Facebook suspended the account of whistleblower who exposed Cambridge Analytica
yahoo.com
yahoo.com
Is it even clear that there was a 'breach' of any kind that Facebook was responsible for? Correct me if I'm wrong here, but it seems like the chain of events is:
1.) Third party (Aleksandr Kogan) creates 'personality quiz' app, Facebook users opt-in to share information from their profile
2.) Aleksandr Kogan hands off data gathered by the app to Cambridge Analytica, violating Facebook TOS
3.) Whistleblower (Christopher Wylie) lets world know that (2) happened
4.) Media / public gets out pitchforks and blames incident on Facebook
It really seems like Aleksandr Kogan, not Facebook, is the problem here.
Does it mean "friends lists", or "the data of the app user's friends profiles"? And in that second case, "the data of the app user's friends visible to the app user", or "as much data as if the friends had installed the app themselves"?
Unless it's that final situation, it's exactly how I assumed Facebook scraping worked already.
Kogan probably breached the terms he agreed to with Facebook. But fifty million people trusted Facebook with their data and, when asked in their privacy settings, said they didn't want it shared with third parties. That information was then shared with third parties.
If someone calls my bank and convinces customer service they are me, it would be reasonable to say the bank was breached. Not electronically. But breached nonetheless.
[1] 'Kogan was able to throw money at the hard problem of acquiring personal data: he advertised for people who were willing to be paid to take a personality quiz on Amazon’s Mechanical Turk and Qualtrics. At the end of which Kogan’s app, called thisismydigitallife, gave him permission to access their Facebook profiles. And not just theirs, but their friends’ too. On average, each “seeder” – the people who had taken the personality test, around 320,000 in total – unwittingly gave access to at least 160 other people’s profiles, none of whom would have known or had reason to suspect.' --from https://www.theguardian.com/news/2018/mar/17/data-war-whistl...
That's a bad analogy. A more appropriate one would be if you called your bank and told them to allow a 3rd party to have access to all of your accounts, then blamed your bank when the 3rd party drained all your accounts.
Facebook has no obligation to protect your data from yourself any more than your bank has the obligation to control what you spend your money on.
Better analogy: you call your bank to allow a third party to have access to all your accounts. My account gets drained. Still a breach.
Still not a breach of the bank, nor a breach of facebook.
The app didn't have any "extra" access or anything other than what the person who installed it would have. The app used the information that the person gave it, and that included information on friends that the person had access to. If you were impacted, blame yourself, your friends that you gave information to who gave it to a 3rd party, and/or the company that made the app.
All facebook did was make the metaphorical parking lot that you got robbed in.
While I agree that there is more they can do here to prevent this kind of thing (like specific and explicit controls on what data an app wants/needs at install time), acting like this is a breach of their information is wrong.
The problem seems to be that people do not realize what it means to agree to information access for a third party, and the question remains weather Facebook is to blame for it being release to a fourth party.
So really the problem is that people are not aware of the scope of the information aggregate of their actions on social media and how it is or may be used or abused.
And I personally don't think Facebook should be to blame for it ending up in a fourth party's hands. They gave it to the 3rd party at the request of the user. What that 3rd party does with it should be of no concern to Facebook.
If Facebook has to police what users are doing with their own data on other platforms, then strict DRM is going to become a legal necessity. That is what I see when I read comments saying how Facebook should take responsibility here.
I agree that people don't seem to grasp what it means when they click the "i agree" button, and that Facebook (and others) should work much harder on getting the user to understand the full extent of what they are doing, as well as greater control over what data is shared and when. But that's not a problem that's easily solvable (or possibly even solvable at all). And calling for Facebook to simply not accept this information (which isn't a possibility, they are a social network, so social data has to exist on their systems), or to not allow users to have control over their own information is the exact opposite of what I and many others have been fighting for for years.
If I want to export my information, or give it to a 3rd party, that is my right. And Facebook should have no ability to stop me from doing that. This will lead to people giving their personal information to parties that they do not intend to, but I feel that is a risk worth taking to keep your information yours.
OTOH you and I both know 99.99% of users don't understand what's going on with their data, so the question here is if adult users should be held responsible for something they don't understand and whether Facebook is actually responsible for not informing its users clearly of what was going on.
Do you think it would have made a difference if Facebook had used a red blinking message alerting users before sharing their personal data with a third party? I think so. So yeah, the responsibility is not 100% on Facebook's users.
