://amp.businessinsider.com/images/5ca400acc6cc5023740b5...

https://www.businessinsider.com/facebook-uploaded-1-5-millio...

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#49
The article claims the practice "was uncovered by Business Insider last week", implying FB was being sneaky about it. But if you look at the Business Insider article (https://www.businessinsider.com/facebook-uploaded-1-5-millio...), you'll see this:

> A Facebook spokesperson said before May 2016, it offered an option to verify a user's account using their email password and voluntarily upload their contacts at the same time. However, they said, the company changed the feature, and the text informing users that their contacts would be uploaded was deleted — but the underlying functionality was not.

> "Last month we stopped offering email password verification as an option for people verifying their account when signing up for Facebook for the first time. When we looked into the steps people were going through to verify their accounts we found that in some cases people's email contacts were also unintentionally uploaded to Facebook when they created their account"

so Facebook discovered this bug in an audit of its code, fixed it, and planned to notify everyone who was impacted.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#50

So this relates to their practice of ransacking all your email contacts without your consent, engaging in data theft as they upload them and analyze them for subsequent actions. And of course Linked In is also notorious for engaging in this criminal vile privacy raping practice. I remember maybe 8 years ago it was here on HN that a company was found to be doing this and it was shocking to some. But an executive of th…

LinkedIn is notorious for this. The app still asks for contact access all the time.

The worst is, even if you deny Linkedin access to your contacts. Your contacts will still show up in suggestions, because others have givein LinkedIn access to their contacts. And LinkedIn maps it with your Linkedin signup email address.
Post reply on HN