Is Facebook eavesdropping on phone conversations?
news10.com
news10.com
This is one of those tech urban legends that keeps popping up. Facebook does have an opt-in feature that can identify what music, tv show or movie you are listening to or watching, but that's it.
http://newsroom.fb.com/news/2014/05/a-new-optional-way-to-sh...
[0] https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headline...
If they are on android, I tell them to open their system settings and show them how Google Search has just about every privilege on your phone and has had it since they turned it on.
Even if people are concerned they still don't stop using Facebook or android. :/
And it's not just the Facebook apps. The Facebook SDK is widely embedded into many other apps Facebook SDK (it's the most popular SDK on iOS for example, according to data published from Cocoapods - https://gist.github.com/ryanolsonk/e33bf9e89677da9fe8ce ). It's so popular because Facebook is basically the most effective network to run so called "App Install Ads" and embedding their SDK providers marketers essential data for tuning their targeting and ad spend.
The SDK gives Facebook access to a ton of additional usage data which they can link together with anything they already have on your from their apps. It also _potentially_ gives them the ability to exploit any permissions given to the host app which embedded the SDK. Now they publish the source of the SDK openly ( https://github.com/facebook/facebook-ios-sdk ) but it certainly would harm anyone if there was more independent scrutiny given to analysing the source and whether there's anything else we're not seeing that go into the final SDK downloads.
Is it a net gain for society if they're more wary, even if this particular instance is wrong?
IIRC they also started off saying it was all algorithmic.
Their investigation found "no evidence of systematic political bias." So, not sure where the very dishonest statement is here.
I think the point is that a casual observer would not have guessed trending tropics were so influenced by human intervention, and might have taken them to be an actual reflection of the Facebook hivemind. Further the statement of "no evidence of systematic political bias" is a bit hard to swallow given reports of Facebook employees asking "what Facebook can do to stop Donald Trump" at their all-hands (one of the top 5 questions in a poll [0] not just a lone employee walking up to the microphone). Further, the people curating these feeds are probably underpaid and young, and hence are probably going to skew left of the average journalist. Bias doesn't have to be explicit to be systematic.
Anyway I find Donald Trump + much of the rest of the GOP field pretty reprehensible politics-wise, Facebook seems to be handling things well [1], and we shouldn't worry about a conflict of interest as much as w/ advertising+privacy [2], but some amount of vigilance seems wise given how much influence these platforms can have over political outcomes [3]. Twitter in particular seems to have made a few fairly illiberal moves lately from my POV.
[0] http://gizmodo.com/facebook-employees-asked-mark-zuckerberg-...
[1] https://medium.com/@glennbeck/what-disturbed-me-about-the-fa...
[2] One shouldn't discount the H1B angle completely though.
[3] http://www.politico.com/magazine/story/2015/08/how-google-co...
One was shut down almost immediately, one was still up when the video was posted.
Won't name them as I don't want to drag politics into HN but I am fairly convinced it is repeatable (and if anyone is interested in giving it a try I can try to dig out a reference and post.)
If moderation is done by humans, you could simply prove that one moderator had a worse morning than the other, or that through luck of the draw Group A went to a sympathetic moderator while group B did not. That could demonstrate individual bias, but not institutional.
If moderation is automated, how do you control for the weight of keywords, phrases, etc? Maybe Group A was full of statements that almost threw a flag but not quite, while Group B contained mostly innocuous wording but (only) one phrase that actually got flagged.
If both groups were designed to be unpleasant, but various "blacklist" words and phrases are weighted differently, Group A might have achieved "flagged" weight while group Group B was "flagged -1." One might have scored 99 pts vs 100 for the other, but the visible difference is that one remains visible while the other does not.
Thinking out loud, now... let's say that Facebook does have a political bias. How do you prove that Facebook's financial success is despite that political bias, and not because of it?
Is it possible to have a monopoly on digital socialization? If you can't declare Facebook a monopoly, and therefore subject to greater regulation, then your only lever over Facebook is social pressure, presumably in the form of bad press and boycotts, which will reduce their advertising revenue. How do you prove that the existing political bias is leading them to sub-optimal revenues?
Couple of months since I saw this, so can't say for sure but I think a major point of the experiment was that the two "hate groups" were equal except which ethnic group they were directed at.
