Live data from Hacker News

Facebook now denying access unless EU users opt-in to tracking

twitter.com

321–330 of 385 posts

Re: Facebook now denying access unless EU users opt-in to tracking

#321

Earlier quoted context omitted.

It is not essential that they sort my feed, though. Everything still works perfectly fine with a simple chronological feed. None of the tracking they do is essential to the service they ostensibly provide to their users, namely as a microblogging/discussion/sharing platform.

I don’t think most users would find value in a product like Facebook or Google without ranking actually. I bet that nobody would! Ranking is what makes these products work...and it requires data to do the ranking.

Why do you think ranking is important? A simple chronological news feed should be perfectly fine.

Sure, rank search results based on how many users a given group has, and put the most popular ones at the top. That doesn't require violating anyone's privacy.

Re: Facebook now denying access unless EU users opt-in to tracking

#322

Earlier quoted context omitted.

I don’t think most users would find value in a product like Facebook or Google without ranking actually. I bet that nobody would! Ranking is what makes these products work...and it requires data to do the ranking.

Why do you think ranking is important? A simple chronological news feed should be perfectly fine. Sure, rank search results based on how many users a given group has, and put the most popular ones at the top. That doesn't require violating anyone's privacy.

Trust me, if ranking had no value...no product team would bother implementing it.

The reason ranking is used left and right these days is because it makes products dramatically better.

Re: Facebook now denying access unless EU users opt-in to tracking

#323
post #309

Earlier quoted context omitted.

Well, first, ads are not the problem, tracking is. Also, they can make money from tracking, but they have to convince people to consent - more like a donation than a payment. But yes, the EU does get involved in plenty of business decisions, just like governments everywhere. Usually when an industry is misbehaving and violating what is established (e.g. by the ECHR) as the rights of individuals.

> But yes, the EU does get involved in plenty of business decisions, just like governments everywhere. Obviously. But that's not what I meant. They did not say "tracking is illegal", they said "it's illegal if not necessary". Are they then say: "It's not necessary because if you completely restructured your business you wouldn't need to track." That's the part I meant - do they really go to that level of detail?

[deleted]

Re: Facebook now denying access unless EU users opt-in to tracking

#324

Earlier quoted context omitted.

Do you have a source for that? I watched the both hearings end to end and I only recall shadow profiles being mentioned once, and the answer was "I’m not familiar with that"...

https://www.theverge.com/2018/4/11/17225482/facebook-shadow-...

The content of the article presents no evidence, proof or confirmation from FB that such profiles exist

Re: Facebook now denying access unless EU users opt-in to tracking

#325

Earlier quoted context omitted.

One of the points of the GDPR is that you cannot make usage of your service contingent on giving up your privacy, unless your service very specifically requires the user to give up personal details in order to it to even function. Strava is a good example, it does not work without GPS position, otherwise it cannot track your bike routes. But Facebook does not require tracking to work. It does not require you to give…

I disagree what FB would work fine if you gave it no data or fake data! The whole point of FB is for people to exchange data about themselves with their friends and family! If people don’t share any data or just fake data FB doesn’t work. For them to offer their service they also have to make money, so they run ads to do that. And to make the ads useful to people they need data for targeting! And now they allow users…

Facebook would work perfectly fine with fake data and without privacy violations.

I can sign up with a fake date of birth and a throwaway email account, under a generic name (remove any identifying unique spelling or middle names, for instance) or a completely fake name. And I could still connect with friends and family, provided I know the names they've chosen to use on FB.

According to the GDPR, anything you share publicly is basically fair game. So if you post something in a public post on your public wall, anyone can view and use that data for whatever they want.

The issue is all of the secret data FB collects. They have disturbingly extensive profiles of every one of their users, including political standpoint, which phase of life they're in (eg. "stable established adult" or somesuch), their sexual preferences, sports teams, club memberships, medical history, the list goes on and on. They get this from your non-public account information and from tracking you across websites you visit.

