Live data from Hacker News

Zuckerberg on Cambridge Analytica situation

facebook.com

301–310 of 583 posts

Re: Zuckerberg on Cambridge Analytica situation

#301

Re: His first "fix": > First, we will investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity. We will ban any developer from our platform that does not agree to a thorough audit. And if we find developers that misused personally identifiable information, we will…

> What happens if they find that 50 different organizations had access to and may have saved as much data as CA?

Isn't this more than guaranteed? Literally any crappy quiz app or game had access to all of this data when they launch Facebook Platform. And I'm betting Kogan's app was far from the most popular on Facebook at the time -- the potential for hundreds of thousands of data harvesters to have exploited this is way too high. I disagree that it's "the end of Facebook", though... in general, users just don't seem to care that much about this sort of thing. I can say for certain that my parents don't understand what this means or why this is bad (they had trouble understanding what was so bad about the Equifax leak as well), so your lowest common denominator user is never going to budge, even after something like this. I'm just hoping that my more technically-inclined friends start to lean away from Facebook's collection of data aggregators.

Re: Zuckerberg on Cambridge Analytica situation

#302

Earlier quoted context omitted.

> They knew it was illegal but put all the incentives for companies not to follow the rules. Offtopic but i cant help it. You get what you measure. Which is why economies that only measure profit optimize for nothing but profit. When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit, we should not be surprised that companies like Facebook do…

> the GAAP has all but ensured that this happens. You want companies to have values? Then measure values! (alongside profit, not inspite of) How do you record company/moral values into Books of Accounts? How does one audit those morals? What category do you assign it under: Asset, Liability or Owners Equity? And moreover, what would happen if morals change and some are deemed obsolete? Also, if you start to measure c…

Aren't intangibles exactly that, though perhaps a little broader than specifying particular moral behaviours?

Goodwill, Brand (which contains value statements), IP, etc, they're given financial value. Perhaps these don't influence shareholder/public actions as much as they could, but the measures are there at least.

Re: Zuckerberg on Cambridge Analytica situation

#303

Earlier quoted context omitted.

So FB opened up their platform to 3rd party Devs in 2007 and this CA incident happened in 2013. FB changed their policy of not allowing broad data access to these Devs in 2014. So my question is: Why they admit that they'd audit the pre-2014 apps now when NYT and Guardian/Observer broke the news? And what policy is in place now that makes sure that these 3rd party Devs won't sell whatever info they do collect as per…

Why they admit that they'd audit the pre-2014 apps now when NYT and Guardian/Observer broke the news? I don't know, they should have done it when Obama committed even worse Facebook privacy violations back in 2008/2012. I guess when you have Chris Hughes working for your campaign, it's easier to keep things under wraps and spin what does become public as a positive. It was only after Trump won that this kind of use o…

> when Obama committed even worse Facebook privacy violations back in 2008/2012

Obama's campaign said they were scraping for academic purposes, downloaded a bunch of data and then lied about deleting it? There are multiple levels of B.S. when it comes to Cambridge Analytica and Facebook. Only one finds comparison in the 2008 or 2012 races (on either side).

Re: Zuckerberg on Cambridge Analytica situation

#304
post #268
post #95

Earlier quoted context omitted.

FB will be fully integrated as part of the surveillance state soon enough. > that Zuckerburg explicitly takes personal responsibility for everything that happens on his platform Sorry, but bullshit. He may say that, but I'll believe it when he publishes the agreement he signed that makes him personally liable for lawsuits.

Seriously, every CEO is held responsible for the actions of the company he runs. He's just restating the obvious here.

I realize you're not the poster I was responding to, but one has to pick one. Either this is a nullop statement, or it is an encouraging, commendable thing to say.

I agree with you, BTW.

Re: Zuckerberg on Cambridge Analytica situation

#305

2010: Zuckerberg says privacy is no longer a "social norm" 2018: Oops https://www.telegraph.co.uk/technology/facebook/6966628/Face...

He honestly isn't wrong. People use Google and Facebook everyday for free in exchange for their privacy and they are ok with that. You can ask most people and they'll say they didn't really care about Snowden's leaks. They are happy to use free software and to be under government supervision (I don't care about the inefficacy of it). Privacy really is a social norm of the past.

Re: Zuckerberg on Cambridge Analytica situation

#306
Basically all I see is a blame game on CA and that researcher. For the sake of brevity, when someone is hosting a REST API web server at Facebook, did not they notice a large number of requests coming from a certain app id (3rd party dev) for a certain type of data (user, his data, his friends, their data and so on)? At that point you knew what exact users were compromised, 5 or 50 million. And then CA came back to your platform and bombarded those same users (or subset of those users) with their propaganda ads etc. Point being, there were data foot prints left when they pulled the data for those specific users and their were data foot prints left when they came back for those users. Facebook is not Techcrunch that you don't care much about the nature of traffic coming in b'coz it is a blog. Facebook is where people literally share their every day life activities. I am assuming that there should be some smart self-governing systems in place at FB platform that would raise flags when such type inward/outward traffic gets generated.

Re: Zuckerberg on Cambridge Analytica situation

#308
post #85
post #26

Earlier quoted context omitted.

I created an app so I could grant myself access to the API with it. It was an embarrassing amount of data on all your friends.

I created an app back in 2009, to grant myself access and look around. Saw too much information about friends, realized some friends began "using" my app, just because it was made by me. Realized all the quizzes and dumb polls are data-gathering apps for the developers. Realized, all the awkward "friend requests" from other side of the world, are fake profiles, to gather more data. Made a fake profile, to seem from a…

[deleted]

Re: Zuckerberg on Cambridge Analytica situation

#309

Earlier quoted context omitted.

> It is against our policies for developers to share data without people's consent. Not to mention that it's arguable that "consent" was really given for facebook to share the data in the first place. I'd be interested to see some polling results asking if facebook users knew what facebook was up to and whether they feel OK with it.

These fake consent (EULA, signup clauses) need to be shot down once and for all. Consent needs to be visible, granular, and explicit.

These have existed for a long time, on paper contracts.

Re: Zuckerberg on Cambridge Analytica situation

#310
post #159
post #24

Earlier quoted context omitted.

This feels strange to those of us from technical spheres, but much of the world works without formal verification of facts. There are in theory severe penalties, both implicit and explicit, that ostensibly act as deterrent to bad actors. This is usually only noteworthy when it fails, but by and large it works. The friction involved if we did not generally accept someone's (signed, notarized, appropriately formalized)…

Could smart contracts (maybe in addition to a Trusted Execution Environment) be used to enforce these sorts of guarantees?

I'm slightly irritated that there seems not to be a single problem currently that someone would not be proposing cryptocurrency as a solution.
Post reply on HN