Live data from Hacker News

Meta accessed women's health data from Flo app without consent, says court

malwarebytes.com

131–140 of 236 posts

Re: Meta accessed women's health data from Flo app without consent, says court

#131
post #72

As much as I don't like facebook as a company, I think the jury reached the wrong decision here. If you read the complaint[1], "eavesdropped on and/or recorded their conversations by using an electronic device" basically amounted to "flo using facebook's sdk and sending custom events to it" (page 12, point 49). I agree that flo should be raked over the coals for sending this information to facebook in the first place…

That's only the first part of the story, though. Facebook isn't guilty because Flo sent medical data through their SDK. If they were just storing it or operating on it for Flo, then the case probably would have ended differently. Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. They knew, or should have known, that they needed t…

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so.

What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they were eavesdropping or not. Whether they were using it for advertising purposes might be relevant in armchair discussions about meta is evil or not, but shouldn't be relevant when it comes to the eavesdropping charge.

>They knew, or should have known, that they needed to check if it was legal to use it

What do you think this should look like?

Re: Meta accessed women's health data from Flo app without consent, says court

#132
post #127

Earlier quoted context omitted.

What does the system look like where a human being individually verifies every pieces of data fed into an advertising system? Even taking the human out of the loop, how do you verify the "legality" of one piece of data vs. another coming from the same publisher? None of your example have anything to do with the thing we're talking about, and are just meant to inflame emotional opinions rather than engender rational d…

That's not my problem to solve? If Facebook chooses to build a system that can ingest massive amounts of third party data, and cannot simultaneously develop a system to vet that data to determine if it's been illegally acquired, then they shouldn't build that system . You're running under the assumption that the technology must exist, and therefore we must live with the consequences. I don't accept that premise. Edit…

It's difficult for me to parse what exactly your argument is. Facebook built a system to ingest third party data. Whether you feel that such technology should exist to ingest data and serve ads is, respectfully, completely irrelevant. Facebook requires any entity (e.g. the Flo app) to gather consent from their users to send user data into the ingestion pipeline per the terms of their SDK. The Flo app, in a phenomenally incompetent and negligent manner, not only sent unconsented data to Facebook, but sent -sensitive health data-. Facebook they did what Facebook does best, which is ingest this data _that Flo attested was not sensitive and collected with consent_ into their ads systems.

Re: Meta accessed women's health data from Flo app without consent, says court

#133

Earlier quoted context omitted.

That's not my problem to solve? If Facebook chooses to build a system that can ingest massive amounts of third party data, and cannot simultaneously develop a system to vet that data to determine if it's been illegally acquired, then they shouldn't build that system . You're running under the assumption that the technology must exist, and therefore we must live with the consequences. I don't accept that premise. Edit…

It's difficult for me to parse what exactly your argument is. Facebook built a system to ingest third party data. Whether you feel that such technology should exist to ingest data and serve ads is, respectfully, completely irrelevant. Facebook requires any entity (e.g. the Flo app) to gather consent from their users to send user data into the ingestion pipeline per the terms of their SDK. The Flo app, in a phenomenal…

So let's consider the possibilities:

#1. Facebook did everything they could to evaluate Flo as a company and the data they were receiving, but they simply had no way to tell that the data was illegally acquired and privacy-invading.

#2. Facebook had inadequate mechanisms for evaluating their partners, and that while they could have caught this problem they failed to do so, and therefore Facebook was negligent.

#3. Facebook turned a blind eye to clear red flags that should've caused them to investigate further, and Facebook was malicious.

Personally, given Facebook's past extremely egregious behaviour, I think it's most likely to be a combination of #2 and #3: inadequate mechanisms to evaluate data partners, and conveniently ignoring signals that the data was ill-gotten, and that Facebook is in fact negligent if not malicious. In either case Facebook should be held liable.

pc86 is taking the position that the issue is #1: that Facebook did everything they could, and still, the bad data made it through because it's impossible to build a system to catch this sort of thing.

If that's true, then my argument is that the system Facebook built is too easily abused and should be torn down or significantly modified/curtailed as it cannot be operated safely, and that Facebook should still be held liable for building and operating a harmful technology that they could not adequately govern.

Does that clarify my position?

