The main problem Facebook seem to have is that the wrong candidate won the 2016 presidential election and the press need someone else to blame.
Incidentally, based on the reporting come out of the Trump campaign, it's not clear they were even doing much or anything in this area. Their campaign leaned heavily on exactly the kind of "political gut instinct" that article decries - used as an input to models rather than directly, and augmented with stuff like A/B testing, but still nothing like the data-guzzling microtargeting machine of Obama 2012. There doesn't seem to have been much sign of CA involvement aside from the initial check the campaign wrote them and their attempts to use Trump's victory in their marketing.
The data collection discussed today used API creds granted to an academic who then used the data he collected through the lens of academic survey for commercial gain, passing it to a 3rd party (CA) not listed in the FB app/api and this seems to be the crux of the violation.
Starting around 11:00
The CA person clearly shows, from the screenshots, they have personal level targeting to predict whether a person is neurotic or not, what ads should be used to exploit that.
Not only that, the one campaign we can confirm did use CA's tech - Ted Cruz in the primaries - flopped, and it certainly didn't get rave reports on its accuracy, ability to convince, and understanding of how they thought from those it was targetting.
Edit: Brad Parscale's actually on video saying that the campaign didn't use psychographics because they didn't think it actually worked: https://www.cbsnews.com/video/secret-weapon/ (6:35ish).
This is not dissimilar to the idea that Russia spending a few million dollars on Facebook ads and automated Twitter bots somehow played a defining role in influencing an election. Even within the context of 1.5yrs+ of 24/7 mainstream TV/internet news coverage, billions of dollars in marketing spend by both parties, the personal influence of two of the most famous celebrities in American history (Clintons and Trumps), a multi-decade legacy of highly partisan politics, etc, etc.
It seems measuring the real-world impact of these tools and tactics is completely ignored in favour of believing we're living in some fantasy scifi world where bots and pseudosciencey psychological profiles can make anyone president.
Has anyone asked how much impact these tools have had on the sales of consumer products over the last decade? If they've hardly revolutionized online advertising of consumer products to make people buy products they didn't want (which AFAIK it hasn't), I highly highly doubt it played a huge role in the election of someone a portion of the voting populace didn't want.
Yes, it's probably unknowable how effective the russian bots were exactly.
Possibly but I'd say it's a very safe bet the amount of outrage and blame being put on this foreign super villain boogieman with his infinitely powerful technology far far outweighs it's real world influence.
Oh well, I'm sure it will be a boon for the tech industry the more people believe in this magical nonsense.
Source: ABC News https://www.cbsnews.com/news/trump-campaign-phased-out-use-o...
You'd have us believe Cambridge Analytica was some vendor the Trump Campaign used sparingly, had very loose connections with, and saw limited success with.
Yet Cambridge Analytica is a Robert Mercer and Steve Bannon outfit. Steve Bannon, the campaign manager, and senior adviser to the president. Or at least it was during the time period in question. Steve Bannon was THE integral player who essentially managed the creation of the tool.
Here's a video of Brad Parscale gushing about the software tool they were able to use to glean insights that lead them to spend heavily in the states that mattered, but we're not in the conventional wisdom.
While your at it, here's the story from the software developer turned whistle blower himself:
https://www.theguardian.com/news/2018/mar/17/cambridge-analy...
[0] https://www.cbsnews.com/news/trump-campaign-phased-out-use-o...
As for the parent, people love to cry about whataboutism, but it is useful to see how people respond when something is done by their favored politician versus an opponent.
Claiming that Obama's campaigns were the true microtargeters, and that if we are angry at the actions of generic people, we must then be angry at Obama, because he did these very things. That is the Whataboutism, or tu quoque fallacy.
In lieu of anything to back that claim up, I'll just stick with Hutchins Razor, and reply "Nuh Uh."
Well, it must not be that bad if it doesn't bother you when "your side" does it.
What if... and try to stick with me here, because this is a pretty radical thought here in 2018... what if both sides are doing a despicable thing, and rather than argue with each other about "whataboutism" we should resist both of them?
