Live data from Hacker News

50M Facebook profiles harvested for Cambridge Analytica in major data breach

theguardian.com

51–60 of 271 posts

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#51
post #46
post #31

Earlier quoted context omitted.

You could get access to the full friends‘ user profile data in Graph API earlier than v2.0. If you had 500 friends, and granted friends_* OAuth permissions to an app, the app had access to 501 user profiles.

You know where you read this?

At $dayjob-1 we relied on this to pull in your Facebook friends as contacts. Eventually FB limited the scope of this to friends who also had the app.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#52
Let's be realistic here. This headline is nothing but partisanship. The only reason this is exaggerated as a "data breech" is because of the connection to the Trump campaign.

The real scandal is that such data is so easily harvested and freely available.

I'd be interested in seeing how much of facebook's data repository was used in targeted political ads by all parties. Including Russian agitators who have been shown playing both sides.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#53

My problem with this 'outing' of CA is that Facebook explicitly commercially exists to harvest user data for Procter & Gamble, Johnson & Johnson, Fidelity etc etc so they can profile us. A million dollars is chump change in the crazy US election game. This all seems overly selective - it's ok for some people to profile but not for others. I'm not in favor of any of it to be clear but there is a definite political bia…

In recent years America seems to be very eager to compromise. First it did for security after 9/11 and now for right thought after Trump.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#54

Earlier quoted context omitted.

Technically perhaps correct, but for the victims it seems rather irrelevant to me. In a data breach, someone would have used a technical vulnerability or some other (e.g. social engineering) vulnerability of Facebook to get illegitimate access to the data. In this case Facebook simply gave them access to the data and took their word that they won't misuse it. Now maybe the latter situation might not be a data breach…

Facebook isn't the victim here, it's voters who may have been specifically targeted at a "physchographic" level and had their opinions unduly influenced. Further, every person who's a member of a democracy that was targeted by Cambridge Anayltica and is now being run by corrupted politicians (or in the case of Brexit by misinformed voters) is a victim.

Why are you calling it Target by CA? Its such a great advancement in technology.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#55
post #46
post #31

Earlier quoted context omitted.

You could get access to the full friends‘ user profile data in Graph API earlier than v2.0. If you had 500 friends, and granted friends_* OAuth permissions to an app, the app had access to 501 user profiles.

You know where you read this?

it was in TFA, btw

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#56
post #28

I was curious how the figure leaped from the 270k cited in the Facebook press release to this 50M figure. It sounds like they never had full access to the Facebook profiles beyond the 270k who installed the app, but just harvested the friend lists of those 270k. This doesn't give the app developer full access to the friends' profile data, but I guess once you have the network of friend connections you can use other p…

From the very beginning there has been a rule that you were not allowed to persist data more than a few days in your own dB. But it was obvious there was no way for fb to verify what you did or did not keep.

There has never been substantial control on profile data harvest on fb. It was whatever you could get users to okay, which was a lot given the value your app had to appear to provide.

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#58
post #45

Earlier quoted context omitted.

Right. They basically just made an app on FB then had users accept the permissions. The horribly beautiful thing about FB permissions is that almost every single app will request EVERYTHING, and if you deny even a single permission that the app doesn't even seem to need, then the app will break or won't let you use it. So every user is indoctrinated into just clicking accept regardless of the supposed "granular" perm…

As of 4 years ago every app needs to be whitelisted by Facebook for every permission they want to request: https://developers.facebook.com/docs/facebook-login/review/w...

And you can remove individual ones! It was actually far better than the Android model at the time.

Many apps didn't get updated to work with the new API though (most hilariously, the NYT refused to let me create an account without my friend list in early 2015).

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#59

My problem with this 'outing' of CA is that Facebook explicitly commercially exists to harvest user data for Procter & Gamble, Johnson & Johnson, Fidelity etc etc so they can profile us. A million dollars is chump change in the crazy US election game. This all seems overly selective - it's ok for some people to profile but not for others. I'm not in favor of any of it to be clear but there is a definite political bia…

> Facebook explicitly commercially exists to harvest user data for Procter & Gamble, Johnson & Johnson, Fidelity etc etc

Sources on this?

Re: 50M Facebook profiles harvested for Cambridge Analytica in major data breach

#60
post #24

This wasn't a data breach, it was a misuse of data by a third party.

Every single definition I find classifies this as a data breach. > A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so.

But they were authorized to access the data, weren't they? The problem wasn't that they accessed it, it was that they used it for things they weren't allowed to.
Post reply on HN