Live data from Hacker News

Facebook recommended that a psychiatrist’s patients friend each other

fusion.net

221–224 of 224 posts

Re: Facebook recommended that a psychiatrist’s patients friend each other

#221
post #202

Earlier quoted context omitted.

Some girl from a dating site Googled my phone number, found my name, searched for me on Facebook and then Facebook suggested I friend her, providing me with her full name, which I did not previously know. If you search for someone on Facebook, then Facebook will suggest to that person that they friend you. Seems a massive privacy hole to me.

I didn't know about this either, but it sounds like you may have found another possible source of the leak: patients putting the name of the psychiatrist into FB search. If B searches for A and C searches for A, does that imply a relationship between B and C? Especially if they live nearby? Who knows :(

In this case I'd almost certainly guess that it is through the phone number. LinkedIn is particularly creepy for this.

Re: Facebook recommended that a psychiatrist’s patients friend each other

#222
post #155

Earlier quoted context omitted.

> I have very little sympathy for a business model based on surveillance and manipulation. I have none whatsoever. But Facebook, as it is today, is a thing that is. I don't see that imagining the current state of affairs to be other than it is helps anything. I'm also not hugely in favor of looking to government for a solution to this problem, because the United States government, for all its many and various qualiti…

We probably agree on quite a bit. I'm not trying to accuse you of victim blaming - or anything else - so if I have implied otherwise I apologize; that was not my intention. It wouldn't be my first miscommunication. My reference to victim blaming was targeted at the the ideas in the thread - and often stated by Facebook and others in the surveillance industry - that people should know not to use Facebook when they hav…

I suspect you're right about the extent to which we probably agree. I also don't think it's so much that you implied I was victim blaming, as that I'm a bit more raw on this topic than I had suspected, and that made it easy for me to find cause for indignation where none in fact exists. I'll keep an eye on that in future; thanks for taking it so equably.

> I never said I saw nothing wrong with it

You said you have nothing against it. If there's a substantive difference between the two, I fail to see it. And while I can only consider it honorable, if admittedly also incomprehensible on a personal level, to choose to submit to a beating rather than betray a personal conviction on the subject of pacifism, it still seems at odds with such a conviction to advocate action which is well known often to result in the infliction of serious harm upon those who are its maleficiaries. I suppose it's possible there is a way to reconcile those, but if so, that's something else I currently fail to see.

On the other hand, it's clear that your perspective on at least some of the people we're discussing is vastly better informed than mine, and intellectual honesty would require that I respect that fact even were I otherwise disinclined to do so. The impression I've gathered in general is that most people who work for Facebook genuinely believe they're improving the world by doing so. Would it be accurate to say that that's especially true for the VP-level people you describe? And in general, it would be interesting to hear whatever else you'd like to describe about Facebook's internal culture and the effect it has on people who partake of it.

> I'm suggesting that they are being negligent in their use of automation

Another point on which we agree. I don't know that it merits the kind of punishment you seem willing to countenance. But I gather also that you're angry about this, in a way that I'm not, and that can easily produce a certain clarity of perspective.

Re: Facebook recommended that a psychiatrist’s patients friend each other

#223
post #59
post #36

Earlier quoted context omitted.

I see so many potential ways of aggregating this kind of information in massively privacy intrusive ways on a day to day basis. And it's terrifying how many of them are just stopped by my lack of willingness to sacrifice my morals over it. Because I know very well how easy it is for people to think "oh, well, but that one little thing isn't so bad, when faced with bills to pay, or a raging boss. Many of which really…

If employees are having trouble saying "no" to unsafe, unethical, or unlawful projects, then a professional association or union is needed. A professional association can create duty requirements external to a company; it's easier to say no to your boss is have the excuse that "as a member of $ORG, I have follow $ETHICS_RULE". Alternatively a union can put pressure companies to never ask for certain things or to meet…

The problem is that it is not black and white. People will often get presented with some hair-raising proposition, turn it down, and later get presented with something slightly bad and go "well that's much better" and consider it acceptable even if perhaps it's pushing boundaries.

I agree with you, and e.g. in the UK we have the BCS, which does have ethical rules you are expected to know and apply (their membership is just a small proportion of the UK tech industry, though; in part because it is not prestigious enough for e.g. employers to ask for, while requirements for membership makes it a hassle to join for a lot of people), but at the same time it is not sufficient.

