Live data from Hacker News

Meta accessed women's health data from Flo app without consent, says court

malwarebytes.com

161–170 of 236 posts

Re: Meta accessed women's health data from Flo app without consent, says court

#161
post #142
post #131

Earlier quoted context omitted.

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…

Yeah, I'm not sure if I'm missing something, and I don't like to defend FB, but ... AIUI, they have a system for using data they receive to target ads. They tell people not to put sensitive data in it. Someone does anyway, and it gets automatically picked up to target ads. What are they supposed to do on their end? Even if they apply heuristics for "probably sensitive data we shouldn't use"[1], some stuff is still go…

I don’t like the analogy because “hosting an event” is a fuzzy thing. If you are hosting an event with friends you might be able to rely on the shared values of your friends and the informal nature of the thing to enforce this sort of norm.

If you are a business that host events and your business model involves photos of the event, you should have a professional approach to knowing if people consented to have their photos shared, depending on the nature of the venue.

At this point it is becoming barely an analogy though.

Re: Meta accessed women's health data from Flo app without consent, says court

#162

Earlier quoted context omitted.

Flo shouldn't have sent those data to FB. That's true. Which is why they settled. But FB, having received this info proceeded to use it and mix it with other signals it gets. Which is what the complaint against FB alleged.

I wish there was information about who at Facebook received this information and “used” it. I suspect it was mixed in with 9 million other sources of information and no human at Facebook was even aware it was there.

Not at Facebook, but I used to work on an ML system that took well-defined and free-form JSON data and ran ML on it. Both were used in training and classification. Unless a human looked, we had no idea what those custom fields were. We also had customers lie about what the fields represent for valid and less valid reasons.

Without knowing how it works at Facebook, it's quite possible the data points got slurped in, the models found meaning in the data and acted on it, and no human knew anything about it.

Re: Meta accessed women's health data from Flo app without consent, says court

#163

Earlier quoted context omitted.

So let's consider the possibilities: #1. Facebook did everything they could to evaluate Flo as a company and the data they were receiving, but they simply had no way to tell that the data was illegally acquired and privacy-invading. #2. Facebook had inadequate mechanisms for evaluating their partners, and that while they could have caught this problem they failed to do so, and therefore Facebook was negligent. #3. Fa…

No one is arguing that FB has not engaged in egregious and illegal behavior in the past. What pc86 and I are trying to explain is that in this instance, based on the details of the court docs, Facebook did not make a conscious decision to process this data. It just did. Because this data, combined with the billion+ data points that Facebook receives every single second, was sent to Facebook with the label that it was…

[deleted]

Re: Meta accessed women's health data from Flo app without consent, says court

#164
post #72

As much as I don't like facebook as a company, I think the jury reached the wrong decision here. If you read the complaint[1], "eavesdropped on and/or recorded their conversations by using an electronic device" basically amounted to "flo using facebook's sdk and sending custom events to it" (page 12, point 49). I agree that flo should be raked over the coals for sending this information to facebook in the first place…

That's why in these cases you'd prefer a judgment without a jury. Technical cases like this will always confuse jurors, who can't be expected to understand details about sdk, data sharing, APIs etc. On the other hand, in a number of highprofile tech cases, you can see judges learning and discussing engineering in a deeper level.

I've also heard you want a judge trial if you're innocent, jury if you're guilty. A judge will quickly see through prosecutorial BS if you didn't do it, and if you did, it only takes one to hang.

Re: Meta accessed women's health data from Flo app without consent, says court

#165
post #142

Earlier quoted context omitted.

Yeah, I'm not sure if I'm missing something, and I don't like to defend FB, but ... AIUI, they have a system for using data they receive to target ads. They tell people not to put sensitive data in it. Someone does anyway, and it gets automatically picked up to target ads. What are they supposed to do on their end? Even if they apply heuristics for "probably sensitive data we shouldn't use"[1], some stuff is still go…

I don’t like the analogy because “hosting an event” is a fuzzy thing. If you are hosting an event with friends you might be able to rely on the shared values of your friends and the informal nature of the thing to enforce this sort of norm. If you are a business that host events and your business model involves photos of the event, you should have a professional approach to knowing if people consented to have their p…

>I don’t like the analogy because “hosting an event” is a fuzzy thing. If you are hosting an event with friends you might be able to rely on the shared values of your friends and the informal nature of the thing to enforce this sort of norm.