Like most things in life, it's shared. Facebook should absolutely be held to a higher standard here. They should be explaining what a user is really doing when they try to do it, as well as giving more fine-grained controls over what they provide to these apps.
But I also don't think that a red blinking message would have changed anything, going by how android permissions used to work (big warning that you have to agree to saying what the app gets on install). Apps will make excuses for why they need data, users will want the app and not care or not want to think about what they are giving up, and not a damn thing will change (I can't count the number of times that I've been told "there will be a warning saying that X needs to access Y, you'll need to say yes to use this software" in various programs, and i've never seen a user say no...)
Like I said, having this ability WILL cause people to give out information they didn't mean to. There's no hesitation there, it's going to happen, and probably pretty frequently, but I still feel that's a necessary evil to allow data liberation.
Also, I think stronger legal structures would help here as well. You aren't going to stop it, so make the consequences for getting caught much more strict, and heavily punish companies that are caught using data in ways that's not okay.
Simple case: G-fucking-mail. Lot of people on it so even if you're not using it most of your emails end there with a free link to infos from other people's contact list (names, phone number etc.). Shadow profiles are what people will be complaining about 5 years from now if they just discovered what sharing things with 3rd parties mean.
...after the bank provided the infrastructure to give full control to a 3rd party, frequently encouraged me to do it and gave me the impression that I delegated access only for a specific task and a limited time - even though actually, such a limitation was impossible to implement on technical means, which the bank knew.
a) Facebook was notified that CA did not delete the data; and
b) The CA-held profiles were used to target politically motivated advertising on Facebook.
One can't avoid linking the two facts. Facebook has no incentive to aggressively protect its user data when it hurts ad spending on the platform.
If Facebook has no means to detain such malicious usage of users' data, they should be more careful to open the access of it in the first place.
That is all it is.
How about a breach of basic responsibility to inform users that their data has been used inappropriately and transferred to a third party. FB knew about this as far back as 2015[1]. Did they let users know at any point? No.
Further FB's Chief Security Officers's tweets on Friday failed to show any concern for FB users who were used as pawns. His main concern was to point out that this wasn't actually a FB problem.
And let's not forget that Mark Zuckerberg dismissed the idea that fake news on Facebook influenced the US elections as "a pretty crazy idea."[2]
So the "pitchforks" are a culmination of a significantly longer time frame and not just a reaction to this single news story.
[1] https://www.theguardian.com/us-news/2015/dec/11/senator-ted-...
[2] https://www.theguardian.com/technology/2016/nov/10/facebook-...
"Now they want to buy a lot of ads on our platform, great!
"Also their ads are getting a lot of engagement somehow, let's make it cheaper for them to buy more!"
"Over the weekend, after news broke that Cambridge Analytica had harvested data on as many as 50 million Facebook users, Facebook’s communications team encouraged Mr. Stamos to tweet in defense of the company, but only after it asked to approve Mr. Stamos’s tweets, according to two people briefed on the incident.
After the tweets set off a furious response, Mr. Stamos deleted them."
[0]: https://nytimes.com/2018/03/19/technology/facebook-alex-stam...
SLIMY
It is my understanding that GDPR will not allow for such simple workarounds by companies to just continue doing what they were doing previously.
> Zuck: People just submitted it.
> Zuck: I don't know why.
> Zuck: They "trust me"
> Zuck: Dumb fucks.
A cynic would interpret the current state of the world to suggest that Zuckerberg, and by extension Facebook, considers a large segment of the world population "Dumb fucks"
http://www.businessinsider.com/well-these-new-zuckerberg-ims...
There are many valid criticisms against Zuck, and I don't think this one quite holds value as much as the others.
What Facebook has become is technically brilliant, but the "dumb fuck" attitude shows no signs of having lessened.
No evidence he doesn’t still think it, but he doesn’t say it.
Facebook's vision for their product and the future world is appalling. Zuckerberg may be doing his best, but he continues to helm a product/service which is structurally bad for its users even before you consider the surveillance aspect. What could you possibly have in mind as evidence for Zuckerberg being any more than superficially competent for the social role he is playing?
I wish I could contradict you but I can't...a large majority of the world population is exactly like that.
(how much will be left after they pre announced the raid on twitter I don't know)
As far as I can tell this was just an app using the API as intended. Except they did some additional modeling on their backend to organize/profile users.
They abused the TOS for sure, but was there an actual security breach?
