Live data from Hacker News

24 year old student lights match: Europe versus Facebook

identityblog.com

131–140 of 222 posts

Re: 24 year old student lights match: Europe versus Facebook

#131
Funny, I had to take a two hour mandatory company privacy training course today and the gist of it was the company could only use personal information customers allowed for the purpose it was intended to be used for.

The personal info can't be used for anything else other than what the customer agreed to. When the information is no longer required or whatever it was used for is finished the information has to be securely destroyed, until that point it has to be stored and guarded as securely as is possible.

Anyway after all that they proudly said we have a TRUSTe rating and showed other sites which also have it one of which is Facebook. Something seems wrong with that picture.

Re: 24 year old student lights match: Europe versus Facebook

#132

There is a cool German word for companies like Facebook or Google, which collect mounds of information about their users: Datenkrake : http://de.wikipedia.org/wiki/Datenkrake

Is that the modern reference to octopus or the legendary reference to the mythic kraken sea creature?

Re: 24 year old student lights match: Europe versus Facebook

#134

So, I'm going to make a statement that I think is important for anyone reading anything on the internet. WHAT IS THE PROOF! (also known as 'consider the author', 'read the article', etc) Now I can't say with certainty that any of these claims are false or true, but it occurs to me that a lot of these claims are based on what facebook MIGHT be doing with your data. I decided to take a look at the complaint and attachm…

Disclaimer, jack works with me at Facebook, so he's going to be biased (as will I). However, it is true that there appears to be a circular dependency between speculation and outrage here, and that probably isn't the greatest thing in the world. All I can do is tell you to keep looking for evidence (seriously, keep us honest), and we will earn your trust again some day.

Correct. I thought that was in my profile info (it wasn't has since been updated). That said, I was going out of my way to make my comment as general purpose as possible (I think evaluating the bias of anything you read on the internet is generally a Good Idea(tm) )

Re: 24 year old student lights match: Europe versus Facebook

#135
post #112

Earlier quoted context omitted.

And that was before large scale facerecognition software that could be employed to determine not only how many people are walking by the device but also who. Now doing this in real time with a large crowd is still not technically feasible but at some point we will probably cross that line. Good to know there is at least one country where you'll be safe from that.

Good to know there is at least one country where you'll be safe from that. Well, until it gets so cheap that there's no way to know whose glasses or contacts are recording and compiling information about you as part of their lifelog. This sort of thing is like the tide coming in: legislation against it can only ultimately be effective by severe restrictions on allowed technologies for the people of the country.

Well, until it gets so cheap there's no way to know whose glasses or jacket contains a gun capable of shooting you dead on the street. This sort of thing is like the tide coming in: legislation against it can only ultimately be effective by severe restriction on allowed technologies for the people of the country.

Substitute whatever anti-social mechanism you prefer.

The drone wars are coming: pilotless aircraft, possibly autonomous, from the size of a small car to the size of a gnat, with intel or lethal payloads.

Bioweapons or nukes. We've had suitcase nukes for a few decades, fortunately they haven't been used. Suitcase-sized conventional explosives are rather frequently deployed in some parts. Weaponized chemicals or biological agents are another option.

It's trivially possible to adulter drugs or drinks. Some of the oldest laws on the books deal with food and alcohol purity.

Having the technical capability to do something doesn't mean it must needs be accepted. Legal sanctions may be swimming upstream at times, but other norms (social, cultural, religions. technological) generally help keep us from tearing one another to pieces, most of the time.

Re: 24 year old student lights match: Europe versus Facebook

#136
post #82
post #45

Earlier quoted context omitted.

Bullshit, it is not "completely voluntary". When everyone is using a communication service and there is no alternative. They claim to have a billion users. Short it is a monopoly, they have a lot of power and when you start to abuse it, like forcing users to accept your unfair terms of service, the government comes into play. I never heard that Google doesn't remove stuff when you remove them inside your service. The…

I remember a while back when there was some commotion about Google not necessarily deleting your emails even when you delete them off Gmail. What they did was they kept your email for an amount of time for ad purposes. Just did some research while writing this post and it seems that Google changed their ToC for Gmail from deleting emails within 60 days of being deleted by the user to "make reasonable efforts to remov…

Read James Fallows "Hacked" article in The Atlantic: http://www.theatlantic.com/magazine/archive/2011/11/hacked/8...

