Such shadow profiles are a much larger problem to me than people who are happy to fork over their private lives themselves.
Such shadow profiles are a much larger problem to me than people who are happy to fork over their private lives themselves.
[1] The Dictator's Handbook: Why Bad Behavior is Almost Always Good Politics
https://www.amazon.com/Dictators-Handbook-Behavior-Almost-Po...
[2] The Dictator's Handbook: A Practical Manual for the Aspiring Tyrant
https://www.amazon.com/Dictators-Handbook-Practical-Manual-A...
http://www.bbc.co.uk/programmes/b08qgbc3
That said, I'm personally certain the laws will evolve rapidly in a favorable manner. Privacy issues resulting from Facebook/Google and co are becoming increasingly unacceptable for the society.
Moral: of, relating to, or concerned with the principles or rules of right conduct or the distinction between right and wrong
I think it is "clearly wrong" that Facebook creates shadow profiles, because it is violating the freedom of people who have not signed up for their service, in the same way that it is clearly wrong for me to take away your favorite pet for ritualistic sacrifice against your wishes, even if "everyone" in the community agrees that it has been a consistently effective method for pleasing the Gods.
Of course, you know these analogies are tenuous, and you will eventually go into very precise definitions of words (or worse, you will actually start taking my pet sacrifice analogy and dissecting it). Perhaps you could tell us about something you think is clearly unethical, and we will try and draw the connection for you.
In your argument you state that it violates peoples' freedom, but you need to define how their freedom is being violated.
It's upsetting because I don't know what I can do about it. How do I protect my privacy in this world? Do I stop having friends? Do I wear a mask everywhere?
Even the best ethics expert in the world would just be one who knows how to describe a bunch of ethical systems and ideas that exist currently and historically. Other than that, they can help you exactly zilch with such decisions. I'm not a psychologist, but I'll claim if it makes you feel upset and disgusted, that means you did decide you consider it wrong. And if it helps, I agree.
As for how to change things, well, ask the EFF for example? There's things you can do which, apart from being a real help, also help you with the dread of this free floating vague blob of worries that you sometimes look at but as you said feel you can't do anything about.
One thing you can always do, is that not giving in. It just takes one person to prove the claim that everybody accepts or wants X wrong. When being that person seems scary, personally, when looking around, I'm not convinced at all that the people who fight no or trivial battles are less scared. It's not actually safer on the side of thugs, generally speaking, and life isn't more fun at mindless parties either, only those who don't have the comparison would think that. I'd rather say that's all built on sand, on holes that have to be temporarily filled with more and more material.
So keep on hanging on, because there might come a point where you feel less upset, more grounded, and the people who drift along will become more and more confused. Real things can hurt, sometimes badly, but real things also have longevity, they bring their own means and nutrients for growth.
At least, that's how I answer these questions for myself, that's how it ended up working out, and while I know that can't be generalized, sometimes it does get darkest before dawn. Don't let it drag you down (Sophie Scholl's outlook = best outlook).. but what you can shoulder, do shoulder. The only way out really is through, ultimately.
If worst comes to worst, don't get crushed when the screeching narcissism machine attempting to eat the planet drives itself and billions of people against the wall and implodes. Easier said than done, but change will come one way or the other. I'm not convinced it would leave spots of unscorched Earth, but that hope dies last, anyway.
The difference is, the GDR is gone and none of this has any consequences anymore. However, the consequences of Facebook et al. are yet to be seen.
That's your interpretation of their reasoning, Facebook's interpretation could assume that they haven't signed up for service yet.
Also, how exactly is their freedom violated? Let's say they could do a certain set of actions on a given day prior to Facebook violation. So if a government violated their freedom (e.g. by putting them under house arrest), a certain subset of those actions, like walking to a store or a park, would be impeded.
What would be an example of actions that would be impeded by Facebook's violation?
That just shifts the question to how does it violate their freedom? That is not at all obvious to me. (NOTE: this does not mean that I'm saying it is OK...just that I don't see how it is a freedom violation).
My computer desk at home is near a large window, which I often look out while I am using the computer. From this window I can see people from my street walking dogs. I can see kids going to and from school. I see cars coming and going. My street is a dead end street about 1 km long, and I'm about 200 meters in. The street bends a little way past my place, so the last 700 meters or so are not visible from my place.
