Live data from Hacker News

Facebook privacy fuckup reveals who has your number in their phone

alexmuir.com

111–120 of 124 posts

Re: Facebook privacy fuckup reveals who has your number in their phone

#111
Phone numbers and addresses are fast becoming like email addresses. In the same way that you can assume putting your email address into any website form that requests it will eventually result in spam, putting your phone number into any phone or your address into the database of any service provider will eventually result in a "leak".

We are to the point that to maintain any semblance of privacy, you need at least two email accounts (one you don't mind getting spammed), two phone numbers (one you don't care about facebook and others tracking) and two addresses (a mailing address/box service and your actual physical address).

Re: Facebook privacy fuckup reveals who has your number in their phone

#112
post #104

It is terrible that your friends' privacy was violated, and I apologize for this comment being off topic, but I feel compelled to address the specific personal circumstances that Alex has uncovered. Alex: as a gay man who came out as an adult, I urge you to reach out to your closeted friend. Let him know that Facebook violated his privacy and you accidentally and unexpectedly came across his secret. Reassure him that…

Your sentiment is clearly well-meant, but that course of action just as well could result in a disaster as it could a happy outcome.

From a data aggregation perspective, it is (unpleasantly) fascinating to me that a programming choice in an ostensibly opt-in social networking database has resulted in a public bulletin-board discussion of what could be perhaps the most private part of a person's life.

Examples like this are the perfect answer to the dangerous nonsense propounded by the "anonymity needs to go away" crowd. Not everyone's life is or should be an open book.

Re: Facebook privacy fuckup reveals who has your number in their phone

#113
post #67

Wow, I just duplicated this perfectly. Signed up with a fake name and throwaway email. Was asked to enter mobile number for verification.[1] Entered mobile number and verified. The top few 'People You May Know' suggestions were all people who I know have that number on their iPhones, all of whom use the Facebook for iPhone application. (It obviously happens if they use any platform's app to sync contacts, not just iO…

"People who have you in their email contacts - and have imported them to Facebook - are probably suggested to you too."

I noticed this behavior when I signed up to test this first using an old email address. It had known friends as suggestions as well as people who had already requested to be my friend, including my actual profile. I don't explicitly remember important my email contacts but it is a possibility.

Looks like it treats both contact books the same, even if a user didn't add the individual contacts at the time of import, it keeps a record of them to potential make suggestions at some future point in time.

Re: Facebook privacy fuckup reveals who has your number in their phone

#114
post #84
post #63

Earlier quoted context omitted.

Mobile apps.

The phone apps can have access to phonebook? OK, I didn't know that. It seems that I am heavily downvoted, so... sorry for my comment.

It's one of the troubling things about iOS (not an Android dev, so don't know from that end).

An iOS app needs explicit user permission to know your location, or to send you push notifications. It doesn't need to ask if it wants into your phone book and calendars.

Any app on the iOS App Store can read your phone book and calendars and do anything they want to this information. This is a mind-bogglingly gaping security hole.

Re: Facebook privacy fuckup reveals who has your number in their phone

#115
post #82
post #57

Earlier quoted context omitted.

Well, what I am wondering is: is this actually an unintended consequence or a conscious choice that has been made?

A company doesn't have a single conscience. It may have been a conscious choice by an engineer, or it may have been an unintended consequence of some other code change. Either way, I highly doubt it involved the check-off from a director-level employee. If every decision had to get approval from the management team, then progress would grind to a halt, and Facebook would end up like Microsoft.

> A company doesn't have a single conscience.

And because of that we should hold it with less responsibility than a single person? Even though it holds an order of magnitude more power than a single person?

Yeah, how about, no.

And about your other remark, that is nonsense. It is very possible to keep those checks to a reasonable level of responsibility and many corporations do so, with proper software engineering principles, without "turning into Microsoft".

When dealing with people's private information, one should err on the side of caution, not on the side of $$$, and it is obvious which route facebook took.

In fact, they are already in violation of several EU privacy laws, just because their privacy-pissing database has grown out of hand, they collect more data than they have the internal corporate infrastructure for to deal with this amount of private data of EU citizens in a legal manner in Europe. They went way overboard, maybe not in the US, but they are also incorporated in the EU and cannot oblige by our privacy laws because they collected too much data.

As far as I'm concerned, Facebook is on the verge of criminal negligence as EU laws for citizen privacy are concerned. So personally, yeah, I think nothing wrong with headlines of "Facebook privacy fuckup", as long as they're behaving like that, singular conscience or not.

That's why we have such laws, to keep corporations responsible.

Re: Facebook privacy fuckup reveals who has your number in their phone

#116
post #48

Earlier quoted context omitted.

