Live data from Hacker News

50M Facebook profiles harvested for Cambridge Analytica in major data breach

theguardian.com

31–40 of 271 posts

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#31
post #28

I was curious how the figure leaped from the 270k cited in the Facebook press release to this 50M figure. It sounds like they never had full access to the Facebook profiles beyond the 270k who installed the app, but just harvested the friend lists of those 270k. This doesn't give the app developer full access to the friends' profile data, but I guess once you have the network of friend connections you can use other p…

You could get access to the full friends‘ user profile data in Graph API earlier than v2.0. If you had 500 friends, and granted friends_* OAuth permissions to an app, the app had access to 501 user profiles.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#32
post #24

This wasn't a data breach, it was a misuse of data by a third party.

Every single definition I find classifies this as a data breach. > A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.

Possibly, but remember it starts with the user authorizing a company (FB) to release his/her data to a third-party. If the user doesn't trust the third-party then it shouldn't authorize the data sharing. The question I guess is that FB then agrees to share the data under certain conditions (that the third party only uses the data for an agreed purpose), and if this agreement between FB and the third party isn't honoured, shouldn't FB then sue for damages on behalf of the user?

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#33
post #24

This wasn't a data breach, it was a misuse of data by a third party.

Every single definition I find classifies this as a data breach. > A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.

Yes indeed, we need to redefine "data breach" to include "against terms of service" to make it easier to go after all the future Aaron Swartz's.

If you redefine a concept and use it against your political enemies don't be all that surprised when they turn around and use it against your political allies.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#34
post #25
post #5

Earlier quoted context omitted.

You're downvoted because you're technically not correct. The case is more like the bank manager allowing the robber into the vault, with full knowledge that the robber wants to and could easily make off with all the valuables, then asking the robber to please not do that before heading back to work, leaving the thief unattended in the vault. Edit: it's a breach of contract, maybe; but not a "data breach" which I thin…

I was completely technically correct. It's a data breach. Plain and simple. > A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.

A data breach, yes, but I believe by GSR not FB? It seems like users did authorized FB to share data with GSR?

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#35
One thing other commenters haven't mentioned is that Facebook asked the other parties to delete the data and promise never to use it again and the other parties even certified that they had done so, but the whistleblower is alleging they lied to Facebook.

Maybe that's legally actionable.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#36
post #17

Earlier quoted context omitted.

I agree. But you should take that first step, and then start lobbying your friends to stop posting pictures of you. Personally, I also excuse myself at gatherings when the cameras come out, because I know it's all going straight to FB. The shaming has already started to decrease; now I'm usually not alone in popping out of the room.

I instead, always asked everyone be tagged as someone else. Typically, people are relatively okay with this because no one notices. It totally breaks the CNNs for face detection.

That is a great idea. Personally I have tried to serve bad data to google captchas for many years. The text capthas were really easy, but the newer image captchas are much more obstinate. Or maybe my shadow profile just got tagged as an unreliable captcha form-filler.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#39

Earlier quoted context omitted.

...and have everyone else who knows you stop, and block their widgets and buttons that track you, and block any org that might leak, sell, or just share some of your info with them. I can’t stop a friend or just some rando at a party from uploading a photo of me. I can’t stop friends from using FB and getting me into their system. In 2018, privacy isn’t just about what we choose to do.

I would be seriously impressed and surprised if they managed to get any information based on photos uploaded that happened to include people who weren't tagged and weren't on Facebook. Aside from the all-or-nothing nature of specific apps, privacy is more about what you choose to do than that - most people just choose to not do much for privacy. At least as far as most private corporations using the Internet goes.

https://news.ycombinator.com/item?id=16474938 https://gizmodo.com/how-facebook-figures-out-everyone-youve-...

The fact that 90% of your friends upload contacts/emails is plenty of information about you.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#40
post #4

This wasn't a data breach, it was a misuse of data by a third party.

You are nitpicking a small part of an article (incorrectly) and it distracts from the main point: A foreign power is working with American billionaires to subvert democracy and install a dictator . This is a serious issue and one of the biggest news stories of our time. > This wasn't a data breach Yes it was. > it was a misuse of data by a third party. So a bank robber who gets into the vault just misused the locks?…

> A foreign power is working with American billionaires to subvert democracy and install a dictator.

Seriously?

I'm no fan of any politician (or really of "tyranny of the majority") but I was kind of impressed at how well it all worked out last time. An "unpopular" candidate won and the ruling elite turned over the reigns just like they're supposed to do trusting the checks and balances in the system to work.

The quickest way to get a dictatorship is to go against the legal results of an election because the unpopular candidate won based on some metric of "unpopular" like "kids rioting in the streets".

Post reply on HN