Facebook Lies
iain.learmonth.me
iain.learmonth.me
The result was... amusing. Facebook kept emailing me the "Hey, did you see what so and so posted?" emails, knowing full well that I didn't see them. But then, after that, I started getting weekly reminders that "You haven't updated your timeline in a week". Facebook, ever the clingy ex-girlfriend it is, seemed to start amping up the frequency of the emails the more I neglected them, so I started just marking them as spam.
Two blissful days went by in which Facebook wasn't a distraction, but then they shifted from email to SMS which, as an Android/Hangouts user, was even more annoying, since now I have to engage in multiple steps to delete.
They really, really want me to use their service.
I've no intention of logging back in to check my notification settings, but when I was using Facebook, I would get a push notification maybe once or twice every couple of days. Now, I get more than a dozen SMS messages a day.
I've built notification systems in the past, and in every instance, respecting the fact that abusing the notification power entrusted to us by our customers was seen as a cardinal sin. Maybe it's the absence of that respect that has catapulted Facebook to where it is, or the presence of it that's held me back in my own endeavors, I don't know, but man, as the recipient of all this spam, it really, really feels unsavory, and further evaporates whatever trust I might have had in the platform.
I think the “user is idle let’s poke the user” is a supposedly a “nice” user engagement to get users back on the system. I hear your concern.
I think at this point:
* opt out notifications before deactivate your account (go to account settings)
* deactivate and opt-out notification at the time of deactivation
* set facebook email as spam or something (although you’d miss any potential real security notifications.)
Or you can also remove your phone number and change the account’s email address. I own a dozen gmail accounts, one for mailing list, one for billing, one for personal, one for school, one for important tech accounts like digital ocean/aws, one for banks, one for general garabge I don’t care and so on. I also run a YouTube channel with a friend so I also own a separate gmail account to be added as a manager of the channel.
Much neater than labels (amazon emails can fuck me up easily, ugh).
I highly recommend this multi-email account approach. I can ignore 50 emails sitting in other accounts most of the time. All of them have second auth and some accounts have different passwords for additional security. Not hard to manage because the address format is always <A>.<purpose>@gmail.com. Consistency!!
The only major issue I've had, with gsuite at least, is not being able to reply from one of the not-actually-existent addresses on my domain.
The keyword in your sentence is customers. The people using Facebook aren't its customers, they're the product and thus open season for all kinds of nefarious things you'd never do to your customers.
If they don't provide the unsubscribe option as a one-click option, mark their emails as spam. It's harsh, but getting flagged for spam when they won't stop spamming you or providing the required one-click opt-out is their problem, not yours.
The best advice I've ever read for the spouse who is on the receiving end of a divorce request/demand and wishes for reparation is to acquiesce quickly and approach the ordeal as a business transaction. You'll find story after story of anecdotes of that working to allow a couple to repair relations and figure out what was broken. Much better than being very emotional and otherwise reinforcing the reasons for the divorce request in the first place.
I think FB is being wise in taking this approach considering how difficult it is to find the real "delete" as opposed to "pause" button.
That's a lesson I've applied to many areas of business to very good outcomes -- customers wishing to terminate, etc.
Just out of curiosity, does anyone know whether by "deleting" your account, facebook removes your account/data completely or do they just mark your account deleted?
Is facebook required to remove your account from all data sources ( dbs, failover sites, recovery sites and even the backup tapes )?
I know certain sites, when you "delete" your account, it just updates a column marking your account "deleted" or "inactive".
But I'm most curious about the backup tapes of logs/data.
This non-committal situation created some anxiety for me, it was a decision that still needed to be made in my mind so wouldn't go away.
Then Bryan Lunduke went through the process on his YouTube channel and he claims his contacts at Facebook were unable to find his data once it was deleted, so that was good enough to push me off the fence and I finally made the decision to delete.
I can never be absolutely certain but there's really not much more I can do besides use European privacy laws to try and force the issue, but that probably won't do much about the NSA backup. ;) But my mind is at rest now, I don't worry about it apart from doing my best to limit tracking online but that's another story.
For instance, how do you easily configure Facebook to ONLY send you emails when you're invited to an event or someone sends you a Facebook message, but NOT when your friends post random stuff?
I still get an endless stream of spam from them.
"Facebook - more AOL than AOL ever was."
[1] whatever that means, wrt them.
Blocking sources of spam is part of being a "good netizen".
[1] I find it exceedingly unlikely that FB mail admins would need to reach me to troubleshoot something, but it is the principle.