By casually observing people walk by, I've gathered data to make several inferences about people who live beyond the bend. I've figured out when some people are having house guests (by seeing people I've never seen before walking dogs that I recognize).
I've inferred sibling relationships among some of the children who walk by (by noticing dress and equipment patterns that clearly indicate that the same person is shopping for both).
I've figured out what kind of cars the parents of the some of the children drive (by seeing those cars stop when passing the children on the way home, and the children getting in, or seeing a strong correlation between days when particular children who walked by to school in the morning do not walk by in the afternoon and days when particular cars drive by in the afternoon).
Am I violating these people's freedom by making these inferences from what I see out my window?
If not, what is the fundamental difference between what I'm doing by observing people that walk or drive by on my street and what Facebook does by observing what its users do on its site?
Imagine, you share your observations with, say, a PI who was hired by a paranoid spouse or by someone's employer.
Facebook is like a vast and far reaching network of nosy neighbours of whom you do not know who they are chatty with. Maybe someone who likes to jump to conclusions?
I would think, that advertising in the local press or, having a sign outside the window to the effect that you were able to sell personal and assumed to be private information about the people who lived in the street would provoke an unpleasant reaction.
Doing something purely for your own benefit that you know will cause significant distress to others is sociopathy I think. Perhaps 'unethical' is the wrong word. 'antisocial' definitely covers it though it might not be strong enough.
You may not violate a freedom but the bigger question to me is why would you even contemplate the thoughts to infer, etc.
What is "wrong" is that people think it is ok to talk about others.
Next time you get together in a group take a poll on how many conversations are just talking about people.
Would you say there is absolutely nothing wrong with this?
The expectation of privacy. The window analogy may seem very clear to you, but a lot of people see Facebook as a sort of postal service carrying their enveloped messages to their friends, and they have to trawl through a pretty large document of legalese to find out how it isn't. Facebook is more like one-way mirrored glass.
That said, I do believe that there's a practical problem, but it's us that must try to solve it, we must educate people, we must ask our friends not to post our photos or personal info on social media, etc.
What if they decide to publish online your computed profile? Maybe they know you better than yourself.
> as long as the don't use coercion
Isn't influence or suggestion a kind of coercion? Why do you think they spend so much resources on profiling everyone?
> That said, I do believe that there's a practical problem, but it's us that must try to solve it, we must educate people
My country used to have over 6000 people killed on roads out of about 60M people. The state tried to "educate" people about not driving while drunk, not driving fast, using seat belts, etc. But in the end, what actually worked was more policemen on the roads.
You say freedom is the lack of coercion but you fail to realize that you are coerced into being part of FB, and your only opt-out is drastic measures like using a blocker.
FB probably has more intelligence capabilities about mere people than any past or present intelligence agency of any country ever had. That raises a lot of questions, the first of them being to make sure that they don't use it against people.
Yes, there is influence, and I would certainly prefer it to no be like that, but freedom of people to use a lousy service as fb is still freedom, and freedom is more important than my feelings.
The massive income Facebook has seems to imply so.
It is not a prove per se these ads really are worth their costs.
If "these ads are working" is defined as "these ads are accomplishing what they were intended to when purchased," peoples' spend is founded more in data than belief.
Buyers have access to ~2BN people and tools to target them by age, interest, and geography -- much of that demographic and psychographic data is explicitly and freely given by those people themselves; tons more are derived and inferred. Buyers repeat their buys because these ads accomplish what they intended at purchase -- they can effectively drive traffic or commerce or whatever else.
This real power to generate revenue makes the issues around privacy, security, transparency, awareness, responsibility, ethics, laws, oversight more important than if it was created by ignorant beliefs. The latter would be temporary; the former generally strengthens as more data gets into the system.
The fact that people buy ads is not at all evidence that they are effective.
So you think that Facebook has collectively convinced thousands of businesses who are repeat customers to use something that is losing them money?
They were steadily losing users in the very significant 13-17 years demographic, had a CTR one fifth of the rest of the web. Several reports of brands quitting facebook or advertising on facebook because it is expensive and does not seem to be effective on a background of unstable rules and "quirky" system with some overcharging and ads not displayed.