Or they will explain how it was "a rogue employee" who put the code there undetected, and caused it to spread to millions of devices.
I think if Facebook say they aren't doing this, then they aren't doing it.
No. Denying is the only smart move here.
One of the urban legends was also that USA government agencies don't collect data at bulk and they were lying about it. We know the truth now.
Facebook has been caught with the hand in the cookie jar too many times already and got away with it. Fuck Facebook.
I'd like to add "and will not do it in the future"
Definitely the corporate culture wouldn't allow anything like this. Believe it or not, many FB engineers have some kind of free software / civil liberties background in their past, and most people don't seem to realize that A) they have options, they can and would walk out if they witnessed anything shady B) the company has enough fake scandals wound up by the press as it is, to risk doing something genuinely evil for short term gain, and have a former employee eventually blow the whistle on.
One controversy after the other, during my time at Facebook I witnessed the chasm between the mostly innocent motivations behind a product feature, and what the press / outside world made of it. This experience probably taught me as much about media cycles and conspiracy theory dynamics, as it did about engineering.
I can't find it anywhere on Facebook's site. I don't believe it exists, or if it exists it was expunged some time ago. I'd like to know from which website ABC News 10 has located this information!
Genuinely curious as the page he's referred me to seems to document a U.S. only feature you need to specifically turn on when you update your status.
"No, we don't record your conversations. If you choose to turn on this feature, we'll only use your microphone to identify the things you're listening to or watching based on the music and TV matches we're able to identify. If this feature is turned on, it's only active when you're writing a status update."
So, not as bad as the news article suggests, but still extremely creepy.
https://m.facebook.com/help/iphone-app/1499418503612943
Got this from someone else's Google search, apparent it took them less than a minute to find this, their Google-fu is clearly greater than my own :-)
You work for a company with 1000s of employees. How are you exactly in a position to confirm this doesn't happen?
I'm sure a Facebook engineer COULD find out if Facebook is doing this - but just working at Facebook is not sufficient enough to say for certain it does not happen, you need to actually do the required investigation.
---
I don't personally think Facebook is listening in the way suggested here, key word would be _think_ though. And unless you're saying you've audited the code repositories, you're limited to your _opinion_ based on the context you have from working within the company.
You cannot say it doesn't happen with any level of certainty (as you've tried) just because you have access to the code repositories.
There are internal groups where features are discussed and debated all the time, and even all hands Q&A sessions with Zuck (weekly IIRC) where sometimes hard questions are raised.
Someone amongst the many engineers with access to the repo will eventually end up spotting shady code if it exists. They might raise this with a colleague first, or in an internal group, and the matter might even bubble up to the Zuck Q&A if it's intentional and particularly controversial.
This level of internal openness is unusual at this company size, and since there are people joining & leaving all the time (including interns who AFAIK have the same level of access to the code) it would take just ONE disgruntled whistleblower to ignite a scandal that the press will be instantly all over like piranhas smelling blood, this being Facebook.
Therefore, doing evil covertly like you suggest just isn't worth the risk for FB, period. Not happening, won't happen. When you see headlines like "Is Facebook eavesdropping on phone conversations?", Occam's razor is always your best friend.
The same week we were provided documents signed by NSA/CIA officials claiming that Google is not even forced to do it, they provided extra interface for NSA so they can grab data whenever they want: http://www.wired.co.uk/news/archive/2013-06/12/google-prism-...
Some recent emails with Clinton showed that top Google employers helped with surveillance in Arab countries a couple of years ago, more journalists described that Google is in relationship with NSA. http://www.techtimes.com/articles/6610/20140507/google-cahoo...
Facebook was accused of working FOR NSA to spy on Belgium: https://www.theguardian.com/technology/2015/sep/21/facebook-...
One of Facebook financial founders was PayPal CEO who... supports global surveillance by NSA http://www.globalresearch.ca/nsa-and-facebook-work-together/...
Question: why should I trust what you say?
Didn't the NSA hack Google's own internal fiber? Why would they need to do that if they had the keys to the kingdom anyway?
Yes, google started encrypting the intra-datacenter traffic once it learned what the NSA was doing.
This issue was quite hot on HN a month ago.