I stopped using Facebook 6 years ago and haven't gotten a single email / sms from them since then, because I used the settings properly.
Yeah, if you just ghost them and never click "update your email settings" at the bottom of every email they send, they'll keep sending them.
"Facebook activated my dormant account and it won’t let me deactivate it"
That doesn't strike me as particularly unreasonable, rather projection of ill will onto Facebook. They have no way of knowing which person is actually the account owner, actual ID would definitively settle the matter.
It's weird to expect that deleting your account will result in the account being deleted and notifications for the account you no longer have to go away?
It's nice to know there's a workaround for when account deletion isn't respected, but you could skip the incredulity, you shouldn't have to go through your settings, and your settings shouldn't affect your notifications, if you delete your account.
But the person above just stopped using their account, didn't delete it (or disable it, which is what facebook sends you on the path towards), so that is why the notifications continued. They still had an active account, just hadn't logged in for some time.
> when the users wish/intent is clear
How is it clear? Their whole post is stating that all they did was not use the site for a bit.
Given that they have an active account and notification are set to notify, why would they ever assume you no longer want notifications? They could very well want all of those notifications (since they have them turned off), so not sending them would actually be the exact opposite of what it should do.
This would be like if my post office stopped delivering my mail because I didn't call them up and tell them to keep delivering my mail.
Why should @bmelton expect Facebook to respect the notification settings after he has evidence they didn't respect the account deletion request multiple times?
It's not weird nor is it magic to expect Facebook to stop the notifications. That's what pretty much all other web sites and services currently do. They may ping you several times, but eventually they will stop. I know because I run a service that does this, and I pay attention to what other services are doing, and I care about what is socially acceptable. Facebook, unlike other services, ramps up their notification schedule when you get quiet, rather than assuming that no contact and no response after multiple attempts means you don't want to use their service.
What Facebook is doing is what's weird here.
Elsewhere in this thread, @wpietri makes a compelling argument that were Facebook a person in your life, the increasing notifications would be considered very annoying and needy. This is the reason it's weird for a company to do the same thing.
No, it's not. This would be like if my post office stopped delivering my mail because I didn't call them up and tell them to keep delivering my mail.
What is the correct functionality for Facebook given this user's settings?
I do not agree that it should stop sending notifications. Let's say I _want_ to keep getting notifications via email without having to open Facebook every so often. I would have my settings match theirs and I would be quite annoyed if it just stopped working because I didn't log in.
You might be lumping all notifications into the same bucket. There's a difference between a Facebook message that notifies you of someone else IMing or commenting on your photo, and a Facebook message that reminds you to use Facebook or upsell you on services.
That difference has standard terminology in the web business sphere: transactional email vs marketing email. Generally speaking these things have a hard line between them, and are easy to define & separate. Marketing is sales, and transactional is private notifications about your account activity & private notifications from social contacts. Marketing is what other sites stop sending after too much inaction, and marketing is what Facebook is increasing in response to inaction. Transactional notifications don't stop, and they shouldn't stop. I suspect you're misunderstanding me and assuming I'm talking about all email, and not just marketing.
I agree that I misunderstood part of what you were saying. It also sounds like we both agree that the notifications ("transactional email", from the sounds of it) should be going through. I was only ever trying to make a statement about those types of emails. I agree that upping the marketing emails is pretty bad.
I think this line in particular is where I misunderstood:
> It's not weird nor is it magic to expect Facebook to stop the notifications.
In this case, I interpret "notifications" as "transactional emails".
However, if that isn't the basis of their expectation, I don't really understand the rest of their post. Especially "knowing full well that I didn't see them" (how?) and proceeding to mark the emails as spam... instead of turning off the notifications...
The latter is why I believe they expected the notifications to stop.
Edit: as far as the notifications getting more frequent, that actually is pretty interesting, but not really relevant to the other points made.
Are you not aware that Facebook is attempting to track emails and links for everyone? The mechanisms are numerous and varied, but putting "tracking pixels" in HTML emails is standard practice. If you ever ran a Mailchimp list, you'd know you get reports on who received your email, who opened and looked at them, who clicked any link in them, etc.
Facebook also track visits to any site on the web with Facebook integration, via cookies, which is a large number of popular sites. They know when you've seen their emails, if you're like "most people" and you use hotmail or gmail and not pine. You have to be pretty privacy & security adept to have a Facebook account and avoid getting tracked. 99% of people who use Facebook are not adept enough (or just don't care enough to fight it), and their emails & visits to Facebook and elsewhere are tracked.
