Cow Game Extracted Facebook Data
theatlantic.com
theatlantic.com
Personal things like messaging history and contact information are certainly enough to build a 'social graph', but what Google does not let apps do is access the information that Google stores about me on their servers just because my friend has both my number and a greedy app on their phone.
Imagine what an app could do if they had access to your entire message history! (Why would anyone give apps access to their messages? So that they can send / receive special emoji, for example.)
Either way, discrete and easy-to-digest information like 'likes' are exactly what they wouldn't have access to from Google, and honestly it seems like automated sentiment analyses are still very error-prone; large corpuses of text don't seem ideal for this sort of targeting.
It's all privacy leakage but it's not at all the same data. Facebook's graph is still noisy but it's better or at least different data than other companies have.
I don't think Google does that...
Photos (on Android and iOS) contain a wealth of information, and any app having access to photos, can clearly figure out where you have been (based on photo's metadata containing GPS location), what you like to eat (if you take a lot of photos of food), where you like to hangout, time of day/week you do certain activities, purely based on image recognition.
Any wonder why Google Lens is integrated in the Google Photos app?
Add to that, the ability of identifying people from photos (Apple, Facebook and Google do it very well) and you can easily connect the dots, and it'll be hard to escape this kind of data digging, even if you are Jack Reacher.
Even pro-privacy Apple doesn't do much in terms of access to photos on iOS. If I want to share one image on Whatsapp on iOS, I have to give Whatsapp access to Photo Album. And once the access is given, a superficial scan can provide WhatsApp full info of locations from my photos, in a few seconds (even if it is 20 GB of photos).
Privacy on iOS in this aspect is bad. I can only imagine that Android is much worse.
I've not seen anyone address this, but reading between the lines, many people seem to hold a view that the existence of these finely-grained personal data profiles at this massive scale is fine so long as they exist only on the servers of fb and goog, but why? What makes that acceptable or reasonable, besides the persuasiveness of large amounts of money?
I think the clearest path forward is that no one should be creating these kinds of data profiles.
I don't think a bot learning my route to work, or a doctor's appt(along with a swath of more "monetizable" personal info) so it can alert me to potential traffic delays is a reasonable trade-off for the massive societal problems the behaviour of creating these data profiles poses.
If this data is such a monumental danger when it escapes the permeable confines of the fbs and the googs, then it shouldn't exist within these companies either, not just because as we've seen the confines are quite permeable, but also because the potential for negative use of the data doesn't change depending on who has access to it.
It can be persuasively argued that simply creating and collecting these data profiles is itself a negative use of the data.
Nothing. And for now, Google's services are worth the data they collect. Facebook's value proposition is comparatively laughable, which might be why so many people are so upset with the scope of how their data was used.
And don't even get me started on how users, including those who have not signed up for the service, get tracked on massive swaths of 3rd-party sites if they don't take pains to prevent it - that's downright sinister.
Also worth considering, Facebook is all about social and preference ("like") data, but live location is something you can get as a mobile app and a lot of stuff can be inferred from where you live/work/visit.
Regardless of how dangerous Android permissions are or aren't, I do agree with the larger point that Google is scared about what will happen to Facebook, because it knows those regulations or even a "privacy revolution" that may come in the wake of this will impact it, too.
It's probably not even just this one event that will hurt Google. This sentiment has been growing over the past few years. If Google hasn't noticed it growing, then they are out of touch. If the anti-privacy trend continues, it will be bad news for Google, Amazon, Microsoft, and even Apple (which seems to be backtracking on some privacy features lately).
I do hope that at the very least the anti-privacy trend pushes companies to limit data gathering and use new privacy-preserving tech that doesn't allow them to look at the data at all. And I hope they do that before it's too late (for them).
Neither does FB I believe. Otherwise their business model of knowing more about you than anybody else would fall apart.
The scummy part was that the data was obtained using an app that’s unrelated to what the data was eventually used for, but Android is totally ripe for that as well.
The additional scummy part was that you could authorize FB to download that data for your friends as well as yourself, so your data might be consumed without you ever being aware of, or giving permission for it. As far as I'm aware Android has no such equivalent.
I don’t believe this is true. You could authorize apps to download a very limited amount of info about your friends. If you have a reference to some authoritative source that proves the opposite, do share.
Extraordinary claims demand extraordinary evidence, and all that.
https://techcrunch.com/2015/04/28/facebook-api-shut-down/
You used to be able to provide access to your friends photos, checkins, posts and more besides.
The worst Android offenders, as always, are the big ad libraries that are installed across a lot of apps. They're able to build a rough personality profile based on the types of apps someone has installed. So they can generally say if a user is into categories like music or politics or comedy. But that problem exists on iOS and the web.
Android has also tightened up its permission model considerably over the last several years.
It depends on what you mean by exposed. In the context of Cow Clicker (or even the CA stuff) the data wasn't really exposed, it was shared. Google shares your private data all the time. Ex 1. Google+ APIs. Ex 2. Android APIs. Ex 3. Gmail API.
