I wish quite badly that the benefit of deactivating FB would outweigh the inconvenience, but FB has become such a mainstay that I'd lose touch with lots of people I really have no other way of contacting. I could say "good riddance," if there is no other way to contact them then perhaps they are not important enough to my life, but that's just not true. Or what about all the local forums (FB groups) in my city that h…
Facebook’s Surveillance Machine
71–80 of 240 posts
Re: Facebook’s Surveillance Machine
#72Maybe i am misunderstanding something about this whole issue, but was there an exploit or a bug that allowed this to happen on Facebooks end? I guess my confusion is that whenever someone grants third party access to your facebook, you can query that users list of friends (which i have seen used for things like games and high scores, etc). But you didn't get the full friends profile, instead you got a small subset of…
I don’t think there was any exploit. My understanding is that a third-party app asked for access, and people gave consent, and CA mined data. I’m the last person you’d see defending FB, but this just seems like the same thing everyone has been doing on FB as a platform since FarmVille launched years ago?
Did people consent to use their data to be mined for a political campaign? Currently, consents are meaningless and vaguely worded that can include anything under the sun. Sooner or later, we are going to go the "Informed Consent" way [0].
Re: Facebook’s Surveillance Machine
#73It's interesting that we have 2 big scandals in tech right now: one with Uber's self-driving car killing a pedestrian, and the other with Facebook revealing too much data about users and their friends to third-party apps. With Uber, we're asking for data (telemetry leading up to the accident) to be recorded and access to be more open. With Facebook, we're asking for access to be more closed; ironic that we usually cr…
Re: Facebook’s Surveillance Machine
#74Earlier quoted context omitted.
I don’t think there was any exploit. My understanding is that a third-party app asked for access, and people gave consent, and CA mined data. I’m the last person you’d see defending FB, but this just seems like the same thing everyone has been doing on FB as a platform since FarmVille launched years ago?
A major part of Facebook's culpability here is that they knew for 2 years that tens of millions of their users were being profiled as part of a political propaganda war on their platform and their response was practically nothing. Edit: FB also knew the data was collected under an academic license and was being processed, outside that license, for financial gain.
According to the article only ~200k people installed the app and consented. Unless there was an exploit, you get a minimal version of the data in their friend list (user id, name, that is all i really see) not a full profile. So didn't they only really get the names of 49.8 million people?
Is the solution to just not allow allow a third party token to access a friend list, and only your personal information?
I am not trying to defend what is going on, i am just struggling to see how they were able to use the extremely minimal amount of information the friend list api returns to make a full profile on 50 million people.
Re: Facebook’s Surveillance Machine
#75Earlier quoted context omitted.
Sure, there's no way to know. But it is possible to distribute trust across multiple VPN services, such that none of them alone can compromise you. You just nest one VPN inside another. It's easy using VMs. Most simply, connect to one VPN provider in the host machine, and to another in a VM. Using pfSense VMs as VPN gateways, you can chain more deeply. It's the same idea that's behind Tor using three-relay circuits.…
Do you realise that this kind of behaviour will make you automatically a suspect? Remember, is not the data that you transfer, but the metadata of it which is always visible. Maintain appearance of normal, but block just what is doing really harm, like advertising and certain cookies. And don't post anything personal online. Use firefox on private window.
And what metadata? All Mirimir metadata points to the final VPN service. I'm sure that resourceful TLAs could use traffic analysis, and walk either way through the VPN chain. But I can't imagine that I'm that interesting. And indeed, I doubt that they'd find much to prosecute. I mean, all that Mirimir does is write about this stuff, mainly here and on Wilders Security Forums. And occasional stuff that's published by IVPN.
Other personas do more iffy stuff, such as seeing how well Freenet nodes worked as Tor onion services. Freenet being sadly loaded with CP. But those personas used different nested VPN chains, and then Whonix for Tor. So they're not related to either Mirimir or my meatspace identity.