Me, I think it's weird to think: "It's perfectly reasonable that if you once give somebody your email they will bother you until the end of time unless you jump through any arbitrary hoops they set up."
I've done this before, just let myself keep getting emails and hoped they stopped. Then I just clicked all of the unsubscribe links they are legally required to put in every email, and I never got an email again.
You don't have to hope for what you want, you can act upon it.
My point is that it's not how it normally works with humans. If a person did this, it would be creepy and controlling. But when a group of people does it because it might make them money, it's ok to blame the person they're bothering.
I get your perspective and agree that it is, for the moment, the dominant one. I just disagree that it's weird to think otherwise.
I don't think it's any more ideal to have to opt out of communications, I'm merely saying that expecting not to have to opt out is a misjudgement.
I'd rather more closely understand reality than hope it gives me exactly what I want. Facebook does not owe me anything.
Although when bringing up paper mail, we should note there are many different standards. Are we talking the standards of 1792, when the USPS was created? Perhaps we use the 1879 mail classification act? The 1920s, when the Direct Mail Advertising Association was formed? How about around the time of the junk mail controversy of 1953? Or perhaps 1970, when Chief Justice Warren Berger wrote, "Everyman's mail today is made up overwhelmingly of material he did not seek from persons he does not know. And all too often it is matter he finds offensive."
1) Clicking "unsubscribe" confirmed that you received the spam mail, so spammers would activate your email address on their other lists, thereby increasing the amount of spam you received. Otoh, acting like /dev/null increased the chance that spammers culled your address to increase their apparent delivery ratio.
2) Following those links gives the spammer access to your web browser, along with tracking cookies, and chances to exploit any plugin vulnerabilities.
3) Your chances of getting phished are way higher if you follow mail that looks like it's from ICQ than if you just go directly to icq.com and find their unsubscribe settings. (I didn't say I got that advice recently....)
[1] In Germany, there is a specific section of the public code governing ToS ("AGB-Gesetz", part of the BGB). Among other things, it forbids "unexpected" terms, acknowledging that people usually cannot read all the ToS that they have to agree to in practice. Quite a few ToS have been nullified by courts because of that rule.
On Facebook, the unsubscribe link is very fine-grained, and is specific to the exact type of notification the link appeared on. I don't think you can fault anyone for giving up on them if you use one but still get Facebook spam.
In fact, those unsubscribe links are the only fine-grained way to control notifications. You can't only preemptively subscribe to the specific notifications you want. The options you get are all, nothing, or dick around with dozens of unsubscribe links for weeks.
Facebook is all dark UI patterns. It's so bad to the point where I don't think any user can be faulted for not knowing how get it to do what they want.
I just don't buy this. I don't get emails. I didn't have to contact customer support. I didn't have to ask for help. I just clicked the link in the email and turned everything off.
That's false; Facebook demonstrably does not work that way at present. If you're getting Facebook emails, the unsubscribe link is scoped only to the particular type of email notification it appeared on. You'll continue to get all the others until you click unsubscribe on each individually, or go into the settings and disable email notifications totally.
Again, they use dark and overly complicated UX patterns to make difficult for people to unsubscribe totally, and this is almost certainly intentional (but deniable). I think it's totally reasonable for someone just assume Facebook's whole unsubscribe system doesn't work, as it's not really reasonable to expect people to invest the time to learn Facebook's deliberately bad unsubscribe system.
So I feel the GP's pain, I've taken to marking them as spam as well because I know that my settings aren't guaranteed to stay where they are. It's not even in Facebook's best interest to try and keep my notification settings where they are.
Microsoft/Gates also had trouble with this. What is "business hardball" in a startup, can be illegal conduct in an almost-monopoly.
In a kitten, pouncing aggression is cute... in a liger, not so much. For the same behavior, you'd put it down.
Individuals can similarly fail to recognize transitions. "You can't do X." "But I've been doing X for years!" "Yes, but here you have relationship Y, so X is no longer ethical/legal."
At some point or another they decided to expand this to include re-engagement garbage like "{{Some person you haven't interacted with in 10 years}} {{ commented on their status || uploaded a photo || added a video}}!", so now I've turned off everything but security alerts.
