Unethical Growth Hacking from YayView
lord.io
lord.io
Us in the tech world need to be honest, we're bad at privacy.
It's a little bit like if people had trouble using forks without stabbing themselves, and the proposed solution was to ban all forks in the country. Well perhaps more work should go towards teaching people how to use a fork, since they can be useful for meals, rather than banning them?
Don't get me wrong, it's a shame that companies like YayView exploit dark patterns to trick people into doing things they don't fully understand, but let's not ban all the things because of it.
Your original point was that you gave explicit consent for them to use your data. But you didn't, you accepted they would only use it for the stated reasons given to you. You didn't consent for them to use it for anything else!
Those employees had no choice whether their names were added to this black list. There was no appeal. No due process.
And when a company abuses it's data gathering and mining powers it's unhelpful to blame the user.
There was also (AFAIR) blacklists of suspects IRA terrorists, also in the construction industry. (Many Irish emmigrants to the UK were poor and worked in manual labour jobs like construction.)
Another example of data protection issues and "terrorists"
The problem is that simply using Facebook gives them tons of personal information. They know who your friends are, who you talk to, what articles interest you from what you click, what websites you visit from the embedded Like buttons, and on and on. And this is without adding a single bit of explicit information about yourself to your profile. Facebook probably already knows what school you went to anyway, based on your friends.
But no! Apparently if you blindly connect to other people's servers, send them all of your personal details, ask them to send you effectively whatever they feel like, and then you executive that code indiscriminately, it's on them! Fucking ridiculous.
Platform is on within FB per default AFAIK. Users are exporting their friendslist without permission of their friends and bring it to apps like these. Defaults like these _are_ bad - and don't blame Europe for it.
I think you're on to something with this statement.
I'd feel much better if selling/transferring customer data was disallowed with explicit consent from the user for each company the data will be transferred to.
[] I consent to Facebook storing and using my personal data
[] I consent to Facebook transferring/selling my personal data to people and companies I add to my "friends list"
[ ] I consent to Facebook transferring/selling my personal data to Ad Tracker Network Inc
[ ] I consent to Facebook transferring/selling my personal data to User Data Broker Limited
With personal data being broadly defined to include anything that could correlate activity with an individual user (tracking ID, session cookie ID, name, location, etc).
I think the average person's understanding of how much they're being tracked would drastically improve if they seen this list of (opt-in) checkboxes when signing up to services.
Let's be honest, shadily sneaking people into giving personal data (like YayView) is not "freely given consent". Facebook doesn't tell you that the FBI/NSA can spy on your data, so it's not unambiguously given consent.
From the article -> "View scans your Facebook friends and creates fake profiles for them."
Having a profile created, that others can edit, and you've never interacted with the app or company? That doesn't sound the least bit like consent. Closer to social rape.
Can I create an investor app, with fake profiles for all the leading investors, including some of whom invested in this company? I'm pretty sure lawsuits would fly. Although most consumers lack the resources of the investor class, they deserve protection to.
Well, that is one of the main jobs of a government in the first place. Companies will always try to exploit you as much as they're allowed to, and governments have the responsibility to make sure they aren't allowed to do that too much. European governments are doing their jobs.
And maybe forks would be banned if they were constructed in a way to make it extremely difficult to use, even for experts, without stabbing yourself? I'm thinking of a fork with some sort of magnetic pull, either towards the plate or towards your own forehead, so you can chose whether it tries to stick to the plate (making food not come to your mouth) or switch to the forehead pull and try to steer it into your mouth without stabbing yourself. That IMHO would be a more adequate comparison to what these dark-pattern infused sites/apps are doing.
To find the app, search for these keywords:
view meet your classmates
A possible connection to an app called Highlight is further indicated by the fact that the AWS landing page for the View app contains the string highlig.ht.Any App Store user can report a problem with an app by first downloading the app (no need to actually run it, and it can't do any damage without being run), then visiting https://reportaproblem.apple.com and signing in. The app will appear at the top of the list of downloaded apps, and next to the app is a "Report a Problem" button.
How sure about this are you?
Some common apps like Hangout and Facebook misuse iOS features to run in the background despite Background App Refresh is turned off, AFAIK.
The only one I'm aware of is marking the app as a VoIP app, which means the system will keep it alive and let it occasionally check in with the mothership. But Apple heavily scrutinized apps marked as such to make sure they actually need it. And even then, I don't think they run until the user starts them at least once.
Even if the app could automatically run on download, it couldn't access any interesting information without being activated by the user and prompting to allow access to location, contacts, photos, etc.
Also, this is the reason why you should have FB platform a) turned off and b) disallow that your friends "bring your data with them when they use apps".
