Edit: FB also knew the data was collected under an academic license and was being processed, outside that license, for financial gain.
Edit: FB also knew the data was collected under an academic license and was being processed, outside that license, for financial gain.
From https://twitter.com/cld276/status/975565844632821760:
> "Facebook was surprised we were able to suck out the whole social graph, but they didn’t stop us once they realized that was what we were doing."
> "They came to office in the days following election recruiting & were very candid that they allowed us to do things they wouldn’t have allowed someone else to do because they were on our side."
According to the article only ~200k people installed the app and consented. Unless there was an exploit, you get a minimal version of the data in their friend list (user id, name, that is all i really see) not a full profile. So didn't they only really get the names of 49.8 million people?
Is the solution to just not allow allow a third party token to access a friend list, and only your personal information?
I am not trying to defend what is going on, i am just struggling to see how they were able to use the extremely minimal amount of information the friend list api returns to make a full profile on 50 million people.
> What the email correspondence between Cambridge Analytica employees and Kogan shows is that Kogan had collected millions of profiles in a matter of weeks. But neither Wylie nor anyone else at Cambridge Analytica had checked that it was legal. It certainly wasn’t authorised. Kogan did have permission to pull Facebook data, but for academic purposes only. What’s more, under British data protection laws, it’s illegal for personal data to be sold to a third party without consent.
> “Facebook could see it was happening,” says Wylie. “Their security protocols were triggered because Kogan’s apps were pulling this enormous amount of data, but apparently Kogan told them it was for academic use. So they were like, ‘Fine’.”
https://www.theguardian.com/news/2018/mar/17/data-war-whistl...
It was also against the terms of service to download and store the information retrieved from the API. They also changed this many years ago, in the name of developer convenience.
I don’t see how this is worse than a targeted ad trying to get me to invest with Schwab. Also a pretty coordinated campaign. Or just Doubleclick in general.
This comes down to people wanting to limit some ads. There are already laws for political ads. Should we change them? I think they currently apply to Facebook ads.