Though the hacker who attacked his wife's account deleted all mail, Google were able to restore the messages -- first the current year's mails, and eventually the full history of the account.

This implies that, though deleted, the data persisted on Google's systems. This is actually a really good system design (most data destruction is accidental deletion by a user, not hacking, and a robust recovery system is a feature). It does raise certain troubling questions, and it would behoove Google (and any other SAAS service provider) to establish a clear policy as to what the grace period during which deleted data may be recovered is.

I've had my own experience where, shall we say, legal obligations made it expedient to remove certain content from our systems. Use of a CDN and extensive caching means that there's no longer a single point of existence for any given piece of data, and explicitly flushing large volumes of content from our systems was, if not horrendously complex at least non-trivial.

Re: 24 year old student lights match: Europe versus Facebook

#137

So, I'm going to make a statement that I think is important for anyone reading anything on the internet. WHAT IS THE PROOF! (also known as 'consider the author', 'read the article', etc) Now I can't say with certainty that any of these claims are false or true, but it occurs to me that a lot of these claims are based on what facebook MIGHT be doing with your data. I decided to take a look at the complaint and attachm…

Your boss has called his users "dumb fucks", doesn't delete data about them that he says he does and is tracking all their website visits and more. Can you perhaps see past your big salary to how people are, in general, worried? Given the number of lies already told and weird stuff already done why shouldn't people believe new rumours? Watch the video report he was emailed, by your company, huge amounts of data. Much of that data was supposed to be deleted.

Re: 24 year old student lights match: Europe versus Facebook

#139
post #40

Earlier quoted context omitted.

You have to look beyond the law to what its purpose is - to prevent companies from exploiting your personal information, and to force them to tell you what data they hold. Facebook are exploiting your browser history, without telling you. And are refusing to even own up to it. I don't believe that 99% of Facebook users would tick a box that said 'Please record every webpage I visit and store it for your own future us…

But if you, as a customer of those websites, agree to them knowing you are there, and they chose to share that with others, what right does the government have to prevent that? Why is this not a 'just don't use the service if you don't like it' deal? Credit bureaus are significantly different - you have literally no choice in that manner; Facebook isn't providing data to be used in that type of decision though. If so…

  Why is this not a 'just don't use the service if you don't 
  like it' deal?
Because people are ignorant/lazy/desperate and need to be protected against themselves. That's one of the things we want our governments to do: to protect us when we overlook something in the complex reality of our daily lives, without caring for why we overlooked it.

You can't sell yourself into slavery, you can't sell an organ and you can't sell the right to your private information without retaining the right to have that information disclosed to you. If you want to do business in the EU, be prepared to disclose any piece of data you have on a user, if he requests you to do so.

Re: 24 year old student lights match: Europe versus Facebook

#140
post #101
post #96

Earlier quoted context omitted.

In a filesystem, the data isn't scrubbed but it's marked as space that can be overwritten. While the completely removal doesn't happen at once, it's slated for complete removal at some undetermined time in the future. In the case of Facebook, they are making a conscious decision that they do not want this data to ever disappear. I doubt very much that there are policies to remove data marked as 'deleted' after a set…

And besides that, it is not the manufacturer of the filesystem that is in control, but the person that installed it, likely the same person that is deleting the files. For web based services the rules change dramatically, because you are no longer in control of the data. Because the past has shown that companies seem to have a hard time to play nice with the data they store on behalf of their unsuspecting users there…

Above and beyond that, any non-trivial web architecture is going to involve multiple tiers of data and caching.

A given text object will exist in the primary database, in its replicas or clusters, and in backups. If the outfit is at all legitimate, multiple backups representing frequent points in time, stored in multiple locations.

A binary object (say an image, video, or audio file) may exist in its originally uploaded format, several variants of different size, resolution, sampling rate, etc., and is often served through some sort of a content distribution network (CDN), which will have its own content management interface. Some of these are surprisingly primitive -- web-based forms in which a few score objects might be entered at a time, if you're lucky. Even script-driven purge methods are frequently limited as to the number of objects which can be included in a single request, and the number of outstanding requests which may be pending.

Given the large numbers of individual objects, scaling variations, redundancy, etc., deletion overhead can easily scale to tens to hundreds of millions of objects in a relatively short period of time (days to weeks). Dealing with all of this is fairly non-trivial. Especially if the site architecture didn't take these needs into consideration.

Post reply on HN