Google for "Facebook privacy European bug", and choose your preferred outlet (wsj, rt, tnw - I prefer the guardian)
Facebook would need to be collecting all ambient noise, just to identify (listen to) specific sources, no?
That said, this is lazy & irresponsible reporting on what is at best a singlural event.
If it was reproduced, this is clearly a violation of Facebooks terms of service, regardless of if the user has opted to let Facebook listen to the music and TV that's playing in the background.
At least that was the case when the feature came out. I think I read something about android now letting you filter permissions and not blindly accept all that an app asks for?
It's great that you can filter permissions, but when you suddenly can't use basic functionality because the programmers added obligatory geolocation to a feature, then you don't have much choice. Remove the app, or allow it to track you.
The other person may have searched for her on Facebook, causing her to be listed as a possible friend. Or perhaps Facebook uses location data to group people that are in the same location for an extended period of time.
It would be interesting if someone at Facebook could provide some insight into this.
https://play.google.com/store/apps/details?id=com.danvelazco...
TL;DR: people don't know because they aren't savvy, and that isn't their fault. Those of us who do know should do a better job, but no, I have no ideas how either.
[0]: https://www.reddit.com/r/androidapps/comments/3catb0/i_cant_...
Top 3 reasons: removing "crap", backing up crap and real adblocking.
I've had good luck with this on stock roms when you can't uninstall the carrier's apps. Settings » Apps » All » Application Name » Disable
Technically the app is still there, but it can't be launched and doesn't appear in the list of apps.
I think that the mobile site is the lowest priority interface.
Super cute cashier girl. No idea what her name is.
As I'm heading out I open up my news feed and what do you know? There she is in recommended friends. WTF
All my recommended friends come from my iOS Contacts, by phone number. So the fact she popped up is absurd
> They couldn't have known you thought she was attractive
Are you so sure? To me (no ML experience) that seems a somewhat solvable problem if you have a competency in ML and Facebook's data.
Just imagine if Tinder shared data back...
We don't know what we don't know to paraphrase that famous romantic Donald Rumsfeld. Who knows if the person behind you on the rollercoaster or grabbing a taco might be the yin to your yang.
I just wish Waze could tell me who my ideal carpool partners might be.
Since anysz mentioned he has 0 friends, there will be no social graph recommendations. Thus less-confident recommendations will show up, including spending some minutes in the same location as someone. It could then consider other factors—opposite genders, relatively close in age, maybe similar interests.
Creepy.
Disclaimer : I'm a former FB engineer but have no specific knowledge of this area. I suspect that IP addresses could be used as input for the PYMK feature though (in the absence of anything better, as you had 0 friends), as they are for security systems.
It's a suggestion based on factors along a social graph.
If it's right, great! Saved you time from searching, or nudged you to create a stronger communications channel than you previously had (ostensibly).
If it's wrong, you just ignore it.
This is a tiny, tiny good I never wanted that I am receiving in exchange for a massive surveillance apparatus profiling my entire internet life.
Swiftly uninstalled.
Probably the first -- since I, and millions of people, stay with hundreds of people we don't know for the same period of time and more (in bars, airports, workplaces, queues, concerts, shops, etc), and they still are not suggested to us.
Now here's the fun part: My government job has a strict electronic device security policy, and employees are forbidden from carrying cellphones, smart watches, and any other connected devices into the building; I have to leave my phone in the car. So, how does Facebook know that I have new connections with these people? The only thing I can think of is that each of them looked me up on the site after meeting me. Another more insidious thought is that Facebook is using GPS location data to see where I go every morning and depart from every evening and is assuming that it's my new job (Google did this in the past when I had an Android phone and had Google Now enabled, it figured out on its own where my last new job was, but that was a documented "feature").
Either way, Facebook now knows where I work even though I deliberately chose not to tell them.
No. One or two looked you up, and they're connected to all of the others. That's how this works.
I don't use FB on my phone, never have. Hence no location/IP/network data. I have not filled out where I work, but searched the place up once before.
A coworker who wanted to friend me and presumably searched for my name still gets suggested as possible friend a year after I quit the place. We have no possible mutual friends, I have never been on his profile, or searched the names of any of my coworkers.