At 7pm GMT we had the Channel 4 News investigation[0] which featured Alexander Nix, the CEO of Cambridge Analytica, in which he appeared to be bragging to a fictional Sri Lankan businessman (who was in fact an undercover reporter) about the things they can do to discredit his opponents involving (with a delicious dose of irony) hidden cameras. Such tactics sounded a lot like they may involve trafficking of Ukrainian sex workers. There were also things that sounded a lot like blackmail and spreading of things that may not be true.
Then, just after that undercover story broke we had the Facebook raid, which really looked a lot to my untrained eye like heroic efforts to protect data of the more evidential variety from being unnecessarily breached to the authorities or the public.
At 10.30pm we got an interview [1], filmed before the undercover reporting broke, with Alexander Nix. Most memorable to me was Mr Nix seemed to attempt to confidently assure us that Dr Aleksandr Kogan had merely shared with them the gradients with which to build additional models upon and had never shared the data harvested from FB as the whistleblower in this article had alleged. We were also either told or given the impression that this was a great big misunderstanding and all part of a spectacularly coordinated attack by journalists who were upset about Trump.
[0] https://www.channel4.com/news/cambridge-analytica-revealed-t...
If you're the kind of person who votes based on targeted advertising, or the hyperbolic posts of people who vote based on targeted advertising, don't ask Facebook to change. Get the f### off Facebook.
If you don't like how Facebook is being used as an addictive propaganda tool by any and all political actors, including Facebook itself, then get the f### off Facebook.
Ask the Facebook "friends" you care about for an email address, phone number, or other messaging account and get the f### off Facebook.
You don't need up to the minute information on the playdate of your cousin's college room mate's toddler. Get the f### off Facebook.
For fuck's sake.
In Dutch, my native language, one is more likely to use diseases (kanker (=cancer), tering (=tuberculosis), typhus (=typhoid fever), etc)), hardly any sexual acts or organs (only 'lul (=dick)' really although 'mierenneuker' (=ant fucker) is also a common mild swear word), excrement (schijt (=shit), zeiken/zeikert/zeikstraal (=to piss/someone who pisses/jet of piss)), religion (verdomme (=damn), godverdomme (=goddammit).
Swedish, my second language, is not a good language for swearing as it uses rather silly, powerless words of sometimes dubious origin, mostly related to religion (fan (=the devil), satan, (i) helvete (=(what the) hell)), sexual organs (kuk (=dick), fitta (=cunt)), excrement (skit (=shit)) and what seem to be random words (sjutton (=the number seventeen...?)), weird combinations (jävla skitstövel (=devilish shit boot)).
German is the most proficient swearing language I know, both due to its rich vocabulary as well as the satisfying vocalisation offered by the language, using words from just about all categories except for diseases (wherein it differs from the related Dutch language). I also know French but my knowledge of French swear words is lacking beyond the basics.
Yeah - see that's not how it works. CA and companies like them have developed far more clever ways to influence you than targeted advertising. The best of these techniques go undetected by you, and are coordinated by machine learning systems which know more about you than you do. Basically, if you are online, you are under their influence whether you know it or not. Don't fall for the illusion that you aren't susceptible. As emotional as you appear to be from your posting style, you are exactly the kind of person that they target.
There are steps you can take to make yourself less susceptible to propaganda, and it starts with disengaging from the Huxleyan, social media, dopamine machine. Until you do that it's near impossible to get a real sense of your own cognitive biases.
If we're going to go down that line, what justice should be served to Jimmy Kimmel, who regularly pushes his political agenda in what's supposed to be a variety show?
The people that vote based on targeted advertising may not be the ones that have a problem with it. This is like if people complained the pool has too much pee in it, you told the complainers to stop peeing in it.
Facebook spent years getting billions of people on the platform and those users haven't left due to lock-in. They are connected to their families, their businesses, their friends.
I barely use Facebook anymore but because I live in a different country that's how I keep up with friends and family. If someone wanted to contact me they would do it through Facebook.
This is why I am on the fence between deleting the account and just poisoning the data.
5 years ago Facebook recruiter reached out to me and invited me to the W hotel in Chicago. I was very excited -not for the job- but for the opportunity to meet with senior Facebook managers and tell them about an evil thing Facebook does. Here is the background story:
I am Kurdish from Iran. And Iran has many provinces. one of them is called Kurdistan. In Facebook profile section for Hometown you could pick all of the Iranian provinces except Kurdistan.