If you are truly concerned about harm to users, did you try reporting this to facebook.com/security or facebook.com/whitehat? FWIW, I've alerted some people. Your post is unclear on one point. Did you see this screen BEFORE confirming via SMS that you were in possession of the mobile number you entered? If it was after confirmation, that's a very different thing.

Facebook does not care about user privacy. They have gone on record saying this multiple times (and then quickly recanted it). They do not care about user privacy because it goes against everything that Facebook needs in order to grow. For example, if you tag a photo with a friend's name, all of that friend's friends can see this photo, even if you restrict who can see your photos. You cannot change this, which means…

> More importantly, I'm moving away from Facebook because they don't give a fuck about privacy.

Yeah me too, I deleted my profile last week.

Re: Facebook privacy fuckup reveals who has your number in their phone

#117

1. Some people don't realize what information Facebook is collecting, and some of those people would object if they did know. 2. Some people don't realize the way Facebook is using the information they collect, and some of those people would object if they did know. Should it disturb us that those statements are true for millions of people? Or do we not care? It will be interesting if we get to where Facebook is requ…

> It will be interesting if we get to where Facebook is required to send a pamphlet to your house explaining how they use the information they collect about you, who they sell it to, etc.

Actually, they are, in the EU.

Well not literally with a pamphlet, of course, they are required to send you a CD with this data on request.

Except that they're (illegally) refusing to provide most of that data under the guise of "intellectual property" (whose? not theirs, under any legal definition of IP I'm aware of) and "trade secrets" (which I'm sure won't hold up).

They just provide the profile and your comments and messages and whatnot kinds of data that are all already visible in some sense or other, on Facebook.

They do not provide the invisible data, the things they collect behind the scenes, such as what data they collect from your phonebook, what data is available about you being tagged in photos, things like that, all the data you know Facebook is collecting (due to deduction from friend suggestions, or just because it's there), but never really get to see because it's either a) buried behind some algorithms (friend suggestions) or b) just stored and not really used for anything.

These two kinds of data are EXACTLY what this EU Privacy law is intended for. The right for EU citizens to know what data about them is being stored especially when it is not immediately obvious that this data is being collected, stored or used in some manner.

These two kinds of data are also EXACTLY what Facebook is withholding from EU citizens legal requests because of "trade secrets". It won't hold up. I really hope it won't.

Their reasoning for why something is a "trade secret" is the same reason why a law exists that requires them to provide that data: because the data is not used in the open and otherwise EU citizens would not be able to know this data is being collected and stored about them.

Remember, the privacy laws protect the fact already that certain data is just stored, not even whether it is used or not.

I bet there's many kinds of data FB is simply storing about its users that it doesn't really use yet, data they should have provided on formal request but declined to do so because of "trade secrets".

Re: Facebook privacy fuckup reveals who has your number in their phone

#118
post #84
post #63

Earlier quoted context omitted.

Mobile apps.

The phone apps can have access to phonebook? OK, I didn't know that. It seems that I am heavily downvoted, so... sorry for my comment.

It was a valid question with a straightforward and informative answer. I wouldn't worry about it, some people seem to be a bit trigger-happy with the downvotes :)

Re: Facebook privacy fuckup reveals who has your number in their phone

#119
post #79

Earlier quoted context omitted.

You got two assumptions wrong here: 1. People may very well have an account with a fake name, so that it doesn't show up in search. In France, for example, a large number of FB users are stripping out the vowels from their last name to make their FB account less findable. 2. According to the article, it's not the "gay friend" that put his phone number on his hidden account. He merely has OP's number in his phone addr…

Hmm. 1) Fake name, yes -- I wasn't aware of that practice; not that common in India, at least in my friend circle. 2) That was what I meant -- syncing actual details with your anonymous persona.

i'm indian and i have several friends with fake names.

Re: Facebook privacy fuckup reveals who has your number in their phone

#120
[Note: I work at Facebook, and have worked on some of the friend suggestion tools.]

There seems to be some confusion about how friend suggestions work, and we definitely want to people to understand how their information is used and their options to control it.

Generally, the contact importing tools and resulting friend suggestions have been used by millions of people to make hundreds of millions of friend connections. We're proud of this (since it is clear that real connections are made) but also understand that people should have control. That's why we include a notice in the contact sync (on phones) and upload (on the web) flows that makes it clear that contacts you import may be used generate friend suggestions for you and others. If you're concerned about being suggested as a friend to others based on the contacts in your address book, you can either not upload it, or if you have already uploaded it, you can remove your uploaded contacts (http://www.facebook.com/contact_importer/remove_uploads.php). You can also block any individual people. These steps prevent what the Alex (or rather, his friends) experienced — people being suggested as friends based on having a phone number in their address book.

Also, some of you have noticed that we don't always require a phone verification for an account. This is a security feature designed to prevent spam and fake accounts that is only triggered when certain conditions aren't met.

Post reply on HN