Facebook Tries to Make Violations of Terms of Use Into Criminal Violations
eff.org
eff.org
http://wikimediafoundation.org/wiki/Terms_of_Use
Facebook could have scraped Wikipedia without asking, but as it happens, there is an agreement in place. I happen to work at the WMF, but don't ask me for more details, I'm not that privy to them.
This thread might help.
http://www.gossamer-threads.com/lists/wiki/foundation/194087
Their argument is B.S., of course, but I'm peevish about throwing that word around carelessly.
The Contacts API (which FB probably uses today) has different terms, and appears to not conflict with this usage.
So we would need to piece together a timeline. Probably not worth the effort.
...I should get back to work.
Isn't it automated when the Gmail extension to Chrome tells me how many new messages I have, without me logging into gmail.com?
Isn't it automated when emails to my Gmail account are synced automatically to my (non-Google) smartphone?
5.3 You agree not to access (or attempt to access) any of the Services by any means other than through the interface that is provided by Google, unless you have been specifically allowed to do so in a separate agreement with Google. You specifically agree not to access (or attempt to access) any of the Services through any automated means (including use of scripts or web crawlers) and shall ensure that you comply with the instructions set out in any robots.txt file present on the Services.
Second, I imagine both of your examples use some for of API [2], which is clearly "the interface that is provided by Google". On the other hand, if your smartphone were to log into the GMail web-app pretending to be someone using a browser and scrape the HTML, it would, most likely, constitute a violation.
Breathtaking hypocrisy.
Clearly very douchey thought.
I have no idea if they use this for gmail or similar methods for other services.
Right away I was presented with suggestions for people on Facebook that I might know, and they were obviously scraped from my GMail account.
So, as far as I could tell, Facebook got access to my GMail account without ever asking me anything about it.
I'm pretty sure they do save email data of non registered "users" because I was invited to facebook a few times. There was nothing strange on the first invite, but every consecutive invite had other additional friends of mine, who are too "waiting for me" to join.
Actually the one who invited me and "caused" me to join was someone I didn't really know, but met once at an event. This person was extremely unlikely to be friends with any of my real friends.
But still, I got suggestions for my actual friends right away, so I still can't see any other way than for Facebook to actually have had access to my GMail account prior to me joining.
1. Not care?
2. Not see this happening?
3. Not see anything wrong?
4. Can't do anything?
5. Know the "truth," which is substantially different than that being reported?
It seems like one of these ought to be true, and at least in the case of (1-3) should be able to report as much to us.
2) they probably do
3) they probably do
4) that's probably it
5) or even worse!
Likely their influence is limited and if they don't toe the company line they'll be 'between jobs' next week or so.
Speaking out in public against company policy can get your ass canned in some companies pretty quickly.
And some do speak up:
http://www.securecomputing.net.au/News/164539,facebook-emplo...
I think that you forgot to suffix that with "for developers in Silicon Valley." With the high unemployment rates, I presume there are a lot of people that don't have the luxury of tossing a job due to moral/ethical dilemmas.
But I implore all of you at facebook to make your feelings known to your higher-ups (if you feel, like many of the rest of us on HN, that something bad's happening).
These kind of decisions generally only go in one direction, and only early-on can they be stopped.
A lot of what they are doing is, at best, ethically unsound or, at worst, privacy invading. In this case I'd say (from initial reading) it sits on the scale slap bang in the middle of "a douchebag thing to do".
But. It doesn't feel hypocritical because their argument is that their ToS attempt to deny users the right to access their accounts this way. The Email services, as far as I am aware, that FB scrape either explicitly allow or do not disallow such action. It seems "axe grinding" to bring that into the discussion.
Notably this article does not appear to discuss or link to articles about the suit Facebook has filed [meta point: I hate that, it feels sneaky]. It appears (from research) that it is an long running dispute between Power and Facebook. They have also filed Trademark infringements and other stuff against them at the same time (no comment on the general legitimacy of such claims for the moment).
