Zuckerberg on Cambridge Analytica situation
facebook.com
facebook.com
As for the rest of it, it's progress. It seems like a lot of good changes, but Analytically Facebook execs probabaly summarized that this is the least they had to do to stave off regulations or monopoly anti trust from congress. Any less, regulations would still be placed on them so it's brilliant strategy to do this and frame it in a way that Facebook is concerned about all the damage and we voluntarily do this for you instead of the truth which was we knew about this forever and only are doing it because of threat of regulations.
Overall, an optimal outcome for all parties currently, except for society as a whole down the line
At the very start of Facebook platform the API would anonymize the user's email address, the app would get an app-specific hash, e.g. abcdefg-app123456@facebook.net It was a working email address with Facebook handling the forwarding.
This proved futile as the very first thing that apps then did was to ask users for their real email address.
* someone used Facebook Connect to login to NYTimes Web site, curious about their Food & Recipes newsletter, wants to sign up
* someone logging into e-commerce shop through Facebook Connect, making a purchase and then deciding that yes, they would like to track and manage their order on the retailer's Web site, and they will even sign up for an account with retailer to do that
There's really no way to check if someone has made a copy of data if you've given them that data.
It's not that hard to check if an application prompts a user for an email address.
> we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications.
To generalize the issue, if you were in charge of APIs at some company A and some company B (not necessarily located in your jurisdiction and not necessarily subject to the same legislative framework as you) told you they used to have the data, but deleted it since then, what additional measures would you recommend company A pursue?
Zuck's announcement seems to have a decent outline -- start with investigating apps with access to large amounts of data, audit apps with strange behavior. But after a year, after the CA (and other) controversies are forgotten, what I was thinking was that FB should be doing regular, random audits/investigations, and publicize the punishment.
I don't mean identifiable shaming, e.g. "Last week, we banned Jane Smith and her Flappy Farm app for misusing the data of 3,000+ users". But maybe weekly/monthly tallies of apps that were shut down or sanctioned, and a breakdown of the reasons why, and users affected, etc. Every once in awhile, an app maker might post a "We Fucked Up" article on HN, which helps even more in reminding people of TOS.
Basically, FB should introduce an App-Engine like platform where the backend of any 3rd-party application that uses FB data has to run on FB-owned servers. Developers of these applications would then ship their code to FB (similar to Heroku) and run in a sandboxed environment where they are not allowed to take data out at all.
That way FB can audit how the data is being used at anytime and kick out people who are out of compliance with their terms. If a user deletes their FB account, now all their data could be deleted from any 3rd party applications automatically. This is basically similar to the way the government handles classified data.
Would that work for mobile apps?
This is even before we get into trust issues most developers would have with Facebook having access to their user data.
Most would be correct - some flows like inviting friends to an app, or showing friends who also happen to use this app (for games, etc.) are so common that they're integrated into the Facebook SDK.
For performance reasons (both on Facebook's end and for the sake of user's experience, just in case his phone moved into a zone with inferior coverage) a fat network request was preferred to multitude of thin small ones - you couldn't really predict when the user would fancy inviting their friends, saving their score, looking at their achievements, or checking out friends who are in same town as them - so a 24-hour cache policy was instituted.
Or perhaps their could be a limited capability for developers to log in to their app as another user of it, but those accesses would be logged and periodically audited (just like the as-another-user-logins of regular FB engineers are).
+--------------+ +----------+ +--------------+
| | | | | |
| other server | | Server | | other server |
| | | | | |
+-------+------+ +----+-----+ +-------+------+
^ | ^
| | |
| http request |
| containing user |
| data for UI |
http request made | rouge http request
with a legit purpose | sending the user data
say fetching assets v to some other server
| +-------+-------+ |
| | | |
+------------+ mobile app +--------------+
| |
+---------------+
And there is really no way of knowing which requests are for legit app purposes and which would be leaking data. Now, you could require that the mobile app make no requests to any service but Facebook, which brings two questions:1. can facebook do this? Apple could; they approve apps and get the binary/manifest before the app is released. But how could Facebook enforce this?
2. would developers be ok with this? Relying 100% on facebook?
It is an option, I'm not saying it's infeasible. An interesting idea for sure, thanks for sharing!
2) Developers simply wouldn't have a a choice in the matter - FB is so big that they can force the market in a certain direction if they want to.
All of this tends to trade one problem for another, though: the user no longer has to worry that the third-party app has access to their Facebook data. But now the user has to worry that Facebook has access to their third-party app data.
This is the status quo as of the 2014 platform policy changes.
The entire debacle is around the data retrieved (and saved) prior to that, which is what Cambridge Analytics has done.
> Or perhaps their could be a limited capability for developers to log in to their app as another user of it
FB Developer app has support for test users, who are marked as such.
How about the ones they agreed to with the FTC in 2011 [1][2]?
[1] https://www.ftc.gov/sites/default/files/documents/cases/2011...
[2] https://www.ftc.gov/news-events/press-releases/2011/11/faceb...
I think the only sane response would be to shut down the developer program. I doubt it contributes much to the FB bottomline and it's clearly something FB doesn't care much about given the breadth of this scandal.
Offtopic but i cant help it. You get what you measure. Which is why economies that only measure profit optimize for nothing but profit. When a nationstate says "It's illegal to do X" but has mandatory accounting practices that do not measure X but only measure profit, we should not be surprised that companies like Facebook do awful things. the GAAP has all but ensured that this happens. You want companies to have values? Then measure values! (alongside profit, not inspite of) https://en.wikipedia.org/wiki/Generally_Accepted_Accounting_...
We don't need accountants to measure legality. That's what we have law enforcement and courts for. Investors care about profits; behaving illegally should hurt profits. Deputising a multi-billion dollar company's thousands of shareholders as its moral police is an absurd proposal.
In the 1930s, the Congress realized that financial crimes were (a) prevalent, (b) serious and (c) difficult to investigate and prosecute. So it created the SEC [1]. Its specialists, with the budget, focus and mandate to pursue securities-related violations, have been effective (relative to pre-1930s finance).
Regulators make rules. They also enforce them. We have no top cop for technology. The costs of that gap are becoming apparent.
https://www.theguardian.com/sustainable-business/2014/oct/01...
Also check out the MSCI links in my other comments to this thread if you have a chance.
How do you record company/moral values into Books of Accounts? How does one audit those morals? What category do you assign it under: Asset, Liability or Owners Equity? And moreover, what would happen if morals change and some are deemed obsolete? Also, if you start to measure company values then it becomes obvious that other things that have been kept out of purview of the Books would want to have an equal footing too; like: legal contracts with clients, employee agreements, court cases, so on and so forth.
There is a very good reason why accounting standards (like GAAP or IFRS) decided to only record transactions into the Books and not be concerned with legalities or moralities. It's impossible to assign an amount to a company/moral value as what is valuable to me as a shareholder may not be considered valuable to say the local tax authority or an would be investor and vice versa.
Please note that I am only replying in the context of GAAP (which you mentioned). If not, I agree with all the ideas you presented and only disagree on the one aspect of it being added to the GAAP/IFRS standards as the purpose of it's creation was to precisely steer away from unknowns and only record the knowns.
Goodwill, Brand (which contains value statements), IP, etc, they're given financial value. Perhaps these don't influence shareholder/public actions as much as they could, but the measures are there at least.
Intangibles can be bought and sold as they aren't attached to anything emotional. Moral behaviours/values, if embedded into the books, have to be through a transaction. How do you transact moral behaviour/values? That is the question I have.
> Goodwill, Brand (which contains value statements), IP, etc, they're given financial value. Perhaps these don't influence shareholder/public actions as much as they could, but the measures are there at least.
Accounting principles state that for anything to be recorded in the Books a prior transaction should exist. Brand and Goodwill, by accounting principles, are only recorded after they are transacted the first time. What that means is: Say you start an enterprise. The enterprise over its lifetime acquires a Brand value. However, you cannot record that Brand value until the enterprise is sold to another entity. Only in that scenario, can the buying entity record it into it's Books as Asset.
EDIT: IP, Copyright or Patents on the other hand can be recorded as Intangibles because you "bought" it from an issuing entity (the Government or any other body which is issuing you the certifications in exchange for a monetary value). Hence a transaction exists prior to the recordation in the Books which has valued the asset.
EDIT: To explain better: The reason you cannot record a Brand value into the Books until it's either sold/acquired is primarily because there is no way to gauge the value of Brand/Goodwill. I may consider my enterprise Brand value to be a million dollars. But you might consider it to have no value. Unless a transaction occurs, a value cannot be arrived at as it inherently has no value. Hence the recordation in the Books happens only and only after a transaction takes place.
(I see now our replies crossed so will leave this and stop posting :)
We will make X and Y the value statements of our company/brand. If our actions reduce the value of X and Y statements, what will that cost us? This at least would provide a 'rough' starting value, to be reviewed/measured against market response. Do companies already do this? I'd think it important for service/advertising based companies (but I am guessing, I have only couch-potato knowledge).