Allowing app developers access to information about a user is standard procedure (because otherwise apps would be terrible).
Many of these platforms (Android, Facebook, etc.) have, over time, tightened up the access to this information.
I hope that local computing can get strong enough to do the same types of assistant type usefulness through local AI and peer to peer sharing. This will also estimate travel time, recognize appointments, etc etc. Open source to the rescue.
How do you know that?
You could argue that "adding a browser keybinding" should be a separate API. You're not wrong (I'd love an extension like this to replace Ctrl+Q with Ctrl+Shift+Q), but browser vendors (at least Mozilla) seem to be very reluctant to add more APIs.
I was going to mention how I've been confused by people having overreactions like "it's just an extension to rewrite 'millenials' to 'snake people', why is it stealing all of my data?", equating the permission to read data from webpages with an implication that it will steal all your data. This never made much sense to me, since it seemed obvious to me that the required permissions for those things would have to be the same. In light of the Cambridge Analytica situation, though, I realize these fears were very well-founded.
They do have the technical means to offer more nuanced permissions. Things like "send emails and read replies on email threads it creates" or "access to emails matching this kind of search where new search terms would require a re-auth". It's not a priority though.
In their defense, millions of people were giving away their passwords to a bunch of external apps and the current situation is better than that.
[1] https://www.theverge.com/2017/5/3/15534768/google-docs-phish...
[2] https://lifehacker.com/unroll-me-the-email-unsubscription-se...
I assume that my name and date of birth are already public domain. They are listed publicly when you register a company. Insurance companies already share that information around anyway.
My issue is when Facebook sells my entire internet browsing history.
I doubt that very much. You also seem to ignore the lack of runtime permissions in desktop OS's such as Windows and Mac OS that could easily do the same thing.
>Every single Android app seems to require access to every single thing
This is a lie. The majority of apps ask for only the runtime permissions they need to work. Regardless, you're still in control of the permissions you grant and if you believe an app is asking for permissions which it shouldn't have then you shouldn't grant it.
. Second - if it's an app you already installed that has required new permissions, that app can run (via BroadcastReceiver) when it is updated and before you have a chance to alter the fine-grained permissions.
Separately, the interface for managing fine-grained permissions in Android is weird. You get most of them in one place, but then it seems you have to check a couple of other places for 'special' permissions?
edit: never mind this - it seems like the old version is the one that will get notified, and the permission change only applied ot the new one.
* * * IMO, which stands for In My Opinion. You are welcome to have your own opinion. Don't expect it to change mine. * *
Not that we shouldn't be outraged. I'm glad we finally have outrage. We should have all been outraged a long time ago.
This is not even remotely true, especially when it comes to the general population. I'm not trying to slam you here, I was of same mindset too, since at least 2009 (I stopped using API in 2013 and assumed things were clamped down).
I don't want to be a nag on his, e.g. Mustnt assume everyone knows what you know! Rather, I think this is an advantageous mindset to have. Anything you know in your profession, especially when it comes to tech or data, you can assume plenty of people (including future customers) don't have a damn clue.
I think one of the societal problems we have right now is an overwhelming lack of tech literacy. It affects the media but also (and more importantly) government. People simply don't understand this stuff, and the problem isn't going to go away, because if you do have tech knowledge you can make far more money as a developer than you can as a journalist or politician.
https://www.theguardian.com/world/2012/feb/17/obama-digital-...
From the article:
> Barack Obama's re-election team are building a vast digital data operation that for the first time combines a unified database on millions of Americans with the power of Facebook to target individual voters to a degree never achieved before.
Also
> Consciously or otherwise, the individual volunteer will be injecting all the information they store publicly on their Facebook page – home location, date of birth, interests and, crucially, network of friends – directly into the central Obama database.
> "If you log in with Facebook, now the campaign has connected you with all your relationships," a digital campaign organiser who has worked on behalf of Obama says.
[0] Washington Post: About 100 million people couldn’t be bothered to vote this year
https://www.washingtonpost.com/news/wonk/wp/2016/11/12/about...
[1] A reported 137,100,229 people voted:
https://en.wikipedia.org/wiki/United_States_presidential_ele...
That's less true for the old school media companies, but most new media companies are very tied to advertising networks for their revenue.
I think that sort of statement applies here. Some people have known about what this data can be used for and truly understood the implications of it for a long time. Those people are also the type of people that have stopped using Facebook years ago. Most others are just now starting to realize it.
My issue is that they’ve always been transparent about collecting and sharing data. They just say it in a friendly way.
There’s a whole episode of South Park with the Eula. And people stil don’t read before clicking.
This happens in many places. Check out the effect of unnoticed binding arbitration clauses - http://www.latimes.com/business/la-na-supreme-court-californ...
I’m happy if laws change to improve this. But I’m surprised too.