And at first I thought it was a bug. For years and years we submitted bug reports and collected petitions for Facebook they never responded why the Kurdistan province cannot be picked while other provinces could be picked.
Till one day, An internal document -guidance- leaked out of Facebook. That explained it all ! One of the pages was talking about Kurdistan. In which they had explained any reference to Kurdistan is considered terrorism. That was on the request of Turkish government.
In "Turkey", the word Kurdistan is forbidden. and many people in Turkey been prisoned for speaking Kurdish. however in "Iran" we officially have a province called "Kurdistan Province). and Iranian government recognizes the name Kurdistan for my homeland. https://en.wikipedia.org/wiki/Provinces_of_Iran
But Facebook decided to enforce the Turkish government racist rule on other countries that have Kurdistan (Iran, Iraq, Syria...)
Also in that leaked guidance memo. Kurdistan flag was considered illegal. And hundreds of Kurdish pages and accounts got banned for having Kurdistan flag.
While Kurdish flag is illegal in Turkey. Kurdish flag is officially recognized in the Constitution of Iraq for Kurdistan regional government.
So when they invited me to W Hotel to recruit me. I was like yes finally I can meet the people in person. Because as a Kurd I have no importance and they will never respond to me but a software engineer I am pretty attractive on the market.
So I asked the question from one of the managers. And told them my story this for years and years I send them emails and nobody got back to me and we made petitions about this so-called bug.
He said these things are decided by higher management.
I told him how often do you show this disagreement to higher managers or Mark Zuckerburg's policies if you have a different opinion. He responded if I disagree with them I wouldn't work there.
I left the W Hotel in Chicago 5 years ago refusing to proceed with a job on FB. I knew Facebook is on the wrong path. And today I see that prediction coming true.
Even today when Turkey committed a massacre in Kurdish city of Afrin, Facebook blocked many voices inside the city who were showing massacres by Turkish government.
10 years ago FB came after kurds and you said not my problem. Today they are coming after all of u
Facebook's culture has a pretension that their internal policies is something like the law itself:
https://talkingpointsmemo.com/edblog/facebooks-heading-towar...:
> Facebook is so accustomed to treating its ‘internal policies’ as though they were something like laws that they appear to have a sort of blind spot that prevents them from seeing how ridiculous their resistance sounds. To use the cliche, it feels like a real shark jumping moment. As someone recently observed, Facebook’s ‘internal policies’ are crafted to create the appearance of civic concerns for privacy, free speech, and other similar concerns. But they’re actually just a business model. Facebook’s ‘internal policies’ amount to a kind of Stepford Wives version of civic liberalism and speech and privacy rights, the outward form of the things preserved while the innards have been gutted and replaced by something entirely different, an aggressive and totalizing business model which in many ways turns these norms and values on their heads. More to the point, most people have the experience of Facebook’s ‘internal policies’ being meaningless in terms of protecting their speech or privacy or whatever as soon as they bump up against Facebook’s business model.
I can't find a reason to fault Facebook's response to this harmful government policy. Would it be better to allow people to select the "Kurdistan" option, knowing full well that this could cause people to be imprisoned, or killed? "Facebook disallows selecting of contested regional identities" is bad, but not nearly as bad as "Facebook helps oppressive governments hunt down disenfranchised people".
Situations where countries try to dictate this kind of thing outside their borders produce stupid bad results. A previous example: no maps are legal in both India and Pakistan. https://blogs.msdn.microsoft.com/oldnewthing/20030822-00/?p=...
For individuals, "Banned from Facebook" has a similar note. For a time now, Kurdish interests have been prosecuted by Facebook. And not just in Turkey.
1- The story I am talking about was 5 years ago, at that time you could not select Kurdistan in hometown. it was the previous version of facebook profile (before they change it and it was like that for more than 10 years) we fought 10 years, hundreds thousands of pettitions. so your screenshot is Irrelevant.
The story of kurdish accounts being banned for having Kurdish flag is still true, specially during the massacare that happened in the city of Afrin Massacre just a few days ago.
2- I did not work at FB, FB reached out to me to hire me, I went there and I asked them the questions inside FB. I will NEVER ever work for FB. Crappy technologies, Crappy company, not inline with my values.
4- They invited me to W hotel in Chicago, I might still have the conversation in my LinkedIn, what are you trying to say ? are trying to imply I made this story up ? I believe the the recruiting team (including managers and developers) was visiting Chicago, and the job was not in Chicago.