My current frustration is how they won't let you get notifications about new messages by email. I don't want the app, I don't want to 'delete' my account since we know it doesn't really remove anything and I'd rather retain a semblance of control, but I also don't want to leave the occasional person hanging who tries to contact me via Facebook Messenger, since people can still message you even if you mark yourself 'offline'.
I know this is completely intentional and designed to get me to install the Messenger app and look at their ads, but damn if it doesn't grind my gears. If I could go back to 2005 I never would have made a Facebook account to begin with.
I never asked FB to send me any texts other than for 2fa and this is pushy and unwelcome.
I think my friends recognize me thank you very much Facebook, otherwise they're not, you know, my actual friends?
Same for Twitter. I signed up once a long, long time ago, and maybe tweeted once and never logged in again. Occasionally I get E-mails from them about people (bots?) who "follow" me despite my inactivity. It's likely because my twitter handle is pretty short and an actual name, so probably some people get confused and follow the wrong person.
Recently I have been busy with a new job, started meditating and reading my Kindle rather than a backlit screen. I use Facebook maybe 15% compared to a month ago. Life feels a bit better better as a result. Kind of like giving up smoking, or cutting down. It's just mental clutter.
https://sheep.horse/2013/10/the_seven_realities_of_social_ne...
You do not have a Facebook page. You never did. Facebook has a page on you.
This isn't true, at all. Facebook collects plenty of data that users and non-users don't directly give them.
1. Facebook collects on you when you interact with their systems
2. You can purposefully interact with facebook systems by requesting content from a Facebook registered IP (eg, FB.com, whatsapp, IG, Messenger, comment widget etc...)
3. You can passively interact with facebook systems by accessing a website that posts metadata/telemetry to a Facebook registered IP (eg. FB pixel etc...)
In either case you are requesting to access or interact with a facebook system, however in the latter you aren't aware of it unless you know to block it specifically.
So yes you do directly give it to them, but it's guilt by association. It's also not hidden at all, you can inspect the page and see the requests clearly [1].
I think the major issue is that 99% of people have no clue any of this is happening and just assume that they aren't under the spotlight of facebook because they aren't on facebook.com. However it's not just facebook, it's thousands of internet companies not to mention all of the ISPs and State Actors. So Facebook isn't really the issue, the issue is that people don't know or care about how their data flows around the world.
Then they stopped allowing me to clear it out. Since people--without prompting--had wished me a happy birthday, FB was sure it was my birthday, and that was that. I could leave the year blank, but the month and day were literally unmodifiable.
That's when I started clearing all the personal data out of FB I could. No likes, no group memberships, nobody allowed to "check me in," and so on. They were collecting data on me I had no provided, against my expressed will.
In this case your network opted in to Facebook and opted your data in - so again "guilty by association."
Eventually Facebook said I had an invalid name and needed to change it. So I tried changing it to another fake name, which was rejected. I tried several more, including perfectly normal names and all were rejected. Not even abbreviations were accepted, it had to be my full exact name. Facebook knew what my real name was.
Later I realized that there was a feature asking you to type in the name of your friends based on their profile picture as a security measure (perhaps for account recovery?) anyway I suspect this one way they may have flagged my account. If friends recovering their account typed in my real name enough times, but got all the other names correct they might flag my account.
You don't have to be signed in, nor do you have to actually click them. They record your visit to the site, thus track you all over the web and build shadow profiles with your web visits, even if you don't have a profile.
It's sort of a grey area. The average person doesn't know that the functionality for the buttons is loaded by Facebook, and thus they are requesting information from Facebook that exposes information about them on every page that has a like button. It's "not hidden" in the same way that a pervasive network of closed caption cameras at all the businesses you frequent being owned by one company and having access to all your interactions at all those companies. Sure, the camera is in plain sight, and if you went up to it you might see a tag that says owned and operated by Facebook if you looked, but the normal expectation is that each business would have their own recordings, not that one company would be compiling all your transactions together to track your habits and make a profile. It's not hidden per se, but it's definitely not obvious and not what is expected by the average person.
Actually, I'm wondering is someone could sue Facebook under existing stalking laws.[1]
I do not think this is true. What happens with my e-mail address when someone else signs up to Facebook and shares their contact list (with my e-mail address in it)?
How did Facebook know who my friends are the very moment I signed in, without sharing my address list?
They already have collected information on my social graph, without my own explicit permission, but with implicit permission from less tech-savy friends.
And that's nothing to say about people tagging me in Facebook pictures to train their giant DeepFace algorithm.
In both scenario's I am not accessing or interacting with a Facebook system, while my information is still being abused.
