Live data from Hacker News

Facebook has sent a cease-and-desist letter to researchers

twitter.com

51–60 of 201 posts

Re: Facebook has sent a cease-and-desist letter to researchers

#51

Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098... “Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”

s/NYU app/Google Chrome/g and somehow FB is ok with it, so it isn't security model, it is the people and the goals of their actions what ire FB.

Re: Facebook has sent a cease-and-desist letter to researchers

#52

Did they even agree to the ToS? It seems like they wrote their own plugin to harvest the data, what agreement did they made with Facebook that they are in violation of?

Having an agreement with someone is not a prerequisite for being able to send them a C&D.

Re: Facebook has sent a cease-and-desist letter to researchers

#53
post #46
post #36

Wait so Facebook can collect data about its users but Facebook users aren't allowed to collect data about Facebook?

If I’m your friend on Facebook should you be allowed to go to my page and give all the information I’ve shared with you to another 3rd party? You trust NYU, OK fine. Can I give the same information about you to pro-Trump researchers?

You shared the information with your Facebook friends without any protections. Why shouldn't they be allowed to share it with other people? What legal obligation do they have to keep the information you shared private?

Re: Facebook has sent a cease-and-desist letter to researchers

#54
post #52

Did they even agree to the ToS? It seems like they wrote their own plugin to harvest the data, what agreement did they made with Facebook that they are in violation of?

Having an agreement with someone is not a prerequisite for being able to send them a C&D.

I agree, but:

> In a letter sent Oct. 16 to the researchers behind the NYU Ad Observatory, Facebook said the project violates provisions in its terms of service that prohibit bulk data collection from its site.

Re: Facebook has sent a cease-and-desist letter to researchers

#55
post #31

Earlier quoted context omitted.

Comparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.

The whole point is that a major problem with CA was the scaled friend’s data collection. The NYU app scraping modality could easily do the same thing which violates the present FB consent/sharing model of you control your data going to or not going to third party apps. FB has to fight as hard as possible against such apps. Remember Clearview AI? If we want FB to fight CA and Clearview they must fight here as well.

> The NYU app scraping modality could easily do the same thing

So could any browser extension with the ol' "read and modify your data on \*" permission. Or any browser. Or any third-party Facebook client.

There is a difference between being technically capable of doing a thing and actually doing the thing- especially in cases where the software authors are well-known and relatively easy to hold accountable. To say otherwise is a little bit goofy!

Re: Facebook has sent a cease-and-desist letter to researchers

#56

Did they even agree to the ToS? It seems like they wrote their own plugin to harvest the data, what agreement did they made with Facebook that they are in violation of?

WSJ: "In a letter sent Oct. 16 to the researchers behind the NYU Ad Observatory, Facebook said the project violates provisions in its terms of service that prohibit bulk data collection from its site."

That's the key point here. The researchers are not a party to Facebook's terms of service. The user installing the add-on may be, but that does not bind the add-on developer. (This is called "privity" in law; contract constraints do not obligate third parties who didn't agree to the contract.)

Facebook could disconnect Facebook users using the add-on, if they can detect them. That would be a bad PR move.

Re: Facebook has sent a cease-and-desist letter to researchers

#57

Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098... “Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”

Doesn't NYU have an Institutional Review Board?

Re: Facebook has sent a cease-and-desist letter to researchers

#58
post #31

Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098... “Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”

Comparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.

The point is that CA's data harvesting looked like it was transparent to users at the time they were doing it — which is precisely the appearance you'd expect a malicious app to try to convey.

The NYU project is probably on the level, but "they're probably on the level" isn't a very good security model at Facebook's scale.

More to the point, the FTC's 2019 Consent Decree [1] makes it fairly clear that FB is responsible for third parties' access to its users' data — and it would be prudent (from FB's point of view) to interpret this responsibility as also covering browser extensions.

[1] https://www.ftc.gov/system/files/documents/cases/c4365facebo...

Re: Facebook has sent a cease-and-desist letter to researchers

#60
post #49
post #45

Earlier quoted context omitted.

It's a browser plugin, not a facebook app. Why should facebook have a say on what plugins I have installed in my browser that did not come from facebook? Should they be able to have a say about ublock origin or other apps I have installed on my computer/browser?

it would be a new angle to require functionality qualifications examination to weed out any compromized browsers or OS's, all in the name of security and privacy of course

SECURITY ERROR

This comment by /u/XMPPwocky cannot be displayed because of a security problem with your device. If this error persists, reinstall your operating system or replace your device.

Technical details: "An enclave could not be verified due to a problem with its digital certificate" (E_BAD_ENCLAVE_SIG).

Logging info:

Local: Success (monotonic counter 5 increment OK)

Remote: Success (200 OK in 0.113s)

Post reply on HN