Facebook built itself on investor story time, with promises of better targeted ads in the future, and up to now is still selling the idea that at some point in the future it will succeed at this. It has yet to deliver on this promise in a consistent way.
The new DPD is strict compared to previous regulation, but there are two parts of the directive that a particularly interesting:
- The Data Portability concept: A company covered by the DPD is required to deliver to the user all data the company has on the user, in a standardised format. That means Facebook now has to hand out all your data (information, pics, likes, posts,...) for you to use freely - also in other services. I think this in effect means you own your data. I'm excited to see the effect of this one.
- The right to be forgotten: A company is required to delete all data they have on a user, if the user requests. Actually, if the user invokes this right, the company is not allowed make public, <b>store or process</b> any data related to the user.
From what I hear in discussions between american colleagues, american companies have no clue whats about to hit them. I know there is a mild panic here in Denmark, and the DPD is the most talked about subject in IT at the moment - and we've always been rather anal with the privacy stuff (e.g. cookie-law).
Edit: Oh, I forgot the fun part; this gets a lot of attention due to the sizes of the fines companies get for not adhering to the directive. Fines are up to EUR 20.000.000 or 4% of the company's global annual revenue, whichever is higher. Facebook made USD27.638.000.000 in 2016, so thats a fine of USD1.105.520.000 for not playing nice.
(I posted this in reply to another post, but seems relevant here too)
The problem here is that those companies use fingerprinting to collect data. This means that in theory they are not 100% sure who is the person they are collecting data from, but in practice they could be 99.99% sure. Still, this makes it impossible to hand out all this data, because there is still a 0.01% chance that the data does not belong to the person who requested it.
Time for some math:
Since it is only a 0.01% chance, it means you need 10000 discrete pieces of information collected on a single individual before there is a chance of error. If a company indeed has that many pieces of information on you, you first of all need to know that for a fact.
There is a chance the company will counter that this is aggregated probability, as in, with an uneven distribution of errors. If it is indeed aggregated probability, the companies which advertise on these platforms need to demand their money back because for all you known, none of the folks they are targeting are actually correct fits for their ads. Fingerprinting puts the burden of proof on the shoulders of the company that they are indeed allowing advertisers to target the audience they want. How can they be so sure if the errors are unevenly distributed?
In any case, everyone should demand the information anyway, and let us start using this fingerprinting theory as an excellent opportunity to get deeper into the practices of these companies.
Smart is not wise. Just complicate what you think people would hesitate to do, and they will get fooled into dong it. Especially if it challenges their intelligence (e.g. algorithms).
The sentence "I have nothing to hide" that often gets thrown about has two problems. The first is obvious: whoever says it most probably do have something to hide, and are not quite realising it. The second is much more insidious: it frames the debate individualistically. This is a common flaw in our western societies —see for instance copyright debates talking about one artist and one consumer or pirate.
People should realise, as you did, that it is not just about them. I would go even further: using Facebook is not just a personal choice. It's a political one, that affects all around you.
Last year for instance, I was forced to use Facebook by friends from my orchestra. I reluctantly set up an account, and kept up for a while. Then I turn off email notifications because they were so annoying. Then I learned, several times, of decisions or events that were discussed only on Facebook, (without my knowledge since I hardly logged in). When they clued in on my ignorance, they said "but I sent the mail" (no you didn't).
(I have since "deleted" my account. I won't use that crap ever again)
The choice is often between giving up your privacy on Facebook, and being ostracised by such and such group of friends. Disgusting.
It's still creepy, but it's likely more about determining knowledge of the friend graph (i.e. suggesting 2nd degree friends via a connecting pseudo-account) than about ad targeting.
Though yes, as soon as that pseudo-account could be tied to an actual account, Facebook could use passively gathered info to target you.
The creepiest part about Facebook is the sheer volume of facial data paired with social connection data. With access to that, even if you have never been online in your entire life, there's a good chance I could take your driver's license photo and know who you associate with.
That's the easy part. There are companies that specialize in this sort of thing, as well as in merging profiles from several devices (pc, tablet, smartphone), you can bet that if two-bit advertising technology companies know about these tricks that Facebook does too, and they probably know a trick or two that has not become mainstream yet.