Even 2007-era Facebook encouraged users to upload/sync their email contacts to "discover friends already using it".
If someone is not European but resides in Europe, do they have this right?
If someone not from Europe travels to Europe and issues the request while inside Europe, do they have this right? (If so, would using a VPN work?)
The fact that I have to come up such mechanisms is a damning indictment of the way things are.
Which was sad, but it ultimately worked well for everyone who ended up using it before the ban. It would untag you from photos, delete your comments, wall posts, photos, information, change your name, and issue a deletion after changing your password (and emailing that to you).
> a regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU). It also addresses the export of personal data outside the EU. The GDPR aims primarily to give control back to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.
Emphasis mine.
Full text at http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:320... .
> The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person.
The specific clause concerning customers appears to be:
> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.
Regarding non-resident visitors, I can't tell. The directive says "whatever their ... place of residence" so almost certainly yes. It also contains text like "data subjects residing on its territory" so you might have problems lodging a complaint if you aren't a resident.
I have started to use Facebook recently as I needed an account for work so decided to explore a bit, my biggest problem with Facebook is that your "feed" is made up of things that your "friends" liked or posted etc... but in what seems a random order, and not all of them appear. One has to wonder what kind of weighting they apply to each post to decide if it will make it to your feed or not.
Twitter has brought something similar recently, but at least you can disable it and get a sane timeline - Just tweeted about this today (check my profile for account).
They can fill your shadow profile with photos, location and time data. It's frightening.
Indeed, curated content, which is very scary.
I few years back I started receiving mail for an account that I never created. The name is not close to mine, but a silly sexual pun.
I have mailed security and account support multiple times, asking for the account to be deleted, or decoupled from my email address, because I keep getting login attempt notifications and even friend suggestions.
Just checking, and coincidentally the very last email is one for the Facebook account. "Hey, it seems you are having trouble logging in! Click here to sign in.". Yes, Facebook, someone, for whatever reason, is trying to log in to a Facebook account for 4 years now, and won't take no for an answer... "If this wasn't you, please let us know by clicking here". Ok, Facebook, this is not me, and it was not me the last 10 times I clicked that button.
(I now assume, that this account is somehow being used to mine my social connections. Something like a public ghost account.)
Timeline:
2013: Hi Fuck, you got more friends on Facebook than you realize! List of 6 people I know IRL.
2013: Hi Fuck, you have 1 friendship request. Log in to accept.
2013: Do you know [3 people I know]?
2013: Hi Fuck, Fuck placed something on your timeline and is waiting to see it.
2013: Do you know [9 people I know]?
2014: We've updated our Terms of Service
2015: Someone asked a new password for your account.
2017: Hey Fuck, it seems you are having trouble logging in.
2017: Hey Fuck, it seems someone tried logging into your account from a new location.
2017: Hey Fuck, we received your request to reset your account password. XXXXX is your reset code.
2017: Fuck, go back to Facebook in just one click.
2017: Hey Fuck, it seems you are having trouble logging in.
I was able to shut down a couple of Instagram accounts that were using my email though. Instagram does not verify emails, but fully trusts them to reset your password.
So maybe the author of this post removed his account at an earlier period when Facebook didn't make such an honest claim. In that case the title should be "Facebook used to lie."
That page uses the phrase "permanently delete[d]" multiple times, says there's "no option for recovery," and calls out some information they do keep because it's not actually part of your count, implying that the rest is not kept.
Years ago they did not delete accounts. They would deactivate it and never delete the data. They do now (apparently), but in the past they were very openly not deleting anything.
Do we know that Facebook actually deletes accounts now?
It also still knew a heck of a lot about me including suggestions for people I had just recently met. And some of them I only met once, in passing, never exchanged info with, and never saw again.
I did delete the account before that date with few other people (mostly because of that policy coming).
I never tried coming back but if they still kept all the data, that is pretty substantional. One could sue facebook for that or am i missimg something?
They are simply looking at the current documentation and thinking "oh yeah, I must have done that, and these guarantees were supposed to apply", when of course that isn't true if those guarantees are new, or if they never followed that procedure in the first place.
I've permanently delete back in 2014 but actually needed a "ghost account" in 2016 to access some FB walled garden content.
I used the same email as my former one and data was gone, no restauration was proposed. (However friend suggestion based on email showed up due to some probable shadow account).
e.g a guy I interned for 10 years ago who I never spoke to/added on FB keeps showing up in my Insta suggestions. It's actually a bit unnerving and makes me worry who my account is suggested to.
