Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

261–270 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#261
post #129

Earlier quoted context omitted.

I would be optimistic if most Americans actually read the BBC ( or read, for that matter). I would venture to say most however, do not. For example, a popular right wing propaganda news source that most Americans watch has had a handful of articles this year, and skimpy coverage on air.

Do you find it hard to believe that an organization based in the UK, and citizens of that union, are more interested in whats going in Yemen than an organization based in the US, and of course the citizens of that union. I know whats happening in Yemen, I've read the facts, and now I don't care anymore. I don't want to see it in the news everyday because it wasn't relevant to me when I read about it and it has practi…

> Do you find it hard to believe that an organization based in the UK, and citizens of that union, are more interested in whats going in Yemen than an organization based in the US, and of course the citizens of that union.

Yes, because on the other side of that conflict is the Saudis, who are one of our biggest "allys", and of course, the other side of the coin is the general hypocrisy of caring what goes on in other parts of the world and not this one because it doesn't fit a specific narrative.

> What Trump said about xxx person at yyy place is varying degrees of relevant to my life, all of those degrees more so than Yemen.

I don't know how to not say this in a disrespectful way, but I really feel sad for you on a personal level if that's truly what you think. I have a feeling that you are just attempting to be a contrarian in this instance.

Re: Ex-Facebook insider says covert data harvesting was routine

#262
post #24

Earlier quoted context omitted.

It reminds me of the Snowden leaks about mass surveillance programs like PRISM. I think most technical people expected something like that to exist ever since the internet became mainstream. Still, if it's just an "educated rumor" without hard evidence there's not much for the media to talk about. Up until now you could only say "it seems pretty likely that Facebook is doing something like that, but we don't know for…

I think the trust is a new thing though, new to the social media age. I remember growing up with computers in the 90's and people I knew wouldn't even consider entering a credit card number on a website. Now we give them freely. People used anonymous handles on AIM. At some point this changed and people decided they could be themselves on the internet, which is a fine idea, but the trust just went too far.

Exactly. Another example is applications "phoning home" (desltop applications sending information back to the server) that not that much ago was considered a serious abuse. And people on forums would lambast you when you asked how to implement something like that. Now it's called telemetry and is the norm.

Re: Ex-Facebook insider says covert data harvesting was routine

#264

Earlier quoted context omitted.

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

>protected data What data was being protected? The data was created when the user chose to engage with the facebook apps. CA pays facebook to put something in front of users faces and then CA gets back information on user engagement. How is that different than any other kind of advertising on the web? We can argue that there needs to be more transparency on facebook but a breach? That's torturing the word.

"protected data" was part of the HIPAA analogy.

> This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was accessed by folks who shouldn't have had it.

Protected data, in the context of HIPAA, would refer to Personal Health Information (PHI)

Re: Ex-Facebook insider says covert data harvesting was routine

#265
post #236

tell me again why you think the EU General Data Protection Regulation (GDPR) is a bad idea?

Because it's over-broad, outlawing for example immutable web server logs. Laws against murder are good too, but I think we all agree that a law against murder which defined saying mean things as murder would be over-broad.

I think a better analogy is automobile laws. Yes it’s a pain to have your car inspected and registered over and over, and there are plenty of places where speed limits are frustratingly below what a driver could safely deal with, but in general these laws do protect people not only from themselves, but others, who are perhaps not so careful with their car.

Re: Ex-Facebook insider says covert data harvesting was routine

#266
post #32

Earlier quoted context omitted.

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

It will offer a possibile solution in Europe, where Facebook has already been under heavy scrutiny. It won't change anything in the US, South America, SE Asia and developing countries where Facebook is already dangerously synonimical to the whole online experience of the average user.

The hope is that Facebook will not have two different data handling strategies for EU and non-EU users and we'll see some sort of regulatory encroachment from the EU to the rest of the world. But obviously GDPR endangers so many of Facebook's shady but lucrative practices that they will have financial incentives to set up two different user silos.

Re: Ex-Facebook insider says covert data harvesting was routine

#267
post #199
post #32

Earlier quoted context omitted.

GDPR can't come too soon. That would definitely put an end to these shady practices, as the penalties of several individual infractions would endanger any company.

and how many people are aware of it and will write to companies like FB asking for their data?

That's not how GDPR works.

Re: Ex-Facebook insider says covert data harvesting was routine

#268
post #235

Earlier quoted context omitted.

When you call it a breach it sounds like they made a mistake. It wasn’t a mistake. It was by design.

Breach doesn't imply a mistake. Anyway, the idea here is that CA breached Facebook users personal data by methods quite similar to phishing and FB look the other way. Not necessarily by design but maybe by a desire to exploit the platform as much as possible so that did not get in the way of people who were doing interesting things.

We all know what a data breach is, calling this a data breach is playing fast and loose with the term.

https://en.wikipedia.org/wiki/Data_breach

Look at all the examples of a data breach in this wiki. The CA/Facebook incident looks nothing like them.

CA either paid facebook to collected data through apps or scraped data from public profiles. Maybe the CA/facebook incident will change what we consider "breach" to mean but right now "unauthorized collection of public data to create a political profile of users" is not a data breach.

Re: Ex-Facebook insider says covert data harvesting was routine

#269

Earlier quoted context omitted.

>> ...but that protected data was accessed by folks who shouldn't have had it. Facebook handed over the data. They need to understand that they don't have control over it once it leaves Facebook. Is a violation of ToS a data breach? Do we really want to conflate those things?

I understand why Facebook doesn't want to call it a breach. But it seems equally reasonable to me that users see it as one. From the user perspective, private data is suddenly in the hands of unknown, suspicious actors who may use it against them. That Facebook would rather not call that a breach so much as "business as usual" is all the more reason legislators may be inclined to define "breach" the way that voters d…

Facebook DO want to frame it as a breach. Because then it's a f*-up, not expected behaviour.

Re: Ex-Facebook insider says covert data harvesting was routine

#270

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

For Facebook, an actual data breach would be better. They could button things up and make some statements and move on. This appears to have been systemic and profitable for them because companies would turn around and pay them for highly targeted ads. They ignored it because of greed.

Yep. If/when the 50M profiles become public, Facebook will be bending over backwards to rebrand this as a breach. However, on the (Twitter) record, their CISO has already said emphatically this was not a breach. He's been demoted.
Post reply on HN