Also, there are no overlaps in interests or Internet activity between Mirimir and my meatspace identity. In communications as my meatspace identity, I rarely use English. Not with family, friends or clients. Occasionally in work-related stuff, but never in social media. So there's not much basis for stylometry.
Finally, I must say the the setup is extremely easy to use. I have VPN client in the host machine, plus several pfSense VMsxas VPN gateways, which can easily be arranged and rearrabged in nested chains. I introduce new middle VMs occasionally, but generally don't change the entry and exit very often. Just update VBox and the VMs periodically.
Re: Facebook’s Surveillance Machine
#76Seeking advice: how do I tell friends and family about the negative aspects of Facebook without coming across as all “I don’t even own a TV” or “meat is murder”? Is that even possible?
It's not only Facebook though. If you look for a restaurant at Google it will show you a link to that restaurant's website, opening hours, etc. but also: how popular the place is at any time, and how much time people spend there. All thanks to tracking phones. In case of Google you can disable that in the phone's settings (and trust that opt-out works), but you can't really do that with your phone operator. Or with t…
For those friends, I ask them if they can just carry this nickle of mine for me, it will track them and Ill know where they are if I need them. They all refuse to be tracked by me.
Then I ask them if they want a raspberry pi or a router from me, with ads blocked and personal access to my virtual private network with access to all my movies music etc, but dont worry of course _I_ will see every domain-name your computers lookup, Ill even warn you, friend, if I notice bad-name lookups, and I pinky promise not to remotely access the router.
They all act like I am a creep and refuse. But, google, an entity they dont even know or have a relationship with - thats fine to let them into their house and know what time they watch porn and how long.
When the surveillence is put into context like this, it usually works, friends smirk and think one more time.
Re: Facebook’s Surveillance Machine
#77I wish quite badly that the benefit of deactivating FB would outweigh the inconvenience, but FB has become such a mainstay that I'd lose touch with lots of people I really have no other way of contacting. I could say "good riddance," if there is no other way to contact them then perhaps they are not important enough to my life, but that's just not true. Or what about all the local forums (FB groups) in my city that h…
I can still contact people (just have to open my computer) and read FB groups. But I don't really post to FB anymore and don't browse the feed at all.
And I don't feel like I am missing anything. (YMMV)
Re: Facebook’s Surveillance Machine
#78> Facebook makes money, in other words, by profiling us and then selling our attention to advertisers, political actors and others. These are Facebook’s true customers, whom it works hard to please. And you just figured this out now? This is like saying "wow, who knew we would get so fat by feeding only on pizza, hamburgers and coke, aren't those companies evil". Well, yes, companies are evil. They don't work for you…
Re: Facebook’s Surveillance Machine
#79I may be wrong - please correct me if I am - but I'm pretty sure that's illegal?
Re: Facebook’s Surveillance Machine
#80Earlier quoted context omitted.
A major part of Facebook's culpability here is that they knew for 2 years that tens of millions of their users were being profiled as part of a political propaganda war on their platform and their response was practically nothing. Edit: FB also knew the data was collected under an academic license and was being processed, outside that license, for financial gain.
I guess my question is from a security standpoint, how do you prevent something like this if you were facebook? Do you ask any company who does a huge number of API requests requesting peoples friends lists? To verify how they are using the data? How do you actually confirm they are doing what they said? According to the article only ~200k people installed the app and consented. Unless there was an exploit, you get a…
> What the email correspondence between Cambridge Analytica employees and Kogan shows is that Kogan had collected millions of profiles in a matter of weeks. But neither Wylie nor anyone else at Cambridge Analytica had checked that it was legal. It certainly wasn’t authorised. Kogan did have permission to pull Facebook data, but for academic purposes only. What’s more, under British data protection laws, it’s illegal for personal data to be sold to a third party without consent.
> “Facebook could see it was happening,” says Wylie. “Their security protocols were triggered because Kogan’s apps were pulling this enormous amount of data, but apparently Kogan told them it was for academic use. So they were like, ‘Fine’.”
https://www.theguardian.com/news/2018/mar/17/data-war-whistl...