You can't, though -- not perfectly, anyway. Whatever the informal norms, there are going to be people who violate them, and so the fault shouldn't pass on to you when you don't know someone is doing that. If anything, the analogy understates how unreasonable it is to FB, since they had an explicit contractual agreement for the other party not to send them sensitive data.

And as it stands now, websites aren't expected to pre-filter for some heuristic on "non-consensual user-uploaded photographs" (which would require an authentication chain), just to take them down when informed they're illegal ... which FB did (the analog of) here.

>If you are a business that host events and your business model involves photos of the event, you should have a professional approach to knowing if people consented to have their photos shared, depending on the nature of the venue.

I'm not sure that's the standard you want to base this argument on, because in most cases, the "professional approach" amounts to "if you come here at all, you're consenting to be photographed for publication, take it or leave it lol". FB had a stronger standard than this.

Re: Meta accessed women's health data from Flo app without consent, says court

#167
post #122

Earlier quoted context omitted.

So they shouldn’t be punished because they were negligent? Is that your argument?

I think their argument is that FB has a pipeline that processes whatever data you give it and the idea that a human being made the conscious decision to use this data is almost certainly not what happened. "This data processing pipeline processed the data we put in the pipeline" is not necessarily negligence unless you just hate Facebook and couldn't possibly imagine any scenario where they're not all mustache-twirli…

It is necessarily negligence if they are ingesting a lot of illegal data, right? I mean, it could be the case that this isn’t a business model that works given typical human levels of competence.

But working beyond your competence when it results in people getting hurt is… negligent.

Re: Meta accessed women's health data from Flo app without consent, says court

#168
post #131

Earlier quoted context omitted.

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…

[flagged]

[flagged]

Re: Meta accessed women's health data from Flo app without consent, says court

#169
> Yet between 2016 and 2019 Flo Health shared that intimate data with companies including Facebook and Google, along with mobile marketing firm AppsFlyer, and Yahoo!-owned mobile analytics platform Flurry. [...] Every interaction inside the app was also logged, and this data was shared.

Proposed resolution:

1. Wipe out Flo with civil damages, and also wipe out the C-suite and others at the company personally.

2. Prison for Flo's C-suite, and everyone else at Flo who knew what was going on and didn't stop it, or who was grossly negligent when they knew they were handling sensitive info.

3. Investigate what Flo's board and investors knew, for possible criminal and civil liability.

4. Investigate what Flo's data-sharing partner companies knew, and what was done with the data, for possible criminal and civil liability.

Tech industry gold rushes have naturally attracted much of the shittiest of society. And the Overton window within the field has shifted so much due to this, with some dishonest and underhanded practices as SOP, that even decent people have lost references for what's right and wrong. So the tech industry is going to keep doing every greedy, underhanded, and reckless thing they can, until society starts holding them accountable. That doesn't mean regulatory handslaps; that means predatory sociopaths rotting in prison, and VCs and LPs wiped out, as corporate veils of companies that the VCs knew were underhanded are pierced.

Re: Meta accessed women's health data from Flo app without consent, says court

#170

Earlier quoted context omitted.

So let's consider the possibilities: #1. Facebook did everything they could to evaluate Flo as a company and the data they were receiving, but they simply had no way to tell that the data was illegally acquired and privacy-invading. #2. Facebook had inadequate mechanisms for evaluating their partners, and that while they could have caught this problem they failed to do so, and therefore Facebook was negligent. #3. Fa…

No one is arguing that FB has not engaged in egregious and illegal behavior in the past. What pc86 and I are trying to explain is that in this instance, based on the details of the court docs, Facebook did not make a conscious decision to process this data. It just did. Because this data, combined with the billion+ data points that Facebook receives every single second, was sent to Facebook with the label that it was…

Mens rea vs actus reus.

In some crimes actus reus is what matters. For example if you're handling stolen goods (in the US) the law can repossess these goods and any gains from them, even if you had no idea they were stolen.

Tech companies try to absolve themselves of mens rea by making sure no one says anything via email or other documented process that could otherwise be used in discovery. "If you don't admit your product could be used for wrong doing, then it can't!"

Post reply on HN