The leaked document inside facebook was also verifies a lot of things I said. (the leaked document was very old not sure how many years ago 6-7 years ago maybe) that they clearly had examples of what flags to and what words to ban. including innocent kurdish flags.
The ban of other languages than Turkish came after 1980 military coup and as far as I know the law abandoned in 1991. I don't think there are any cases where someone was imprisoned solely because they spoke Kurdish.
If only there was a way to create a bill of rights to protect us against corporations... if only there was a force more powerful than them that could keep them in check ... Maybe we'd give this force a monopoly on violence so they could protect us from the fucking assholes at Facebook... If only /s
Which is what is happening. The initial headline called it a breach and it isn't all that inaccurate to call it a breach, so it stuck.
Kogan was granted permission to ephemerally use, for academic purposes, the data of a quarter of a million people who authorized the access. Kogan got fifty million peoples' data (i.e. Facebook let him scrape the data of people who had not given authorization, some of whom had explicitly gone into their privacy settings to turn off the sharing of their data with third parties), kept it, and then forwarded a copy to CA.
There were no systemic barriers in place that Kogan had to circumvent to get access to the data; the Facebook API worked as expected and gave it to him. Regardless of the original “purpose” of the app (a small textarea input you supply to FB), the API would provide the data. The “purpose” of an app does not affect what data is available to it in any meaningful way.
The idea that he should have notified Facebook of the changes is laughable; all he had to do is change a few text inputs to update the TOS. The FB platform does not treat an app differently based on its purpose. This is CYA language from FB trying to obfuscate the fact that any and every app has access to this same data, and FB has no control over what happens to the data once an app extracts it. Indeed, much of their business model depends on this premise.
Further, the practice of changing terms / functionality of an app is a laughably commonplace way of circumventing the nearly non-existent FB platform review process.
I have personally seen much worse incidents of FB app abuse in the wild. For example I once reverse engineered a top 10 iOS social app and discovered they were injecting custom JS into the WebView provided by FB to get the ID of all your friends, rather than the top 50 you can see. The app’s FB “app” was classified as a game which gave it the requisite permissions for abuse and even allowed the app to secretly invite all your FB friends to it without you ever knowing.
"Breach" doesn't have to involve a technical malfunction. An employee handing confidential information to an outsider is a breach. Facebook collected users' information. The information was accessed, stored, and distributed without Facebook's (nor their users') authorization. That's a breach.
The crucial point here is that the users authorized the app to collect the data. Facebook has an extremely extensive authorization system for you to grant apps access to your data. Did Kogan use this system differently than every other FB app? What technical measures did he need to circumvent in order to get access to the data that you say constitutes a “breach?”
To me, it looks like the system worked exactly as designed and intended. The only system he really circumvented is the honor system, which is about the only limitation on what an app can do with the data FB gives to it.
A quarter of a million people authorized the app to collect their data. It then gained access to fifty million peoples' data. Those extra data were accessed without proper authorization. All of the data were then used in an unauthorized manner.
> What technical measures did he need to circumvent in order to get access to the data that you say constitutes a “breach?”
"Breach" isn't constrained to technical vulnerabilities. If an FSB agent walks out of Langley with a bunch of sensitive CIA documents, that constitutes a breach.
Kogan exploited Facebook's lack of verification around restricting third parties' data access to that which users had authorized to be accessed by third parties. He should have only been able to collect a quarter of a million users' data. He was given access to more than he was properly authorized to access.
Kogan also exploited Facebook's lack of verification around his use and retention of the former's users' data.
> Yet the bug is the system itself
Which is why we're talking about regulation.
Regulation to say what? That people can't freely give away their own data? To tell Facebook not to share people's data with other apps, even if the users themselves authorize it?
I don't really care if you want to give a lot of your personal data in exchange for filling out a quiz that is unrelated to what your personal data will be used for, but the network effect (combined with how many things your "facebook friends" can see) of Facebook means that other people in your social graph should care.
(FWIW, I agree that "breach" is the wrong word. It's far too soft on Facebook. "Exploitation of the soon-to-be-criminal disrespect for users' privacy" is much more accurate IMO.)
We may very soon see a software developer expounding on all of these "clean code" principles before congress as their defense. How conventional wisdom, and industry wide best practices recommend that software be built in a manner that lends itself to all of these positive effects that allow large software projects and companies to proliferate in the first place. Separation of concerns being the main concept that comes to mind. Is this the 21st century's "just following orders"?