Mashing value metrics in to accounting practices seems problematic at best.
On the whole I think it's a tricky subject because we want to be careful not to stifle innovation, and sometimes problems only become evident after quite a few pavers have been laid on the road of good intentions.
https://www.msci.com/esg-ratings
https://www.msci.com/research/esg-research
Recommended watching the following TED video to introduce the topic: https://www.ted.com/watch/ted-institute/ted-state-street/aud...
Why would they intend for it to happen? They didn't make any money off of this exfiltration, CA paid people via Mechanical Turk to install the application so that they could mine their data. Facebook didn't get a dime. In fact, they have a monetary interest in preventing this, because their data is worth something and these guys just got it from free usage of their API. So the insinuation that Facebook wanted this to happen, or looked away because it benefited them, makes zero sense.
What kind of safeguards are you imagining? How do you have 3rd parties interface with Facebook without letting those applications reason about the information within a Facebook account? Tinder is valued at over a billion dollars and it's not possible to use it without a Facebook account-- should Facebook shut that down and ban the entire concept of 3rd party Facebook interaction?
I do not understand the anger. They did nothing wrong. I can't believe that people are legitimately arguing that users shouldn't have a right to expose their information to apps.
Are you honestly suggesting that CA wrote Facebook a check?
> We'll require developers to not only get approval but also sign a contract in order to ask anyone for access to their posts or other private data.
Sounds like they'll make the developer agreement legally binding so they can take legal action for violating the ToS.
It's even mentioned in that article how to get around the fix they put in so you couldn't target a group of less than 20 people.
I'm not sure if this particular method still works, but let's take a step back and think before we make claims about what is and is not possible in a complex system with lots features and knobs to twiddle. Whether this was an emergent feature from other features of the system or a specifically desired and designed behavior, at least at one point Facebook allowed very fine grained targeting.
1: http://ghostinfluence.com/the-ultimate-retaliation-pranking-...
That said, since you can target specifically, if the system did allow some way to exfiltrate user data, it would make financial sense for larger analytics companies to do so to provide value-added services where they could target much more specifically than Facebook intended (or at least intended to make obvious?).
I assume their scraper was more in depth. If you had friend-type permissions back then you could perhaps see their posts and shares. You'd need post and share content to run text analysis, figure out their hot buttons based on language and frequency, sort them into groups and then target then.
Affiliate marketers could also upload lists of unique user ID's (like the FB group members scraped above) for specific ad campaigns, y'know, disguised hookup sites, skin cream credit card rebill offers, etc.
Back then, many of the privacy options were deeply hidden, obscure, changed names a couple times a year or were unavailable.
What, exactly, are you claiming about this that was “illegal”? When you singup for Facebook, you agree that anything you post might be shared with others on the platform.
The Facebook developer platform became so limited in 2014 that most developers (including me) left. There was no point in developing apps for the social graph that had no ability to be use the social graph. But even prior to that, the sharing of this information with apps, even those authorized by a friend, wasn’t “illegal”. You agreed to it when you signed up for Facebook and voluntarily handed them your information. Even the idea that developers were supposed to delete the information they had before was just a civil agreement between the company and themselves - it wasn't illegal. Facebook can certainly sue them over it, but there are no violations of the law occurring here.
So what about this whole situation is "illegal"?
If the are companies in the UK, or people working in the UK, the sharing or retention of data may have been illegal under British law.
http://www.bellacaledonia.org.uk/2018/03/20/scl-a-very-briti...
Perhaps not in the US, but I'd like to point out that it's not the same way everywhere: I think the EU is moving towards another direction. There's a whole thing around whether a company has a responsibility to do due diligence around preserving the personal information of its users. Just because you gave them your data doesn't always mean that they can now do whatever they want with it (e.g. give access to detailed information in large amounts to third parties). Even if you sign an agreement, in many jurisdictions there are certain rights a company can't just make you sign away.
There was no consent because tracking was not opt-in but opt out.
More recently regarding user personal details and lack of consent, again deemed illegal in Germany https://amp.theguardian.com/technology/2018/feb/12/facebook-...
The pattern I see is that europe considers facebook's methods to commoditize users' data to be unreasonable and will be regulated.
Voluntarily putting your info on a free site is the consent.
Would you also cry "illegal" if HN sold your post history, which they have tied to your IP address, which they can easily link to who you are?
Each country has its own laws covering this situation.
Giving someone personal information still restricts them legally irrespective of what they think i've consented to or their own definition of consent. The legal system has its own opinion.
Now the majority of Facebook data, which is visible only to a selected group of individuals, can not contradict privacy laws of a country. Despite whatever agreement you signed. Law trumps user agreements.
As an extreme example I can sign that I give you the right to kill me, but if you do that you have still committed pre-meditated homicide. So it does not matter what Facebook made you sign it is likely they committed (and still do) a crime in most European countries. For the U.S. the waters appear extremely blurry from what I understand... But I can not offer an opinion. If there is a lawyer/ privacy expert to pitch in this discussion that would be nice.
This sounds as if nobody can agree to voluntarily take part in a potentially fatal experiment, like testing a potent medicine or be a test pilot. I believe legal provisions exist here.
Even the opposite can be true. Life saving medication may be illegal in one country but another provides it without restriction.
Anyways, my point here is you can not override law (or you shouldn't be able to).
Having said this there are some job roles that are excluded from specific parts of the legislation due to their unique nature (e.g. the Army)
The two links suggest awareness by Facebook of the illegality.
So, where is the irrelevance of the two links with regards to the privacy concerns highlighted by this whole story?
Almost EVERY free site is trying their damn best to collect as much info and link everything together to sell it so they can- you know.. make money.
I guess those people are instead willing to pay for virtually every site they use on the internet, right? Right? crickets
What matters is how criminal law views this particular data collection in the context of Facebook's working relationship with this particular client, within all of the various jurisdictions that Facebook operates.
The article "What Colour Are Your Bits", is a pretty good look at this - http://ansuz.sooke.bc.ca/entry/23
Except you CAN'T sign away your rights in many jurisdictions, including this thing called HIPAA. So if Facebook sold people's mentions of health problems to third-parties... is that a violation?
I mean, this is the exact scenario people grilled Windows 10's spyware. But somehow, Facebook doing it, isn't an issue? What's the difference? I'm honestly asking.
There's no consent on behalf of the friends if one shares information about their friends to an app. Consent is given directly
Almost no one reads them, so they should not be enforceable.
I mean, as developers we know when a session is established, pages are visited, and can easily see how long they've been on the page.
No one can read the typical T&C in 10 seconds .. let alone 1 minute .. especially without even opening the page! So the options should be something like:
[x] I don't care, just whatever dude.
[ ] No. Get me out of here. Because I don't know how to close the browser window myself.
EDIT: Found this as a way of proof http://www.pcpitstop.com/spycheck/eula.asp
It varies depending on where in the world you are but its actually pretty unclear as to whether they are enforceable. Or at least, a specific set of T&Cs with a specific user/customer may be found to be unenforceable for a wide range of reasons.
Of course, the company that puts the T&Cs in front of you isn't going to tell you that.
What about the punishment to Christopher Wylie, by closing/suspending his accounts in facebook, whatsapp, etc ?
He was part of Cambridge Analytica at the time. So they suspended his account along with the rest of them I suppose.
The Christopher Wylie that, by his own account, was a knowing, active, and key participant in the things they punished CA for, and in fact claims to be the one who came up with the concept for it?
What about it?
This appears to solve the issue of having wide permissions, but it does not do so. In reality, this is an attempt at transferring facebook's risk to shady app developers, while the overall lifecycle for the app won't change.
In essence, this is a do-nothing from the standpoint of app developers who have requested additional permissions. Any app developer who is told they need to undergo an audit, due to transcribing the entire social network, can simply say no and get their account banned. It will likely have no effect, as the account will almost certainly have already been suspended in such a spot.
They intended for cool apps to go viral across their social graph so Facebook could be a “social utility” and the operating system of human relationships and other airy fantasies they spouted in 2012, 2013, 2014 when they built the app platform.
Their hopes of a beautiful future of joy and freedom were dashed when they discovered humans are capable of garbage behaviour.
Ironically they believed the walled garden of Facebook would clean up the cesspool of blog comments. Oops.
“First, we will investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity. We will ban any developer from our platform that does not agree to a thorough audit. And if we find developers that misused personally identifiable information, we will ban them and tell everyone affected by those apps.“
Might be a too little, too late attempt at self regulation since they've apparently known about this cambridge analytica situation since before the election and since then there have been facebook employees embedded with CA to help them target ads.
MSNBC is already playing this as: 1) starts with a denial 2) admits wrongdoing 3) claims behavior will change 4) changes are not carried out and we're in the same place a year down the road.
