Live data from Hacker News

Ex-Facebook insider says covert data harvesting was routine

theguardian.com

351–360 of 418 posts

Re: Ex-Facebook insider says covert data harvesting was routine

#351

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

>This is similar to a HIPAA "breach"

It's not, at all. The FB API was designed to give out this information before it was changed. That means the friend data was not need-to-know like healthcare data.

Re: Ex-Facebook insider says covert data harvesting was routine

#352
post #3

What's utterly horrifying about this whole thing is how the media is acting as if this is some sort of surprise. Like what did you think was happening at a company collecting data about billions of people? Especially at a company that has a CEO who is famous for calling its own users dumb fu * * s? A company that experimented on at risk teens. Like come on. --edit--- Or lordy, didn't expect this comment to blow up th…

> Funny thing is, this would all blow over after a few months, and everyone will go back to the usual habbits.

It can't blow over in the UK or the EU, because it is seriously f-ing illegal in those places.

Yes, we "knew" it was happening before this (hence all the regulatory steps taken that were dismissed as anti-American protectionism), but we were lacking hard evidence, so all we could do was reinforce regulations and regulatory authorities.

Now that shit has leaked, it's simply not an option for those authorities to not act. Not to mention the fact that they really, really want to act.

So no, this will not blow over. Maybe in the US and/or the media, but not where it matters.

Re: Ex-Facebook insider says covert data harvesting was routine

#353

Earlier quoted context omitted.

http://fortune.com/fortune500/list/ There's your list. Seriously. I obviously can't share with you the list of specific clients I work for, but this attitude is pervasive enough that you should assume that any and all major corporations have this same mindset. All of them.

If you "I obviously can't share with you the list of specific clients I work for", then don't immediately precede that with "I can give you an entire list of F500 companies I've worked at that have the same mindset." That was your original claim. Listing the Fortune 500 doesn't actually add anything substantive to the discussion or add evidence to your position (if anything, I doubt you even more now). Do us all a fa…

Oh no! I'm so hurt that you, a random stranger on the internet with no consequence to my life, doubt me now. /s

Believe me or don't believe me, I don't care. I too see the irony in saying "I can provide you a list" and then following it up with "I can't provide you a list", but that's immaterial to the point being made, which you conveniently dodged.

Re: Ex-Facebook insider says covert data harvesting was routine

#354
post #342

Earlier quoted context omitted.

I think ethical guidelines by definition are not enforced per se. They're just that, guidelines. However, as mentioned by GP there are boards of ethics at universities and medical/engineering organizations and such that might be able to dole out a modicum of justice. For instance, not following those guidelines would conceivably end one's membership of the ACM, and many companies have their own ethical guidelines (I…

Exactly. Nothing is done and the code of ethics is not enforced. Let's say I'm a structural engineer or a lawyer and I act legally but unethically: I can be censured by my professional association/college, because law and engineering are professions and thus are self-regulating. Can the same be said of software development? Certainly not. The cult of the amateur, self-taught basement coder and the entirety of startup…

Professional ethics aside, how about plain old personal ethics? Do programmers have a higher incidence of unethical behavior in general than the rest of the population? I agree with you that it seems like there could be a more rigorous professional standard for enforcing ethics in coding/CS, but I like playing devil's advocate.

Re: Ex-Facebook insider says covert data harvesting was routine

#355

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

Was this a security breach in the sense that the company with the data got “hacked”? No. Was this a breach in trust to Facebook users? I think undoubtedly yes. And was there a breach of a the Terms of Service by companies taking all this data and using it for non-academic purposes? Yes there was. So the type of breach seems to be a worthwhile distinction to make.

> And was there a breach of a the Terms of Service by companies taking all this data and using it for non-academic purposes? Yes there was.

There's a legal concept of 'waiver' meaning that even if something is prohibited in a contract, but the parties don't enforce that part, then that part is later not enforceable. Facebook was fully aware of this behavior, chose not to enforce the ToS, and therefore it waived that clause. Therefore no breach.

Re: Ex-Facebook insider says covert data harvesting was routine

#356
post #262

Earlier quoted context omitted.

