Live data from Hacker News

Meta accessed women's health data from Flo app without consent, says court

malwarebytes.com

201–210 of 236 posts

Re: Meta accessed women's health data from Flo app without consent, says court

#201

Earlier quoted context omitted.

If Disney mistakenly sends you a prerelease copy of the new Star Wars, playing that in your local movie theater is still a crime. Possession of data does not give you complete legal freedom.

But if you have an agreement with Disney that says “if you send us a movie we will show it”, and Disney send you the wrong thing it’s Disney’s fault, not yours. Which is what happened here.

I don't think comparisons are useful here. We are dealing with an evil corporation which we all know and it has been proven many times that it broke the law and every time gets away with it. who are you protecting?

Re: Meta accessed women's health data from Flo app without consent, says court

#202
post #154
post #72

As much as I don't like facebook as a company, I think the jury reached the wrong decision here. If you read the complaint[1], "eavesdropped on and/or recorded their conversations by using an electronic device" basically amounted to "flo using facebook's sdk and sending custom events to it" (page 12, point 49). I agree that flo should be raked over the coals for sending this information to facebook in the first place…

At the time of [1 (your footnote)] the only defendant listed in the matter was Flo, not Facebook, per the cover page of [1], so it is unsurprising that that complaint does not include allegations against Facebook. The amended complaint, [3], includes the allegations against Facebook as at that time Facebook was added as a defendant to the case. Amongst other things the amended complaint points out that Facebook's beh…

>At the time of [1 (your footnote)] the only defendant listed in the matter was Flo, not Facebook, per the cover page of [1], so it is unsurprising that that complaint does not include allegations against Facebook.

Are you talking about this?

>As one of the largest advertisers in the nation, Facebook knew that the data it received

>from Flo Health through the Facebook SDK contained intimate health data. Despite knowing this,

>Facebook continued to receive, analyze, and use this information for its own purposes, including

>marketing and data analytics.

Maybe something came up in discovery that documents the extent of this, but this doesn't really prove much. The plaintiffs are just assuming because there's a clause in ToS saying so, facebook must be using the data for advertising.

Re: Meta accessed women's health data from Flo app without consent, says court

#203

Earlier quoted context omitted.

I wish there was information about who at Facebook received this information and “used” it. I suspect it was mixed in with 9 million other sources of information and no human at Facebook was even aware it was there.

Not at Facebook, but I used to work on an ML system that took well-defined and free-form JSON data and ran ML on it. Both were used in training and classification. Unless a human looked, we had no idea what those custom fields were. We also had customers lie about what the fields represent for valid and less valid reasons. Without knowing how it works at Facebook, it's quite possible the data points got slurped in, t…

How it happened internally is irrelevant to whether Facebook is responsible. Deploying systems they do not properly control or understand does not shield against legal or normal responsibilities!

There is a trail of people who signed off on this implementation. It is the fault of one or more people, not machines.

Re: Meta accessed women's health data from Flo app without consent, says court

#204
post #202
post #154

Earlier quoted context omitted.

At the time of [1 (your footnote)] the only defendant listed in the matter was Flo, not Facebook, per the cover page of [1], so it is unsurprising that that complaint does not include allegations against Facebook. The amended complaint, [3], includes the allegations against Facebook as at that time Facebook was added as a defendant to the case. Amongst other things the amended complaint points out that Facebook's beh…

>At the time of [1 (your footnote)] the only defendant listed in the matter was Flo, not Facebook, per the cover page of [1], so it is unsurprising that that complaint does not include allegations against Facebook. Are you talking about this? >As one of the largest advertisers in the nation, Facebook knew that the data it received >from Flo Health through the Facebook SDK contained intimate health data. Despite knowi…

No...

In the part of my post that you quoted I'm literally just talking about the cover page of [1] where the defendants are listed, and at the time only Flo is listed. So nothing against Facebook/Meta is being alleged in [1]. They got added to the suit sometime between that document and [3] - at a glance probably as part of consolidating some other case with this one.

Reading [1] for allegations against Facebook doesn't make any sense, because it isn't supposed to include those.

Re: Meta accessed women's health data from Flo app without consent, says court

#205
post #97

Earlier quoted context omitted.

I would say you have a responsibility to ensure you are getting legal data. you don't buy stolen things. That is meta has a reponsibility to ensure that they are not partnering with crooks. Flo gets the largest blame but meta needs to show they did their part to ensure this didn't happen. (I would not call terms of use enough unless they can show they make you understand it)

> you don't buy stolen things. This happens accidentally every single day and we don't punish the victim

We do punish the victum - we take away stolen goods. if they know it was stolen goods they can be punished for it. money laundy laws get a lot of innocent people doing legal things.

Re: Meta accessed women's health data from Flo app without consent, says court

#206
post #186

Earlier quoted context omitted.

I don't like to defend facebook either but where does this end? Does google need to verify each email it sends in case it contains something illegal? Or AWS before you store something in a publicly accessible S3 bucket?