They’re also pointing out that Zuck is fine meeting with Xi Jinping, meeting with Medvedev but refuses to appear before the US Congress and sends the company counsel instead.
This strikes me as especially interesting. I mean, I'd personally theoretically have my reservations about this congress over and above the average congress, but FaceMark refusing strikes me as a deeply telling datum about how he's thinking about this.
This is not a deeply telling datum. It is a boring an standard one.
More accurately there is risk in talking to the US congress when the topic sounds more like an inquisition than when congress is asking for opinions.
The matter then is why is it a risk for Facebook to discuss the CA issue? Are they worried about a witch hunt or a public ethics execution?
> ...my reservations about this congress over and above the average congress...
ugh, come on. it's not like the whole congress votes on how you're to be treated, and the questions you'll be asked. the biggest heels on both sides of the aisle are free to harangue you all they want.
Not the whole Congress, but how exactly do you think procedure and parameters for hearings are set and objections during hearings are resolved? Both the specific personalities in leadership positions and the attitudes of the majority matter a lot.
EDIT: It's true that there is a tradition of providing some semblance of balance in committee process, including hearings, with the majority (not necessarily by party) mainly controlling what items are considered and what hearings are held, and ultimately the outcome; but not only is partisanship greater than in the past, but precisely those traditions have noticeably weakened over the last couple decades and particularly in the current Congress.
Any exec hauled on the carpet is going to want a drink afterwards. That's not the concern.
Worth noting that Zuck wants something from Xi and Medvedev, has everything he needs in terms of support from the US Gov.
Facebook as almost insured that it becomes the whipping post of the FAANG companies as the government wants to look hard on tech. Im genuninely not sure what Zuck can do as long as Apple, Google and Amazon don't make mistakes in the same way.
The next 10 years are going to be a lot like the old ad age about being chased out of a campsite by a bear. It's unimportant to be the fastest (best) of the group, you just cant be the slowest.
It seems that it worker out for Bill Gates pretty well.
I get the feeling, but you'll agree that a legally binding legal procedure that is an actual existential threat to your hundred billion dollar company that employs 25k people requires a different approach then a seduction meeting with a despot to try to loosen regulations.
I've said variations on this before: https://news.ycombinator.com/item?id=16438362, but FB will get serious about it when users stop using it.
Until that time, everyone can complain, but the concept of "revealed preferences" is relevant. Do people actually care? If so, they'll change their behavior, FB will likely notice, and changes will happen.
People have been complaining about FB and privacy since practically day 0. Throughout that entire period, FB has only become more popular.
The election woke people up.
I found this from 2011 when they shut it down as a "mistake." (https://newsroom.fb.com/news/2011/11/our-commitment-to-the-f...).
Unfortunately, it looks like they removed the launch release - but it would be interesting to see how it was presented in light of the recent news.
They're not a product company, they're a distraction company.
Not exactly. In all fairness, as Zuck points out, this is a key part of the story, and in theory, why this is different:
In 2015, we learned from journalists at The Guardian that Kogan had shared data from his app with Cambridge Analytica. It is against our policies for developers to share data without people's consent.
This raises the question of what Facebook was doing (if anything) to prevent this sort of action, but the fact that they just took CA at their word that they deleted this ill-gotten data (of course they didn't), it makes me think they did very little. I think this is just as concerning as any other part of this story. Even if people are knowingly willing to hand over data to Facebook (or the devs of some app) in exchange to use a service, they wouldn't think that it's a free for all and anyone can mine the data for whatever they want.
Not to mention that it's arguable that "consent" was really given for facebook to share the data in the first place. I'd be interested to see some polling results asking if facebook users knew what facebook was up to and whether they feel OK with it.
I think this is from 2013.
This was openly covered last year by BBC when they interviewed Trump's digital campaign manager at the time Theresa Hong [interview linked]. The campaign spent $16M on Facebook. Understandably, Facebook gave them the white glove treatment, even had their own employees embedded in Project Alamo (the headquarters of the campaign's digital arm).
But today Facebook claims they had no idea who one of their multi-million-dollar clients in 2015-2016 were. That it was just some random quiz-making hacker dude selling data to some other random company.
https://twitter.com/bbcstories/status/896752720522100742?lan...
This piece of work posted today by Facebook is what we call damage control. Don't expect the truth from it-- it will contain truths, but it will not be the truth of the matter. And don't let it set your dialogue, man.
https://web.archive.org/web/20080214193303/http://www.facebo...
Correction, they are a surveillance company. Need I remind everyone of Google and FB's In-Q-Tel CIA partners in crime? They just figured out a way for everyone to willingly report on themselves, but not just on themselves, on others too! FB is bad and should collapse like every other dotcom boom-bust that uses and abuses it's users... but the difference is the level of monopoly on non-technical users that didn't exist in the 90's. Back then the technical community could have dropped a product like hotcakes and watched it bust... but due to the increase of non-technical users who sign any EULA/TOS and don't give a crap about privacy... I expect nothing will happen until something really bad and at a massive scale happens.
For those who are younger, consider this the slashdot/digg/reddit cycle. Reddit will die next the closer it gets to IPO too.
It's the beauty of computing though. Every market is ripe for disruption if someone has a good vision and follow-through. The problem is that so many of them use the exact same model and a few years later are the ones dying due to lack of integrity.
Can you substantiate this claim of tech product companies getting large/successful and then “dying due to lack of integrity”?
I haven’t noticed the pattern but if there is one I’m sure interested in the evidence. (And in what sense do they lack integrity?)
Number of times the word "advertising" was mentioned: 0
Facebook continues to pretend it's business model is unicorns and kittens, not selling user data for money.
"learn from this experience", "doesn't change what happened in the past. ", "responsibility", "going forward", "together".
You find this same boilerplate from athletes who beat their wife, do drugs, or kill people.
Yet, maybe it serves a purpose? It doesn't matter how sorry they actually feel, nobody is going to feel better from a large, public, self-flagellating apology. Nobody is going to be happier or more mollified or satisfied. All it's going to accomplish is to provide grist for the lawsuit mill - after all, why apologize if you're not guilty?
Again, you're completely right. They're clearly not sorry.
Because you get more money for a cow than milk over a long time period and can use the cash to expand the cow-selling business?
(And that original metaphor was a bit mismatched, actually.)
FB provides a platform for ads, sure, but it can be used for way more than just ads.
3P tracking can infer who (even specifically) is viewing ads and it knows the social graph by other means. It can also do effective mass psychometric tests. A/B testing infrastructure can be used for more than just optimizing ads ... all of the psychometric dimensions tested by Kogan’s 2013 app can be expressed as embedded imagery and messaging in ads, and the same types of tests can operate at the same scale by integrating 3P data and tracking (some of which certainly originates from policy-compliant FB apps) which already knows the social graph beyond what FB will allow a single app or ad to draw.
Targeted campaign products leak data about the user’s targeted attributes by their very nature.
If you want FB’s targeting data, simply buy targeted campaigns and associate the target attributes with the users who click once they are on your server. At scale, the targeting data is transparent.
Big ad analytics companies and ad exchanges can and do basically sit in the center of many campaigns and slurp up the targeting data which is naturally leaking from FB by virtue of their selling capaigns based on those targets.
Whether they want to or not, they are selling their data.
Edit: Care to reply instead of downvote? Is everything above not true?
Some others, like CA and ilk, also get easy access to user’s psychometric data, by embedding the psychometrics into A/B tested ad content.
The adage “you are the product” has only become more true as FB has advanced, whether by their intended or explicit policies or not.
Honestly, at the moment, Facebook has huge economic incentives to keep as much data to itself as possible. Facebook being the only place where you can microtarget to such an extent is a huge moat around their business.
And microtargeting can be abused (or just plain used, depending on your perspective) to infer only additional data by incorporating it into the 3P analysis once users click and start loading non-FB content. Microtargeting by its nature leaks information about the target segments ...
Figuring out the data FB uses to microtarget is simply a matter of buying enough ads, or getting in the middle of enough campaign-to-user relationships (as a central 3P ad exchange or tracking service).
I wouldn't argue that micro-targeting can't end up with very specific privacy concerns, but I don't think it's nearly the same scale as "you should probably assume that if you signed up to enable the Graph API on Facebook all information about you prior to 2015 is available to people you probably don't trust".
The resulting dataset over even short periods (< 1 yr) time is comparable to a total datadump, including an accurate social graph. A “very specific pivacy concern” it is not.
But no, we've got to pretend Facebook is a touchy-feely community. I get the feeling that Facebook is ashamed of the way they make their billions.
You seem lost in a false narrative that he is out to get you :(
I challenge you to rethink your position assuming he means well...just for the fun of it...and share with us what your conclusion would be
Even then, the surprising, and technically not against TOS, open secret to every single social app that leverages it, is the comparative ease with which one could scrape a user's peer nodes' entire public history without explicit permission from said node. This is the thing that allows for all those "you may know" invite suggestion engines.
