Live data from Hacker News

Meta accessed women's health data from Flo app without consent, says court

malwarebytes.com

171–180 of 236 posts

Re: Meta accessed women's health data from Flo app without consent, says court

#171
post #97
post #72

As much as I don't like facebook as a company, I think the jury reached the wrong decision here. If you read the complaint[1], "eavesdropped on and/or recorded their conversations by using an electronic device" basically amounted to "flo using facebook's sdk and sending custom events to it" (page 12, point 49). I agree that flo should be raked over the coals for sending this information to facebook in the first place…

I would say you have a responsibility to ensure you are getting legal data. you don't buy stolen things. That is meta has a reponsibility to ensure that they are not partnering with crooks. Flo gets the largest blame but meta needs to show they did their part to ensure this didn't happen. (I would not call terms of use enough unless they can show they make you understand it)

> you don't buy stolen things.

This happens accidentally every single day and we don't punish the victim

Re: Meta accessed women's health data from Flo app without consent, says court

#172
post #165

Earlier quoted context omitted.

I don’t like the analogy because “hosting an event” is a fuzzy thing. If you are hosting an event with friends you might be able to rely on the shared values of your friends and the informal nature of the thing to enforce this sort of norm. If you are a business that host events and your business model involves photos of the event, you should have a professional approach to knowing if people consented to have their p…

>I don’t like the analogy because “hosting an event” is a fuzzy thing. If you are hosting an event with friends you might be able to rely on the shared values of your friends and the informal nature of the thing to enforce this sort of norm. You can't, though -- not perfectly, anyway. Whatever the informal norms, there are going to be people who violate them, and so the fault shouldn't pass on to you when you don't k…

> I'm not sure that's the standard you want to base this argument on, because in most cases, the "professional approach" amounts to "if you come here at all, you're consenting to be photographed for publication, take it or leave it lol". FB had a stronger standard than this.

It depends on the event and the nature of the venue. But yes, it is a bad analogy. For one thing Facebook is not an event with clearly delineated borders. It should naturally be given much higher scrutiny than anything like that.

Re: Meta accessed women's health data from Flo app without consent, says court

#173

Oh boy, what's Mark up to these days.

Thanks for asking! Also on the front page today: https://news.ycombinator.com/item?id=44898934 From that article: “It is acceptable to engage a child in conversations that are romantic or sensual,” according to Meta’s “GenAI: Content Risk Standards. [...] The document seen by Reuters, which exceeds 200 pages, provides examples of “acceptable” chatbot dialogue during romantic role play with a minor. They include: “I t…

Can someone explain me why this shouldn't be illegal?

Re: Meta accessed women's health data from Flo app without consent, says court

#174

Earlier quoted context omitted.

I wish there was information about who at Facebook received this information and “used” it. I suspect it was mixed in with 9 million other sources of information and no human at Facebook was even aware it was there.

Is your argument that it's fine to just collect so much information that you can't possibly responsibly handle it all? In my opinion, that isn't something that should be allowed or encouraged.

I’m not the OP but no, I think their point is if you tell people that this data will be used for X, and not to send sensitive data that way and they do it anyway you can’t really be responsible for it - the entity who sent you the data and ignored your terms should be

Re: Meta accessed women's health data from Flo app without consent, says court

#175

Earlier quoted context omitted.

> The app people were sending user data to meta with no restrictions on its use And then meta accessed it. So unless you put restrictions on data, meta is going to access it. Don't you think it should be the other way around? Meta to ask for permission? Then we wouldn't have this sort of thing.

Here's the restriction: don't send it to fb in the first place!

If Disney mistakenly sends you a prerelease copy of the new Star Wars, playing that in your local movie theater is still a crime.

Possession of data does not give you complete legal freedom.

Re: Meta accessed women's health data from Flo app without consent, says court

#176
post #122

Earlier quoted context omitted.

So they shouldn’t be punished because they were negligent? Is that your argument?

I think their argument is that FB has a pipeline that processes whatever data you give it and the idea that a human being made the conscious decision to use this data is almost certainly not what happened. "This data processing pipeline processed the data we put in the pipeline" is not necessarily negligence unless you just hate Facebook and couldn't possibly imagine any scenario where they're not all mustache-twirli…

You're absolutely right, a human being didn't make the conscious decision to use this data. They made a conscious decision to build an automated pipeline that uses this data and another conscious decision not to build in any checks on the legitimacy of said data. Do we want the law to encourage responsibility or intentional ignorance and plausible deniability?

Re: Meta accessed women's health data from Flo app without consent, says court

#177
post #140
post #70

Earlier quoted context omitted.

If you read the court documents, "eavesdropped on and/or recorded" basically meant "flo used facebook's SDK to sent analytics events to facebook". It's not like they were MITMing connections to flo's servers. https://www.courtlistener.com/docket/55370837/1/frasco-v-flo...

I think it a distinction without a difference. To make it more obvious imagine it was one of those AI assistant devices that records your conversations so you can recall them later. Plainly obvious that accessing this data for any purpose other than servicing user requests is morally equivalent to easedropping on a person's conversations in the most traditional sense. If the company sends your conversation data to Fa…

I disagree - the blame lies with the people who sent that data to Facebook knowing it was sensitive. Whrhther meta use it for advertising or not is irrelevant.

By that logic, if I listen in on your conversations but don’t do anything about it I’m not eavesdropping?

Re: Meta accessed women's health data from Flo app without consent, says court

#179
post #142
post #131

Earlier quoted context omitted.

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…

Yeah, I'm not sure if I'm missing something, and I don't like to defend FB, but ... AIUI, they have a system for using data they receive to target ads. They tell people not to put sensitive data in it. Someone does anyway, and it gets automatically picked up to target ads. What are they supposed to do on their end? Even if they apply heuristics for "probably sensitive data we shouldn't use"[1], some stuff is still go…

The problem is, the opposite approach is...

"We're scot free, because we told *wink* people to not sell us sensitive data. We get the benefit from it, and we make it really easy for people to sign up and get paid to give us this data that we 'don't want.'"

Please don't sell me cocaine *snifffffffff*

> The fault should still lie with the entity that passed on the sensitive data.

Some benefits to making it be both:

* Centralize enforcement with more knowledgable entities

* Enforce at a level where the misdeeds can actually be identified and have scale, rather than death from a million cuts

* Prevent the central entity from using deniable proxies and cut-throughs to do bad things

This whole notion that we want so much scale, and that scale is an excuse for not paying attention to what you're doing or exercising due diligence, is repugnant. It pushes some cost down but also causes a lot of social harm. If anything, we should expect more ownership and responsibility from those with concentrated power, because they have more ability to cause widescale harm.

Re: Meta accessed women's health data from Flo app without consent, says court

#180

Earlier quoted context omitted.

Here's the restriction: don't send it to fb in the first place!

If Disney mistakenly sends you a prerelease copy of the new Star Wars, playing that in your local movie theater is still a crime. Possession of data does not give you complete legal freedom.

But if you have an agreement with Disney that says “if you send us a movie we will show it”, and Disney send you the wrong thing it’s Disney’s fault, not yours.

Which is what happened here.

Post reply on HN