Here's one that we really don't want to acknowledge because it may give some sympathy towards Facebook (i do not work for them but am well aware of Cambridge Analytica); Cambridge Analytica was entirely a third party using "Click here to log in via Facebook and share your contacts" via FB's OpenGraph API. Everyone in their mind is sure that it was Facebook just giving away all user details and that's what the scandal…

> But if we think about it for even a second quite often these precedents are terrible and stifling to everyone in tech.

Doesn't everything else in your post kinda point to the industry needing a little stifling? Or, more kindly, a big rethink on privacy and better controls over one's own data?

Do you have an example of a similarly terrible precedent in your opinion? One that doesn't include the blatant surveillance state power-grabbing "think of the children" line. Just curious.

Re: Meta accessed women's health data from Flo app without consent, says court

#207
post #142
post #131

Earlier quoted context omitted.

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…

Yeah, I'm not sure if I'm missing something, and I don't like to defend FB, but ... AIUI, they have a system for using data they receive to target ads. They tell people not to put sensitive data in it. Someone does anyway, and it gets automatically picked up to target ads. What are they supposed to do on their end? Even if they apply heuristics for "probably sensitive data we shouldn't use"[1], some stuff is still go…

It doesn't work like that, though.

Companies don't get to do whatever they want just because they didn't put any safegaurds in place to prevent illegally using the data they collected.

The correct answer is to look at the data and verify it's legal to use.

I might be sympathetic of a tiny startup who has increased costs, but it's a cost of doing business just like anything else. And Facebook has more than enough resources to put safegaurds in place, and they definitely should have known better by now, so they should get punished for not complying.

Re: Meta accessed women's health data from Flo app without consent, says court

#208
post #142

Earlier quoted context omitted.

Yeah, I'm not sure if I'm missing something, and I don't like to defend FB, but ... AIUI, they have a system for using data they receive to target ads. They tell people not to put sensitive data in it. Someone does anyway, and it gets automatically picked up to target ads. What are they supposed to do on their end? Even if they apply heuristics for "probably sensitive data we shouldn't use"[1], some stuff is still go…

It doesn't work like that, though. Companies don't get to do whatever they want just because they didn't put any safegaurds in place to prevent illegally using the data they collected. The correct answer is to look at the data and verify it's legal to use. I might be sympathetic of a tiny startup who has increased costs, but it's a cost of doing business just like anything else. And Facebook has more than enough reso…

> The correct answer is to look at the data and verify it's legal to use.

So repeal Section 230 and require every site to manually evaluate all content uploaded for legality before doing anything with it? If it’s not reasonable to ask sites to do that, it’s not reasonable to ask FB to do the same for data you send them.

Your position seems to vary based on how big/sympathetic the company in question is, which is not very even-handed and implicitly recognizes the burden of this kind of ask.

Re: Meta accessed women's health data from Flo app without consent, says court

#209
post #204
post #202

Earlier quoted context omitted.

>At the time of [1 (your footnote)] the only defendant listed in the matter was Flo, not Facebook, per the cover page of [1], so it is unsurprising that that complaint does not include allegations against Facebook. Are you talking about this? >As one of the largest advertisers in the nation, Facebook knew that the data it received >from Flo Health through the Facebook SDK contained intimate health data. Despite knowi…

No... In the part of my post that you quoted I'm literally just talking about the cover page of [1] where the defendants are listed, and at the time only Flo is listed. So nothing against Facebook/Meta is being alleged in [1]. They got added to the suit sometime between that document and [3] - at a glance probably as part of consolidating some other case with this one. Reading [1] for allegations against Facebook doe…

>Reading [1] for allegations against Facebook doesn't make any sense, because it isn't supposed to include those.

The quote from my previous comment was taken from the amended complaint ([3]) that you posted. Skimming that document it's unclear what facebook actually did between 2019 and 2021. The complaint only claims flo sent data to facebook between 2016 and 2019, and after a quick skim the only connection I could find for 2021 is a report published in 2021 slamming the app's privacy practices, but didn't call out facebook in particular.

Re: Meta accessed women's health data from Flo app without consent, says court

#210
post #131

Earlier quoted context omitted.

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…

Should large corporations be able to break the law because it's too hard for them to manage their data? Should they be immune from law suits because actively moderating their product would hurt their business model? Does Facebook have a right to exist? You know exactly what it would look like. It would look like Facebook being legally responsible for using the data they get. If they are too big to do that or are gett…

>Should large corporations be able to break the law because [...]

No, because this is begging the question. The point being disputed is whether facebook offering a SDK and analytics service counts as "intentionally eavesdropping". Anyone with a bit of understanding of how SDKs work should think it's not. If you told your menstrual secrets to a friend, and that friend then told me, that's not "eavesdropping" to any sane person, but that's essentially what the jury ruled here.

I might be sympathetic if facebook was being convicted of "trafficking private information" or whatever, but if that's not a real crime, we shouldn't be using "intentionally eavesdropping" as a cudgel against it just because we hate it. That goes against the whole concept of rule of law.

Post reply on HN