But almost no one realized that there employment history was being shared with the Trump Campagin, because THEIR GRANDMA took a personality quiz to find out "Which Golden Girl She Was Most Like".
And where did we consent to this actually? When I signed up for Facebook 3rd party apps didn't exist. When my friends started installing them, I thought I was protected because I stayed away. I consented to sharing my information with Friends obviously, but with 3rd party apps they install???
I'd really like to see how that language was written, for a condition that didn't even exist yet.
Nerd being a nerd: Foo is terrible for privacy!
Nerd trying to look non-nerdy: Nerds say this, but ordinary people don't care! So Foo will win, get used to it.
This scandal however, makes it seem more like ordinary people would care, except they don't know about the terribleness of Foo.
Actually I think the it's a confusing mishmash of the two. People don't learn about stuff because they don't care. And its rational not to care about something if there isn't something you can do about it.
But when a scandal like this hits, more people decide to care because "join the bandwagon of protest" becomes a thing you can do. And that makes more people know about it, which make the potential bandwagon bigger, etc.
This 'outrage' wasn't real until it impacted politics.
EDIT: In an attempt to protect my karma from those who have drunk far to much kool-aid I should point out I did not vote for Trump and I think he is a total clown. I just think the current clickbait/outrage media culture is far more a danger to the american values I cherish then 3 more years of this ass-hat.
http://www.dailymail.co.uk/news/article-5520303/Obama-campai...
If you'd like a more in-depth explanation, I found this post by the former Chief Scientist of Obama For America campaign (2012) that goes into the key differences between how the data was collected & used compared to Cambridge Analytica: https://medium.com/@rayid/why-what-cambridge-analytica-did-w...
This is not about using Facebook. It's about doing shady, manipulative stuff.
The Obama app was clearly a political campaign app
They did not use fake quizzes to steal user data
they asked supporters to contact their friends explicitly
they did not download friend of friend data surreptitiously
they did not buy or re-sell data in violation of FB's TOS
they did not lie and claim to have deleted it when required
they used user submitted data to build a database of potential supporters and contacted them to encourage them to vote
they did not engage in psychometrics to spread fear and fake news
they did all this domestically with US residentsAct I - https://www.theverge.com/2012/2/7/2782947/path-ios-app-user-...
Act II - https://twitter.com/davemorin/status/976624270477545472
It absolutely did care about the Facebook TOS, had a contract with Facebook about what data could and could not be used and retained, and didn't share Facebook data beyond aggregated demographic information (age, gender, region). We were very careful not to do anything even remotely sketchy with the data.
But this is the sort of company with a brand and something to lose, and a relationship with Facebook.
However Facebook itself seemed willing to expand the TOS to extremes. At one point it was possible to get games that the user's friends were playing; I was amazed at whoever got them to agree to that.
If it wasn’t it would be enforced in the code
Would it be difficult for facebook to be aware all data brokers in the market and also at what price point, under what agreement and and estimated transactions volume?
It is a bit tedious to manually allow js on websites to get them to work properly but...gee, just refer to the article's topic. Scripts from 'facebook.net' are somewhat ironically, but predictably, loaded with the page.
The problem is that they were, and are, insincere in saying that. The user has no option to say NOPE I'm not giving you, that, that, that and that. No way to see what something does before giving them anything at all.
If that was done right users would have the choice.
Failing that Facebook is culpable.
The trouble with the culpable or "rule of law" approach though is that it's up to politicians, maybe bored law enforcement people, maybe some bribery and corruption. i.e. it generally works poorly if at all, all too often it achieves the opposite.
I say avoid legislation and give individuals their own control. Real control.
Wow.
EDIT: NoScript did the trick.
This doesn't mean you have to stay; if this behavior annoys you, don't read their content. But don't complain that their website is "sending you away", because that's exactly what they want. You laid out your demands (ignore the fact that I'm using an ad-blocker), and they're showing you the door.
But, it would be nice if there were some way to filter out sites like this one, and others that have interstitials or the infamous "Forbes Thought Of The Day" and all the other nuisances.
Because I don't want to be on their site any more than they want me on their site. They just keep showing up in my various news feeds.
Personally, I make a judgement call. On the Atlantic I got the ad block message recently and decided to switch it off as I find the content unique and well-written. They're not a news-aggregator or a spammer, their ads aren't that intrusive... I think it's a fair-call.
Class of customer, in the sense of the question, is a visual attribute of a customer making them unwelcome due the low probability of them being profitable for the store.
curl https://www.theatlantic.com/amp/article/556214/ \
|sed -n '/<section id=\"article/{s/.ad width=/<!ad width=/g;s/<div/<!div/g;/<p>/,/<\/p>/!d;/amp-img.*cdn.theatl/{s/amp-//g;s/layout=.responsive.//;};p;}'|tr -cd '\12\40-\176' > 1.htm
firefox file:///1.htm ;
The file "1.htm" contains no Javascript.