Live data from Hacker News

How to Force Facebook into Handing Over their Secret Tracking Data

europe-v-facebook.org

71–80 of 107 posts

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#71
post #65

Earlier quoted context omitted.

You're allowed to (and should) black out your photograph and your social security number, they don't need those for ID. Only your government, your employer and a list of government-sanctioned organisations can require social security numbers for ID purposes. the rules for photo ID are even more strict. Additionally you should write in big letters over the scan "Request to access Facebook Data ", so that nobody else c…

> Additionally you should write in big letters over the scan "Request to access Facebook Data ", so that nobody else can use the scan of your ID-card for anything else. This serves no purpose as it is trivial to 'shop these big letters out of the image.

I dunno what your ID cards look like, but ours have intricate patterns all over them. Additionally there's a punctured-hole pattern that vaguely corresponds to the photograph, so that's unique for every ID.

I can't really imagine how you'd want to reconstruct that, and even if you could I'd hardly call it trivial.

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#72
post #21

So let's say I launch TrackMyEatingHabits.com. If a user that happens to live in the UK signs up, they can send me a request for all of their data and I have to comply, right? So this means that when I design the software for TrackMyEatingHabits.com, I should also be mindful to have a process (and data model) that makes it easy to locate this user data quickly, right? Also, I should have in place processes to verify…

No, probably not. Usually you only have to abide by a countries laws if your server are based there, or you have a company incorporated there. If you have a US company with servers hosted in the US, acbd an EU citizen uses it, and claims you are breaking their laws, then there its nothing the courts in that country can do to make you abide them. To put it another way, are you worried if your US company breaks Chinese…

Unless it is a US law. You better believe that those apply globally. They can and will shut you down and/or throw you in prison.

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#73
post #32
post #30

Earlier quoted context omitted.

I think you're close, but missing something: The companies who wouldn't do this are run by developers or other people who don't interact much with the actual users . Irreversible actions are horrible UX, and any irreversible action in a commonly used area of the app will make a large number of people steaming mad on a daily basis — guaranteed. People who will blithely click "Delete" — and then click "Yes" even though…

I highly doubt Facebook went with the delete flag because of the customer service perspective.

I think that it is probably one of the major reasons, though certainly not the only one. In my experience, one of the most common customer service complaints/requests is "Oh no, I did this irreversible thing you warned me not to, fix it." I imagine facebook also gets its fair share of complaints like "Oh no, my ex-boyfriend deleted my account, fix it." This stuff is really common, and I can understand why a company would rather be able to say "Oh yeah, sure" than "Sorry, for privacy reasons your online life for the past two years has been lost irretrievably."

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#74
post #61

Earlier quoted context omitted.

It's not Facebook's call. The USA PATRIOT Act allows for National Security Letters, or NSLs, that legally function like warrants but require no judicial review. The US government uses them over 60,000 times per year. The law allowing them turns ten years old next month.

It'd be interesting to know if that covers 100% of data releases to the state. Does Facebook release data to law enforcement in cases other than either: 1) pursuant to a warrant; or 2) compelled by a National Security Letter? I would guess yes, but I'd be interested in a solid statement either way.

It's not like the telecomm corps in the US haven't been caught handing over info to cops/FBI without warrants or NSL letters (or handing over more than required when presented with a warrant or NSL).

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#75
post #32

Earlier quoted context omitted.

I highly doubt Facebook went with the delete flag because of the customer service perspective.

I think that it is probably one of the major reasons, though certainly not the only one. In my experience, one of the most common customer service complaints/requests is "Oh no, I did this irreversible thing you warned me not to, fix it." I imagine facebook also gets its fair share of complaints like "Oh no, my ex-boyfriend deleted my account, fix it." This stuff is really common, and I can understand why a company w…

I'd venture that a major reason has less to do with customer UI and law enforcement and more to do with data mining.

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#76
post #69
post #61

Earlier quoted context omitted.

It's not Facebook's call. The USA PATRIOT Act allows for National Security Letters, or NSLs, that legally function like warrants but require no judicial review. The US government uses them over 60,000 times per year. The law allowing them turns ten years old next month.