That is the issue here, the tracking and storage of personal information that people want to keep private. FB's tracking and privacy violations are not vital to the service they provide. Their business model may depend on (targeted) ads and privacy violations, but that is not an excuse. You cannot base your business model on breaking laws and hoping to get away with it.

FB isn't "allowing" users to either agree to the ToS or go pound sand, they're basically saying "fuck you, we'll exploit your private information as much as we want, and you don't have a choice". They're doing this to muddy the waters and make people think "oh I already agreed to this, make it go away", when the actual GDPR consent form pops up after the 25th.

But users do have a choice. The GDPR very specifically says that you cannot make access to your service contingent on opting in to private data collection and tracking, because consent has to be given freely, ie. not under threat of access denial.

You can only do this if your service cannot possibly work without the collection of personal data. Something like Strava (which tracks bike rides via GPS) cannot function without collecting GPS locations. So they have a good argument that they cannot provide their service, if users do not opt in to location tracking. But they have to very clearly state what they will use this collected data for, and they cannot change it later without collecting new freely given consent from their users.

Re: Facebook now denying access unless EU users opt-in to tracking

#326
post #262

Earlier quoted context omitted.

American here; I just don't quite understand the premise. "Here is what you are giving us, and here is what you're getting in return" seems perfectly legit to me. If this interpretation of the law is correct, then the government is essentially saying the "in return" portion has to be eliminated. Which seems to be against the idea of trade.

The GDPR effectively outlaws certain business models. "You pay with your data" is one of them.

No, that business model is still perfectly valid, but the users have to give their unequivocal consent for the business to do this, and the user have to give it freely, ie. you cannot say "you have to opt in to giving us all of your personal data, before you are allowed to use Facebook."

Re: Facebook now denying access unless EU users opt-in to tracking

#327
post #101

GDPR doesn't cover enough of the population using Facebook to warrant such a change to their business model where you can use the service without them using your data. They believe they are entrenched enough to just require this (and likely are for many EU residents).

Are you talking with real knowledge of the facts, or is this a guess? Because my guess would be that it would be cheaper to adhere to the rules rather than let a competitor grow big in Europe and eat their market elsewhere.

Its a guess. Facebook also controls many of the "competitors" currently. Its also not about not being compliant, they want their customers, its just not worth reevaluating core aspects of the business when they believe people will sign whatever they have to to continue using Facebook.

Re: Facebook now denying access unless EU users opt-in to tracking

#328
post #309

Earlier quoted context omitted.

Well, first, ads are not the problem, tracking is. Also, they can make money from tracking, but they have to convince people to consent - more like a donation than a payment. But yes, the EU does get involved in plenty of business decisions, just like governments everywhere. Usually when an industry is misbehaving and violating what is established (e.g. by the ECHR) as the rights of individuals.

> But yes, the EU does get involved in plenty of business decisions, just like governments everywhere. Obviously. But that's not what I meant. They did not say "tracking is illegal", they said "it's illegal if not necessary". Are they then say: "It's not necessary because if you completely restructured your business you wouldn't need to track." That's the part I meant - do they really go to that level of detail?

Sorry, I don't really know, my knowledge of EU directives related to companies is sparse at best.

Re: Facebook now denying access unless EU users opt-in to tracking

#329

Earlier quoted context omitted.

Even though you never hear the counterpoint on HN, it’s important to remember that FB’s behaviors are not necessarily objectively bad - people can have different views on these things.

I agree that people can have different views on these things for various reasons. But I don't see how "FB's behaviors are not necessarily objectively bad", unless one considers only the profit motive as prime without giving any thought to other factors. Can you expand on that?

>But I don't see how "FB's behaviors are not necessarily objectively bad", unless one considers only the profit motive as prime without giving any thought to other factors. Can you expand on that?

Anti-Disclaimer: I do not work for Facebook nor have I ever have in the past.

