Live data from Hacker News

Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

bloomberg.com

91–100 of 105 posts

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#91
post #8

Earlier quoted context omitted.

They need to increase the fine substantially for each repeated violation. After a few violations its going to be hard to justify a $50B fine to investors.

Totally agree, at the third time there is really no excuse anymore to not bump this up to maybe even threaten the existence of an organization or it changes its behavior. For FB this is the nth time. I don't even know what n is anymore.

Neither do any of the regulators...

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#92
post #84

Earlier quoted context omitted.

Where is that fundamentally different in other countries for very large (especially domestic) players? Will Germany actually take a swing at Volkswagen? Will Germany try to go after those that defrauded the government with cum-ex-trades? Everybody vs banks regarding the Libor scandal? Sure, they paid some fines, but the fines were far below the damage done, and it appears to still have been a good investment for the…

I was referring to the fact that you can outpay your opponent. Yes, large corporations can get away with much more in other countries as well, but rarely by outpaying their opponents.

Disagree. The money is very important to creating and maintaining the position they sit in.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#93

I'm glad the attorney general is getting involved. We need to start charging Facebook execs for these flagrant privacy violations. They're being fined 3 billion dollars for legal expenses relating to an FTC inquiry… and their stock price went up by 8% [1]. The market just does not care; it's time regulators and law enforcement started to. [1] https://www.barrons.com/articles/facebook-stock-is-up-becaus...

No matter how the market reacts 3 billions is still 3 billion. People need to stop trying to look for justice in the market trends, investors are not pricing facebook based on how much cash they have in the vault right this instance, and if a verdict comes in below expectations the price is bound to rise.

Could you imagine the absurdity of them passing down a verdict of “and they shall be fined a billion per month until their stock price falls by at least 10%!”

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#94

Earlier quoted context omitted.

Not just execs, I hope. The engineers who wrote the code and managers who told them to do it should also face justice.

That would require all developers to become lawyers so they can make sure everything they are being asked to do is legal.

Are you saying that we can only expect lawyers to follow the law? I have no legal training, yet I manage to avoid breaking the law every day. Why are developers special here?

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#95
post #93

I'm glad the attorney general is getting involved. We need to start charging Facebook execs for these flagrant privacy violations. They're being fined 3 billion dollars for legal expenses relating to an FTC inquiry… and their stock price went up by 8% [1]. The market just does not care; it's time regulators and law enforcement started to. [1] https://www.barrons.com/articles/facebook-stock-is-up-becaus...

No matter how the market reacts 3 billions is still 3 billion. People need to stop trying to look for justice in the market trends, investors are not pricing facebook based on how much cash they have in the vault right this instance, and if a verdict comes in below expectations the price is bound to rise. Could you imagine the absurdity of them passing down a verdict of “and they shall be fined a billion per month un…

I think the point is that we need to punish companies like Facebook in ways that might actually incentivize them to behave differently. If they get slapped with a fine that they can easily pay and then see their stock price go up, what's the point?

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#96
post #93

I'm glad the attorney general is getting involved. We need to start charging Facebook execs for these flagrant privacy violations. They're being fined 3 billion dollars for legal expenses relating to an FTC inquiry… and their stock price went up by 8% [1]. The market just does not care; it's time regulators and law enforcement started to. [1] https://www.barrons.com/articles/facebook-stock-is-up-becaus...

No matter how the market reacts 3 billions is still 3 billion. People need to stop trying to look for justice in the market trends, investors are not pricing facebook based on how much cash they have in the vault right this instance, and if a verdict comes in below expectations the price is bound to rise. Could you imagine the absurdity of them passing down a verdict of “and they shall be fined a billion per month un…

The purpose of the fine is to discourage FB from engaging in illegal and unethical behavior. The problem here is that FB sees a $3B fine as the cost of doing business, since they surely made much, much more than $3B engaging in these invasive, user-hostile tactics. If they know that regulators will only come after them for an arbitrarily low percentage of revenue generated from these activities, why would they stop doing them?

If a punishment no longer deters bad behavior, then it's no longer a punishment.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#97

Why is "we will never ask for your passwords at any time" not a thing anymore? What Facebook did was phishing, basically. With the password Facebook could be doing a lot more rather than just "upload contacts". Imagine those passwords landing (or accidentally leaking) into the hands of third-party services Facebook is working with! On the user end, what happened to "never ever give away your passwords"? I mean, that'…

Asking for passwords has been an industry standard for a decade or more. Bad security practice? Yes IMO but companies have been getting away with it.

