Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

231–240 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#232

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

A much better example would be GDPR, which comes into force EU-wide in about two months.

Re: Ex-Facebook insider says covert data harvesting was routine

#233

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

All this lawyering over the definition of 'breach' is failing to see the forest for the trees. It is a breach of trust, even if not a breach of technical security controls.

Re: Ex-Facebook insider says covert data harvesting was routine

#234
post #49

Is there any reason to believe that the situation isn't the same in, say, the Android ecosystem? In my experience many 3rd party apps require ridiculous amounts of permissions (contact list etc...) for something that's not core functionality. Surely all these free-to-play crapware games on the Android market have siphoned all the data they could and sold them to the highest bidder? Does Google do a better job of moni…

Wait until you see the video of these guys: https://www.sentiance.com/ (via https://news.ycombinator.com/item?id=16626752 )

Yeah that's exactly the type of things I'm worried about. Smartphone apps have potential access to an incredible amount of sensitive data and I always found Android's permission system to be woefully inadequate.

Re: Ex-Facebook insider says covert data harvesting was routine

#235
post #190

Earlier quoted context omitted.

It's definately a breach, just not breach into Facebook's technical infrastructure. As I wrote previously, don't you think that it can be a breach in the same sense of a breach by phishing? After all, both of the cases are about people giving their "secrets" for one reason but the info being used for something else. I mean, in the case of traditional phishing the user is tricked to provide the password by impersonati…

When you call it a breach it sounds like they made a mistake. It wasn’t a mistake. It was by design.

Breach doesn't imply a mistake.

Anyway, the idea here is that CA breached Facebook users personal data by methods quite similar to phishing and FB look the other way. Not necessarily by design but maybe by a desire to exploit the platform as much as possible so that did not get in the way of people who were doing interesting things.

Re: Ex-Facebook insider says covert data harvesting was routine

#236

tell me again why you think the EU General Data Protection Regulation (GDPR) is a bad idea?

Because it's over-broad, outlawing for example immutable web server logs.

Laws against murder are good too, but I think we all agree that a law against murder which defined saying mean things as murder would be over-broad.

Re: Ex-Facebook insider says covert data harvesting was routine

#237
post #36
post #15

Earlier quoted context omitted.

Just so the quote [2004] isn't out of context: Zuckerberg: I have over 4,000 emails, pictures, addresses, SNS [Friend]: What? How'd you manage that one? Zuckerberg: People just submitted it. Zuckerberg: I don't know why. Zuckerberg: They "trust me" Zuckerberg: Dumb fucks

I'm sure you can do a better job at illustrating your point than ressucitating a +10y old quote from Zuck, 19 at the time. Teenagers and college students say a lot of condescending, dumb, immature stuff in group discussions. It's not news and no evidence at all.

> Teenagers and college students say a lot of condescending, dumb, immature stuff

Please. 19 is not 5.

Re: Ex-Facebook insider says covert data harvesting was routine

#238

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

Was this a security breach in the sense that the company with the data got “hacked”? No. Was this a breach in trust to Facebook users? I think undoubtedly yes. And was there a breach of a the Terms of Service by companies taking all this data and using it for non-academic purposes? Yes there was. So the type of breach seems to be a worthwhile distinction to make.

>Was this a breach in trust to Facebook users? I think undoubtedly yes.

How naive is the average person? The purpose of facebook is to gather this information, hence why its offered as a "free service".

Frankly, I don't understand why the stock is going down, facebook is fulfilling its core mission: Get private information on millions of people and package that information for sale to its clients. If anything CA situation should show how FB is fulfilling its core mission.

The fact that the public is now waking up to this is not a breach, its simply casting a light on what has always existed.

Re: Ex-Facebook insider says covert data harvesting was routine

#239
post #145

Earlier quoted context omitted.

Data protection laws are so strong in Germany that they let registration offices sell your data if you don't explicitly opt out. Most people don't even know whats going on and that they have to opt out to avoid that. Or German credit scoring institutions, who are allowed collect data about you even if you don't have any mutual agreement with them.

German credit scoring institutions collect data on behalf of banks, insurances, etc., and you need to consent that they send data to the credit scoring company. So you are actually consenting. If you never give consent to any such party, the scoring company must not store data about you (and most probably won't, they are tightly observed by data protection agencies). It will become interesting with GDPR, when custome…

I guess he wants to hint you to the fact that the "Einwohnermeldeamt" is allowed to sell your data to a "Addresshändler", see https://www.teltarif.de/datenweitergabe-adresse-einwohnermel...

Re: Ex-Facebook insider says covert data harvesting was routine

#240
I see a lot of Facebook sympathizers here. Is this what devs do at Facebook? Browse HN and defend the reputation of Facebook at any cost? Yes we all knew what we were in for when we signed up for Facebook and Instagram. Yes, they can sell our data to show us ads about what coals to buy for July 4th bbq party and we are OK with that. But not to turn blind eye to foreign entities which in return use it against us and jeopardize the American democracy and social fabric.
Post reply on HN