I think the challenge on expanding on that is that you have not made a case for why it is objectively bad. Your posture is one of an assumption that everyone here understands and has the facts that you have. So it is hard to answer your question without knowing what you are thinking.

Additionally, I am wondering why the question is specifically about FB devs, as opposed to Google's? Or frankly, so many other companies who are likely making money in similar ways. Guessing that should include Yelp, LinkedIn, etc (not sure, though). Are we targeting FB merely because they're very effective?

For me, I have said it here and in person before: I do not see a problem so far in what Facebook is doing. I mean, I have quite a lot of personal issues with Facebook, which is why I have never had an account. Over 10 years ago when my friends in college asked why I did not have an account, my response was always "Why would I want a private company to know who my friends are? That is information that is precious." However, that's my personal issue, and my stance is and has always been that if a particular user is OK with Facebook having that information in exchange for their services, there is no ethical/moral dilemma. It is a transaction, and neither party is being coerced. So I have never been in favor of legislation that limits this relationship.

Now it should not be hard to understand that for me, if I've lived a fine life all this time without Facebook, any kind of argument that "not joining Facebook is not a realistic option" will not receive my sympathies.

The basic data collection is fairly transparent: Everything you provide to them (content, contacts, etc) is available to them. No user should be surprised that they utilize this information. It is the default assumption for any online service. If you use your Facebook account to log into other sites, it should be obvious that Facebook has that info. With regards to the more "shadowy" aspects (e.g. cookies tracking you across sites, etc), a point could be made, but honestly none of this is shadowy any more - it's been in the press repeatedly for years. Once again, if the users don't care, I don't see how it can be "objectively bad".

People tend to invoke the user's ignorance: Most users are not tech savvy and cannot be expected to know how all this works - so they cannot reasonably know they are making a bad bargain. I am not sympathetic to this. The reason is that in all the years Facebook has been in existence, I have talked to and educated many average folks about the potential downsides of giving a private company so much information about you. Everyone I spoke to was quite OK with the whole concept. Not one person felt it was problematic. So not only do I not have a reason to think FB is "objectively bad", I cannot even invoke social proof! Whatever bad people keep claiming is coming out of FB is something most of the population does not think is bad.

I have few sympathies for the (very few) people who are whining about it, because their behavior is similar to irresponsible adults who continually make bad decisions and have lives wrecked as a result, and then expect to get bailed out. Like not buying earthquake insurance in an earthquake zone and then demanding compensation when they lose their house.

Facebook did not become what they did by being clever against their users. They got there by working with them. Any discussion of issues about Facebook without implicating the users who happily helped them is biased.

Finally, and perhaps the most controversial part of my comment: Let's not kid ourselves. People are upset about this because it helped Trump more than any real concern about our privacy. Had a more likeable candidate (Obama, etc) used data from CA to help win an election, I would expect a fraction of the coverage this is getting right now. In fact, I think Obama did heavily utilize these services in 2008 and 2012 - just not as effectively as Trump's campaign did. If anything, Trump's campaign was merely more effective.

Re: Facebook now denying access unless EU users opt-in to tracking

#330

Earlier quoted context omitted.

The GDPR talks about "executing a contract, which includes the provision of services" (not the exact wording, but something like that). So if you define "using the social network in return for having targeted ads displayed" as the contract, it is necessary. > just that not every avenue of funding is allowed Funding by targeted ads isn't illegal last time I checked.

Performance of the contract does not mean whatever they want it to mean. Here's the ICO FAQ on the GDPR (emphasis mine): "The processing must be necessary to deliver your side of the contract with this particular person. If the processing is only necessary to maintain your business model more generally, this lawful basis will not apply and you should consider another lawful basis, such as legitimate interests." https…

What does "freely given" mean in this context? Is GDPR forcing me to give access to my service for free if my business model is targeted ads?
Post reply on HN