The main problem Facebook seem to have is that the wrong candidate won the 2016 presidential election and the press need someone else to blame.
Incidentally, based on the reporting come out of the Trump campaign, it's not clear they were even doing much or anything in this area. Their campaign leaned heavily on exactly the kind of "political gut instinct" that article decries - used as an input to models rather than directly, and augmented with stuff like A/B testing, but still nothing like the data-guzzling microtargeting machine of Obama 2012. There doesn't seem to have been much sign of CA involvement aside from the initial check the campaign wrote them and their attempts to use Trump's victory in their marketing.
Starting around 11:00
The CA person clearly shows, from the screenshots, they have personal level targeting to predict whether a person is neurotic or not, what ads should be used to exploit that.
Not only that, the one campaign we can confirm did use CA's tech - Ted Cruz in the primaries - flopped, and it certainly didn't get rave reports on its accuracy, ability to convince, and understanding of how they thought from those it was targetting.
Edit: Brad Parscale's actually on video saying that the campaign didn't use psychographics because they didn't think it actually worked: https://www.cbsnews.com/video/secret-weapon/ (6:35ish).
This is not dissimilar to the idea that Russia spending a few million dollars on Facebook ads and automated Twitter bots somehow played a defining role in influencing an election. Even within the context of 1.5yrs+ of 24/7 mainstream TV/internet news coverage, billions of dollars in marketing spend by both parties, the personal influence of two of the most famous celebrities in American history (Clintons and Trumps), a multi-decade legacy of highly partisan politics, etc, etc.
It seems measuring the real-world impact of these tools and tactics is completely ignored in favour of believing we're living in some fantasy scifi world where bots and pseudosciencey psychological profiles can make anyone president.
Has anyone asked how much impact these tools have had on the sales of consumer products over the last decade? If they've hardly revolutionized online advertising of consumer products to make people buy products they didn't want (which AFAIK it hasn't), I highly highly doubt it played a huge role in the election of someone a portion of the voting populace didn't want.
Yes, it's probably unknowable how effective the russian bots were exactly.
Possibly but I'd say it's a very safe bet the amount of outrage and blame being put on this foreign super villain boogieman with his infinitely powerful technology far far outweighs it's real world influence.
Oh well, I'm sure it will be a boon for the tech industry the more people believe in this magical nonsense.
Source: ABC News https://www.cbsnews.com/news/trump-campaign-phased-out-use-o...
You'd have us believe Cambridge Analytica was some vendor the Trump Campaign used sparingly, had very loose connections with, and saw limited success with.
Yet Cambridge Analytica is a Robert Mercer and Steve Bannon outfit. Steve Bannon, the campaign manager, and senior adviser to the president. Or at least it was during the time period in question. Steve Bannon was THE integral player who essentially managed the creation of the tool.
Here's a video of Brad Parscale gushing about the software tool they were able to use to glean insights that lead them to spend heavily in the states that mattered, but we're not in the conventional wisdom.
While your at it, here's the story from the software developer turned whistle blower himself:
https://www.theguardian.com/news/2018/mar/17/cambridge-analy...
Claiming that Obama's campaigns were the true microtargeters, and that if we are angry at the actions of generic people, we must then be angry at Obama, because he did these very things. That is the Whataboutism, or tu quoque fallacy.
In lieu of anything to back that claim up, I'll just stick with Hutchins Razor, and reply "Nuh Uh."
Obama's campaigns were pretty well known to be engaged in extensive microtargeting. Here:
https://www.mediavillage.com/article/how-data-and-micro-targ...
Well, it must not be that bad if it doesn't bother you when "your side" does it.
What if... and try to stick with me here, because this is a pretty radical thought here in 2018... what if both sides are doing a despicable thing, and rather than argue with each other about "whataboutism" we should resist both of them?
(In this particular case, I don't think that the campaigns did the exact same things... I think they've been doing all they can possibly get away with for a very long time. So it gets worse every campaign not necessarily because anybody is worse than ever before, but because especially in this century, every four years "all they can possibly get away with" has been growing like gangbusters.)
So you can blame the countless people employing this tactic maliciously, including the House of Representatives Intelligence Committee, for any disproportionate skepticism I apply to its use.
[0] https://www.cbsnews.com/news/trump-campaign-phased-out-use-o...
As for the parent, people love to cry about whataboutism, but it is useful to see how people respond when something is done by their favored politician versus an opponent.