1) Click the down arrow (▼) in the top right, then go to 'Settings'.
2) Click 'Apps' in the bar on the left side.
3) Click 'Edit' under 'Apps, Websites, and Plugins' then 'Turn Off'
4) Click 'Edit' under 'Apps Others Use' and uncheck everything, then 'Save'.I thought the Facebook API does not allow pulling the complete friends list anymore. i.e. it excludes those friends that do not already have the corresponding Facebook app installed, precisely to stop this tactic?
https://developers.facebook.com/docs/graph-api/reference/fri...
Edit: I did a quick test and at looks like I can see the friend list of many users that is not in my immediate network as long as I am logged in to Facebook. It should then be easy to use something like Perls WWW::Mecanize to make a scraper that log inn and scrapes the profiles you want, as long as one do not need so many that Facebook detects and banns you.
I have looked around on Facebook and it looks like one can see other users friend list, even if you are not in their immediate network.
Even if Facebook has a limitation, like you can only see the friend list of friends of friends the company behind this app could probably make some fake Facebook users and befriends someone on each university to get an ok coverage.
I'd argue that this is another case which shows that the privacy scaremongering isn't scaremongering, but the privacy issues are real.
For me, half of the Facebook's utility was the ability to check people out without having to commit to a relation with them first. A publishing platform, a little bit like personal pages of old, but much more streamlined and accessible to the mainstream. But it turned out there's enough bad actors around (stalkers, marketers) that people voted against this, and so Facebook is now a very locked down place. I think most of those fears people have are overblown, but well, that's only my opinion and it seems that most people disagree.
It's not the first time I will rant about this, but why use the word 'hacking' here?
YayView sort of exploited the system by automatically creating users from freely available data on the social networks, but is it 'hacking' per se? I think that YayView is not a hacker company, and just a startup using very unethical business tactics.
IMHO, term `hacking` is used everywhere to raise `click-bait-itness`, no matter it fits there or not.
</rant>
exactly. There is business development, though if there is a article which title has 'developer' in it, it does mean `a software developer` mostly, unless you read a particular business development article.
Though `growth hacking`, personally, I think is made up buzzword, for some managers to feel good and cool, that they are like the hacker from 90s. Startup growth falls under `business development and management` in my head, not under `(growth) hacking`.
I don't think being an unsophisticated asshole and a hacker are mutually exclusive. Plenty of hacking is unsophisticated and most people are assholes, hacker or otherwise.
and plenty of hackers aren't programmers. In Eric Raymond's definition of a hacker http://www.catb.org/esr/faqs/hacker-howto.html it states:
"There is a community, a shared culture, of expert programmers and networking wizards that traces its history back through decades to the first time-sharing minicomputers and the earliest ARPAnet experiments. The members of this culture originated the term ‘hacker’. Hackers built the Internet. Hackers made the Unix operating system what it is today. Hackers make the World Wide Web work. If you are part of this culture, if you have contributed to it and other people in it know who you are and call you a hacker, you're a hacker."
I mention this because Merriam-Webster's definition on the other hand is somewhat flawed:
1: one that hacks
2: a person who is inexperienced or unskilled at a particular activity <a tennis hacker>
3: an expert at programming and solving problems with a computer
4: a person who illegally gains access to and sometimes tampers with information in a computer system
In particular, #3 doesn't mention hackers that aren't experts in programming but might solve problems with hardware/networking. A better #3 definition would be: "A person that computer programming, computer networking, or other technology at an expert level to come up with an innovative solution."
"-er" is a suffix used to turn verbs in to nouns. A kicker is one who kicks, a stabber is one who stabs, a hacker is one who hacks. While you can certainly create a stereotype of the general "stabber", it shouldn't and doesn't really come in to whether or not a specific act was a stab. If most people who stab others are large, hooded men, but a petite, bow tie in hair girl thrusts a knife through someones torso, she stabbed them. Talking about the incident? She was the stabber. She does it regularly enough for it to be part of her general description as a person? She is a stabber.
Now, seeing as two very common definitions of the word hack are:
A: to cut or sever with repeated irregular or unskillful blows
B : to cut or shape by or as if by crude or ruthless strokes <hacking out new election districts>
it seems both odd to take people whose relationship with programming could be describe this way and not call them a hacker, and to call people who program out of a love of freedom and voluntary mutual help hackers. How the hell do freedom and voluntary mutual help relate to the word "hack" at all other than just by correlation?
People who made programs in a non-professional environment were and are more likely to hack together their programs. This group of people historically has had some values as mentioned in your article there. But to say those values are now the requirements or the defining characteristics of the term? Ridiculous.