I think the trust is a new thing though, new to the social media age. I remember growing up with computers in the 90's and people I knew wouldn't even consider entering a credit card number on a website. Now we give them freely. People used anonymous handles on AIM. At some point this changed and people decided they could be themselves on the internet, which is a fine idea, but the trust just went too far.

Exactly. Another example is applications "phoning home" (desltop applications sending information back to the server) that not that much ago was considered a serious abuse. And people on forums would lambast you when you asked how to implement something like that. Now it's called telemetry and is the norm.

Indeed, I remember the backslash ZoneAlarm got for this. Lots of people changed to another firewall as a consequence.

Re: Ex-Facebook insider says covert data harvesting was routine

#357
post #290

Earlier quoted context omitted.

The first sentence from your link: "A data breach is the intentional or unintentional release of secure or private/confidential information to an untrusted environment." Sounds like exactly what happened with CA and FB. People came for friends and fun personality tests, their information got into the hands of a propaganda machine. Definitely a breach. As for the examples, do you want me to edit the Wikipedia article…

Based on many of the comments in this thread I don't see how you could say it "sounds like exactly what happened with CA and FB." Debatable maybe. Clear cut, obviously not. And as for your glib comment on editing the wiki article, you should read more carefully what I said. My argument was that the numerous examples of a breach in that wiki do not fit the CA/FB incident. Adding the incident to the list would do nothi…

The definition from the Wikipedia article certainly does match this incident.

The comments on this thread aren't generally dealing with the question of the applicability of that definition so brining that up doesn't help you.

I guess you're really trying to get at is that you disagree with that definition. That's fine. But it's a very weak argument to appeal to an authority and then disregard the authority where it contradicts your position.

Maybe you need to edit the Wikipedia article ;)

BTW, not sure if this is the part you don't like, but the distinction between intentional and unintentional is tricky. For one, we'd have to pin down whose intentions we're talking about (the people controlling the data store that has been breached, or the people's whose private information has been taken). Then, peer into the minds of people we don't know or, worse, try to determine intention for a corporate entity. If intent is part of the definition of a breach then it would demand a lot of assumptions to be applied (or some kind of long, expensive process like an investigation and trial).

In the end, the impact on the people's whose private information was taken is the same: their private information has been taken, en mass, without their permission, by someone they don't know, for purposes they don't know.

Re: Ex-Facebook insider says covert data harvesting was routine

#358

the platform was designed to entice and integrate into every aspect of people's lives and then ENCOURAGED you to get your friends to participate by inviting them to the platform. it was a data harvesting, advertising mongrel from the start and everyone KNEW it, but no one cared. like all things in life... people cry foul when things come back to bite them in ass. like i said yesterday in a comment... delete ALL forms…

Would you not consider HN Social Media? I personally don't think it's the same as FB, but there are some strong similarities. Maybe "Social News" is a better term?

Where do you draw the line for Social Media?

Re: Ex-Facebook insider says covert data harvesting was routine

#360

Can we not let this become framed as a "breach"? No systems were compromised. Nothing of Facebook's was accessed that wasn't supposed to be accessed. This was data intentionally exposed by Facebook , just exfiltrated and given to an entity whom Facebook hadn't authorized. This is simply the extent to which we've permitted these Internet giants to collect information about us. It's business as usual. Edit: To clarify,…

> Can we not let this become framed as a "breach"? No > systems were compromised. Nothing of Facebook's was > accessed that wasn't supposed to be accessed. This was > data intentionally exposed by Facebook, just exfiltrated > and given to an entity whom Facebook hadn't authorized. This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was acces…

> This is similar to a HIPAA "breach" where the word doesn't imply that a security system was compromised, but that protected data was accessed by folks who shouldn't have had it. In this context, framing it as a breach is perfectly accurate.

Data breach is a compound noun with a very specific meaning in information security. It means that the data was protected, and a malicious entity defeated the protections.

Breach of contract, breach of trust, physical breaching of the hull of a ship, etc. are all different usages of the word breach, but it's not a data breach unless someone accessed a protected system without or exceeding authorization as defined by the CFAA.

Post reply on HN