The data collection discussed today used API creds granted to an academic who then used the data he collected through the lens of academic survey for commercial gain, passing it to a 3rd party (CA) not listed in the FB app/api and this seems to be the crux of the violation.
If you pay a company for a service, and then use the service against the terms of use, putting millions of people into danger, you have created a massive data breach of unauthorized data access that has massive real-world physical consequences.
This was a data breach of the highest order.
But they did authorize data acquisition which means they weren't "breached" but fully consented to handing over the data.
Be like HN saying I can read all the comments I want but can't copy them to my hard drive, if I did copy them and used them for some other purpose would this also be a "textbook definition of a data breach"?
Users did not authorize the app to do any of this. You are incorrect in that assumption.
This was a data breach. Facebook also knew about it and did not care. It is a data breach made worse by likely criminal negligence.
Edit: I have been (temporarily?) banned from replying or writing comments on HN. Maybe it is because of all the downvotes. Here is my response to the comment reply below (and with this, goodbye, I'm no longer allowed to post on HN I guess).
> In what sense did they 'not authorize' this?
Users did not authorize the data that was collected by these apps to be retained for more than a day or two, as described by Facebook's terms of service for CA using the data.
Are you saying their accounts were hacked? In what sense did they 'not authorize' this?
From Facebook's perspective, what happens when if csv file gets released publicly. Or a government official or law-enforcement officer sees it. It apparently has >50M real-names connected with political affiliation, gender, sexuality, home town, etc. It is an email attachment away from getting released by a whistle-blower...
So even if the data was taken with scraped without unauthorized privileges, what happens when that data becomes public. Has there (yet) been a public leak of millions of private facebook-like or gmail-like profiles? Sure emails, sure PII, but ever 50M people's admitted sexuality linked to their real name leaked to The Pirate Bay?
I'm wondering if I should start a seed of the ~300-500 million useds info in JSON files (I was only interested in name, sex, profile photo) I was able to get from facebook via the thousands of credentials people check in on public repos that everyone else can still do today (beyond the name, sex and profile photos)… but I've been hording it to start up in Indonesia the project I shut down in the US (seeding profiles used to crowd source fur thing information about people like geoip location graphs of people interested in them, pseudo anonymous messaging if you have their email [acting as an email forwarder], and other personality information, and having it publicly accessible by default and/with an api). I'd be willing to give it away to any who ask though as long as they build something with it.
In the past me and my friend monetized with adsense, but now were going to mine monero while people engage with the site and give up information about their friends/enemies/lovers.
We half joked about being an "open source" NSA/BND/[insert ones favorite SIGINT acronym] or what it would be like if everyone had access to the data to leverage for their own ends instead of the privileged few do today.
Thank you "open graph", oauth and the weakest link, other developers and the apathy of most people.
Either way, this genie is not going back into the bottle unless you can convince billions of useds of platforms like facebook to exercise some discretion over things they, for the most part, don't care about nor choose to understand on a technical level.
This Twitter user has numerous posts about this. Not sure exactly who they are, but they have multiple sources of information about this story. https://twitter.com/emlas/status/975138624911151104
I feel extremely concerned also that new generations are growing up without knowing how the web was intended to be de-centralised and "free" and self-correcting.
Maybe that doesn't work at scale and things need regulation, but I feel like there was a chance to set culture and tone so that even when a large number of people would come on to the Internet, it would be more with a Wikipedia like attitude perhaps.
Now imagine if the first introduction to the Internet for a billion-ish people in India (current penetration is 460mil) would have been through Facebook's internet.org. Imagine if that happened in a country as large as India set that precedent for other countries with low internet penetration.
I used to scoff in university at a batchmate who told me over lunch that he doesn't use gmail because Google is too large and could become evil. I'm not scoffing anymore I guess.
Just a side-note, Channel 4 is an entirely separate wholly commercial public-service broadcaster, whereas the BBC is publicly funded via a license that's required to watch live TV
For completeness, from [1]:
>Although largely commercially self-funded, it is ultimately publicly owned; originally a subsidiary of the Independent Broadcasting Authority (IBA),the station is now owned and operated by Channel Four Television Corporation, a public corporation of the Department for Culture, Media & Sport […]
This guy was not just an observer of unethical practices. He was the technical lead for this behavior.
Whistleblower protections usually shield you from retribution by your employer. What people argue for when they criticize Facebook over this is more akin to immunity.