Most people who bowl do it for the fun of it. If bowling suddenly becomes a lucrative sport and I take it up simply to chase the money and don't intrinsically care for rolling a ball at some pins, am I not a bowler? One who is partaking in bowling? Who goes to the bowling club to bowl?
He is an authority on hacking and jargon: https://en.wikipedia.org/wiki/Eric_S._Raymond
In summary: every programmer/developer/software engineer is not a hacker and you don't have to be a software-hacker to be a hacker. If you want to learn the history of the term rather than try to define it, that would be great, rather than just debating it.
Discussion with someone who disagrees requires debate to settle the matter. We apparently disagree. Either debate or remain silent on it.
> Either debate or remain silent on it.
I disagree with you. I provided evidence showing that Eric wrote a dictionary of jargon including the term "hacker". I see no other reason to continue this debate because you obviously cannot click on the link to read what I provided, and I'm not going to take the time to copy and paste every detail here, which I won't force you to read anyway if you don't want to.
I do not have to remain silent, and you just contradicted yourself when you both said that someone had to debate if they disagreed but at the same time had the option to be silent. Did you ever take a class in logic? It would serve you well to study it.
I said it was required to settle the matter. I didn't say the matter had to be settled. Have you studied reading comprehension? It's incredibly useful!
>I provided evidence showing that Eric wrote a dictionary of jargon including the term "hacker".
He wrote something and called it a dictionary. Great! I can do that. Anyone can do that. It's not a credential. It's enough to garner interest, and like I said, I read the entry, but writing something and slapping Dictionary as a heading is hardly evidence of that thing being true. That evidence is what he fails to even try to provide. I have provided a definition of both the word hack and how the suffix -er functions. Neither seem to be in dispute so the idea that there's disagreement over the combination is frankly nuts.
In other words it's marketing without much resources. Nothing much to do with hacking. When you repair your car with a used part or a part from a different model, are you "hacking your car" ?
This word is getting way too much abuse, soon it won't mean anything anymore.
If you follow a popular on-line tutorial for that, then not really.
But if you find yourself with a broken car, and you figure out yourself that you can fix it by duct-taping some otherwise unrelated component into it, and the resulting solution somehow works better than original, then yes. Hacking is about playful cleverness.
Tagged.com did a very similar thing to get users to sign up, and they had to pay over $1 million in fines back in 2009. This in itself may not be a big disincentive for many companies, but the consequences if it is done after a settlement are.
Perhaps, but we all know there is plenty of money to be had for a company that toes the line in terms of legality. "This may be illegal" is not the same as it being so.
It's complex, especially when there are multiple jurisdictions involved, the laws on these subjects tend to vary from place to place. Another complication is that (like many things during dd) this straddles the line between technology on the one side and legal on the other.
If I were to come across it during a dd I'd flag legal to take an in-depth look. (Regardless of it being un-ethical.)
Don't be surprised if to the parties investing this was not a red flag and they invested anyway, also don't be surprised if they simply were ignorant of the matter due to time pressure or unfamiliarity with the territory. Not all investments are done after a full process dd.
The bigger surprise to me is that investors would want to fund a dating site - period. The dating site business is somewhat known for being hard to attract investors because of their churn problem due to losing two customers whenever there is a successful match.
[1] https://www.crunchbase.com/organization/highlight#/entity
"This is never disclosed to the user"
I thought that the Facebook API no longer exposed ANY friend info to apps, without special permission that the user grants! And that permission has to be reviewed by facebook.
But no, as a layman I can't see how this is getting by the CAN-SPAM act. It doesn't give you the option to not send it and sends it anonymously. From the recipient point of view it's just a random unsolicited email. I guess it's one of those it's easier to ask forgiveness than permission things.
My guess is the moment someone with potential legal clout challenges this the invites will be changed to a "Do you want to invite your friend yes/no" system
If I am building a network driven product like a dating app or social network, you better be damn sure that it is going to be using 'growth hacking' (read:scraping) methods to increase the viral coefficient per user.
Would it also be news to you if I told you that 719 singles in your zip code did not, actually, want to see you tonight?
That doesn't make it acceptable.
The people who fund, manage and work for these types of companies should be blacklisted in the industry.
Probably. But it's long exactly because people are not willing to blacklist as much as they should.
The market is under no obligation to respect you. In fact, competitive pressures push everyone towards exploiting you as much as it is possible. So the limit of crap we're being served is the same as what we're willing to endure.
Yes, LinkedIn is well known for essentially spreading itself like a virus with a bunch of interactions unknown to the user and that's exactly why no one should be using it. If I see that someone has a LinkedIn profile it's pretty much a minus nowadays.
Just saying.
I have all @facebook.com email on blacklist on my email server because I get daily spam from Facebook trying to get me to spend more time on the page, even with everything turned off.