Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

321–330 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#321
post #65
post #27

Earlier quoted context omitted.

My thoughts exactly. People seem to hold on to Facebook whatever the stories are, so there is no real problem. I was even thinking of buying stocks soon (wait one more week to have the market process these 'new' facts).

It may not be seen as ethical here, but I also plan on buying some more FB. This is a huge overreaction, and we all know it'll blow over inside of a week.

FB is the media’s scapegoat of the season...nothing to see here...keep shopping folks ;)

Seriously though, go buy that stock...it’s ridiculously under valued!

Re: Ex-Facebook insider says covert data harvesting was routine

#322
post #49

Is there any reason to believe that the situation isn't the same in, say, the Android ecosystem? In my experience many 3rd party apps require ridiculous amounts of permissions (contact list etc...) for something that's not core functionality. Surely all these free-to-play crapware games on the Android market have siphoned all the data they could and sold them to the highest bidder? Does Google do a better job of moni…

I don't know which one I'm more worried about. On the one side Facebook can track preferences and something akin to feelings closely, but on the other Google can track day-to-day activities much better.

If you've ever seen your Google activity log; that's very scary. The accuracy with which your phone can track your movement and where you are at every point in time is unprecedented. I'm very careful with what I allow 3rd parties to access but I can see a lot of users blindly accepting (like they did for this personality quiz that leaked all this Facebook info in the first place).

Re: Ex-Facebook insider says covert data harvesting was routine

#323

Earlier quoted context omitted.

I was actually surprised by the generally positive reaction the GDPR got in recent threads here on HN. I guess the suspicion of data hoarding overcame conspiracy theories about government regulation or EU protectionism. BUT it’s important to note that GDPR would probably not have had an effect on the specific situation with Cambridge Analytica. CA is obviously toast if not by law then by the attention alone. Facebook…

>they got the users’ permission initially, and there isn’t much you can do to protect yourself against malicious actors. The EU is clearly moving against that blatant circumvention. I don't know exactly what they are going to do, but the whole, "just sign all your rights to privacy way with one click" is something they want to change. I think the mostly likely situation will be one where each specific instance of use…

I think the insurance company would care a whole lot!

Facebook's big data is getting to where they can predict things like pregnancies, illnesses based on parsing minor changes in behavior and correlating it against the big data set. This is of course super interesting, but it also gives you results like 'suddenly this guy is 42% more likely to die in the next 6 months and doesn't know it'. There are no certainties, but to an actuarial entity like an insurance company?

That's more than worth getting your lobbyists to repeal any shred of requirement that you have to keep faith with such a person. Insurance combined with big data and stripped regulations makes such an industry purely a financial play: handled properly they can, for a time, collect money and never pay any of it out, until it becomes obvious that's what they're doing.

Those are the entities most interested in having Facebook tell them you're probably getting sick. And why would Facebook ever tell you? That's their inference. You never said a thing about it, and indeed they could be wrong. But don't bet on it.

Re: Ex-Facebook insider says covert data harvesting was routine

#324

Earlier quoted context omitted.

> you'd think the systems were actually compromised We're seeing a divide between the technical and popular interpretations of the term "breach". When an industry drops the ball and responds pedantically, that's a strong sign that further regulation is needed. If only to force a common language. Facebook insists they were not "breached" because many states require notification in the event of "security breaches of in…

> When an industry drops the ball and responds pedantically, that's a strong sign that further regulation is needed. If only to force a common language. We already have plenty of regulation here that Facebook is unambiguously subject to; the question is whether the relevant authorities will actually follow through on that. For what it's worth, it's been two days, and we're already seeing an FTC investigation and a Co…

[deleted]

Re: Ex-Facebook insider says covert data harvesting was routine

#326

Earlier quoted context omitted.

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

>protected data What data was being protected? The data was created when the user chose to engage with the facebook apps. CA pays facebook to put something in front of users faces and then CA gets back information on user engagement. How is that different than any other kind of advertising on the web? We can argue that there needs to be more transparency on facebook but a breach? That's torturing the word.

> What data was being protected?

Personally-identifiable information [1]. Many states require notification in the event this data is found to have been accessed improperly. The definition of a "breach" is not limited to technical malfunctions.

[1] http://www.ncsl.org/research/telecommunications-and-informat...

Re: Ex-Facebook insider says covert data harvesting was routine

#328

Earlier quoted context omitted.

Even if they complied with your erasure request and deleted everything from all their servers and their backups (spanning the world over a decade), think of all the non-EU third-parties who have your FB data already

I wonder if GDPR could be applied to companies I don't have a relationship with but have my data (i.e. CA-type data collection companies)?

The GDPR basically states that a company have a relashionship with you if they have data about you.

Re: Ex-Facebook insider says covert data harvesting was routine

#329
post #257

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

It's the problem with that kind of speech, it's impersonal and dehumanizing. Let's say it like it is: facebook betrays users expectations giving their data to other businesses. Same for hacking: some people invaded system such and such and took private information. It doesn't matter if it was a breach, a floodgate, a window, what matters is what happened, and what happened is that player X did Y. Let's just state tha…

It’s important for the public discourse that someone point this sort of stuff out occasionally. Even if this was not even the most egregious example I’ve seen this week.

Once in a while I reread http://www.derailingfordummies.com and review the definition of “horizontal aggression”. Sometimes it saves me from engaging with people who are derailing the conversation. Accidentally or willfully.

Re: Ex-Facebook insider says covert data harvesting was routine

#330
From the story: > They seemed to be entirely focused on limiting their liability and exposure rather than helping the country address a national security issue.

This is a national security issue. That seems like the most pertinent issue, and yet there is no mention of it in the discussions here. Facebook has amassed huge amounts of data about all citizens, and adversary nations are leveraging this data to manipulate the nation, including by helping elect a president who will be friendlier towards them.

Facebook is Russia's biggest cyberweapon. Just as private companies would not be allowed to stockpile WMDs, private companies should not be allowed to stockpile so much digital information either. This is a national security issue.

Post reply on HN