The only way around this restriction would be using a private API Apple could have provided. Given that Apple has even integrated some aspects of Facebook into iOS, this is not totally impossible, but it's hard to imagine Apple having an incentive in allowing Facebook to passively record and transmit all user audio. To date, Apple actually seem to be pretty good at protecting user's privacy.
When they were found to be tracking GPS positions even with GPS disabled? (Sorry it's impossible to find a link to this anymore)
How about the Bluetooth vulnerabilities their desktop computer suffer -- I've seen keyboard connections trivially hijacked.
I'm not suggesting that Apple has made a deal with Facebook (I think you're right on not being incentivized to do this), but to say Apple is "pretty good" at protecting a user's privacy, I question that.
Let's not hijack this thread to talk about Apple's security record.
For myself I went the extra mile to just have my laptop record ALL audio but then felt this was a little too douchey/NSA-y and disabled the whole thing and wiped the audio. I wanted such a system not only for "You said this then and now you are saying that now" but to remember things I had said myself. I wanted to hook it up to STT to have a searchable archive of what I had said but again it was an invasion of privacy (to people around me) that I personally couldn't stomach.
You'll be happy having the audio even if there are restrictions. Simply don't tell anyone about it until the benefits (saving your ass) outweigh the drawbacks (potential charges).
As for you, there's nothing morally wrong in wanting to not be trapped by a liar. And it doesn't magically become morally wrong if you walk into a two-party state.
Transcribing audio to text
I'm guessing your phone would have to be pretty close to the child though.
For that matter, I'd love the same concept with video, if there was a way to always record what I'm seeing without having to think about it in advance or wear a camera on my face, to capture anything interesting that happens to me, I'd be interested. I remember a story about an exec at Microsoft installing implants in his head for this purpose.
I'm terrified of anyone but me having access to this kind of data, though. It's nobody's business but mine.
Don't know about HeardApp, but I automatically assume the primary use case is for the company's benefit and not mine. Is it installing SilverPush on my phone and listening for things besides me to cross-reference and track my activity? I don't know...
This is by far the biggest problem with this kind of tech. If there were a way to guarantee the privacy of the recordings, it would be a super useful tool. You could basically have a perfect photographic memory. Not to mention all the cool processing you can do with the data. The idea really excites me, but equally terrifies me.
But I think given enough time and progress in encryption/speech recognition/legal issues, I think something like this is inevitable. It's hard to see a future where we record less. I think another key part is having access to data of you. That way you don't feel like it's being recorded to be used "against" you.
Some apps actually use this to work around background activity restrictions. If they can come up with a plausible excuse to run the microphone, they can use that to keep the app active in the background indefinitely.
It does place a really obvious red bar at the top of the screen, though, so it's not something an app can do secretly. I believe only one app can do it at a time, too, so you can't have a bunch of them all spying on you at once.
This is a terrible article. There's an easy way to figure out if it's a coincidence... repeat the experiment.
When it comes to "speaking out"... NSA started surveillance projects long before Edward Snowden was employed. There will always be people who will develop things like this and who will not speak out. It's just a matter of correctly selecting these few people.
Example: my girlfriend was given a box of Flonase by her parents and immediately got a Facebook ad for it. She had not mentioned Flonase anywhere on Facebook ever. Spoopy eavesdropping? No --- she did talk on Facebook about her ENT appointment that morning. And what products might be relevant for someone going to an ENT doctor? Allergy medication.
And in cases like that, it's very likely that your two recommendations from different sources will happen to match --- what brand of medication are your parents likely to recommend? A popular one that spends a lot of $ on advertising. What brand is likely to buy ads? A popular one that spends a lot of $ on advertising.
https://en.wikipedia.org/wiki/List_of_cognitive_biases#Frequ...
An experiment could easily be ran where a new Facebook account is created without any posts or messages, and the Facebook App is installed on a mobile device. Spend a few days using language that is easy to advertise to in proximity of the device, and see what happens.
That may be true, but my friends and I once did this with a made-up phrase about some housewares (think 'pots and pans' or something similar): we repeated the phrase over and over in discussion that evening — and sure enough, an ad popped up on Facebook.
Not gonna install it, just not going to. And I'm beginning to think I should politely ask people who do have it installed to go elsewhere.
However they could do it with Whatsapp. There is no alternative to that.