(In this particular case, I don't think that the campaigns did the exact same things... I think they've been doing all they can possibly get away with for a very long time. So it gets worse every campaign not necessarily because anybody is worse than ever before, but because especially in this century, every four years "all they can possibly get away with" has been growing like gangbusters.)
So you can blame the countless people employing this tactic maliciously, including the House of Representatives Intelligence Committee, for any disproportionate skepticism I apply to its use.
Obama's campaigns were pretty well known to be engaged in extensive microtargeting. Here:
https://www.mediavillage.com/article/how-data-and-micro-targ...
Kogan was granted permission to ephemerally use, for academic purposes, the data of a quarter of a million people who authorized the access. Kogan got fifty million peoples' data (i.e. Facebook let him scrape the data of people who had not given authorization, some of whom had explicitly gone into their privacy settings to turn off the sharing of their data with third parties), kept it, and then forwarded a copy to CA.
There were no systemic barriers in place that Kogan had to circumvent to get access to the data; the Facebook API worked as expected and gave it to him. Regardless of the original “purpose” of the app (a small textarea input you supply to FB), the API would provide the data. The “purpose” of an app does not affect what data is available to it in any meaningful way.
The idea that he should have notified Facebook of the changes is laughable; all he had to do is change a few text inputs to update the TOS. The FB platform does not treat an app differently based on its purpose. This is CYA language from FB trying to obfuscate the fact that any and every app has access to this same data, and FB has no control over what happens to the data once an app extracts it. Indeed, much of their business model depends on this premise.
Further, the practice of changing terms / functionality of an app is a laughably commonplace way of circumventing the nearly non-existent FB platform review process.
I have personally seen much worse incidents of FB app abuse in the wild. For example I once reverse engineered a top 10 iOS social app and discovered they were injecting custom JS into the WebView provided by FB to get the ID of all your friends, rather than the top 50 you can see. The app’s FB “app” was classified as a game which gave it the requisite permissions for abuse and even allowed the app to secretly invite all your FB friends to it without you ever knowing.
"Breach" doesn't have to involve a technical malfunction. An employee handing confidential information to an outsider is a breach. Facebook collected users' information. The information was accessed, stored, and distributed without Facebook's (nor their users') authorization. That's a breach.
The crucial point here is that the users authorized the app to collect the data. Facebook has an extremely extensive authorization system for you to grant apps access to your data. Did Kogan use this system differently than every other FB app? What technical measures did he need to circumvent in order to get access to the data that you say constitutes a “breach?”
To me, it looks like the system worked exactly as designed and intended. The only system he really circumvented is the honor system, which is about the only limitation on what an app can do with the data FB gives to it.
A quarter of a million people authorized the app to collect their data. It then gained access to fifty million peoples' data. Those extra data were accessed without proper authorization. All of the data were then used in an unauthorized manner.
> What technical measures did he need to circumvent in order to get access to the data that you say constitutes a “breach?”
"Breach" isn't constrained to technical vulnerabilities. If an FSB agent walks out of Langley with a bunch of sensitive CIA documents, that constitutes a breach.
Kogan exploited Facebook's lack of verification around restricting third parties' data access to that which users had authorized to be accessed by third parties. He should have only been able to collect a quarter of a million users' data. He was given access to more than he was properly authorized to access.
Kogan also exploited Facebook's lack of verification around his use and retention of the former's users' data.
> Yet the bug is the system itself
Which is why we're talking about regulation.
Regulation to say what? That people can't freely give away their own data? To tell Facebook not to share people's data with other apps, even if the users themselves authorize it?
I don't really care if you want to give a lot of your personal data in exchange for filling out a quiz that is unrelated to what your personal data will be used for, but the network effect (combined with how many things your "facebook friends" can see) of Facebook means that other people in your social graph should care.
(FWIW, I agree that "breach" is the wrong word. It's far too soft on Facebook. "Exploitation of the soon-to-be-criminal disrespect for users' privacy" is much more accurate IMO.)
We may very soon see a software developer expounding on all of these "clean code" principles before congress as their defense. How conventional wisdom, and industry wide best practices recommend that software be built in a manner that lends itself to all of these positive effects that allow large software projects and companies to proliferate in the first place. Separation of concerns being the main concept that comes to mind. Is this the 21st century's "just following orders"?