Live data from Hacker News

Facebook has sent a cease-and-desist letter to researchers

twitter.com

121–130 of 201 posts

Re: Facebook has sent a cease-and-desist letter to researchers

#121
post #102
post #85

Good. I didn't agree for NYU to have my Facebook data and for them to operate a plugin at scale which crawls my data (if anyone with permissions to see my profile installs this plugin) is a violation of my rights.

How do you feel about it when anyone who has you in their phone's contacts list hands over all that personal information about you when they install WhatsApp or any other app that requests contacts data? Seems like the same thing.

An app should request contacts data to do what contacts data is intended for ... place calls and messages to contacts. Anything else is an abuse of trust.

Re: Facebook has sent a cease-and-desist letter to researchers

#122

> The researchers (w/ the help of others) are responsible for a browser plug-in called Ad Observer, which allows FB users to voluntarily share very limited and anonymous data about the political ads that FB shows them. You can read about Ad Observer here: https://adobservatory.org ================= Absolutely preposterous takedown demand. Facebook doesn't get to dictate what software I run on my own client devices, i…

A lot of people felt Facebook should do more to proactively stop people from scraping and aggregating data from their site after the CA debacle. Which is what they are doing here, and you are labeling “absolutely preposterous”.

Which way is it? Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco? Or try to proactively stop it like they are now?

Re: Facebook has sent a cease-and-desist letter to researchers

#123

> The researchers (w/ the help of others) are responsible for a browser plug-in called Ad Observer, which allows FB users to voluntarily share very limited and anonymous data about the political ads that FB shows them. You can read about Ad Observer here: https://adobservatory.org ================= Absolutely preposterous takedown demand. Facebook doesn't get to dictate what software I run on my own client devices, i…

A lot of people felt Facebook should do more to proactively stop people from scraping and aggregating data from their site after the CA debacle. Which is what they are doing here, and you are labeling “absolutely preposterous”. Which way is it? Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco? Or try to proactively stop it like they are now?

> Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco?

Yes.

Re: Facebook has sent a cease-and-desist letter to researchers

#124

> The researchers (w/ the help of others) are responsible for a browser plug-in called Ad Observer, which allows FB users to voluntarily share very limited and anonymous data about the political ads that FB shows them. You can read about Ad Observer here: https://adobservatory.org ================= Absolutely preposterous takedown demand. Facebook doesn't get to dictate what software I run on my own client devices, i…

A lot of people felt Facebook should do more to proactively stop people from scraping and aggregating data from their site after the CA debacle. Which is what they are doing here, and you are labeling “absolutely preposterous”. Which way is it? Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco? Or try to proactively stop it like they are now?

This looks like a strawman dressed in false dilemma. With Cambridge Analytica debacle, as I understand it, it was a facebook quiz hosted by facebook and the data collected from facebook directly and used for nefarious purposes.

This is a an extension developed by researchers asking users to install it on their machines and used exactly as advertised: scrapes advertisement data that facebook shows them.

Re: Facebook has sent a cease-and-desist letter to researchers

#125

> The researchers (w/ the help of others) are responsible for a browser plug-in called Ad Observer, which allows FB users to voluntarily share very limited and anonymous data about the political ads that FB shows them. You can read about Ad Observer here: https://adobservatory.org ================= Absolutely preposterous takedown demand. Facebook doesn't get to dictate what software I run on my own client devices, i…

A lot of people felt Facebook should do more to proactively stop people from scraping and aggregating data from their site after the CA debacle. Which is what they are doing here, and you are labeling “absolutely preposterous”. Which way is it? Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco? Or try to proactively stop it like they are now?

> Which way is it? Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco? Or try to proactively stop it like they are now?

No, they should assume all the data they serve about people is being collected and indexed by all the people they serve it to, and then restrict what they serve accordingly. Suing people for asking their computers to record what Facebook served them is insane.

Re: Facebook has sent a cease-and-desist letter to researchers

#126
post #56

Did they even agree to the ToS? It seems like they wrote their own plugin to harvest the data, what agreement did they made with Facebook that they are in violation of?