I haven't fully digested all the information to have a complete opinion on this but... I think that this is part of Facebook trying to win the wider battle with Power.com, I'm not sure it reflects a deliberate move by them to try and turn ToS violations into criminal violations. However I am definitely in agreement with the EFF that if a potential side effect of any eventual ruling will bring in such criminal elements then it is a bad thing and should be fought. Hopefully when I can actually open all the PDF filings the picture will be clearer :)
References (I believe this is the suit being referred to):
http://www.niallkennedy.com/blog/2009/01/facebook-vs-power-v...
http://jolt.law.harvard.edu/digest/9th-circuit/facebook-inc-...
http://en.wikipedia.org/wiki/Facebook,_Inc._v._Power_Venture....
EDIT: amusingly TechCrunch seems to have the best summary of things from last year... http://techcrunch.com/2009/07/09/powercom-countersues-facebo...
This will get facebooks attention.
What the EFF are worried about (I've read their submission but the original FB brief is downloading reaaaaly slowly) is that where Facebook are claiming Power have committed a criminal offence in ignoring a cease and desist and accessing peoples accounts (apparently contrary to the ToS) the extension that could come from a favourable ruling is that individuals may be breaking criminal laws too (Cal sec 502(c) in particular).
Clearly that is silly and the EFF are asking the courts to see that.
It's getting a little creepy.
I wasn't aware of anything else specific that was bending the privacy policy to the limit? Anyone care to fill me in on the TL;DR version?
(the social graph, as far as I saw, obeys your privacy settings)
Constantly changing what is private and what is public.
Getting upset at someone using the data that they provide to the public for research purposes.
There is more.
Simply, no. There is no check you can write to facebook to in order to get a particular facebook user's, or set of users', information.
- 3rd parties (app developers, Facebook Connect users, etc.) no longer have a 24hr limit on storing user data
- Open Graph basically means your Facebook info has the potential to be plastered all over the web if you're browsing without being logged out of Facebook
There will be a plenty of both sensible and silly articles targeting Facebook.
Facebook is acting, people are re-acting. It's only natural that facebook should come under some scrutiny, for one they're huge, secondly they behave like a bull in a china shop with respect to other peoples privacy.
You've been a HN member for all of three months and 10 days, I think it is a little early to start accusing people here of being in some kind of conspiracy against facebook.
There also is no conspiracy against apple, google, microsoft or any other big name company or website.
And if you're a FB employee, no disrespect to you. If nothing in these posts are true, consider then what FB might be doing wrong so that these kinds of reactions can fester.
What if I agree to developer Terms of Service that say I can't disseminate users' information, then publish a Identity Theft Target List with information pulled from the Facebook API?
Seems like that should be a criminal violation, even though I "only" violated a TOS.
Having access to Facebook's API makes it practical to scrape massive amounts of data, however.
I agree that it's not so clear-cut. Like a lot of legal matters, intent is also relevant, in addition to the actual effect.
For example, there could be a law saying that anyone who disseminates information they agreed to keep private is guilty of an offense. That would make certain kinds of TOS related to information confidentiality legally enforceable. Of course, Facebook might then themselves be guilty of that offense with their retroactive privacy-policy changes...
Remember that Palin's Yahoo! mail account was hacked because someone figured out the answer to her security questions. Security questions are a dumb idea. Send me a fucking SecureID...
There's probably way to accomplish the same effect without making the aggregated data public. Maybe sharing the results with some news outlet?
I can imagine less effective scenarios. 1) Not changing your life at all. 2) Not touching your Facebook page again. 3) Dressing up in a chicken suit and dancing around a major intersection. etc.
If you delete your Facebook page, it's one less user that Facebook can claim to have; if enough people do it, it could put a dent (however minor) in their bottom line.
And you are not a mass, you are one person. And if your friends are anything like mine, you are not going to convince them to leave. Most people are happy to give up a little privacy, for the ease of keeping in touch with their friends that FB offers.
FB has a critical mass, so it is not as easy as suggesting an alternative.