Besides Facebook I can think of LinkedIn and Mint as two big examples of SaaS that ask for 3rd party passwords. Mint is even getting your banking information, whereas LinkedIn and Facebook were just doing contact import.

And of course before the era of SaaS giving applications passwords was normal, e.g. putting your email passwords into an email client like Eudora or Thunderbird. It only really becomes questionable in SaaS where the passwords inevitably end up on a server somewhere subject to a data breach, or, in Facebook’s case, misuse by another piece of its own software.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#98
post #36

Earlier quoted context omitted.

> Should a developer be responsible because the cookie banner they implemented wasn't compliant with the laws of 100 countries even though the legal team already told them it was ok? Yes. 100%. "I was just following orders" is not a valid excuse, ever - Nuremberg is the obvious extreme example, but it's true everywhere.

In fact, "I was just following orders" often is a valid excuse. It didn't work at Nuremberg because it was an extreme example. The orders there were to do things that could not even conceivably be legal, so those who carried them out were considered to have knowingly acted illegally. When the orders are to do something that is plausibly legal, and you have good reason to believe that it is in fact so, "I was just fol…

Iff they have confirmation from their product lead that what they're doing is perfectly legal and it isn't obviously illegal, I agree that there's no liability.

If it's either obviously illegal or it's clearly at least dodgy and they didn't get explicit confirmation from the project lead, "following orders" is not a valid excuse.

To take the VW case as an example: if your project lead tells you to implement a way to recognise test conditions and adjust the performance to reduce emissions, that is dodgy af and you should at least get confirmation that this isn't illegal (i.e. that it's not intended to cheat on certifications but maybe just for certain internal testing scenarios). In the end the entire chain of command that led to this being implemented is guilty, but if the person implementing that behavior knew what they were doing was illegal or at least suspect and they didn't get confirmation, they're still guilty.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#99

Earlier quoted context omitted.

What's wrong with introspection about what you're doing on an ethical level? There's no legal standard involved so you don't have to be a lawyer, just a bit more thoughtful.

The law isn't just ethics. Companies have whole legal teams because laws are so complex. Should a developer be responsible because the cookie banner they implemented wasn't compliant with the laws of 100 countries even though the legal team already told them it was ok?

This is a ridiculous example because it equates clearly immoral and possibly illegal actions with legal trivia (because a hypothetical country may simply require a certain wording for compliance and it's trivial to mess that up).

Facebook claims to "value privacy" (and some devs have even told me that they value it "more than any other company") but their actions consistently show either neglect or outright abuse.

Should a developer be punished for implementing something illegal that the legal team signed off on and that wasn't obvious illegal? No, because the legal team is supposed to take the responsibility and if it wasn't obviously illegal the developer had no reason to assume the legal team was lying.

Should a developer be punished for implementing something obviously illegal even when the higher ups say "don't worry about it"? Yes. If your boss tells you to rob a bank, you still go to prison for bank robbery.

For everything in between: whistle blowing is a thing. If you suspect something fishy is going on, document everything, raise concerns and report what is happening.

Also if you are a well-paid employee in a position where you can easily find another job in the industry, speak up to your superiors and refuse to be complicit. Organise.

Re: Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.

#100
post #45

Earlier quoted context omitted.

I didn't like it (which is why they didn't get my damned password), but they were pretty open about what they planned to do with your credentials. The problem isn't how open they are, it's that most people don't understand what the harvesting means. Facebook could have asked for the sacrifice of the firstborn and people would have snapped it up on the prospect of a few likes on their fake online alterego. It's human…

>I didn't like it (which is why they didn't get my damned password), but they were pretty open about what they planned to do with your credentials. From what I read FB had a "bug" where the feature was not removed properly, so the text about harvesting was removed but by "mistake" the harvesting code was left running.

I think what happened was that they had an "import friends from your email contacts" feature in the past and the code was reused for "verify your identity via email" but they didn't realise the code would still also upload the email contacts.

At least that's the story I've heard about why this was an "honest mistake".

Post reply on HN