And this is by design, obviously, as it is literally the only thing that makes facebook valuable.
Precisely. Acting astonished at why people are upset just shows a disconnect from the reality of the masses.
Free, valuable products are all over the internet: Google Docs, Trello, WhatsApp, Waze, Spotify...just to barely scratch the surface.
It’s not obvious to most users that the costs of some of these includes privacy violation / spying on the user.
Personally I quit Facebook upon signing up the first time in 2009. I friended a real life friend then 20 assholes from high school saw that action on my friends timeline and tried friending me. Right away I closed my Facebook account and never signed up again.
It was obvious back then Facebook shares my actions I don't want public with anyone they feel like. If you don't want them to do that then you shouldn't use the service.
Because Trump won and Zuck is the new scapegoat. No one gave a shit when Obama's campaign did the same thing, and they were even public and boastful about it at the time.
Zuckerberg is the one with control over the terms in a contract of adhesion. A contract of adhesion that gates access to a popular tool, that people want to use and don't bother reading or understanding the terms.
Whether or not you like contracts of adhesion, Facebook is taking advantage of people. When society finds terms in contracts (especially contracts of adhesion) to be immoral, they're allowed to voice that. And sometimes that causes the law to act to void contracts or prevent parties from certain actions even with contractual connect.
> Second, we will restrict developers' data access even further to prevent other kinds of abuse.
> Third, we want to make sure you understand which apps you've allowed to access your data. In the next month, we will show everyone a tool at the top of your News Feed with the apps you've used and an easy way to revoke those apps' permissions to your data.
All of these points don't address what actually happened. It's not like CA had a feed of FB's user data. It was harvested. And saved. And data, like diamonds, is forever.
The problem is that FB simply has too much information about us. The #deleteFacebook moment is a wake-up call not so much for FB's tone-deaf execs, but moreso for the masses that (probably until now) never realized how much data FB has on every single one of us.
How is it at all possible to certify that data has been deleted and no copies were taken..?
[1] http://www.businessinsider.com/well-these-new-zuckerberg-ims...
There's tons of substance to be discussed here without reaching for the global hash table (https://news.ycombinator.com/item?id=9722096). Fortunately the community has mostly been doing that, but let's not spoil it.
The point isn't to defend Zuckerberg, btw; it's to defend the quality of this community. If we're to realize our dreams of doing marginally better than internet median, we need people to check their worst instincts here.
Seems to be plain copyright infringement... FB licensed the data to Kogan, not CA, hence CA violates FB's copyright on the data.
By, e.g., signing a paper which says that.
You probably meant how can you know that, which is a different issue than how can you certify it, and which amounts to a question of degree of internal accountability and control of data access.
Certification is about assuming responsibility for the truth of the thing certified, which doesn't actually require knowing it (though obviously knowing it to a reasonable degree of certainty makes it more comfortable to certify it.)
This is usually only noteworthy when it fails, but by and large it works. The friction involved if we did not generally accept someone's (signed, notarized, appropriately formalized) word as bond would cause our world to grind to a halt.
Including many technical spheres, and particularly including the vast majority of the software world; formal verification exists in software, of course, but is most notable in not being used for most of it. Yet, even without that, there's usually a release process that includes the moral equivalent of a certification—without formal verification or certain knowledge—that the software does what it is supposed to.
'Fake news' takes advantage of something much more simple. People believe what they want to believe. In other words the people led on by fake news tend to already want to believe what the news is about. When we see something that confirms our biases, many of us don't question it. And this is made even worse since people tend to work as apologists for fake news from sources they like, so instead of being able to discuss the issue of fake news - it ends up dividing people into splits on the 'fake' topic at hand, which in contemporary times is most often political.
Well, yeah, that's what I was referring to. If you perceive someone as being from your tribe then you are predisposed to believe what they say, and if you don't then you aren't. Nowadays tribes are much bigger than they used to be, and tend to center around ideologies more than geography. But otherwise it's monkeysphere dynamics at work.
You can do some clever things to figure out who it is that leaks stuff, but that's another issue.
That said, I do agree with your sentiment that the blockchain-as-a-solution space is getting a bit ridiculous. I can't imagine a way to translate this problem into a smart-contract-solvable form.
Even the flimsiest of technological improvements could radically improve the trustworthiness of the notarizations, but by and large the system works, so there's not much of a reason to fix it yet.
All our data associated with FB unique id is out there. My understanding this has stopped in 2015 but for sure?
Hopefully the data that is out there becomes less relevant over time.
[1] https://medium.com/@jamesallworth/what-the-f-was-facebook-th...
If someone leaks facebook data to a journalist, can FB demand that they delete it as well?
It costs Facebook nothing to ask developers to sign a contract written on virtual paper, yet can be used as a defense to cover their butt further down the line.
https://www.telegraph.co.uk/technology/facebook/6966628/Face...
How does that in conflict with your FSF link?
A few years later the data was much more restricted, much harder to get, and much clearer to the user what was going on.
It's easy to point to Fb and say they are evil, but it really seems to me like it's the 3rd parties that are causing most of the issues, and Fb has been pretty decent at locking it down in the last number of years. Keeping in mind that they were the first who had social data in such large amounts where there was no prior example.
Maybe in 2010 your comment would apply, but when this happened they knew very well they weren't supposed to be doing this.
Basically everything you see on yourself, plus pages you visit and like, groups you belong to, your picture, your friend list, as well as their friends, so it was really three steps out and included things not available through FB normally.
It was totally predictable this data would get collected and abused.
That’s a fair product to build and provides lots of great value!
Now can it be abused...of course it can, a rouge app developer could try to use this data for whatever, or sell it. That’s a problem.
I think FB did a great job over the years though to improve UX for users to make it more clear what is happening and what information is being shared.
Back in the day you could for example get a users friend list for example (only public profile information though)...I think they did the right thing in limiting that to only users who also use the app.
It’s what makes apps like Spotify great...the fact that I can easily find my friends on it.
I think there is tradeoff in anything we build. And 2B people believe it’s a good tradeoff! And don’t tell me that users are stupid and don’t know...because then I am gonna flag you as stupid first :)
We also don’t sue Ford or the state that owns the streets for any accident that happens...that be nuts! We ask drivers and pedestrians to be responsible and that works for the most part. Of course there is the occasional deadly accident...but we accept that risk for the benefits of mobility.
Saw too much information about friends, realized some friends began "using" my app, just because it was made by me. Realized all the quizzes and dumb polls are data-gathering apps for the developers.
Realized, all the awkward "friend requests" from other side of the world, are fake profiles, to gather more data.
Made a fake profile, to seem from a different part of the continent, with such an awkward for us name. Facebook recommended me to befriend people from that area. Some accepted the friend request. Soon I had 30+ friends on a fake profile, all within the same "web" of friends, within same region.
Then I made more of those fake profiles, and made more fake apps with same theme, since this soo easy, for this and other regions which I suspected had hot women, and I was 25ish single at the time. My devious plan was to get outside my own social network and cast my net to catch the women who my algorithm would say - they are not on the edge of their own social network - they are a hub a popular and single etc. But that was too much work to complete. Later facebook gave me the graph search query where one could say "friend of my friends and single in this city", but that was still meh compared to what I had planned - since I would be doing the data gathering and analysis.
I wanted to catch the woman who had good privacy settings, those not show up on fb own searches, those not installing my app, but appearing in friend list of those who do accept fake friend requests or use dumb quizz apps. Those who appear to be recommended by many fake profiles.
If your friends can see your posts, the app can see your posts. If your friends can see your birthdate, the app can see your birthdate. And so on, so forth.
You used to be able to do searches on Facebook like "photos taken by friends of _____" and you could easily stalk them without being friends with them. Today that search will yield photos only if you are friends with them, or they enabled their privacy settings to public.
Neither exposed data that wasn’t available from using the product normally. For example you could visit someone’s profile, see who their friends were, and then look at those friends’ photos.
However, there were many, many apps that also did the same. A number of dating apps, companies like Zynga, business networks like BranchOut etc. They were just inhaling data wholesale, especially Likes which were fully exposed to all friends in your graph.
I could totally see how you could use that data circa 2014 to build psych profiles and resell it for sophisticated targeting years later.
There is an enormous risk of companies who rose and fell during the Zynga era to have resold or improperly disposed of FB profile data during their final liquidation. This is just the tip of the iceberg.
Democracy only works when everyone gets an equal vote. What are the consequences when special interest groups, including from abroad, can pay to use the official Facebook APIs and craft targeted messages to shape the public opinion?
We have seen the consequences of this approach. Trump won by the smallest margin. Brexit was nudged with 100% false and misleading statements (300m for NHS, showing refugees from Syria etc.) Should we be OK with this much power available on tap?
