Live data from Hacker News

Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

businessinsider.com

241–250 of 310 posts

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#241

Since FB has gone out of their way to weaponize "friendship", my suggestion to everyone who actually likes to have some standards in their life and don't like to be manipulated like that is simple. Just do it back to them. "Unfriend" (IRL) everyone you know who works at Facebook and tell them you will "friend" them back once they leave the company.

I would never friend someone again who dropped me because of my employer

I wouldn't say I necessarily agree with doing this when it comes to Facebook, but is there really no circumstance in which you think it'd be justified to cut off contact with a friend because of where they work?

For instance, if I had a friend whose job it was to design missiles that are used to bomb innocent people (Lockheed-Martin for instance) I would seriously reconsider my friendship with that person. Yes, it's "just their job" but choosing to have a job which requires having such warped ethics would make me reconsider whether I want to continue associating with them.

Nobody is forced to work at such companies. Yes, effectively all companies do things which we don't agree with on some level (unimaginably large amounts of tax avoidance being the most obvious example). But if a company's ethics are completely antithetical to your own, then I don't see how you could morally justify working for them.

(Obviously there are some understandable exceptions to the above -- the most obvious being that in the US employees are effectively blackmailed into working for their employer because they'll lose their heath insurance otherwise.)

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#242

FB has said they'll be notifying the people whose contacts they "unintentionally" uploaded. How about notifying those contacts whose private details they illicitly obtained that their privacy has been compromised by Facebook - the innocents who signed up for FB and had their contact-list stolen (let's call it what it is) may or may not feel any moral obligation (more likely, don't even see the issue) to notify their…

It’s amazing what these companies can get away with without paying a single dime to anyone.

People can sue if they can find some claim to real-life damages... You'd only need a small percentage of the 1.5 million people and FB would probably settle out of court.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#243
post #10
post #4

First they ask for email passwords. Then the new users assume Facebook won't comprehensively mine their emails. Then Facebook awkwardly gets caught uploading 1.5 million users' email contacts. It doesn't make sense for people to trust the service at all unless you assume one of two things: 1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't kno…

Group #2 somehow lacks the imagination to see what could go wrong. They will learn when a cause effect of Facebook usage is put in their face. I guess the recent news does not push it in their face enough. Its like that with skimming, lock picking, server security, infrastructure security, basically everything security related.

You can add willingness to switch to electronic voting to that list. It's sad how many people don't understand the danger.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#244
post #234

Can't someone file a class action lawsuit against Facebook? I mean, it's nice that they are deleting the information now, but they clearly did something wrong, and by basic standards, they should be punished. And the deleting the stolen information isn't punishment, and since they probably won't delete any new ad targeting information they gathered as a conclusion from the contacts, they are still profiting from it,…

[deleted]

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#245

Earlier quoted context omitted.

You are making a distinction that the criminal justice system does not make.

There's no law that makes "hacking" a criminal offense. This particular case is just manipulation/social engineering so you probably shouldn't be calling it "hacking" on a message board that's mostly populated by software professionals to whom "hacking" has a meaning that does not include what is basically a con-man trick (though I see you have already edited the parent comment to reflect this).

We were literally just discussing the law that makes hacking a criminal offense. The Computer Fraud and Abuse Act makes it a federal offense; most if not all states also make it a state crime; most if not all other countries also make it a crime in their jurisdictions.

And yes, tricking someone into giving up their password is hacking (as any hacker will tell you), and it is a crime to use that password to swipe someone's contact database.

I'm not sure I can continue this thread with you because it seems you are very confused. I have also not edited any comments here.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#246

Since FB has gone out of their way to weaponize "friendship", my suggestion to everyone who actually likes to have some standards in their life and don't like to be manipulated like that is simple. Just do it back to them. "Unfriend" (IRL) everyone you know who works at Facebook and tell them you will "friend" them back once they leave the company.

Judging from other comments this is an unpopular idea, but why does business get to be some sort of quasi morality-free zone where nobody has to take responsibility for anything? If a friend works for a company that engages in activity that I find morally reprehensible, why shouldn't this affect our friendship? I think our society could really benefit from a little accountability, so in lieu of regulations and laws protecting us from corporations I think protecting our social circles from people who endorse the bad actions of their employers because "it's just business" is perfectly okay.

I see other comments talking about personal responsibility, but in the case of FB the notion of a company selling their data is too abstract to clearly understand the risks/consequences for many. Should we put no responsibility on corporations to act civilly or at least legally? Should one not have a personal responsibility to engage only with corporate entities that behave civilly/lawfully/etc? I really don't understand this mindset.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#247

LinkedIn pulled something similar a few years back. At the time, I was using the same password for both my email and LinkedIn account, and found that people from my email address book were showing up as suggested connections. I can only assume "consent" for this was buried in the T&Cs.

Yeah people always forget this! LinkedIn is super-shady and what they were doing was the darkest of all patterns.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#248
post #242

Earlier quoted context omitted.

It’s amazing what these companies can get away with without paying a single dime to anyone.

People can sue if they can find some claim to real-life damages... You'd only need a small percentage of the 1.5 million people and FB would probably settle out of court.

How about consumer and privacy laws? I know it varies from country to country but the government can sue and fine companies and people in order to protect it's citizens. I know I know.. I'm old fashioned like that.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#249

Earlier quoted context omitted.

Start by keeping the primary copy of the user's data on the user's own device so that the developers never have access to it to begin with. Then, if you ever have to hold a copy of the user's data, make sure it's encrypted by the client and your servers are never in possession of the plaintext. To access the user's data, your developers should have to intentionally crack the user's password. And if they attempt to do…

"Start by keeping the primary copy of the user's data on the user's own device" It's an organizational policy, procedural, ethics and legal question - not a technical one. They should have feature reviews before the code reviews. The feature review panel puts bounds on what the code can do.

> It's an organizational policy, procedural, ethics and legal question - not a technical one.

Not really. You have to fall back to those things when a good technical solution isn't available, but sometimes it is.

Suppose you have a car, and four children. You can enact all the laws and policies and procedures you like, you can lecture the kids not to misbehave a thousand times. But the most important thing you can do, if you really don't want them out joyriding in the street, is to not give them the keys to the car.

Re: Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent

#250
So, when is the FTC going to actually bring down the hammer on FB for violating the consent agreement? There's no way this was "unintentional."

At $40,000 per user per day [1], even at just one day of violation, that's a $60 billion fine FB should be liable for. "Under the settlement, Facebook agreed to get consent from users before sharing their data with third parties," so this seems to be EXACTLY in violation of that agreement.

[1] https://www.cnet.com/news/facebooks-ftc-consent-decree-deal-...

*Edit: on second thought, it should be even higher, as each of the 1.5M users had multiple contacts uploaded. So, for example, let's say 1 user had 150 contacts who were not part of the other 1.5M users who had contacts uploaded. That alone should be a violation of the consent rights of those 150 people, so $6 million per day. If every one of the 1.5 million people had, on average, 150 contacts exclusive of the other 1.5 million people who had contact info uploaded, that's a $9 trillion liability for one day of violation.

The FTC has been toothless on this for quite some time now, so I'm expecting no significant action as FB lawyers will defend that no one had data shared with "third parties," technically. Well, shouldn't my contact info shared by a friend with FB be a consent violation as FB is a "third party" from my perspective?

Post reply on HN