Sure, convincing a group of people to delete their Facebook accounts is better than just deleting your own, but discouraging people en masse from enacting simple changes also discourages emergent behaviours in the crowd before they even start.
Focusing on and performing little actions distracts from doing the the big things that actually make a noticeable difference.
As people (and I) have said over and over, don't put anything on the net that you don't want to be public.
Well, I haven't put my mother's maiden name up. But the more information about me that's up, the more connections are possible, until someone derives my mother's maiden name (or some other security question). Remember, we don't always get to choose a security question, that's relatively new. Banks, credit agencies, phone company, someone has something about you that's derivable.
Like I said, I don't care if FB changes or not, that's not necessary for me to want to leave, or at least diminish my presence.
How To Delete Your Facebook Account: http://www.facebook.com/group.php?gid=16929680703
Believe it or not, there is a social web beyond Facebook.
Well, actually, as Lauren Weinstein pointed out, the political reaction to Mark Zuckerberg and Facebook's attitude towards privacy and the usual likely overreaction might hurt all Web 2.0 players, good and bad:
"He appears to be unapologetically reveling in taking advantage of many Facebook users' naivete about privacy risks, and shows no signs of backing down."
http://www.nnsquad.org/archives/nnsquad/msg03450.html
So I do have a greater stake in this, but there's not a whole lot that I see that I can do. That won't be true for others of course.
I think it would read something like "The value of a communications network decreases with the square of the amount of people that have left it".
It makes the exceedingly questionable assumption that we value all possible connections equally. Many different approaches to quantifying the value of networks converge on the much more reasonable estimate that value tends towards n log(n) rather than n*n.
See http://spectrum.ieee.org/computing/networks/metcalfes-law-is... for more.
I think everybody realizes that Metcalfe's law is not a 'law' in the sense that it is a given or an absolute, any of those - including Moores law and others like it are to be taken with a grain of salt.
The practical upshot of all this is that if the value of a network goes up with a non-linear factor when the number of participants increases the reverse also holds true. What we call it doesn't really matter and Metcalfe's law will do as good as any other shorthand description that will convey the point.
Thanks for the interesting read by the way, it's nice to see that even if Metcalfe was maybe wrong in the 'absolute' in principle the concept of non-linear value increase seems to hold true.
In an interesting twist, Metcalfe's law comes closest to being true in mediums where existing social relations are less important. For instance eBay is a classic example. If I want to sell, I really do value the network at the size of said network because I have no idea who wants to buy from me. Which is one reason why it is so hard to compete with eBay. (Despite how badly they mess up.)
So, if I understand your piece correctly the value of the power changes over time depending on the size of the network and the available pool, in other words even the log(n) factor is not exact, in the beginning it is probably closer the to the original n^2, whereas later on it moves to more sedate territory, but it always seems to be higher than the '1' added by attaching another node to the network.
The 'competing with ebay' has a nice counterpart. In the netherlands there was a small local site called 'marktplaats' that had entrenched itself in the early days of the web, and nothing ebay did to dislodge it worked, so they ended up buying it.
The kicker is that 'hyves' (the dutch counterpart to facebook) is losing ground because people have a lot of international connections to friends and family, but trade seems to be limited to geographic boundaries and hence marktplaats succeeded where hyves is in trouble.
In the piece I quoted, it isn't that value scales like nn then like n log(n). The argument is that value scales like n log(n), which for small n looks more like nn than it does for large n. That said the argument given implicitly assumes that most of the people in the network have most of the people they really care about in the network as well. This assumption is less likely to be true for small networks than large ones.
It didn't make it into the paper, but an interesting optical illusion was discussed while we were writing it. Most of us judge the ubiquity of a network according to how many people we personally know who use it. Therefore people's value from belonging to a network tends to scale linearly with the size they perceive that network as having. (A typical American neither perceives nor values the growth of that network in China.) Which means that each individual observes what Bob Metcalfe did when he came up with his rule of thumb. We found that interesting, but left it out of the paper.
