Live data from Hacker News

Facebook has sent a cease-and-desist letter to researchers

twitter.com

91–100 of 201 posts

Re: Facebook has sent a cease-and-desist letter to researchers

#91
post #52

Did they even agree to the ToS? It seems like they wrote their own plugin to harvest the data, what agreement did they made with Facebook that they are in violation of?

Having an agreement with someone is not a prerequisite for being able to send them a C&D.

Sure, but at that point they'd have to be breaking some kind of law to warrant one, wouldn't they?

Re: Facebook has sent a cease-and-desist letter to researchers

#92
post #9

Earlier quoted context omitted.

How was their acquisition of Instagram and Whatsapp legal? Haven't antitrust laws broken up companies for less?

Pre-Reagan, sure. Since then, none. There's zero interest in breaking up monopolies in the US from both Democrats and Republicans. Hell, today's AT&T has more market share than Bell Systems did before it was split up. EU, on the other hand, appears to be slowly progressing towards the goal of breaking up tech monopolies. Leaked plans would shake up the tech quite a bit: https://www.eff.org/deeplinks/2020/10/eu-vs-big…

Nice re-writing of history. Microsoft anti-trust was post Reagan. AT7T now is about 34% market share. The rest is between Verizon, Sprint etc. Not the same as what Bell had.

Re: Facebook has sent a cease-and-desist letter to researchers

#93
post #31

Earlier quoted context omitted.

Comparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.

The point is that CA's data harvesting looked like it was transparent to users at the time they were doing it — which is precisely the appearance you'd expect a malicious app to try to convey. The NYU project is probably on the level, but "they're probably on the level" isn't a very good security model at Facebook's scale. More to the point, the FTC's 2019 Consent Decree [1] makes it fairly clear that FB is responsib…

For a project like this to happen at a major US university (especially once outside funding is involved), it needs approval of the university's Institutional Review Board. Getting IRB approval entails researchers proposing a strict set of guidelines for how the data will be collected/used/stored, examining the potential for harm to participants, and convincing a room of very very risk averse individuals that the project is safe and bounded in scope.

This is in stark contrast to CA. "They're probably on the level" because they have entire systems in place to keep them there.

Re: Facebook has sent a cease-and-desist letter to researchers

#94
post #4

Earlier quoted context omitted.

Yes, the FAANGs are very close to being public utilities, and therefore deserve a special treatment.

I see this repeated often, but it's totally incorrect, they do not resemble utilities at all, not even a little bit. I think everyone agrees these companies need more regulation, but the idea that they are in any way comparable to utilities is absurd.

> they do not resemble utilities at all, not even a little bit.

I think that these large communication platforms absolutely resemble other large communication platforms that are currently covered by common carrier laws.

Specifically, a lot of the functionality that these platforms provides, fulfills a usecase that is similar to the phone network.

And the phone network is both a large communication platform, and is all covered by common carrier laws.

The laws need to be updated to recognize that many of the online communication platforms are now as important as the phone system, and therefore should be covered by our existing common carrier laws.

Re: Facebook has sent a cease-and-desist letter to researchers

#95
post #35

Earlier quoted context omitted.

How so?

I admit I use some Google services. At the same time, I have no relationship with the non G:s of FAANG, which arguably is 80% of them (though perhaps not 80% of the influence). I'm not sure how they can really be considered public utilities at that point. None of the services they provide are essential.

> None of the services they provide are essential.

I use online messaging and online communication more than I use the telephone network.

To me, and many others, these online platforms are as or more essential than the phone system, which is already covered by common carrier laws.

Re: Facebook has sent a cease-and-desist letter to researchers

#96

Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098... “Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”

Turns out Cambridge analytics might have been practically useless https://www.wired.co.uk/article/cambridge-analytica-facebook...

That's not what the article you posted is arguing. The article is arguing that the data they collected directly through their trojan apps is not particularly useful, NOT that the full connection graphs (including data drawn from connections of users who didn't use their app) they collected and allegedly used to target advertising is useless.

Re: Facebook has sent a cease-and-desist letter to researchers

#97
post #88

Earlier quoted context omitted.

Users have to install a browser extension in order to participate in the study. That's a way higher barrier than the personality quizzes that Cambridge Analytica used. It also happens at a different layer of abstraction. Cambridge Analytica extracted data through the permissions framework that Facebook itself implemented. Facebook's interest in its users' data doesn't need further explanation after you see that most…

The researchers ask people to opt in tracking a restricted amount of data, and then install an extension that has access to their entire Facebook accounts. There is no way for Facebook or anyone else to prove that the current or a future version of the NYU's extension won't scrape more data than people agreed to.

the plugins are just javascript, so verifying that is actually a trivial task. You just open the plugin and read the source. NYU could also provide the code, to make it even easier.

Re: Facebook has sent a cease-and-desist letter to researchers

#98
post #74
post #50

Earlier quoted context omitted.

> If we want FB to fight CA and Clearview they must fight here as well. Or they could partner with NYU, offer technical insight to maintain integrity and privacy (me stifles laughter) and do everything to support researchers who potentially could help build trust in their platform. Going after this group just isn't a good look if you're Facebook. If there are valid concerns then don't start with a Cease and Desist.

They might be willing to partner if NYU is willing to indemnify Facebook against any and all liabilities which may result. How likely is NYU to take on that risk? Why should we expect Facebook to take on the risk for NYU?

So is your opinion just that facebook just shouldn't be researched?

Re: Facebook has sent a cease-and-desist letter to researchers

#99
post #31

Earlier quoted context omitted.

Comparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.

The point is that CA's data harvesting looked like it was transparent to users at the time they were doing it — which is precisely the appearance you'd expect a malicious app to try to convey. The NYU project is probably on the level, but "they're probably on the level" isn't a very good security model at Facebook's scale. More to the point, the FTC's 2019 Consent Decree [1] makes it fairly clear that FB is responsib…

To clarify:

WHAT they were doing with the data was not transparent. HOW they were doing the data collection was completely transparent.

The worst of both worlds. Which is to say—we're saying the same thing.

Univeristy research projects such as these go through extensive review. the univeristy is basically putting their name on the line for any research project that happens under their watch.

I'm not sure what you're advocating for. Is it that Facebook shouldn't be researched because they do not allow it? Not very sound reasoning to me.

Re: Facebook has sent a cease-and-desist letter to researchers

#100
post #88

Earlier quoted context omitted.

Users have to install a browser extension in order to participate in the study. That's a way higher barrier than the personality quizzes that Cambridge Analytica used. It also happens at a different layer of abstraction. Cambridge Analytica extracted data through the permissions framework that Facebook itself implemented. Facebook's interest in its users' data doesn't need further explanation after you see that most…

The researchers ask people to opt in tracking a restricted amount of data, and then install an extension that has access to their entire Facebook accounts. There is no way for Facebook or anyone else to prove that the current or a future version of the NYU's extension won't scrape more data than people agreed to.

> There is no way for Facebook or anyone else to prove that the current or a future version of the NYU's extension won't scrape more data than people agreed to.

How so? The extension is open source, anyone can audit it.

Post reply on HN