They say there is good E2E encryption. Great claims require great proof.
Of course, it's not totally trustworthy, because in the end it's still a proprietary app, distributed as a binary blob, connecting to proprietary servers, for which you can't have access to the source code and in spite of any well meaning partnerships, they can always push an update that undoes all of that.
But you know, at this point that's still better and more trustworthy than other mainstream alternatives. So now I have WhatsApp installed.
Then again, Moxie said he himself oversaw the implementation of the encryption and that he has trust in it...
"I was very closely involved for the integration, had full access to the source code, did plenty of review, and have a lot of confidence in the engineers that are maintaining it.
There are plenty of engineers in the world who are capable of inspecting the binaries they're distributing, so it would be incredibly risky of them to inject surveillance code client side."
Is that feasible client-side without burning all your battery?
However, a secondary stream from the app to a different endpoint would be detectable, so there are other practical challenges to the GP's scenario.
[1] https://www.usenix.org/event/usenix10/tech/full_papers/Carro...
It seems that there is a subgenre of geek-oriented clickbaiting, which has a strong claim about something tech-related like AMAZGOOGBOOK with little proof or scientific study. We, as a community, can be better at identifying and pointing out deficiencies in the scientific method, instead of saying ‘I’m not sure they do it, but it would be scary, if they did’.
The story about uber tracking your battery status is legit and has been proven and I don’t remember it climbing as high as no 2 on the front page, so IMO we can readjust our BS-meters.
https://play.google.com/store/apps/details?id=com.nam.fbwrap...
http://bgr.com/2016/02/01/facebook-android-app-battery-life-...
http://www.cnet.com/how-to/improve-iphone-battery-life-delet...
http://www.huffingtonpost.com/entry/facebook-iphone-battery-...
Now is that because of voice? Very unlikely.
Whether it really was a bug or intentional is a subject of debate though.
This had also the effect that when you were listening to music or a podcast and opened the FB app it would stop playing your audio.
Sending audio to Facebook would be so obvious that presumably somebody would have noticed by now.
So that leaves speech-to-text on the phone. However, if that was on "all the time" or even some significant fraction, wouldn't that take an enormous amount of battery power? I'm not sure exactly how much juice on-handset speech-to-text takes but it seems like it would be nontrivial.
On the flip side, I do have to admit that Facebook probably already shows up on the top of most people's CPU and data listings already, but, still, it seems like this could easily be an order of magnitude beyond even that for many people. Surely someone by now would have noticed that they didn't even open Facebook today but it's the top battery draw and/or data user for the day?
Forget whether Facebook wants to do this. I'll take it as read that, duh, yes they do. The question in my mind is can they actually do this without being noticed somewhere other than a local news channel? I mean this question seriously; as you can see above I've already sort of laid out the parameters, so I'd ask that replies here not just "guess" how much juice speech recognition takes, I already did, please tell me if you know. (I can't enforce this request, of course.)
Maybe they aren't listening to the conversations per se, but for an audio beacons in television and radio?
http://www.theatlantic.com/technology/archive/2015/11/your-p...
https://f-droid.org/repository/browse/?fdid=org.indywidualni...
I find it interesting how people accept such things without a question. But I guess articles like these are good even if they're late to the party.
“That is kind of weird,” she laughed. “I’m still not so sure this isn’t just coincidence. I don’t think Facebook is really listening to our conversations.”
Question for the experts: How much battery would it actually drain if the mic was constantly activated and the app was scanning for keywords. I mean, you could limit the scanning to times were someone actually speaks and otherwise remain in a sleep mode. The keywords are then synced only when the user opens the app.
Did anyone ever check if something similar was mentioned in the google now TOS?
[0] https://support.google.com/websearch/answer/6031948?hl=en
Cmon, HNers. You're better than this. This obsesssion with "listening" to what you say is so twentieth century. Metadata beats data anytime. with the surround of information that comes from auth, apps, and FB usage, there's no problem associating people that meet each other, then immediately check FB.
(It's electronic communications, your assumption should be, without a doubt, that someone is listening, seeing, hearing.)
I guess we're just going to ignore the fact that she could have been looking up safaris in Africa the day prior to their little demonstration? At no point do they indicate it was a randomly chosen topic.