Live data from Hacker News

Meta accessed women's health data from Flo app without consent, says court

malwarebytes.com

71–80 of 236 posts

Re: Meta accessed women's health data from Flo app without consent, says court

#71
post #55

Everybody misses the key information here - it’s a Belarusian app. CEO and CTO are Belarusian (probably there are more C-level people who are Belarusian or Russian). Not only are users giving up their private information but they are doing so to the malevolent (by definition) regimes. When the Western app says they don’t sell or give out private information, you can be suspicious but still somewhat trustful. When a d…

The company cut all ties with Belarus more than three years ago, and all employees relocated to Europe.

Re: Meta accessed women's health data from Flo app without consent, says court

#72
As much as I don't like facebook as a company, I think the jury reached the wrong decision here. If you read the complaint[1], "eavesdropped on and/or recorded their conversations by using an electronic device" basically amounted to "flo using facebook's sdk and sending custom events to it" (page 12, point 49). I agree that flo should be raked over the coals for sending this information to facebook in the first place, but ruling that facebook "intentionally eavesdropped" (exact wording from the jury verdict) makes zero sense. So far as I can tell, flo sent facebook menstrual data without facebook soliciting it, and facebook specifically has a policy against sending medical/sensitive information using its SDK[2]. Suing facebook makes as much sense as suing google because it turned out a doctor was using google drive to store patient records.

[1] https://www.courtlistener.com/docket/55370837/1/frasco-v-flo...

[2] https://storage.courtlistener.com/recap/gov.uscourts.cand.37... page 6, line 1

Re: Meta accessed women's health data from Flo app without consent, says court

#73
post #6

Whenever you think of a court versus Facebook, imagine one of these mini mice trying to stick it to a polar bear. Or a goblin versus a dragon, or a fly versus an elephant. These companies are for the most part effectively outside of the law. The only time they feel pressure is when they can lose market share, and there's risk of their platform being blocked in a jurisdiction. That's it.

All they need to do is impose a three digit fine per affected user and Facebook will immediately feel intense pressure.

Who's this "they" you speak of, and why would they bother doing that?

Re: Meta accessed women's health data from Flo app without consent, says court

#74
post #71
post #55

Everybody misses the key information here - it’s a Belarusian app. CEO and CTO are Belarusian (probably there are more C-level people who are Belarusian or Russian). Not only are users giving up their private information but they are doing so to the malevolent (by definition) regimes. When the Western app says they don’t sell or give out private information, you can be suspicious but still somewhat trustful. When a d…

The company cut all ties with Belarus more than three years ago, and all employees relocated to Europe.

Where in Europe? Belarus is in Europe, and so is much of Russia (the largest European country). Plenty of variation in the rest of Europe.

What do you mean by cut all ties? The owners and management have no assets in Belarus or ties to the country?

Re: Meta accessed women's health data from Flo app without consent, says court

#75
post #71
post #55

Everybody misses the key information here - it’s a Belarusian app. CEO and CTO are Belarusian (probably there are more C-level people who are Belarusian or Russian). Not only are users giving up their private information but they are doing so to the malevolent (by definition) regimes. When the Western app says they don’t sell or give out private information, you can be suspicious but still somewhat trustful. When a d…

The company cut all ties with Belarus more than three years ago, and all employees relocated to Europe.

[flagged]

Re: Meta accessed women's health data from Flo app without consent, says court

#76
post #32

Earlier quoted context omitted.

> I only noticed him (I was in the process of ordering a sandwich) because he was being ‘eeeeeeee’d’ by a couple of random women that he didn’t seem to know. He seemed pretty uncomfortable about the whole thing. Pretty funny considering that Facebook's origin story was a women comparison site, or this memorable quote: > People just submitted it. I don't know why. They 'trust me'. Dumb fucks.

Have you ever ordered a really good steak, like amazing. And really huge, and inexpensive too. And it really is amazing! And super tasty. But it’s so big, and juicy, that by the end of it you feel sick? But you can’t stop yourself? And then at the end of it, you’re like - damn. Okay. No more steak for awhile? If not steak, then substitute cake. Or Whiskey. Just because you got what you wanted doesn’t mean you’re happ…

Personally, I see it as poetic justice. He started off on objectifying women with FaceMash, he doesn't get to cry about being objectified and drooled over himself.

Re: Meta accessed women's health data from Flo app without consent, says court

#77
post #72

As much as I don't like facebook as a company, I think the jury reached the wrong decision here. If you read the complaint[1], "eavesdropped on and/or recorded their conversations by using an electronic device" basically amounted to "flo using facebook's sdk and sending custom events to it" (page 12, point 49). I agree that flo should be raked over the coals for sending this information to facebook in the first place…

That's why in these cases you'd prefer a judgment without a jury. Technical cases like this will always confuse jurors, who can't be expected to understand details about sdk, data sharing, APIs etc.

On the other hand, in a number of highprofile tech cases, you can see judges learning and discussing engineering in a deeper level.

Re: Meta accessed women's health data from Flo app without consent, says court

#79
post #74
post #71

Earlier quoted context omitted.

The company cut all ties with Belarus more than three years ago, and all employees relocated to Europe.

Where in Europe? Belarus is in Europe, and so is much of Russia (the largest European country). Plenty of variation in the rest of Europe. What do you mean by cut all ties? The owners and management have no assets in Belarus or ties to the country?

you can open "contact us" page on their website.

Re: Meta accessed women's health data from Flo app without consent, says court

#80
Another aspect of this is why Apple/Google let this happen in the first place. GrapheneOS is the only mobile OS I can think of that lets you disable networking on an per-app level. Why does a period tracking app need to send data to meta (why does it even need networking access at all)? Why is there no affordance of user-level choice/control that allows users to explicitly see the exact packets of data being sent off device? It would be trival for apps to have to present a list of allowed IPs/hostnames, and users to consent/not otherwise the app is not allowed on the play store.

Simply put, it should not be possible to simply send arbitrary data without some sort of user consent/control, and to me, this is where the GDPR has utterly failed. I hope one day users are given a legal right to control what data is sent off their device to a remote server with serious consequences for non-compliance.

Post reply on HN