Especially give that a lot of things first become truly problematic in aggregate.

E.g. Developer #1 gets asked to ensure you pull in the phone contact list to tie your local contacts to your Facebook friends, to enable extra functionality (lets say a "call" button when you view their profile) that seems entirely benign.

Then developer #2 gets asked to match on phone numbers that have already been pulled in, possibly without even being aware that the phone numbers he is working on are not necessarily just phone numbers of Facebook friends but also unrelated contacts.

You can say that they should have verified, but often it is very easy to assume that it's fine, and not think about consequences. E.g. it doesn't seem so unreasonable to suggest friend-of-a-friend. The problem in the article is that it is not suggesting friend-of-a-friend but contact-of-a-contact, which is an entirely different relationship. But if you're told "here you can find a bunch of phone numbers for each user", build a "friend-of-a-friend" recommendation feature, it is not that strange if people assume it's actually "friend of a friend" - people like to assume the best.

Here's an example from my own past, that I did stop, but only at the last minute, when I realised what was about to happen:

And old boss asks me for a database dump from a "sort-of-still-client" that was leaving us. Nothing odd with that - they kept asking for more up to date copies to make their migration easier, and kept paying us for a year after they'd migrated their site in order to be able to continue to use their old reporting facilities.

So I prepared the database dump. Then I asked him how to deliver it, and he asked me to pass it to X. X was not the client, but someone in a new corporate parent. If my boss had instead asked me to deliver it to him instead of X, I'd have done it without further questions, and he would have passed it to X and the damage would have been done.

What X wanted to do was to mine it for potential customers. The almost-ex-client were not in any way competing with the new corporate parent, so it would not harm them was , but apart from likely violating our contracts with them, it was also a blatant Data Protection Act violation (UK).

My former boss thought this wasn't a problem because we were passing the data internally in the same company and we held the data in our system legally anyway. But the point is the data had been provided by the customers of our client for a specific purpose, and was handed to us for a specific purpose, and that purpose no longer existed. We certainly had not been given permission to use the data for sales. It was hair-raising when I realised what he wanted to do.

He accepted it when I explained why, but it was rather shocking that it took an explanation for him to realise it in the first place.

He was stupid to think his suggested use was remotely ethical, and that's the only reason I caught it: If he'd realised how unethical (and illegal) it was, and he still wanted to do it, he'd have asked me to provide the data to him, which I would have - that'd have been routine. If he'd asked me to put it up for download and provide a username and password, I also would have - assuming reasonably enough he was intending to pass that info to the client. Though after that incident I started being more sceptical about providing him with data without knowing the purpose first, and making sure the client had actually requested it.

Re: Facebook recommended that a psychiatrist’s patients friend each other

#224
post #149
post #79

Earlier quoted context omitted.

How often do you see doctors being hired that are not members of the AMA (or similar professional associations)? Their Code Of Medical Ethics[1] isn't perfect and certainly there individuals that have ignored it for $REASONS, but at least they have created a culture where it is expected that doctors will at least try to avoid unethical behavior. > only hire them? I suspect this is the knee-jerk hostility toward union…

I see a few problems. Dwindling pool of non-members: Facebook is an especially bad example here, because they have enough money and clout to get around this. How often do you see doctors being hired that are not members of the AMA: Doctors need to be on location, but this restriction doesn't apply to software. Facebook can always find talent in a country that doesn't have an 'AMA.'

More importantly: You don't need to hire only amoral people. You just need enough people with "flexible" enough morals to be able to justify actions that in themselves may not even seem particularly amoral in suitable positions to be able to get certain types of functionality built without having to hand it to the staunch defenders of morality...

In most organisations "everyone" will know who are "difficult" when it comes to dealing with privacy and other issues. Sometimes that means they are the ones you go to, when you e.g. want to be certain everything is right. But if you have something you think is ok but you think they will raise issues with, they will just go to someone more "flexible" in the organisation instead.

Unless the organisational culture itself strictly punishes this kind of behaviour and rewards protecting privacy even in instances were doing so might hurt revenue, there will be plenty of room for amoral people to find each other and "work around" safeguards

Post reply on HN