Precisely. If you want to place blame, it goes squarely on the Bush Administration. (And yes, I'm sure I'll be down-voted for saying that, but it's still unquestionably, uncontroversially, non-debatably true.) If you want this fixed, it has to be fixed politically at a federal level.

The provisions were all due to sunset by now, but Obama signed the renewal.

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#77
post #47
post #21

Earlier quoted context omitted.

No, probably not. Usually you only have to abide by a countries laws if your server are based there, or you have a company incorporated there. If you have a US company with servers hosted in the US, acbd an EU citizen uses it, and claims you are breaking their laws, then there its nothing the courts in that country can do to make you abide them. To put it another way, are you worried if your US company breaks Chinese…

Like most legal matter it's a bit more complex than that. As far as I know, you can be targeted by foreign laws with a .com domain, and servers physically in the US. If you specifically target/advertize (e.g. with translated interfaces) your services to EU citizens, a judge might decide that EU laws apply to you.

Is this just your opinion or do you have some examples to back it up? I don't see why a US judge would care at all if a US company breaks laws of another country.

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#78
post #69
post #61

Earlier quoted context omitted.

It's not Facebook's call. The USA PATRIOT Act allows for National Security Letters, or NSLs, that legally function like warrants but require no judicial review. The US government uses them over 60,000 times per year. The law allowing them turns ten years old next month.

Precisely. If you want to place blame, it goes squarely on the Bush Administration. (And yes, I'm sure I'll be down-voted for saying that, but it's still unquestionably, uncontroversially, non-debatably true.) If you want this fixed, it has to be fixed politically at a federal level.

> Precisely. If you want to place blame, it goes squarely on the Bush Administration. (And yes, I'm sure I'll be down-voted for saying that, but it's still unquestionably, uncontroversially, non-debatably true.)

Wasn't the Patriot Act recently renewed, where "recently" means "post-Bush"?

> If you want this fixed, it has to be fixed politically at a federal level.

And Dems, who voted for the initial version overwhelmingly, were uninterested in doing so when they held all three elected branches and that didn't change when they lost one.

So, yes, it's true that it was passed under Bush, but no one is interested in fixing it. (Yes, I'm ignoring Ron Paul and Dennis Kucinich.)

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#79
post #13

Unbelievable: http://europe-v-facebook.org/EN/Data_Pool/data_pool.html They delete sh*t, if you delete your posts they don't remove them from their databases. This makes me really angry, there is a reason why i delete this stuff. I can't believe this, they have a responsibility. Edit: WTF http://europe-v-facebook.org/EN/Data_Pool/data_pool.html#Mac... This is maybe the most frightening: http://europe-v-facebook.org/E…

You may be surprised that many (at a guess, maybe most?) companies/websites actually consider a delete function to be changing a 'deleted' flag to 1 in a database. The data persists, but is no longer shown. I would also make a very big assumption that the only companies who wouldn't do this are those run by developers or other people who have had experience implementing that sort of system. There's nothing bosses lov…

This is almost certainly not true for a lot of medical data (in Canada and Australia at least, don't know about the US).

There was a rather interesting example in Queensland ~two years ago when govt. health sector payroll data (from an outgoing system) was deleted due to privacy concerns, and then the replacement system mis-functioned (never really worked) and the entire state's health payroll information was lost. $200 million and counting to fix the lost data.

Re: How to Force Facebook into Handing Over their Secret Tracking Data

#80
post #38

Earlier quoted context omitted.

No, there's no general right-to-data law. There are general right-to- government -data laws, so you can e.g. request your own FBI record. But private businesses don't normally have to disclose what data they collect on you. There are a few exceptions for specific areas; for example, the credit-ratings agencies have to provide you with a copy of your credit report, and in some cases an employer may be required to prov…

So for those of us that live in the US, is it not possible for us to request to have the data that Facebook stores about us??? Related (well, maybe): You can easily download a copy of your Facebook data no matter where you are located, by logging in and clicking "Account Settings" > "Download a copy of your Facebook data". This will include all things like messages, pictures, etc., but I am positive that it isn't nea…

I would like to see the data they're using to target ads at users (i.e. the metadata assembled from a user's input).
Post reply on HN