Even if it gets reactivated, it will be useless.
It's annoying that this has to be done. There are several other well known companies that make account deletion a stupid hassle. Amazon for example should have already archived my account automatically after not being used for 7 years at all. Apple is another idiotic company that makes it hard to remove stuff from your account (you have to have a mac to disassociate credit card from your account, their web app doesn't allow it for no reason whatsoever (despite being able to add CC info there), only iTunes app on the mac can do it)
Companies should think more about account removals.
I just wrote a few document.querySelectorAll() based loops in the console that artificially clicked the right elements in the right order with some delay.
Fun thing is that while most things are very fats on facebook, deletion is super slow. It takes like 2 seconds to complete. They must have some artificial delay somewhere just to frustrate this kind of scripting.
Anyone else have similar results?
I think, it's a matter of them being required by law (won't be the case in all countries) to have true account deletion, but then they try to deflect as many users as possible from actually deleting their accounts by having an account deactivation option and having it in a far more prominent place.
Your account has been deactivated from the site and will be permanently deleted within 14 days. If you log into your account within the next 14 days, you will have the option to cancel your request.
However, as someone else mentioned, the reality is you don't have a FB account, FB has an account on you.
Now I’ve got the “Facebook handcuffs”.
Stop using Facebook and recreate accounts for everything or keep My account active.
I know FB doesn’t care but I have my own little revolt I’ve staged.
- unfriended everyone and added random people
- swapped out my info (I know they still have it)
- post some bs links and nonsense just to dork with any ML running against my account
I wish more sites added functionality to sever Facebook auth from your account.
While I'm all for bashing Facebook when they do something nefarious, this seems more to do with someone else having the author's password and using their account at an inopportune time (during the FB account deletion process).
As a refresher for all:
- FB delete != FB deactivate
- You can't log in (or let anyone else log in) for 2 weeks post FB delete through https://m.facebook.com/help/delete_account
- The only way you can be sure they delete your info is if you're in the EU, where the government has stepped in appropriately.
Facebook will very likely still know who you are, and have tons of information/"shadow profile" on you, because your friends will still post stuff there.
Does anyone know of a similar site that provides hashes? I don't need the complete list - just the hashes for my email.
You can check your own passwords (hashes recommended) through their new Password service.
Also why wouldn't I get the full details for free anywhere? HIBP obviously has them. Criminals have them. I bet it isn't that hard to find them on bittorrent.
In fact, here they are: https://hashes.org/public.php
Edit: Although that doesn't match them up with usernames, so it's not entirely useful.
Edit 2: In fact I just discovered that a long password I used to use is still in the 'not cracked' category of the Last.fm leak (unsurprising since it is 13 random alphanumeric characters). That is useful information.
For example, given the email address generic@genericmail.com, if I were to sign up for facebook with generic+facebook@genericmail.com, does the HIBP site provide a simplified method for checking all variations?
I had disabled Facebook about 3 weeks ago. For good measure, I went ahead and deleted all apps, history, or any method by which I might wander back.
Needless to say I was a bit thrown off this morning by the slew of “welcome back to Facebook” texts from my friends. I assured them somebody had created a false account, but sure enough there I was seemingly alive and well with an active profile.
The only explanation I can think of is that an application or service attempted to authenticate via Facebook connect- if this is enough to reactive an account, it damn well shouldn’t be.
Given that social media has overtaken reality for most, it feels a lot like a company unknowingly took my life and ran with it. It’s a bit eerie to scroll through a feed of your friends trying to reach you, and living your life without you. For a few days, Facebook was a more believable authority on my life than I was.
With regard to Facebook, not exactly the same thing, but in August, I tweeted that I haven't logged in to Facebook in over a month. The next day, I got an email from Facebook asking if I'm having trouble logging in to Facebook. I never gave Facebook my Twitter account. https://twitter.com/AmrEldib/status/899423898139148289
I’m also surprised that his hacker didn’t bother changing his password - maybe it wasn’t intended to be an account takeover.
But OT: I'm sure that unless they are legally forced to remove the data, they'd rather keep it.
I honestly never thought about that. Spammer accounts often are cleaned up pretty well.
Liars, cheaters, fake news and privacy violations you will found only from facebook.
I really questioning whole company morals
Turns out they never delete anything.
How is it possible this reaches so high up Hacker News? None of you have seen users (or yourselves) make similar mistakes?