Live data from Hacker News

Facebook has sent a cease-and-desist letter to researchers

twitter.com

101–110 of 201 posts

Re: Facebook has sent a cease-and-desist letter to researchers

#101

Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098... “Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”

Well, what exactly should NYU do instead? There is no API with fine-grained permissions that they can use: To get the data they are interested in (ads), they have to resort to scraping - and a scraper will always have access to all data on the page.

So there is no way for NYU to not have access to friend data if they want access to ad data.

Re: Facebook has sent a cease-and-desist letter to researchers

#102
post #85

Good. I didn't agree for NYU to have my Facebook data and for them to operate a plugin at scale which crawls my data (if anyone with permissions to see my profile installs this plugin) is a violation of my rights.

How do you feel about it when anyone who has you in their phone's contacts list hands over all that personal information about you when they install WhatsApp or any other app that requests contacts data? Seems like the same thing.

Re: Facebook has sent a cease-and-desist letter to researchers

#103
post #74
post #50

Earlier quoted context omitted.

> If we want FB to fight CA and Clearview they must fight here as well. Or they could partner with NYU, offer technical insight to maintain integrity and privacy (me stifles laughter) and do everything to support researchers who potentially could help build trust in their platform. Going after this group just isn't a good look if you're Facebook. If there are valid concerns then don't start with a Cease and Desist.

They might be willing to partner if NYU is willing to indemnify Facebook against any and all liabilities which may result. How likely is NYU to take on that risk? Why should we expect Facebook to take on the risk for NYU?

Hang on. The whole chain of reasoning started with FB protecting users' interests through the permission system, which NYU ostensibly circumvented. How is it in the users' interests to indemnify Facebook?

Re: Facebook has sent a cease-and-desist letter to researchers

#104
post #31

Earlier quoted context omitted.

Comparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.

Sure. So what exactly is the binding rule which Facebook should apply here? Rsearchers can get access to anyone's Facebook data if people enable it? What about the ones in chinese universities? Or just respected universities? Which universities is that? How do we decide? You're missing the point. There needs to be a black and white line, and whatever Facebook allows they're always being demonised, nobody gives them t…

> Rsearchers can get access to anyone's Facebook data if people enable it?

Yes. Where is the problem?

Re: Facebook has sent a cease-and-desist letter to researchers

#105
post #8

FB claims automated data collection, the data is apparently input to the app by a user , i think the hairs will be split between copy paste mechaniics, or ten finger entry in response to prompt, thus massaging the definition of automated entry. (1)FB has consistently refused to publish anything about how the ads are targeted . (2)The NYU researchers have tried to fill that gap, offering the Ad Observer plug-in to use…

Though presumably the Ad Observer plug-in didn't sign up to Facebook's terms of service. If anyone's violating their terms it's probably the users who install the plug-in.

Re: Facebook has sent a cease-and-desist letter to researchers

#106
post #62
post #53

Earlier quoted context omitted.

You shared the information with your Facebook friends without any protections. Why shouldn't they be allowed to share it with other people? What legal obligation do they have to keep the information you shared private?

>Why shouldn't they be allowed to share it with other people? >What legal obligation do they have to keep the information you shared private? Those exact same questions can very well be asked of the whole Cambridge Analytica scandal, and yet some people will give different answers to those two scenarios. Cambridge Analytica app was explicitly asking users for permission to access their data and data their friends pub…

> However, Facebook does have the obligation to not share info of users who didn't explicitly consent to it with third party apps

But Facebook is not sharing info of users' friends. Users are sharing information about their friends.

If a user should not be able to access particular information about their friends, then the onus is on Facebook to restrict that access. It was Facebook's fault for exposing excessive data to users' friends during the Cambridge Analytica scandal and it's their fault for doing the same thing now.

Facebook needs to clean up their own mess instead of suing research groups for taking advantage of it.

Re: Facebook has sent a cease-and-desist letter to researchers

#107
post #46
post #36

Wait so Facebook can collect data about its users but Facebook users aren't allowed to collect data about Facebook?

If I’m your friend on Facebook should you be allowed to go to my page and give all the information I’ve shared with you to another 3rd party? You trust NYU, OK fine. Can I give the same information about you to pro-Trump researchers?

By that logic, why is it ok for Facebook to have that data? Why is it ok for Facebook to scrape my address book?

Re: Facebook has sent a cease-and-desist letter to researchers

#108
post #31

Some takes From Benedict Evans that are worth considering: https://twitter.com/benedictevans/status/1320378054150148098... “Meanwhile: the NYU app has access to friend data in your feed and friend data is also in the ads it scrapes. And it replaces an actual security model with our trust that NYU are nice people and won't abuse this access. That is exactly how Cambridge Analytica happened.”

Comparing Cambridge Analytica, who harvested data though means that were not transparent to users (and for malicious purpose), to NYU has explained what data and why, AND has the consent of its users, seems disingenuous at best.

There's no way to see what these third parties actually access of your data. I don't think anything substantial has changed since CA to ameliorate this. The problem is Facebook Ads itself: it's impossible to trust period, let alone with what scraps of information they toss us about how we're actually transacting for services paid with ads.

Re: Facebook has sent a cease-and-desist letter to researchers

#109
post #91
post #52

Earlier quoted context omitted.

Having an agreement with someone is not a prerequisite for being able to send them a C&D.

Sure, but at that point they'd have to be breaking some kind of law to warrant one, wouldn't they?

Given the wonders of the US legal system Facebook can probably throw a few million in legal fees into fighting the NYU researchers who will have to back down as unable to afford their own legal fees irrespective of who's right or wrong.

Re: Facebook has sent a cease-and-desist letter to researchers

#110
post #97
post #88

Earlier quoted context omitted.

The researchers ask people to opt in tracking a restricted amount of data, and then install an extension that has access to their entire Facebook accounts. There is no way for Facebook or anyone else to prove that the current or a future version of the NYU's extension won't scrape more data than people agreed to.

the plugins are just javascript, so verifying that is actually a trivial task. You just open the plugin and read the source. NYU could also provide the code, to make it even easier.

You cannot verify that the researchers won't change the plugin to malware in the future.
Post reply on HN