Re: Meta accessed women's health data from Flo app without consent, says court

#134
post #86
post #84

To any other women in here, check out Drip. https://dripapp.org They seem to be the most secure.

Honestly, this is something I would just self host. This isn't data I'd trust anyone with, and I don't even have sex with men.

I think that is the best approach for people who can do that. :)

Re: Meta accessed women's health data from Flo app without consent, says court

#135
post #55

Everybody misses the key information here - it’s a Belarusian app. CEO and CTO are Belarusian (probably there are more C-level people who are Belarusian or Russian). Not only are users giving up their private information but they are doing so to the malevolent (by definition) regimes. When the Western app says they don’t sell or give out private information, you can be suspicious but still somewhat trustful. When a d…

> When the Western app says they don’t sell or give out private information, you can be suspicious but still somewhat trustful.

Hey guys, that ycombinator "hacker" forum thing full Champagne socialists employed by the Zucks/Altmans/Musks of the world told me everything is fine and I shouldn't worry. I remain trustful.

Surely not even some, ahem, spilled tea can't possibly occur again, right? I remain trustful.

Speaking of tea, surely all the random "id verification" 3rd parties used since the UK had a digital aneurysm have everything in order, right? I remain trustful.

---

Nah, I'll just give my data to my bank and that's about it. Everyone else can fuck right off. I trust Facebook about as much as I trust Putin.

Re: Meta accessed women's health data from Flo app without consent, says court

#136

5 years ago I was researching the iOS app ecosystem. As part of that exercise I was looking at the potential revenue figures for some free apps. One developer had a free app to track some child health data. It was long time ago so I don't remember the exact data being collected. But when asked about the economics of his free app, the developer felt confident about a big pay day. As per him the app's worth was in the…

I don't understand why anyone would let these psychopathic corporations have any of their personal or health data. Why would you use an app that tracked health data, or use a wearable device from any of these companies that did that. You have to assume, based on their past behavior, that they are logging every detail and it's going to be sold and saved in perpetuity.

Re: Meta accessed women's health data from Flo app without consent, says court

#137
post #58

Earlier quoted context omitted.

> The app people were sending user data to meta with no restrictions on its use And then meta accessed it. So unless you put restrictions on data, meta is going to access it. Don't you think it should be the other way around? Meta to ask for permission? Then we wouldn't have this sort of thing.

Do you think AWS should ask for permission before processing some random B2C app user's data?

If they are going to add it to a person's profile and/or sell ads based on it, yes.

Re: Meta accessed women's health data from Flo app without consent, says court

#139
post #131

Earlier quoted context omitted.

That's only the first part of the story, though. Facebook isn't guilty because Flo sent medical data through their SDK. If they were just storing it or operating on it for Flo, then the case probably would have ended differently. Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. They knew, or should have known, that they needed t…

>Facebook is guilty because they turned around and used the medical data themselves to advertise without checking if it was legal to do so. What exactly did this entail? I haven't read all the court documents, but at least in the initial/amended complaint the plaintiffs didn't make this argument, probably because it's totally irrelevant to the charge of whether they "intentionally eavesdropped" or not. Either they we…

>What do you think this should look like?

My honest answer that I know is impossible:

Targeted advertising needs to die entirely.

Re: Meta accessed women's health data from Flo app without consent, says court

#140
post #70

Earlier quoted context omitted.

From the article: "The jury ruled that Meta intentionally “eavesdropped on and/or recorded their conversations by using an electronic device,” and that it did so without consent." If AWS wanted to eavesdrop and/or record conversations of some random B2C app user, for sure they would need to ask for permission.

If you read the court documents, "eavesdropped on and/or recorded" basically meant "flo used facebook's SDK to sent analytics events to facebook". It's not like they were MITMing connections to flo's servers. https://www.courtlistener.com/docket/55370837/1/frasco-v-flo...

I think it a distinction without a difference. To make it more obvious imagine it was one of those AI assistant devices that records your conversations so you can recall them later. Plainly obvious that accessing this data for any purpose other than servicing user requests is morally equivalent to easedropping on a person's conversations in the most traditional sense.

If the company sends your conversation data to Facebook that's bad and certainly a privacy violation but at this point nothing has actually been done with the data yet. Then Facebook accesses the data and folds it into their advertising signals; they have now actually looked at the data and acted on the information within. And that to me is easedropping.

Post reply on HN