Is it even clear that there was a 'breach' of any kind that Facebook was responsible for? Correct me if I'm wrong here, but it seems like the chain of events is:
1.) Third party (Aleksandr Kogan) creates 'personality quiz' app, Facebook users opt-in to share information from their profile
2.) Aleksandr Kogan hands off data gathered by the app to Cambridge Analytica, violating Facebook TOS
3.) Whistleblower (Christopher Wylie) lets world know that (2) happened
4.) Media / public gets out pitchforks and blames incident on Facebook
It really seems like Aleksandr Kogan, not Facebook, is the problem here.
Does it mean "friends lists", or "the data of the app user's friends profiles"? And in that second case, "the data of the app user's friends visible to the app user", or "as much data as if the friends had installed the app themselves"?
Unless it's that final situation, it's exactly how I assumed Facebook scraping worked already.
Kogan probably breached the terms he agreed to with Facebook. But fifty million people trusted Facebook with their data and, when asked in their privacy settings, said they didn't want it shared with third parties. That information was then shared with third parties.
If someone calls my bank and convinces customer service they are me, it would be reasonable to say the bank was breached. Not electronically. But breached nonetheless.
[1] 'Kogan was able to throw money at the hard problem of acquiring personal data: he advertised for people who were willing to be paid to take a personality quiz on Amazon’s Mechanical Turk and Qualtrics. At the end of which Kogan’s app, called thisismydigitallife, gave him permission to access their Facebook profiles. And not just theirs, but their friends’ too. On average, each “seeder” – the people who had taken the personality test, around 320,000 in total – unwittingly gave access to at least 160 other people’s profiles, none of whom would have known or had reason to suspect.' --from https://www.theguardian.com/news/2018/mar/17/data-war-whistl...
That's a bad analogy. A more appropriate one would be if you called your bank and told them to allow a 3rd party to have access to all of your accounts, then blamed your bank when the 3rd party drained all your accounts.
Facebook has no obligation to protect your data from yourself any more than your bank has the obligation to control what you spend your money on.
Better analogy: you call your bank to allow a third party to have access to all your accounts. My account gets drained. Still a breach.
Still not a breach of the bank, nor a breach of facebook.
The app didn't have any "extra" access or anything other than what the person who installed it would have. The app used the information that the person gave it, and that included information on friends that the person had access to. If you were impacted, blame yourself, your friends that you gave information to who gave it to a 3rd party, and/or the company that made the app.
All facebook did was make the metaphorical parking lot that you got robbed in.
While I agree that there is more they can do here to prevent this kind of thing (like specific and explicit controls on what data an app wants/needs at install time), acting like this is a breach of their information is wrong.
The problem seems to be that people do not realize what it means to agree to information access for a third party, and the question remains weather Facebook is to blame for it being release to a fourth party.
So really the problem is that people are not aware of the scope of the information aggregate of their actions on social media and how it is or may be used or abused.
And I personally don't think Facebook should be to blame for it ending up in a fourth party's hands. They gave it to the 3rd party at the request of the user. What that 3rd party does with it should be of no concern to Facebook.
If Facebook has to police what users are doing with their own data on other platforms, then strict DRM is going to become a legal necessity. That is what I see when I read comments saying how Facebook should take responsibility here.
I agree that people don't seem to grasp what it means when they click the "i agree" button, and that Facebook (and others) should work much harder on getting the user to understand the full extent of what they are doing, as well as greater control over what data is shared and when. But that's not a problem that's easily solvable (or possibly even solvable at all). And calling for Facebook to simply not accept this information (which isn't a possibility, they are a social network, so social data has to exist on their systems), or to not allow users to have control over their own information is the exact opposite of what I and many others have been fighting for for years.
If I want to export my information, or give it to a 3rd party, that is my right. And Facebook should have no ability to stop me from doing that. This will lead to people giving their personal information to parties that they do not intend to, but I feel that is a risk worth taking to keep your information yours.
OTOH you and I both know 99.99% of users don't understand what's going on with their data, so the question here is if adult users should be held responsible for something they don't understand and whether Facebook is actually responsible for not informing its users clearly of what was going on.
Do you think it would have made a difference if Facebook had used a red blinking message alerting users before sharing their personal data with a third party? I think so. So yeah, the responsibility is not 100% on Facebook's users.