The real questions Zuckerberg needs to answer are: what political campaigns are being run? Who is being targeted with political messages? What are the budgets like? Most importantly, who is ultimately paying for shaping the political opinions in our democracies?
This is a question that strikes at the heart of our society. Facebook is not going anywhere. Google is not going anywhere. People will continue to put all their personal data in cloud services without thinking about any Privacy policies whatsoever.
We should have an open debate about how much digital opinion shaping is acceptable before we have built a tool that sells the democratic decision making to the highest bidder. There is a reason why political spending is so carefully controlled in Europe. Facebook needs to own up and come clean on the state of political advertising taking place on their platform.
Democracy only works with an educated population. Regulating data might act as a short to medium term buffer against this issue; however, as we learn more about how our psychology works, the more often we'll be manipulated. Combined with the interesting argument that being politically uninformed could be rational:
> If the odds that your vote will be decisive are minuscule—Brennan writes that “you are more likely to win Powerball a few times in a row”—then learning about politics isn’t worth even a few minutes of your time. [1]
... we have an interesting problem on our hands. I personally believe that the long term solution is within education, but instead of teaching people "what to think," we ought to be teaching people "how to think". People typically learn naively about how to think: both how to emotionally cope with struggling and with parsing and understanding information. At the minimum I think schools ought to be teaching kids strategies for both arenas.
I personally really enjoy two approaches around "how to think.":
1. The now out of print "How to Develop Your Thinking Ability," is a super old, easy read loosely based on Korzybski's controversial "Science and Sanity." It taught me how to approach my perception as gambles (i.e. to avoid universal judgment). The principles, all often obvious, as I recall, are roughly:
a. Up to a point e.g. that person is annoying, up to a point.
b. To me. That movie is awesome to me.
c. As far as I know. Warren Buffet is 92 as far as I know.
d. Indexing by time: I like John at this point in time.
e. Indexing by place: I like John when we're at the club, but not when we're at the office.
f. Indexing by subindex: Instead of: Guy_1, Guy_2, Guy_3 are all scum, therefore all men are scum, we use indices to avoid generalization.
2. The Happiness Trap: enumerates Acceptance and committance therapy. ACT roughly uses a variety of defusing techniques, mindfulness, and values oriented behavior to help a person handle their thoughts in constructive manners.
[1] https://www.newyorker.com/magazine/2016/11/07/the-case-again...
Data exfiltrations of roughly this kind has been going on at least since 2009. Handled according to the formula above. I just posted links to two writeups from back then:
http://theharmonyguy.com/oldsite/2009/05/28/about-that-verif...
https://www.lightbluetouchpaper.org/2009/06/09/how-privacy-f...
confounded's comment https://news.ycombinator.com/item?id=16641777
over in https://news.ycombinator.com/item?id=16640437 ("Big Other: Surveillance Capitalism and Prospects of an Information Civilization") is well worth reading and keeping in mind in this context.
I wonder why the Facebook of pre-2014 thought that this was an acceptable level of data sharing to developers?
Did they trust that all platform developers would forever have good intentions? Or perhaps they felt the data being collected was harmless in perpetuity (i.e. did not anticipate the political ramifications of the CA abuse)? Or that their legal team could effectively enforce their TOS to prevent abuse?
In hindsight, the pre-2014 policy seems ridiculously careless - but I'd love to understand why they didn't anticipate a breach of this magnitude at the time (or if they did, why they dismissed the concern).
The reason this whole thing became a scandal is because data is powerful at scale. To quote The Guardian's original article:
"(Cambridge Analytica) used them (data) to build a powerful software program to predict and influence choices at the ballot box."
Facebook now have a $50bn business based on using exactly this kind of data "to predict and influence choices" people make. That's why their ad system works now, and didn't just a few years ago. They got very good at using large quantities of otherwise mundane data to guess who will click an ad and sign up to a cookie subscription or who needs a mortgage.
This is the same thing. If you know who's a maker and what seminar's they'll like, you know whos a Tory and what conspiracy meme they like. FB now know how powerful that is, but I'm not sure they did then.
Still... this sounds only semi-tangentially related to privacy. It is technically user data, but IDK if individual users were violated that much, at least relative to other breaches. It's not like the icloud breech, or Ashley Madison. Generally not data that people are horrified to find someone knows.
I think the meat of this issue is "power got into the wrong hands." At least that's what The Guardian was concerned with. User privacy is just the only violation. Power is the problem.
On that note, is FB the "right hands?."
Incidentally, all this is interesting in the context of Zuck running for office, or even just being involved in a politics. Whatever Cambridge Analytica could do, Zuck could day a lot more.
On top of that, he heads the biggest and most influential news/media company that ever existed. He should probably be banned from political involvement.
- Allow its users to delete their accounts as if they never existed
- Show users which person and or service has accessed their data (also FB internally)
- Use backend permission management instead of frontend permission management
2) requiring every single advert and it's targeting parameters, that runs on the system to be made available in a fully searchable advert pool for anyone to search. This would allow people to see what is being targeted, journalists to figure out what targeting is happening (much of the Cambridge Analytica nonsense happened under the radar for a long time), and regulators to uncover scams.
Mere transparency. they could probably figure out a way that this will make them more money if they actually looked at it (e.g., support an ecosystem of people studying the data and figuring out what works better, to better utilize the platform).
I'd totally support that requirement even tho it's a massive task (it's not like FB lacks the funds/resources).
Which all leads you to conclude, any Facebook data you had prior to 2015 is probably in the hands of someone you don't really trust. That's not a fun scenario; even if facebook fixes things from that point forward.
[1] https://gdpr-info.eu/art-17-gdpr/
[2] https://www.imperva.com/blog/2017/03/gdpr-series-part-4-pena...
When you allow apps to access all the information about people's friends as well, informed consent becomes impossible.
Then maybe stop putting data on a "free" site which owes you absolutely nothing?
I just don't get how everyone is on an uproar: "OMG they have my data! Which I voluntarily gave them! Which they are using for advertising/etc!"
You can find a plenty of hits searching for 'facebook run psychological experiment on users.' Here [1] is one of a plethora of sources discussing it.
[1] - https://www.telegraph.co.uk/technology/facebook/10932534/Fac...
I don't think that's it. I think the problem is that what was revealed was far too abstract for most people to fundamentally grasp.
[0] https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...
Is it all public and friends-visible activity? Or it is basics such as name, email, profile photo, etc.? I cannot find so far addressed in the coverage exactly what kind of information CA have had on a per-person basis.
If someone can share coverage that outlines this I would be very grateful.
https://photos.app.goo.gl/x6WQmxyX0JIL26d62
If I'm remembering correctly the API would return all of the things you mentioned if that info was shared to your friends
I would not exactly call that public, though.
Here is today's episode of The Daily where they discuss this: https://www.nytimes.com/2018/03/21/podcasts/the-daily/cambri...
This TechCrunch piece from 2015 talks about the reaction to the API access going away: https://techcrunch.com/2015/04/28/facebook-api-shut-down/
> It was always kind of shady that Facebook let you volunteer your friends’ status updates, check-ins, location, interests and more to third-party apps. While this let developers build powerful, personalized products, the privacy concerns led Facebook to announce at F8 2014 that it would shut down the Friends data API in a year. Now that time has come, with the forced migration to Graph API v2.0 leading to the friends’ data API shutting down, and a few other changes happening on April 30.
> First, we will investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity. We will ban any developer from our platform that does not agree to a thorough audit. And if we find developers that misused personally identifiable information, we will ban them and tell everyone affected by those apps. That includes people whose data Kogan misused here as well.
What happens if they find that 50 different organizations had access to and may have saved as much data as CA? If they admit that, that would be the end of Facebook. This basically precludes Facebook from being open and honest here - even if its only this one bad actor, that the incentives for FB are not to be open would cause any reasonable person to question their efforts.
Most companies, when they learn of a data breach, they take measures to notify their affected users (whether contacting them directly, or publicizing it). Instead, FB's saying, "Here's a tool at the top of your feed, you can check the safety of our data yourself". (And fat lot of good that'll do people who don't even use FB.) This lets them continue to do business as usual, putting the onus on users to safeguard their privacy, while they can stick their heads in the sand.
Isn't this more than guaranteed? Literally any crappy quiz app or game had access to all of this data when they launch Facebook Platform. And I'm betting Kogan's app was far from the most popular on Facebook at the time -- the potential for hundreds of thousands of data harvesters to have exploited this is way too high. I disagree that it's "the end of Facebook", though... in general, users just don't seem to care that much about this sort of thing. I can say for certain that my parents don't understand what this means or why this is bad (they had trouble understanding what was so bad about the Equifax leak as well), so your lowest common denominator user is never going to budge, even after something like this. I'm just hoping that my more technically-inclined friends start to lean away from Facebook's collection of data aggregators.