If you want an explicit explanation of how such a link could be made it's a hard choice: too many possibilities.
I've done technical due diligence on about 10 advertising technology companies, node identification in a graph gets easier through two things:
- more known nodes in the graph (Facebook has many)
- more activity by the unknown node (just wait and track)
Sooner or later there is a moment where just for an instant that node can be strongly associated with a real world ID, for instance, a contact in someone's address book, a tag in a photograph and some shared online activity or something as simple as a phone call. At that point it is game over, the contact can now be associated with the device ID on the other side for instance through some running app.
Apropos games, many games monetize by embedding a library supplied by an advertising technology company that wishes to gain access to devices without waiting for the user to visit a website. These libraries leak information all over the net.
https://developers.facebook.com/products/app-monetization
Is one example by FB, there are many more and some of those require permissions that make no sense at first sight until you realize what is happening under water. If you ever wondered why some shitty game requires access to your contacts, location and other interesting bits of data this is it.
It is very hard to stay off the radar of the likes of Google and Facebook, I have a pretty good idea of how this stuff works in the background and I have no clue how I could not leak enough bits for those two companies to tie my online activity to my real world identity in a single profile.
Technically each and every advertising agency that creates a profile on you, gives you a cookie and stores your IP address is in violation of the law. (IP addresses count as PII, Personally Identifiable Information).
I don't see the legal hammer coming down on the advertising industry (of which Facebook and Google are the major players) any time soon if ever.
One way hashed (that can't be rainbow tabled) are not however PII afaik however, so it's quite easy to turn an IP address into a "net location ID" or something similar that can't be tracked back to a physical IP for analytics.
No need for rainbow tables, the search space is small enough to brute force.
Given a GPU farm however I'm sure it might be feasible. However at that point surely you just add a salt?
If you add a salt, then that "net location ID" becomes of very limited use. You won't be able to grep through the logs for request from specific IP, you won't be able to tell how many distinct IPs are accessing your services, etc etc. The only use I can see is keeping it in the session to check if IP address had changed, as a security measure.
How would that work? You'd have to use the same salt for every IP (which completely negates any benefit of the salt), otherwise how do you know that bcrypt(salt_1, IP_1), which you stored in your database yesterday, refers to the same IP as bcrypt(salt_2, IP_1) that you stored a month ago?
Recently Facebook got fined 110 millions by France for lying to antitrust regulators during the vetting of the whatsapp deal, a few days before it got fined the maximum of 150k euros for repeated infringement to local privacy laws (maximum has since been raised to a percentage of the worlwide revenue) and a few days later it got a 3 millions fine in Italy for a similar privacy offense.
I'm not sure shadow profiles are covered by the legal obligation as facebook never acknowledged the existence of those for they are illegal in the EU.
More about the difficulties and process to get your data from facebook here: http://europe-v-facebook.org/EN/Get_your_Data_/get_your_data...
The new DPD is very strict, but there are two parts of the directive that a particularly interesting:
- The Data Portability concept: A company covered by the DPD is required to deliver to the user all data the company has on the user, in a standardised format. That means Facebook now has to hand out all your data (information, pics, likes, posts,...) for you to use freely - also in other services. I think this in effect means you own your data. I'm excited to see the effect of this one.
- The right to be forgotten: A company is required to delete all data they have on a user, if the user requests. Actually, if the user invokes this right, the company is not allowed make public, <b>store or process</b> any data related to the user.
From what I hear in discussions between american colleagues, american companies have no clue whats about to hit them. I know there is a mild panic here in Denmark, and the DPD is the most talked about subject in IT at the moment - and we've always been rather anal with the privacy stuff (e.g. cookie-law).
Edit: Oh, I forgot the fun part; this gets a lot of attention due to the sizes of the fines companies get for not adhering to the directive. Fines are up to EUR 20.000.000 or 4% of the company's global annual revenue, whichever is higher. Facebook made USD27.638.000.000 in 2016, so thats a fine of USD1.105.520.000 for not playing nice.
[1]: http://ec.europa.eu/justice/data-protection/reform/index_en....
I think the practices of online tracking joined up with offline tracking, as Google is now doing is going to be forbidden unless you consent.
https://www.washingtonpost.com/news/the-switch/wp/2017/05/23...
