Live data from Hacker News

Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

bloomberg.com

61–70 of 105 posts

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#61
post #52

Earlier quoted context omitted.

Can we please stop calling these privacy violations bugs? It sounds like a benign thing. These are not bugs anymore. It's unauthorized access to records of millions, and Facebook is the one who performed the violation. I can give a dog walker or cleaning personel the keys to my apartment, still if they steal stuff and I have evidence they will be prosecuted. It's not a bug that they don't have business ethics.

So a hacker took all of Equifax's data including your SSNs, address, names, DOB etc. By your analogy, all of Equifax engineers should be in jail right now! BTW, just in case you are unaware, Equifax got away with this hack with zero fines in US.

Your are mixing things up.... In this situation the hacker is Facebook.

Most of the other Facebook data breaches where they didn't secure data accordingly would compare more to what you refer to.

This case is different though as Facebook performed unauthorized actions on email accounts, basically breaking in.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#62

So this relates to their practice of ransacking all your email contacts without your consent, engaging in data theft as they upload them and analyze them for subsequent actions. And of course Linked In is also notorious for engaging in this criminal vile privacy raping practice. I remember maybe 8 years ago it was here on HN that a company was found to be doing this and it was shocking to some. But an executive of th…

LinkedIn is notorious for this. The app still asks for contact access all the time.

Off topic, but I have to ask - what do you use the app for? In my head LinkedIn is a 'work' thing so I only use it on my laptop.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#63
post #32

Earlier quoted context omitted.

You know someday when we have consumer protection laws for things like this, a company will be forced to trace every piece of derived data on a user based off of what was unlawfully collected - and provably delete it. Instead of simply paying a fine and moving along with the new insights they have on you. Like an entrance fee to the club. Sidenote: I bet you could make a business out of tracing derived data to comply…

It’ll be very hard because it can be impossible to trace a model back to it’s constituent data, especially if it’s ephemeral

One way is to make sure the provenance is known from source tuples to all the way to the model version, and (eventually) retrain the model when any records upstream of it are deleted.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#64
post #32

Earlier quoted context omitted.

You know someday when we have consumer protection laws for things like this, a company will be forced to trace every piece of derived data on a user based off of what was unlawfully collected - and provably delete it. Instead of simply paying a fine and moving along with the new insights they have on you. Like an entrance fee to the club. Sidenote: I bet you could make a business out of tracing derived data to comply…

It’ll be very hard because it can be impossible to trace a model back to it’s constituent data, especially if it’s ephemeral

Well see that's the other thing: "Someday" they'll have to make these connections in case they are legally obligated to erase a data source and it's derivatives.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#65
Why is "we will never ask for your passwords at any time" not a thing anymore? What Facebook did was phishing, basically. With the password Facebook could be doing a lot more rather than just "upload contacts". Imagine those passwords landing (or accidentally leaking) into the hands of third-party services Facebook is working with! On the user end, what happened to "never ever give away your passwords"? I mean, that's why spear-phishing is so successful, because naïve people give away their passwords in the hopes that this darn annoying login-screen goes away.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#66
post #32

Earlier quoted context omitted.

You know someday when we have consumer protection laws for things like this, a company will be forced to trace every piece of derived data on a user based off of what was unlawfully collected - and provably delete it. Instead of simply paying a fine and moving along with the new insights they have on you. Like an entrance fee to the club. Sidenote: I bet you could make a business out of tracing derived data to comply…

It’ll be very hard because it can be impossible to trace a model back to it’s constituent data, especially if it’s ephemeral

Ephemeral is not an option then, isn't it? In face of regulation, some things can't/shouldn't be optimized. It's already the case for more established industries like pharma.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#69
post #63

Earlier quoted context omitted.

It’ll be very hard because it can be impossible to trace a model back to it’s constituent data, especially if it’s ephemeral

One way is to make sure the provenance is known from source tuples to all the way to the model version, and (eventually) retrain the model when any records upstream of it are deleted.

AFAIK Palatir made a business model out of this (i.e. tracking provenance for datasets and models, along with permissions).

(Just hearsay, not affiliated with Palantir in any way)

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#70
post #61

Earlier quoted context omitted.

So a hacker took all of Equifax's data including your SSNs, address, names, DOB etc. By your analogy, all of Equifax engineers should be in jail right now! BTW, just in case you are unaware, Equifax got away with this hack with zero fines in US.

Your are mixing things up.... In this situation the hacker is Facebook. Most of the other Facebook data breaches where they didn't secure data accordingly would compare more to what you refer to. This case is different though as Facebook performed unauthorized actions on email accounts, basically breaking in.

I am making a case for the OP's comment that Facebook may have made a genuine mistake by introducing this bug - like they literally called out in their statement.

A bug is a bug. Whether it allows a hacker to sneak in to steal all your data or whether it allows a company to collect data it wasn't supposed to (as in this case Facebook specifically mentioned that it didn't turn off the feature though it intended to).

Post reply on HN