Live data from Hacker News

Facebook e-mail mess: Address books altered, e-mail lost

news.cnet.com

161–170 of 194 posts

Re: Facebook e-mail mess: Address books altered, e-mail lost

#161

Earlier quoted context omitted.

If you aren't buying a product, you are the product. That's worth drilling into your head. Yes, that means that User = product from HN's perspective, but I am willing to bet it is a lot more of a complex connection than it is with facebook ;-)

I didn't buy my copy of Debian, yet they treat me better than many companies I pay. I pay for cable, yet I still get advertising. That "not paying means you're the product" is a nice sound bite, but it doesn't actually mean anything.

I never said that's a bad thing. But at least with the open source software I work with, if you use the software, great. Maybe you will come to me for services later. I wonder how many Debian-involved businesses have such a model.

Paying for media is an interesting exception. Very often for newspapers, etc, you are both buying a product and becoming a product.

But in the end it's a good warning to know the business model of those you get free stuff from.

Re: Facebook e-mail mess: Address books altered, e-mail lost

#162

Earlier quoted context omitted.

passwords for other sites Wait, seriously? People are using websites where the password reset emails are being sent from somebody's Droid phone? I think you've gotten a little carried away.

Ever seen sites with the ability to connect via Facebook? It often grants said site(s) with the user's Facebook primary-email. Now all personal emails, including password recoveries, are going through Facebook for said site(s).

if the site is using facebook for authentication, you don't have a password on said site therefore you don't have a password recovery leakage vector

Re: Facebook e-mail mess: Address books altered, e-mail lost

#163

Earlier quoted context omitted.

If you aren't buying a product, you are the product. That's worth drilling into your head. Yes, that means that User = product from HN's perspective, but I am willing to bet it is a lot more of a complex connection than it is with facebook ;-)

I didn't buy my copy of Debian, yet they treat me better than many companies I pay. I pay for cable, yet I still get advertising. That "not paying means you're the product" is a nice sound bite, but it doesn't actually mean anything.

It seems the "not paying means you're the product" is short for "not paying a for-profit company means you're the product".

Re: Facebook e-mail mess: Address books altered, e-mail lost

#164

Earlier quoted context omitted.

passwords for other sites Wait, seriously? People are using websites where the password reset emails are being sent from somebody's Droid phone? I think you've gotten a little carried away.

I said nothing about password reset emails. I come from an IT background. I can't even count the number of times I've sent temporary passwords over email to co-workers, customers, etc., including from my phone. If something can be sent via email, it will be, and when the numbers are in the millions...there's a lot of data that people consider private.

Maybe a phone call to communicate a password would be better. Not as convenient of course, but security and convenience don't often go together. That assumes your voice provider isn't recording the call.

Re: Facebook e-mail mess: Address books altered, e-mail lost

#165

As I understand it, when an email address on Facebook gets synced to a phone, that's just a cache. Any updates to the email address on Facebook automatically update the cache. When friends update their email addresses, the cache gets overwritten and you don't have their old addresses anymore. But now, Facebook changed people's email addresses without their permission. The cache gets updated, and boom, the old address…

That's an excellent explanation. It also fits the mold of just about every other "service X broke into service Y and stole my info" story, wherein people forget lots of other plausible explanations.

And a good lesson as to why you should never make unannounced changes to your user's data. They will think you "broke" something, even if it never worked the way they thought it did.

Re: Facebook e-mail mess: Address books altered, e-mail lost

#166

Facebook simply doesn't have an ethical central core. They've shown over and over that when user privacy or security conflict with facebook's goals, they'll choose facebook over the user. It's always relatively subtle; they strive to only do what they can get away with...but it's always pushing the line, and is never based on trying to do what's right, merely avoiding backlash. Facebook, the company, is kind of a soc…

> I have several friends within facebook whom I like and respect, and they produce a lot of great technology. I find this idea interesting. Can an entity like a corporation have a life beyond that which is given to it by its employees? Like the ship of theseus, can you replace all employees and still have a business that "feels" the same?

Therein lies the difference between a company and a quality company.

Re: Facebook e-mail mess: Address books altered, e-mail lost

#167
post #105

The more important question is, what are Apple and Google doing allowing apps write access to a user's address book?? I can't believe anyone at Facebook was dumb enough to think this was a good idea. But at the same time, I can't believe some "rogue engineer" did this by accident. I'm curious to see what Facebook says about it.

They have to allow write access to some applications otherwise there can be no third-party address book apps. If there was such a permission, you can bet that facebook would have asked for it by default. You can also be sure that hundreds of millions of people would have granted it and we would be seeing the exact same problem. The root of the problem is facebook. The important questions should be directed at faceboo…

iOS 6 beta now prompts for permission to allow access the address book - the same way you get prompted now for gps or notification permissions when apps request it.

I noticed a lot of those permission alerts, over and over.

Re: Facebook e-mail mess: Address books altered, e-mail lost

#168

Facebook simply doesn't have an ethical central core. They've shown over and over that when user privacy or security conflict with facebook's goals, they'll choose facebook over the user. It's always relatively subtle; they strive to only do what they can get away with...but it's always pushing the line, and is never based on trying to do what's right, merely avoiding backlash. Facebook, the company, is kind of a soc…

Sounds like they just tried to steal a huge network of e-mail addresses and run it through their infrastructure.

To me, this is essentially theft.

Re: Facebook e-mail mess: Address books altered, e-mail lost

#169
post #4

Well, this is my gripe with their "go fast and break things" mantra. It works as long as you have such a highly desirable product that your users just don't care if you're doing everything right. (Or maybe you're in a non-mission-critical business, or better yet, your customers are a bunch of kids!) I'm all for going fast and sincerely believe in "A sense of urgency", but Facebook is really lucky they're not serving…

It works on facebook because no one uses facebook for anything important. But messing with iOS contacts... that's reaching out and breaking things that aren't on facebook.

Define important. It's become my de facto social calendar, and it's how I communicate online with most people that aren't geographically close to me. (I'm honestly not even sure I even have their email addresses, especially not since this fiasco.)

Re: Facebook e-mail mess: Address books altered, e-mail lost

#170

Earlier quoted context omitted.

I said nothing about password reset emails. I come from an IT background. I can't even count the number of times I've sent temporary passwords over email to co-workers, customers, etc., including from my phone. If something can be sent via email, it will be, and when the numbers are in the millions...there's a lot of data that people consider private.

Maybe a phone call to communicate a password would be better. Not as convenient of course, but security and convenience don't often go together. That assumes your voice provider isn't recording the call.

Sure, sometimes that's what you need to do. But, other times, if you know you're sending to a trusted server, such as your own company server that you manage yourself (or people who are trusted manage), it's deemed acceptable to send passwords via email. The problem here is that facebook has introduced a new vector.

It's low grade evil; but low grade evil multiplied by millions starts looking like more serious evil. Just like low grade incompetence begins to cause serious harm when it is inflicted on millions.

Post reply on HN