- Steve Smith (Vice President, Intel)
(a) Users were duped into giving up their data under a false pretense. This alone cannot be called a breach.
Also, one of the following occurred:
(b.1) Facebook was duped into letting a fraudster install an app on their platform. If this happened, it was a breach.
or
(b.2) Facebook knew all along that the academic research was only a cover for duping users into giving up their data. If this happened then it was not a breach, because Facebook themselves effectively sold the data.
So what Facebook appears to be saying is: There was no breach. We sold the data!
[Edit] Judging by what this man says, it was probably b.2: https://www.theguardian.com/news/2018/mar/20/facebook-data-c...
My conclusion is that there was no breach.
It is WORSE than a breach, because FB is complicit.
A breach in which the custodian is complicit is still a breach, not something worse. Obviously, the its worse from the perspective of the custodians degree of responsibility if they are actively malicious rather than negligent or innocent, but this is still within the usual definition of a breach of private data. A breach is about the subject’s privacy being violated, which can happen with or without the complicity of the custodian of the data.