Another discussion we had was on different networks that scale differently. The two extremes we came up with are the telegraph networks and eBay. In the case of the telegraph network there is an asymmetry between senders and receivers. It is easy to make every resident of a major US city a potential receiver, at which point the network value scales linearly with the number of senders. And at the opposite end, auctions scale in a less approximately linear fashion. However we decided against including that because we didn't have detailed enough data to support our preliminary conclusions.
Also you should note that the IEE Spectrum article is an abridged form of http://www.dtc.umn.edu/~odlyzko/doc/metcalfe.pdf. The full version offers several different lines of reasoning that all converge on n log(n) scaling rules.
I've seen this coming for some time. There is going to be a war over who owns the data about each person, the person themselves or some service provider. I know that legally the service provider owns it, but I'm not thinking that is the way most people see it. This is a case where the law has gotten very far out of sync with the public (and with the first principles of natural law and personal property, but that's a discussion for another time)
That's not the way most member states of the EU see it either, they have ruled very clearly that the user owns the data and has the right to access it, amend it and ask for it to be removed at any time.
http://www.facebook.com/apps/application.php?id=206330625089
But, yes, let a hundred flowers bloom in this market space.
Why stop there? They could go on and create a sort of alt-Facebook.
That said, your basic point still stands because the issue is one of who gets to control the data about each person. In effect, Facebook has tried to trap the data for its own exclusive use through its terms of service, even while confirming that technical ownership lies with the user.
Some highlights from the EFF brief that bring out some of the tension on these issues:
1. FB is really trying to apply a heavy hand against third parties such as Power Ventures who have the temerity to supply tools that allow users to gain more control over their own data and how they use it. Section 502(c) of the California Penal Code criminalizes unauthorized access to network data (among other things) whenever someone "knowingly accesses and without permission" does certain things with such data (including if someone merely "accesses or causes to be accessed" such data). The major 502(c) precedent of a thirty party getting busted by Facebook itself is the case of ConnectU, which had been sued by FB for scraping email addresses of non-ConnectU customers from the FB site and then spamming them. In that case, the access violated Facebook's terms of service and ConnectU was found liable. However, ConnectU had accessed the information from FB users who had not given it permission to gain that access. ConnectU had argued that it did not violate 502(c) because the users had made their email addresses available to FB and that it thus did not engage in unauthorized access in violation of the statute. The court disagreed, finding that the FB users could disclose their email addresses for "selective purposes" only without giving third parties broad rights of access to them. Given this precedent, FB is claiming that Power Ventures is similarly liable for gaining access to FB user data in violation of FB terms of service. Thus, the key distinction by which EFF seeks to distinguish the precedent is by saying that, here, the users not only own the data but also give their permission to Power Ventures to access it. EFF further argues that any violation of FB terms by Power Ventures or by users might be grounds for civil liability but is irrelevant to the question of whether a criminal act has been committed by such access because the only time this would amount to a crime is when a user's rights are violated by someone who hacks into their data without their permission. Therefore, "[w]hen a person is authorized to access certain information . . ., mere use of an unapproved technology to access that information cannot constitute a criminal act under California Penal Code section 502(c)." (Brief at p. 10) The EFF brief (submitted as an "amicus" or friend-of-the-court brief) is compelling on this point and makes FB's position look pretty laughable - I think the court will side with Power Ventures on this one.
2. FB has already won a round in this fight with Power Ventures by getting a related ruling to the effect that the FB terms of service effectively deny users the right to authorize circumvention of FB's technological protection measures for purposes of copyright circumvention. In other words, even though users might authorize a third party to have access to their information, FB can block such access on at least one important ground via its TOS (thus trapping the data for its exclusive use).
3. In February 2009 Facebook tried to modify its terms of service to give FB the right to continue to use content indefinitely, even if a user tried to delete it or even quit the service. This created a firestorm and FB dropped this effort. This was not for legal reasons but for practical ones - it could not afford to alienate users in this way.
