Live data from Hacker News

Your Facebook password should be none of your boss' business

aclu.org

91–100 of 106 posts

Re: Your Facebook password should be none of your boss' business

#92

Earlier quoted context omitted.

I'm not a lawyer, but it seems that this practice is so wide-spread that there's enough grey area for hiring managers to get away with it, so the current laws aren't enough. Internet social networking is such a new and world-changing concept that I believe new laws are necessary to specifically address these issues.

But the underlying information - your social interactions and personal communications - are not new. An employer could ask for your email history, banking information, etc. Should that be illegal as well? What about background checks, credit history check, etc? My only point is that I don't see why there needs to be a special exemption for social networking data, if the predatory behavior is already illegal b

Asking for you to provide such information, or asking for your permission to request such information from third parties (as is done with employment or credit references, for instance) seems fine. What seems to cross a line here is asking for sufficient authority from you to permit them to pose AS YOU to a third party in order to access that information.

It's like if, in order to perform a credit check on you, they asked for your SSN, mother's maiden name, etc., and then applied for a couple of credit cards on your behalf to see if you get accepted.

There are ways to perform credit checks without committing identity theft. I would think there must be ways to obtain 'social references' without identity theft either.

Re: Your Facebook password should be none of your boss' business

#93

Is this really becoming common? I agree that it's absolutely wrong, but, every headline I've seen gives the impression this is becoming a common practice. I've never heard of it actually happening anywhere but the few cases cited in the articles.

I've never asked a candidate for their password, that to me is ludicrous. I do however (~90% of time) 'google' the person by "name" and location. I understand that a candidate's personal life can be very different from their professional life, but the two are connected by a single thread called 'self'. I really could care less about political affiliations, religious beliefs, sexual orientation and the like. However,…

I understand that employers, just like employees, need every advantage they can get. But some events in my own past (namely, getting stalked) have led me to think that gathering details about someone on the Internet without their knowledge is in some ways even creepier than openly asking them for their Facebook password. Do you tell candidates that you're going to google them? If yes, do you give them a chance to ask you not to do that?

Re: Your Facebook password should be none of your boss' business

#94
post #80
post #73

Earlier quoted context omitted.

I'm not a lawyer, but my guess is that if you could get a request like this in writing, the right lawyer would be able to get you a hefty settlement under existing law. Just guessing, but I'd be surprised if it's legal to ask prospective employees to engage in unlawful activities as a condition of employment. As mentioned before, sharing your Facebook password is illegal.

I'm certain that anyone asking to snoop through your Facbook knows they are doing something "wrong" - maybe they don't understand the full implications, but I'm sure none of them would be stupid enough to put the request in writing.

I've heard of it being on applications before, or at least in the offer of employment. That's definitely in writing.

Re: Your Facebook password should be none of your boss' business

#95
post #89

Earlier quoted context omitted.

"...sharing your Facebook password is illegal." Illegal is the wrong word for it. It's not illegal, it's a violation of the Facebook TOS - a matter for at most a civil (and not criminal) court.

There was a thread here on HN some time ago, where someone argued that it's illegal anyway, because of some misguided law that makes it a federal crime to violate an internet company's TOS. I can't find that thread right now, though.

That would be the Computer Fraud and Abuse Act[0,1]. The relevant bit is "Whoever ... intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer ... shall be punished as provided in subsection (c) of this section." A "protected computer", by the way, is any computer "which is used in or affecting interstate or foreign commerce or communication."

That's not relevant, though, because US v. Lori Drew[2] decided that a user can't be prosecuted under the CFAA for breaking a ToS agreement. (BTW, IANAL.)

0: http://www.law.cornell.edu/uscode/text/18/1030

1: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

2: https://wikispaces.psu.edu/display/IST432TEAM24/United+State...

Re: Your Facebook password should be none of your boss' business

#97

Earlier quoted context omitted.

Not to highjack the topic but I also read the IRS uses social media profiles to see if you are living above your means. Something slightly similar to your "temporary access" theory happens if you owe the IRS even a small amount of money. They enter your bank account to seize cash and the bank charges you $100 for the inspection/invasion. As for the topic at hand, I don't see why one cannot simply say they have no Fac…

You could say you had no account , but if they later found that out to be a lie it could be used to dismiss you as you lied during your application.

What if you created an account after being hired, or had plausible deniability to that effect? Would you be obligated to inform your employer whenever you manage other social media accounts?

The implications of this are terrifying. I'm glad that organizations like the ACLU are on this, because if corporations can set a precedent for this sort of privacy invasion, we're screwed to the nth degree.

Re: Your Facebook password should be none of your boss' business

#98
post #95
post #89

Earlier quoted context omitted.

There was a thread here on HN some time ago, where someone argued that it's illegal anyway, because of some misguided law that makes it a federal crime to violate an internet company's TOS. I can't find that thread right now, though.

That would be the Computer Fraud and Abuse Act[0,1]. The relevant bit is "Whoever ... intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer ... shall be punished as provided in subsection (c) of this section." A "protected computer", by the way, is any computer "which is used in or affecting interstate or foreign commerce…

Which the prosecution used against Lori Drew, and ultimately failed. The hysteria about it being illegal to violate TOS was a feature of the original verdict against her, which was set aside on acquittal. It's a (now) non-story.

Re: Your Facebook password should be none of your boss' business

#100

Facebook should try and do something about this, because it's in their best interest. If this keeps going, people will either simply quit Facebook, or start making mock-accounts to show to the employees.

> Facebook should try and do something about this, because it's in their best interest. If this keeps going, people will either simply quit Facebook, or start making mock-accounts to show to the employees.

What can Facebook do? At best, they can lobby the Government and/or employment regulators in an attempt to bring this practice to light and make requesting passwords and access to private accounts illegal. It's a very indirect method and may not change things now, tomorrow or even next month.

Post reply on HN