> I disagree that it's "the end of Facebook", though
If they do what they say and publically shame the apps in a way that people would see, it might. It would be hilarious for them to put up 100 logos of apps on the top and say oh yeah by the way all these apps have been taking your personal information, with lovely trustable names like "e-quiz" and "sofunni"
I remember the old days of the graph API - there was a whole lot you could do with someone's account, and it was common for users, especially non technical users to blindly hit accept on the permissions screens. If I'm not mistaken, you could even make a developer account without a verified phone number at the time.
I don't think banning some of those apps is any kind of consolation really. The API sat like that for years. Anyone with nefarious motives already took what they wanted and ran. What repercussions will they face? The will be banned from Facebook? The apps are probably long gone. There was a time when Facebook apps were at their peak, that fad died off. The data is probably sitting in a database somewhere today. If I'm not mistaken, Facebook Games could still grab the friend list permission until quite recently.
Also what authority does Facebook have to do any kind of audit? How would that audit even work? If someone copies all the data to an external drive and locks it up, what will the audit reveal? "Yep there's no data here, pinky swear!"
The basic premise of Facebook is flawed. If your private thoughts or photos are posted on a platform where you don't control the data, the data is never safe. A good product that serves the user faithfully and takes this into account is probably closer to a decentralized product - maybe something like Mastodon (I haven't looked into it in much detail). Facebook has already acquired the users - if they can figure out a way to make money and switch to a decentralized model at the same time, they can solve this once and for all. They would arguably even gain users who would now have a reason to trust their service.
This would allow app developers to create a copy of the data and re-sell that. And Facebook wouldn't see a dime. If their crown jewel is people's data, why would Facebook give away a copy of their crown jewels?
I am skeptical of Facebook's ability "guarantee" that a third party developer has not cached any data. I would equate this to finding all N needles in a haystack of size M where M >> N; it's just not a feasible task to complete. Even if you find N-1 needles, the last needle can be used as a sort of "mold" to reproduce all N-1 needles. My "golden rule" for the internet is: Once you give up information, assume it's everywhere and impossible to rescind.
I believe this statement will be eaten up by the press, and Facebook will continue to carry on its operations as if nothing happened. The stock will probably recover, and we'll go back to square one. Give it a few weeks.
The true demise of Facebook requires several things to happen simultaneously; a resonance of perfect conditions, so to speak. You've probably heard that Einstein and Newton discovered their theories because "they were decently smart men in the right place at the right time". A similar effect is also true here. If we want to see Facebook's demise, the world must have a suitable alternative in place, one which already has a critical mass. Until then, Facebook has a monopoly on attention and they will keep it as long as they are producing enough positive externality.
They abuse their position to extract hundreds of billions of dollars by selling their user's limited time on earth to advertisers for peanuts per user.
Feel pity for Mark Zuckerberg and Larry Page that they have such fundamentally corrupt businesses and are apparently incapable of fixing them.
And applaud Apple for having created a business so well aligned with its users. It's very difficult to find examples of Apple failing to do the right thing and very easy for the other two, as in this example.
Startups should reject the rent-seeking Facebook/Google monopoly model and embrace the Apple innovation and direct-to-users model.
Why do we not even have this?! These features sound fantastic -- where the hell are they? The most comical part of the situation with centralized social networks is that we give up our personal & friends' data to advertising monoliths, and we don't even reap any of the benefits from it in terms of improved user experience.
Facebook doesn't give you the best calendar, the best maps, and the best address book. It gives you the Facebook calendar, the Facebook maps, and the Facebook address book. For any of this to actually work from a user's end (never-mind the creepy privacy stuff), Facebook has to design the best-in-class experience for each of these product categories, which they of course have not done because that is an impossible thing to ask.
No one company is actually going to monopolize the social data market, yet every player in the field is trying (and assuming they eventually will) do so. It's maddening. Society will eventually wake up and realize we need a large-scale replacement to W3C focused on standardizing access to the social graph, which should be a public utility like roads. That's all there is to it. Until we figure that out, we're going to be having the same conversation every decade, nothing will change, and we'll keep begging Daddy Zuck to pwetty pwetty pwease fix all of our issues out of the kindness of his heart. Keep doing that, if you want.
Seems to be the go to business model nowadays...
> that Zuckerburg explicitly takes personal responsibility for everything that happens on his platform
Sorry, but bullshit. He may say that, but I'll believe it when he publishes the agreement he signed that makes him personally liable for lawsuits.
I agree with you, BTW.
I think that the whole issue is not surprising at all. Definitely not newsworthy. I'm pretty sure that everyone and everyone's mum knew that Facebook was doing stuff like this.
What changed is that now we all distrust and dislike Facebook at some deep level... So we respond strongly to even the most mundane criticisms against it.
I think that what's happening is that Facebook is so good with analytics that they are always able to churn out a perfectly optimized statement in response to any situation... But it doesn't change the fact that everyone is eagerly awaiting the next scandal.
"Everyone" knew Facebook was gathering tons of data on its users and everyone else, but we didn't understand many of the implications until now. People assumed it was just useful for banner-ad type stuff. There are probably even more implications of this data collection that we have still yet to discover.
And Facebook is not that bad. You can use Facebook with a fake name and without a phone number. But for example in Russia social network sites require a phone number to register. They have much more to leak.
"Protect" is the keyword. He means protect while letting Facebook be profitable. Facebook's business will not let him do that without losing a large chunk of its profits.
I expect a lot of talk but little effect on how they sell their data. The problem is that "free to user" = "sell my data". The model fundamentally works against the everyday user.
The only fix is for people to guard their data. It's your data! Facebook is not your friend so don't act as if it is.
Memorable quotes:
"We have responsibility to protect your data"
"We will investigate"
"..we announced that we were changing.."
"I started Facebook"
Isn't there a bit of moral hazard here - as in, Facebook potentially getting material business advantages from reading other people's repos? Are they going to put up a Chinese Wall between the audit team and the product team?
Regardless of my feelings about how this was handled, I appreciate the level of leadership accountability demonstrated in this statement. I wish that more founders, CEOs, and politicians facing difficult circumstances would adopt this perspective. Even if you didn't personally code/negotiate/write it - you made managerial decisions (hiring, culture, review process, etc) that induced it.
Because months earlier, he was making public comments that it was a 'crazy idea' that his company could have influenced elections shortly after his chief information security officer was pushing against him and Sheryl Sandberg to investigate and disclose russian activity on the platform. Additionally, his company was actively advertising election related products.
This man isn't owning responsibility; he's trying to defuse a PR bomb of his own creation.
Short of some breakthrough in homomorphic encryption sharing data for analysis is problematic. Penalties can be enforced but the data is out at that point.
> Second, we will restrict developers' data access even further to prevent other kinds of abuse. For example, we will remove developers' access to your data if you haven't used their app in 3 months.
Won't this behavior break a ton of apps?
Would they really be moving fast and breaking things if it didn't?
The problem was data that was secretly kept, right? How would removing access change anything? Or am I misunderstanding what happened?
> we immediately banned Kogan's app from our platform.
So my guess is the app still existed, and could probably keep querying data to keep user profiles updated. What you like, do, who you interact with; it all changes with time, so the data's value is slowly lost as it diverges from reality.
Moreover, there might be apps I gave access to back in the day when I didn't know better that could potentially still access my information. Even if the actors aren't malicious now, this could probably to prevent Chrome-extension like situations. Apparently legit extensions have been bought in the past by malicious actors with the purpose of exploiting their broad install-base and permissions [1]. I could see something similar happening with Facebook apps.
[1]: https://arstechnica.com/information-technology/2014/01/malwa...
Engineers hate this kind of stuff. Expect an outflux of talent from the company in the next year or so.
So the above statement should be "...name, email address, age, ethnicity, gender and countless other things future ML systems can infer from profile pics."
“They were worried that the large app developers were building their own social graphs, meaning they could see all the connections between these people,” he said. “They were worried that they were going to build their own social networks.”
[1] https://www.theguardian.com/news/2018/mar/20/facebook-data-c...
It's good that Facebook took steps to secure the platform against third parties crawling the graph and scraping millions of users' personal details, which is what Cambridge Analytica reportedly did, and which was not a violation of their policy at the time. Kudos.
So the consensus seems to be that what Cambridge Analytica did in the Brexit vote and the 2016 US Election was wrong. Now they won't be able to do the same thing via Facebook. But what's keeping Facebook themselves from doing the same thing that Cambridge Analytica did in future elections?
Strange to see that bullet point, specifically, as an advertised facebook feature in 2018. I absolutely would not want my facebook friends to know my address, and that's without any specific threat to me such as a domestic abuse situation.
Edit: this feature was also heavily used by the Obama campaign in 2012 and I would venture to guess was designed at their request.
The point is this - I don't and will never trust facebook as a company. There is no way to salvage that. Once you've established yourself as untrustworthy you can't talk your way out of it, because there in no reason to believe your excuses and trust there aren't omissions.