WSJ: "In a letter sent Oct. 16 to the researchers behind the NYU Ad Observatory, Facebook said the project violates provisions in its terms of service that prohibit bulk data collection from its site." That's the key point here. The researchers are not a party to Facebook's terms of service. The user installing the add-on may be, but that does not bind the add-on developer. (This is called "privity" in law; contract…

> The researchers are not a party to Facebook's terms of service.

Unless the researchers have their own personal FB accounts. You know, like 3.1 billion other people.

Re: Facebook has sent a cease-and-desist letter to researchers

#127

Earlier quoted context omitted.

A lot of people felt Facebook should do more to proactively stop people from scraping and aggregating data from their site after the CA debacle. Which is what they are doing here, and you are labeling “absolutely preposterous”. Which way is it? Should they let people do whatever they want with their accounts as you suggest, and risk a repeat of the CA fiasco? Or try to proactively stop it like they are now?

This looks like a strawman dressed in false dilemma. With Cambridge Analytica debacle, as I understand it, it was a facebook quiz hosted by facebook and the data collected from facebook directly and used for nefarious purposes. This is a an extension developed by researchers asking users to install it on their machines and used exactly as advertised: scrapes advertisement data that facebook shows them.

CA data was from a quiz, developed by a researcher at Cambridge University, hosted by that researcher, which scraped FB APIs after being authorized by a user.

This data is from a browser extension, developed by researchers at NYU, hosted by those researchers, which scrapes the FB site after being installed by a user.

IMO the situations are pretty analogous.

Re: Facebook has sent a cease-and-desist letter to researchers

#128
post #127

Earlier quoted context omitted.

This looks like a strawman dressed in false dilemma. With Cambridge Analytica debacle, as I understand it, it was a facebook quiz hosted by facebook and the data collected from facebook directly and used for nefarious purposes. This is a an extension developed by researchers asking users to install it on their machines and used exactly as advertised: scrapes advertisement data that facebook shows them.

CA data was from a quiz, developed by a researcher at Cambridge University, hosted by that researcher, which scraped FB APIs after being authorized by a user. This data is from a browser extension, developed by researchers at NYU, hosted by those researchers, which scrapes the FB site after being installed by a user. IMO the situations are pretty analogous.

The situations are in no way analogous. CA gathered data on users who did not opt in. They paid 270k users to take a quiz, and gathered information on 87MM of their Facebook friends who never consented to sharing their information.

Re: Facebook has sent a cease-and-desist letter to researchers

#129
post #97

Earlier quoted context omitted.

the plugins are just javascript, so verifying that is actually a trivial task. You just open the plugin and read the source. NYU could also provide the code, to make it even easier.

You cannot verify that the researchers won't change the plugin to malware in the future.

You cannot verify that Facebook will not change its product to malware in the future. That it to say, at some point, you trust the software publisher in the same way you trust the service operator.

Re: Facebook has sent a cease-and-desist letter to researchers

#130

Earlier quoted context omitted.

> However, Facebook does have the obligation to not share info of users who didn't explicitly consent to it with third party apps But Facebook is not sharing info of users' friends. Users are sharing information about their friends. If a user should not be able to access particular information about their friends, then the onus is on Facebook to restrict that access. It was Facebook's fault for exposing excessive dat…

>It was Facebook's fault for exposing excessive data to users' friends during the Cambridge Analytica scandal I don't follow this logic at all. The data shown to users' friends is the same data that is shown to them now. Which is usually all their public photos (nothing from private albums), the friend list (if they didn't make it private), etc., only the stuff that friends are expected to be able to access (and stil…

Facebook created a platform which allows users to access information about others users who have agreed to be "friends". A third party then came along and asked users for the information which their friends gave them access to. The users gave the third party the data.

I'm not missing anything here, right?

If the third party should not have access to the data, then neither should the friends who gave it to them. Facebook is responsible for allowing the users access to the data.

If users should have access to the data, then it's the friends' fault for agreeing to be Facebook friends with those users in the first place. Alternatively, it's Facebooks fault for not making it clear what data is made available to friends.

Either way, I don't see how this is a problem with thr research group.

I guess you could argue that the data was still technically owned by the friends and therefore the users had no right to give it away. In which case the fault belongs to the users.

Post reply on HN