Like most things in life, it's shared. Facebook should absolutely be held to a higher standard here. They should be explaining what a user is really doing when they try to do it, as well as giving more fine-grained controls over what they provide to these apps.
But I also don't think that a red blinking message would have changed anything, going by how android permissions used to work (big warning that you have to agree to saying what the app gets on install). Apps will make excuses for why they need data, users will want the app and not care or not want to think about what they are giving up, and not a damn thing will change (I can't count the number of times that I've been told "there will be a warning saying that X needs to access Y, you'll need to say yes to use this software" in various programs, and i've never seen a user say no...)
Like I said, having this ability WILL cause people to give out information they didn't mean to. There's no hesitation there, it's going to happen, and probably pretty frequently, but I still feel that's a necessary evil to allow data liberation.
Also, I think stronger legal structures would help here as well. You aren't going to stop it, so make the consequences for getting caught much more strict, and heavily punish companies that are caught using data in ways that's not okay.
Simple case: G-fucking-mail. Lot of people on it so even if you're not using it most of your emails end there with a free link to infos from other people's contact list (names, phone number etc.). Shadow profiles are what people will be complaining about 5 years from now if they just discovered what sharing things with 3rd parties mean.
...after the bank provided the infrastructure to give full control to a 3rd party, frequently encouraged me to do it and gave me the impression that I delegated access only for a specific task and a limited time - even though actually, such a limitation was impossible to implement on technical means, which the bank knew.
a) Facebook was notified that CA did not delete the data; and
b) The CA-held profiles were used to target politically motivated advertising on Facebook.
One can't avoid linking the two facts. Facebook has no incentive to aggressively protect its user data when it hurts ad spending on the platform.
If Facebook has no means to detain such malicious usage of users' data, they should be more careful to open the access of it in the first place.
That is all it is.
How about a breach of basic responsibility to inform users that their data has been used inappropriately and transferred to a third party. FB knew about this as far back as 2015[1]. Did they let users know at any point? No.
Further FB's Chief Security Officers's tweets on Friday failed to show any concern for FB users who were used as pawns. His main concern was to point out that this wasn't actually a FB problem.
And let's not forget that Mark Zuckerberg dismissed the idea that fake news on Facebook influenced the US elections as "a pretty crazy idea."[2]
So the "pitchforks" are a culmination of a significantly longer time frame and not just a reaction to this single news story.
[1] https://www.theguardian.com/us-news/2015/dec/11/senator-ted-...
[2] https://www.theguardian.com/technology/2016/nov/10/facebook-...
"Now they want to buy a lot of ads on our platform, great!
"Also their ads are getting a lot of engagement somehow, let's make it cheaper for them to buy more!"
"Over the weekend, after news broke that Cambridge Analytica had harvested data on as many as 50 million Facebook users, Facebook’s communications team encouraged Mr. Stamos to tweet in defense of the company, but only after it asked to approve Mr. Stamos’s tweets, according to two people briefed on the incident.
After the tweets set off a furious response, Mr. Stamos deleted them."
[0]: https://nytimes.com/2018/03/19/technology/facebook-alex-stam...
SLIMY
It is my understanding that GDPR will not allow for such simple workarounds by companies to just continue doing what they were doing previously.
As far as I can tell this was just an app using the API as intended. Except they did some additional modeling on their backend to organize/profile users.
They abused the TOS for sure, but was there an actual security breach?
> Zuck: People just submitted it.
> Zuck: I don't know why.
> Zuck: They "trust me"
> Zuck: Dumb fucks.
A cynic would interpret the current state of the world to suggest that Zuckerberg, and by extension Facebook, considers a large segment of the world population "Dumb fucks"
http://www.businessinsider.com/well-these-new-zuckerberg-ims...
There are many valid criticisms against Zuck, and I don't think this one quite holds value as much as the others.
What Facebook has become is technically brilliant, but the "dumb fuck" attitude shows no signs of having lessened.
No evidence he doesn’t still think it, but he doesn’t say it.
Facebook's vision for their product and the future world is appalling. Zuckerberg may be doing his best, but he continues to helm a product/service which is structurally bad for its users even before you consider the surveillance aspect. What could you possibly have in mind as evidence for Zuckerberg being any more than superficially competent for the social role he is playing?
I wish I could contradict you but I can't...a large majority of the world population is exactly like that.
(how much will be left after they pre announced the raid on twitter I don't know)