Consider the microphone accusation (and the legalese they used in their oddly specific denials), Zuckerberg's wish to run for president, the incredibly extensive profiles they construct on their users ("Is the kind of person to look at their phone in akward situations") without justifying it to the users, and now this.
It's way too late for people like me. I've deleted my facebook.
Can't you? I mean clearly this is a common opinion, it's the basis of the American belief that all crimes should result in 30 year prison sentences. But I don't see why you should think this way.
Perhaps this will prompt Facebook to start cutting out third party developers and build more home grown social apps, leveraging the data it already has on what eye balls engage with. Maybe they'll only grant API access to large companies, eg. TripAdvisor, who they can hold accountable and would be worth investing the time to audit. Perhaps they will start their own internal Cambridge Analytica where no data sharing is even necessary, assuming they haven't already.
Facebook needs to come clean with whose data has been abused, and by whom.
This scandal is bigger than Cambridge Analytica. It also covers what the Obama team did in 2012 and 2008, and probably a whole host of others that we don't yet know about.
We have a right to know.
It appears to be that facebook may be in breach of many legal obligations that are present throughout the world (i.e. Australian Privacy Act, GDPR, etc).
Does FB have the contractual power to stop CA from using works built or derived from this data?
I have Google scholar alerts for Kogan and Kosinski; Kogan especially has a lot of citations and continues to work. I would bet that Kogan will never let his work die, even if his OCEAN model ends up being experimentally proved ineffective (my personal opinion = actions are far more valuable than modeled emotions).
Is Zuck still at school? "I'm sorry for running a business model that made me squillions" just doesn't cut it with me.
The introvert in me wants to say that's a good outcome in that Facebook serves as a honeypot for certain types of personalities which I tend not to like very much. But speaking more broadly, it makes me worry for society.
Also, there are various ethical issues with the users consenting to provide data under the guise of academics and then the data being turned over to commercial and political interests.
A decision that looks better every day.
"I want to share an update on the Cambridge Analytica situation -- including the steps we've already taken and our next steps to address this important issue.
We have a responsibility to protect your data, and if we can't then we don't deserve to serve you. I've been working to understand exactly what happened and how to make sure this doesn't happen again. The good news is that the most important actions to prevent this from happening again today we have already taken years ago. But we also made mistakes, there's more to do, and we need to step up and do it.
Here's a timeline of the events:
In 2007, we launched the Facebook Platform with the vision that more apps should be social. Your calendar should be able to show your friends' birthdays, your maps should show where your friends live, and your address book should show their pictures. To do this, we enabled people to log into apps and share who their friends were and some information about them.
In 2013, a Cambridge University researcher named Aleksandr Kogan created a personality quiz app. It was installed by around 300,000 people who shared their data as well as some of their friends' data. Given the way our platform worked at the time this meant Kogan was able to access tens of millions of their friends' data.
In 2014, to prevent abusive apps, we announced that we were changing the entire platform to dramatically limit the data apps could access. Most importantly, apps like Kogan's could no longer ask for data about a person's friends unless their friends had also authorized the app. We also required developers to get approval from us before they could request any sensitive data from people. These actions would prevent any app like Kogan's from being able to access so much data today.
In 2015, we learned from journalists at The Guardian that Kogan had shared data from his app with Cambridge Analytica. It is against our policies for developers to share data without people's consent, so we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications.
Last week, we learned from The Guardian, The New York Times and Channel 4 that Cambridge Analytica may not have deleted the data as they had certified. We immediately banned them from using any of our services. Cambridge Analytica claims they have already deleted the data and has agreed to a forensic audit by a firm we hired to confirm this. We're also working with regulators as they investigate what happened.
This was a breach of trust between Kogan, Cambridge Analytica and Facebook. But it was also a breach of trust between Facebook and the people who share their data with us and expect us to protect it. We need to fix that.
In this case, we already took the most important steps a few years ago in 2014 to prevent bad actors from accessing people's information in this way. But there's more we need to do and I'll outline those steps here:
First, we will investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity. We will ban any developer from our platform that does not agree to a thorough audit. And if we find developers that misused personally identifiable information, we will ban them and tell everyone affected by those apps. That includes people whose data Kogan misused here as well.
Second, we will restrict developers' data access even further to prevent other kinds of abuse. For example, we will remove developers' access to your data if you haven't used their app in 3 months. We will reduce the data you give an app when you sign in -- to only your name, profile photo, and email address. We'll require developers to not only get approval but also sign a contract in order to ask anyone for access to their posts or other private data. And we'll have more changes to share in the next few days.
Third, we want to make sure you understand which apps you've allowed to access your data. In the next month, we will show everyone a tool at the top of your News Feed with the apps you've used and an easy way to revoke those apps' permissions to your data. We already have a tool to do this in your privacy settings, and now we will put this tool at the top of your News Feed to make sure everyone sees it.
Beyond the steps we had already taken in 2014, I believe these are the next steps we must take to continue to secure our platform.
I started Facebook, and at the end of the day I'm responsible for what happens on our platform. I'm serious about doing what it takes to protect our community. While this specific issue involving Cambridge Analytica should no longer happen with new apps today, that doesn't change what happened in the past. We will learn from this experience to secure our platform further and make our community safer for everyone going forward.
I want to thank all of you who continue to believe in our mission and work to build this community together. I know it takes longer to fix all these issues than we'd like, but I promise you we'll work through this and build a better service over the long term."
Nah. They need to not offer any identifiable information to 3rd parties. Email is fine. Yes, I know can figure out ways to identify an individual by their email, but there's nothing more closely tied to one's identity than their name and face.
https://penguindreams.org/blog/discoverying-friend-list-chan...
> Last week, [...] We immediately banned them from using any of our services.
Can someone explain how they banned them twice, or what the differences are between FB's "platform" and their "services" ??
"In 2015, we learned from journalists at The Guardian that Kogan had shared data from his app with Cambridge Analytica. It is against our policies for developers to share data without people's consent, so we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications."
What does banning or disabling app means? If you were responsible enough and you cared about user data you should have made it public right there and then! This is no excuse!
1) Data acquisition. 2) Using such fine-grained psychographic data to politically influence voters at massive scale.
Cambridge Analytica was clearly outside the lines for #1, but they clearly are not the only organization that does such precise campaigns to influence people.
I think #2 is much more important as data is not just available from facebook (although it's an easy source) and working in adtech, this is basically the pitch for all the modern advertising companies that use psychographic and intent targeting. It really goes back to the wider ad industry having very little oversight while selling mass influence to anyone with a credit card... perhaps we should solve that first.
...so instead of looking into it at all, or vetting our partners, we relied on media to tell us?
We all need a way to have the equivalent of frequently-rotated encryption keys in our online discourse. If I revoke privileges for some entity, everything they have on me should become useless to them.
> We will reduce the data you give an app when you sign in -- to only your name, profile photo, and email address.
What about localization info such as language?
Are all apps switching to 100% US English? Are they supposed to guess a users language from their name and email?
My guess (and this is just a guess) is that the users preferred language is already considered “public” on the graph so perhaps apps don’t need special permission to access it.
If that’s the case, this statement is doing a bit of misdirection by calling out name and profile photo, instead of saying “we will only give your email address plus other information we deem public”
These SV firms are like kids, always pushing further until people shout. I seriously hope this harms them beyond repair.
- how was this episode discovered? what was FB's initial reaction and can it be justified?
- are the allegations true? including the one that FB employees collaborated on it. Silence on it only deepens suspicions.
- was this done in a similar way (3rd party dev, etc)? If not, how was it done?
- who were the actors in that episode? What was the actions taken then?
- what about the pedigree of those who rightly raised the issue in the 'Cambridge Analytica' episode? Did they not have the information for the 2012 episode? How did they find this out?
I want to share an update on the Cambridge Analytica situation -- including the steps we've already taken and our next steps to address this important issue.
We have a responsibility to protect your data, and if we can't then we don't deserve to serve you. I've been working to understand exactly what happened and how to make sure this doesn't happen again. The good news is that the most important actions to prevent this from happening again today we have already taken years ago. But we also made mistakes, there's more to do, and we need to step up and do it.
Here's a timeline of the events:
In 2007, we launched the Facebook Platform with the vision that more apps should be social. Your calendar should be able to show your friends' birthdays, your maps should show where your friends live, and your address book should show their pictures. To do this, we enabled people to log into apps and share who their friends were and some information about them.
In 2013, a Cambridge University researcher named Aleksandr Kogan created a personality quiz app. It was installed by around 300,000 people who shared their data as well as some of their friends' data. Given the way our platform worked at the time this meant Kogan was able to access tens of millions of their friends' data.