This was exactly my point a while back. That the default option should be to get explicit permission for each piece of data you collect AND infer, even if the inference is being done in situ as the code executes (otherwise it will become another out clause). Of course, the geeks who get all delirious by seeing a mountain of data to analyze would not want that kind of friction in the process.
I wonder what would happen if someone would spend the time to completely dissect and reverse engineer exactly how lookalike profiles are being generated. My guess is that it will expose data collection practices which will confirm our worst fears.
Then there is the secret negotiation of TAFTA where the US wants to siphon data without providing privacy and Germany refuses to let TAFTA go on until there are adequate privacy measures.
So yeah, this battle has been an ongoing one for years now.
Still, I'm absolutely sure it's best to keep private stuff to oneself, and parties you trust. With understanding of full consequences of doing so. If one trusts Facebook, they'd better think why do they do so, as their trust may be misplaced.
I think one of problems is that when users post data they don't even think they send it to Facebook - they believe they send it to their friends there.
It's a defense mechanism.
https://support.google.com/googlecloud/answer/6056650
> Does Google use my organization’s data in G Suite services or Cloud Platform for advertising purposes?
> No. There are no ads in G Suite Services or Google Cloud Platform, and we have no plans to change this in the future. We do not scan for advertising purposes in Gmail or other G Suite services. Google does not collect or use data in G Suite services for advertising purposes.
You could drive several trucks sideways through the holes in that statement.
What other purposes would they use it for? Can anyone think of one?
https://www.theverge.com/2014/8/5/5970141/how-google-scans-y...
Oh, and for indexing, of course.
They could sell that to a third party, then buy back the profile compounded with other third parties's data to use for advertising. Bonus points if Alphabet (aka Google) control all the companies involved.
?
That's just nonsense, nobody does this, people just send mail through some client and never ever check MX records by hand unless they are trying to debug some kind of problem, in fact, the vast majority of people have no clue that something like an MX record even exists. To them email is roughly equivalent to magic.
I get that it's not common or simple, but "absolutely no way" doesn't mean absolutely no way that's common and simple. It's doable and, if you want to avoid it, there's plenty of ways to ensure that you never send directly to a Google server.
That's your problem right there. The general population has no way of knowing this, you do, but that's only because of your professional background.
So, for lay people there is absolutely no way and that's the vast majority of them, for us internet techies there are ways but they are moderately involved and too impractical for everyday use. And even then, you've established that you will send your email through google, what are you going to do now? Ah yes, send it anyway.
user@example.com$ cat "./forward"
user@gmail.com
How will you know that user@example.com ends up at Gmail?With a very large fraction of all email now passing through Google's servers you can expect them to be able to piece together the missing bits with high fidelity.
The clowns are being elected by the voters, not by companies, terrorists will always be able to do their deeds in an open society, if some fail just throw more bodies at the problem, and financial meltdowns can be prevented by banking oversight (and a lot of that oversight just got canceled by the stroke of some clowns pen so you can brace for the next round in ~5 to 10 years from now).
If I write "Leroy Jenkins likes rushing" in an email, does Google create a persona called Leroy Jenkins, assigns a quality "likes rushing" to it and tries to match it to other data?
I always heard that user data is firewalled by default inside Google (PII data from one user isn't used on other users, unless explicitly shared).
Even on Photos Google seems to only allow you to appear as a suggestion on your contact's photos after you explicitly opt-in and explicitly selecting "which one is your face":
https://9to5google.com/2017/05/25/google-photos-suggested-sh...
Sometimes they do the right thing but I most certainly wouldn't bank on it! If we want change there has to be grass roots movements I think. If tech people would find a way to use word of mouth to convince people not to use FB then FB would collapse. Something along the lines of "Won't somebody please think of the children!" might do the trick ;)
FB absolutely knows more about me than any individual person at this point. I've decided, for good or ill, to accept that and leverage it; rather than feeling upset about my inability to enforce a right to privacy, I've decided it's more important that I should be able to enjoy being myself rather than having to hide everything. If powerful forces wish to abuse that, they can, but I'm happy to have that moral argument.
When you're using Facebook, you are doing 2 things: first, you reveal the personal information of everyone around you (bit by bit, each time you reveal your personal information). Second, you strengthen the network effect that incite, sometimes even force people to cave in, use Facebook themselves, and thus reveal their private information.