4. The civil claims that Facebook might assert against third parties for violations of its terms of service are considerable and this appears to be the main vehicle by which FB is trying to prevent others from gaining access even if the users themselves are giving the third party permission to have such access. The contract claims are pretty clear in such cases, and FB can even terminate the accounts of users who violate its TOS in this way - but, again, the tension point is that FB does not want to alienate its users even as it seeks to corral their data for its own commercial use exclusively. Yet the contract-type barriers are formidable in this respect and FB may well get away with it if its TOS are ultimately upheld and are not found to violate public policy so as to render them unenforceable.
My own observation: it seems that, more and more, companies are trying to set up their own playgrounds where they control everything and capture the value for themselves (the parallel with 3.3.1 in Apple's terms of service cannot but come to mind). In each case, third parties attempt to gain access to the walled-off platform in an attempt to make its value (information in the case of FB; apps in the case of Apple) accessible to other competing platforms and are met with stiff resistance in the form of overbearing terms of use that seek legally to prevent that value from being shared. Of course, in any such scenario, two things happen: (1) the users lose because of the arbitrary restraints; and (2) the law is pushed to the limit and questions begin to arise about how enforceable some of these restraints really are. All this will be tested over time but the battle is already pretty fierce.
The theory is this: are computers, programs, and data pieces of external property that can be manipulated in a traditional manner by the courts? Or are they extensions of the individual's mind? I think the law views it as the former, but I think the citizenry is more and more viewing it as the latter. And no amount of precedence or legal force is going to change that. Sometimes the law IS an ass. You can have all the Facebook Dred Scott cases you want, and it's only going to make matters worse.
I have been standing by mostly idle as this developed, but I more and more feel compelled to act -- protest, write letters, petition, sue, etc. That's unusual for me, as I am not an activist by any means.
http://www.google.com/accounts/TOS?hl=en
6. Your passwords and account security
6.1 You agree and understand that you are responsible for maintaining the confidentiality of passwords associated with any account you use to access the Services.
6.2 Accordingly, you agree that you will be solely responsible to Google for all activities that occur under your account.
6.3 If you become aware of any unauthorized use of your password or of your account, you agree to notify Google immediately at http://www.google.com/support/accounts/bin/answer.py?answer=58585.
It's not absolutely clear, but 6.1 says to me "don't give your password to anyone." Whether it's for auto-scraping or not. If I give my password to FB to scrape my contacts, I (but not necessarily FB) have violated 6.1 because my password is no longer confidential.So FB is at least relying on someone (me) violating TOS.
Or: it will further open up a toehold for new startups to develop alternatives to Facebook - alternatives that treat their user communities better.
Recently there was a case ( MDY industries vs Blizzard ) in which they argued that because MDY broke the EULA for Blizzard's software, they were no longer authorized to use the software, and in such- copyright infringers. The judge agreed. ( its now on appeal )
The way I see it, the only way to continue using facebook for its actual purpose (social interaction??) is to have my data tainted in an (non-machine-detectable) obvious fashion so it becomes useless for most automatic classification/categorization attempts.
I remember a recent commenter suggesting there was but didn't see any follow up.
Conceptually, there is no contract between FB and its users. It's use at your own will; essentially a one-way deal and therefore cannot be a contract. That said, knowing they monetize our content, can argument be made that our content is 'consideration' and therefore a contract is implied?
What ?? source http://bits.blogs.nytimes.com/2009/01/02/facebook-sues-power...
How timely this post by sushi!!!!
So what is the point of the Open Graph then? Doesn't that allow me to access my information through automatic means or am I misunderstanding something?
Why is this simple notion mentioned nowhere in the EFF letter?
The EFF lawyer knows this, and that's why your inequality wasn't mentioned.
It should be up to facebook to find and ban violators from their system. TOS is not a contract and, even if it were, a contract dispute is a civil case not a criminal one.
Comment TOS: Reading my comment is strictly prohibited. Violators will be punished to the fullest extent of the law.
To the contrary, if Facebook is advised by competent lawyers, I would expect them to make banned accounts invisible to the public but to keep them in their business records indefinitely.