In 2014, to prevent abusive apps, we announced that we were changing the entire platform to dramatically limit the data apps could access. Most importantly, apps like Kogan's could no longer ask for data about a person's friends unless their friends had also authorized the app. We also required developers to get approval from us before they could request any sensitive data from people. These actions would prevent any app like Kogan's from being able to access so much data today.
In 2015, we learned from journalists at The Guardian that Kogan had shared data from his app with Cambridge Analytica. It is against our policies for developers to share data without people's consent, so we immediately banned Kogan's app from our platform, and demanded that Kogan and Cambridge Analytica formally certify that they had deleted all improperly acquired data. They provided these certifications.
Last week, we learned from The Guardian, The New York Times and Channel 4 that Cambridge Analytica may not have deleted the data as they had certified. We immediately banned them from using any of our services. Cambridge Analytica claims they have already deleted the data and has agreed to a forensic audit by a firm we hired to confirm this. We're also working with regulators as they investigate what happened.
This was a breach of trust between Kogan, Cambridge Analytica and Facebook. But it was also a breach of trust between Facebook and the people who share their data with us and expect us to protect it. We need to fix that.
In this case, we already took the most important steps a few years ago in 2014 to prevent bad actors from accessing people's information in this way. But there's more we need to do and I'll outline those steps here:
First, we will investigate all apps that had access to large amounts of information before we changed our platform to dramatically reduce data access in 2014, and we will conduct a full audit of any app with suspicious activity. We will ban any developer from our platform that does not agree to a thorough audit. And if we find developers that misused personally identifiable information, we will ban them and tell everyone affected by those apps. That includes people whose data Kogan misused here as well.
Second, we will restrict developers' data access even further to prevent other kinds of abuse. For example, we will remove developers' access to your data if you haven't used their app in 3 months. We will reduce the data you give an app when you sign in -- to only your name, profile photo, and email address. We'll require developers to not only get approval but also sign a contract in order to ask anyone for access to their posts or other private data. And we'll have more changes to share in the next few days.
Third, we want to make sure you understand which apps you've allowed to access your data. In the next month, we will show everyone a tool at the top of your News Feed with the apps you've used and an easy way to revoke those apps' permissions to your data. We already have a tool to do this in your privacy settings, and now we will put this tool at the top of your News Feed to make sure everyone sees it.
Beyond the steps we had already taken in 2014, I believe these are the next steps we must take to continue to secure our platform.
I started Facebook, and at the end of the day I'm responsible for what happens on our platform. I'm serious about doing what it takes to protect our community. While this specific issue involving Cambridge Analytica should no longer happen with new apps today, that doesn't change what happened in the past. We will learn from this experience to secure our platform further and make our community safer for everyone going forward.
I want to thank all of you who continue to believe in our mission and work to build this community together. I know it takes longer to fix all these issues than we'd like, but I promise you we'll work through this and build a better service over the long term.
This...is not comforting.
Can 1 billion diverse people be a community? What ties them together? Not place, not creed, not nation, not language, nothing except their humanity (I don't think I'm going out on a limb on that one except for the bots) and the fact that they use FB. I guess it sounds better than "our users", community has that ‘we're all in this together’ vibe. Google would never call its users our community, nor Apple neither, nor Amazon, yet FB can? Is it because it's a social media platform? I think it's a gross sleight of hand to be honest.
This is so disingenuous. When almost the entire world has a FB account, ‘fixing it’ now is essentially closing the stable door after the horse has bolted. The data has been harvested, it can’t be unharvested. There is no fix.
Personally, I’m disgusted that my data has probably been compromised just because I have some less technically astute friends who sign up for these idiotic apps.
I could deal with FB having my data, and I could deal with being targeted for ads through tools provided by FB. But to have my raw profile data being handed around and potentially misused isn’t acceptable.
I hope the fallout from this is severe for them. It is absolutely a massive breach of trust.
Now just imagine what happens to your contact info when your friend links their email account or their address book to "find their friends" on all of these services?
We need an equivalent of haveibeenpwned
I know this won't be a popular opinion but I'd welcome some regulation and bureaucracy for technology firms. This way there wouldn't be this weird gray/imaginary line situation going on that we have right now. I think Congress should probably outsource the regulation and bureaucracy similar to how the SEC works...but maybe not tied to the POTUS and instead creating a structure outside the purview of the POTUS.
I, for one, am tired of hearing tech companies say that they are sorry - believing that this makes whatever the issue is, immediately a thing of the past so that they can start again from day zero with regard to whatever they failed at.
A company the size of FB must police the usage of their data if they want to be able to promise security of it. That this wasn't being done is a mistake of unforgivable magnitude.
If we discovered today that 6 years ago there was some malware on the Google Play Store that stole a bunch of user data and sold it (but the malware itself is long gone, having been removed from the Play Store 4 years ago), would there be a similar level of rage directed at Google?
> No one forced us
A totally useless sentiment. People weren't generated all this data with benefit of hindsight and understanding. Effectively ZERO users EVER read the terms-of-service even, let alone understand the ramifications of giving up all this personal data.
It's hard enough to get people to save enough buffer to get through predictable crises that come up. Get them to be thoughtful and responsible in the face of a system designed to hide every aspect of concern and hesitation??
Facebook is one of several actors here, but it's complete nonsense to suggest that they are just a normal, innocent player in a internet world where people just do things a certain way because of culture. Facebook actively designed things for certain results.
It's not like Facebook is solely to blame, but the situation is NOTHING like you describe. Facebook wasn't just a neutral tool like email protocol and people just used it.
https://www.nationalreview.com/corner/mark-zuckerberg-plays-...
Facebook, you provided them with that data, you fuckers!
This likely explains many of his motives.
Fool me once, shame on you. Fool me 763 times, shame on me.
But from reading HNers comments, it doesn't seem I missed anything.
a. it might be in your interest to help keep the data updated. Say, if your app depends on an accurate home address, you'll ask the user to update it.
b. you might generate more data or content. Say, to publicize your app you might ask the user to post on facebook.
Moreover, it's always advantageous to have other developers depend and build on your platform. It makes your platform richer by adding functionality you may not have the resources to develop, and gives you leverage (ie, Apple and Google's mobile OSes).
If I recall correctly it wasn't "full access to all of friend's data", but similar access to what you had on the user? I thought it was very exciting. I could think of a ton of potential apps, and got to use it at a hackathon once before they limited the access. Back then I thought it was a bummer, but the move made a lot of sense.
Their third party app platform really helped with user growth and engagement over the years but now it's come back to bite them.
So it was both a good idea and a bad idea.
It's a large amount relative to other ongoing insider sales, across all US stockss, but not a deviation from ongoing activities.
Though by September, concerns over privacy and propaganda were well established.
Anyways, what really makes me wonder is that it's such a huge scandal right now, every newspaper does updates twice a day, society is "alert", Facebook loses 60B in capitalization over night. It's a big deal! And yet it seems there's nothing new here, nothing we didn't know a year ago. In fact, I remember hearing about Cambridge Analytica, Facebook and USA presidential elections/brexit voting a year ago from Jordan Peterson, and psychology professors aren't typically the ones to hear tech-related news first.
So what gives? Why now?
suicide fuel
What is the real alternative to centralized social networks?
Since Friday, or earlier of knowing about the incident, they could have conducted the audit and closed any lose ends and used this opportunity to say we have already done x and y.
Instead, it's just announcements. Not good enough.
Way before the rule changes.
Shame on you FB and Zuck you Suck.
If they are so honest or like to be honest going forward why can't they make it easy to see all my pics and posts that are public? Why can't they make it easy to see who can see what I posted? Which app or user is using my data. They have billions of dollars and can't implement simple features?
Its just a game they are playing and they will go back to their old ways in no time when no ones watching or under a different name.
I was reading FB fanboy Robert Scoble's post and it pathetic. You almost feel like he's being paid by FB. He used to be a well respected tech journalist.
I have deleted my FB account and I am so done with this company.
Further there been plenty of sexual harassment claims under his name. I doubt that he worries too much that he will catch some more dirt for praising Facebook these days.
Not a FB power user by any means but at least on desktop that's pretty easy to know
>Why can't they make it easy to see who can see what I posted?
Doesn't each post have icon showing who can see it?
https://techcrunch.com/2017/10/20/robert-scoble-has-allegedl...
You can do all of that... trivially. As you say, those are simple features. Ones they implemented years ago. Perhaps you should be more specific about what you're asking for?
It's fairly simple to do any of those things? You can even view your profile as certain friends to make sure everybody can see what you want them to see, or vice versa.
There's also always been an app list in the privacy settings, IIRC, where you can revoke their permissions and whatnot. I know this because I've had to delete permissions for dumb apps I installed when I didn't know any better.
It's not difficult at all.
I can't stop laughing at this remark. Robert Scoble is a shilling, sexist excuse for a "journalist."
I thought Facebook forbid you from doing that. Same with his wife.
"They trust me -- dumb fucks" right at the start was not enough warning?