You don't know it, but using Facebook is not just a personal choice. It's a political choice.
You don't know it, but using Facebook is not just a personal choice. It's a political choice.
I do know that, I don't know why you would think otherwise. Whether you understand my political motives is another question, though it's clear you don't agree with them.
But now you're telling me you're aware of these issues… I don't want to assume, but you sure look like an egotistical bastard at this point. Or a cynic. I'm not sure which is worse.
That seems a bit extreme... The effect on others is pretty minimal, what is so bad about using Facebook just because you like it, despite the small side effects on others? So your saying that anyone who uses Facebook after hearing about shadow accounts is a 'egotistical bastard'?
It's not just about shadow accounts, by the way. There are more direct effects. For instance I was once forced to set up an account for logistic reasons (they used Facebook extensively, if not exclusively). Worse, when I tell them I didn't got some news (because I didn't check that account very often, and I turned off the very annoying notifications), they say "but I sent the mail" (they only used Facebook). I have since "deleted" my account, good riddance.
So, the effect on me was direct and significant. Depending on how you use Facebook, you can have a similar effect. The worst you can do is set up events and invitations on Facebook only, forcing your friends to either use Facebook, or drift apart.
With a billion daily active users, the problem is well beyond the individual human scale. Facebook lives, in its own right. If those users were cells, Facebook would be an organism of quite respectable size. There's only one action I can see, on the part of the individual, that poses a credible risk to the health of the whole.
Find a way to give Facebook cancer, and we can talk about individual actions affecting the problem as a whole. Until then, I don't see what it helps to throw around ultimata, especially ones like yours which in the past have embodied a significant threat of politically motivated violence - not, to be sure, something of which I accuse you, but connotations do matter, and those in particular are not conducive to worthwhile discussion in any way I can see.
In any case, I'm less interested in parsing details of precisely which speculative definitions of artificial intelligence Facebook taken as a whole might satisfy, than taking the view (if perhaps only for the sake of this argument) that it does certainly satisfy at least some definitions of life based on its behavior, in particular its evident tropisms toward growth and self-preservation, for which no particular intelligence is even necessary - kudzu need not be intelligent to be a pestilential and highly effective thief of the resources required for a proper ecology to thrive.
Suppose, in any case, that I persuaded my valued social circle (perhaps 10 intimates, 40 casual friends, 150 acquaintances) to move off FB to some other platform. This is unlikely as I'm not the only or most important reason reason they're on FB, but anyway: what would be different? OK, there would be less commercial exploitation of our information, but that doesn't seem like your primary concern. The NSA would, doubtless, still be vacuuming up our conversations just as the NSA vacuums up all the discussions we have here, and can easily cross reference our HN handles with our more detailed and specific identities on other platforms. I could posit a secure platform where everything was encrypted and all interpersonal communications metadata on said platform was cryptographically obscured, but then we'd have 200 going to the same site every day, presumably to communicate with each other in secret. That in itself would be of interest to intelligence gatherers, and how difficult would it be to social engineer oneself into a group of 200 people? Not very, and once inside one has most of the access one needs already because otherwise where is the utility?
I can't help feeling that you're arguing for a very highly highly elaborated version of security through obscurity. I prefer the security of knowing that if anything happens to me it will upset enough people to have negative ramifications for my antagonist. I find the conceit that we can have a situation where private actors enjoy all the benefits of instantaneous and frictionless communication but government actors are enjoined from participating even at the user level by virtue of the political authority they wield neither theoretically nor practically sensible.
I wouldn't be so sure. Ads make money for a reason. I'm not sure I want giant corporations to play tricks with my mind so I by their products.
> we'd have 200 going to the same site every day, presumably to communicate with each other in secret.
If all communications were end-to-end encrypted, it wouldn't even look suspicious.
> how difficult would it be to social engineer oneself into a group of 200 people? Not very, and once inside one has most of the access one needs already because otherwise where is the utility?
Consider the costs and the scale. Unencrypted conversations can be archived and indexed at negligible cost. This is what enables mass surveillance. Social engineering however requires that an agent spends time on it. This is expensive, and thus only enables targeted surveillance.