Even though legally they are in the right, we as users should make this fact irrelevant and just abandon the platform. Let them be right, let them win the argument but lose the battle with the general public.
Even though legally they are in the right, we as users should make this fact irrelevant and just abandon the platform. Let them be right, let them win the argument but lose the battle with the general public.
Exactly. That's why they must be regulated. Pharma companies, food companies, and airlines, to mention three, have the same sorts of characteristics in their businesses.
Examples: Airlines have regulations because the typical user has no way to evaluate maintenance regimes or navigation procedures. The big information-hoovering dotcoms need the same sorts of regulations for the same sorts of reasons. "We obtained user permission" needs to be a stronger claim than "we tricked users into checking a box."
But because European politicians have some integrity left and internet is inherently global, most internet companies need to do these for everyone.
Yes, it’s not perfect, but a great first step.
Having that in mind, the project Gutenberg lawsuit makes sense. Imagine a service that copies a requested book and sends you that copy, all by postal services. If that company shipped into a country where the book in question stills protected by copyright, then it is clear that there will be legal action.
If regulations were introduced because of users not knowing what's good and beautiful, believe me, IT industry would be the most regulated thing in the world.
a social media platform that can be used to organize and manipulate hundreds of millions of people globally is far more dangerous than any airplane.
The formula is simple: promote emotionally powerful events that support your agenda, ignore events that inspire feelings counter to your agenda, deify supporters, demonize opponents, censor and ostracize anyone who speaks against the agenda.
That formula has led nations to war, sent innocent people to prison, changed laws, overthrown governments, led to acts of terror, and caused hundreds of millions (perhaps billions) of deaths throughout history.
But with digital information replacing newspapers, magazines, and TV, and with access to digital information being filtered through a handful of companies, those companies have immense power approaching that of governments that strictly regulate the media.
I don't agree with GP's assessment that users "haven't realized" but I do agree that the "majority however won't care". So why regulate if a majority of people are ok with it? They're not too stupid, they just don't prioritize the way some here do. Doesn't have to be a law to force them to prioritize this way. This false equivalence to expertise of airplane mechanics is completely different in a security context and these kinds of analogies only help to make others want to dismiss the point quicker. You want to regulate transparency, ok. But if some accept these things, let them.
While I agree that most people aren't stupid, I would argue that many people are ignorant. They simply don't know why they should care, probably due to a lack of understanding what it means for a company to have a copy of their data, and what that could enable those companies to do and figure out.
If that's true, solve that problem directly via education and enforcing transparency. There are also other solutions such as grants w/ stipulations, enforcement of existing fraud statutes, etc.
Let's assume there are 3 segments of people here: 1) the ignorant, 2) the non-ignorant accepting, and the 3) non-ignorant unaccepting. We have to stop letting #3 (arguably the smallest group but probably consisting of most here) run the show wrt to laws. There are too many consequences to pieces of legislation that all of us business owners have to conform to regardless of whether it is targeted to us. Most often we don't even recognize the consequences because we are so focused on how good we're going to do and how much we're going to help everyone. I dub it digital security theater.
This doesn't always apply. Should car regulations be abolished in favor of educating the ignorant?
Google plus failed, so why wouldn't Facebook eventually do so also? The youth don't have Facebook, it's mostly the 20-40 year olds who do. This 20-40 generation follow the mainstream media news and most of them are capable of realizing the harm in not protecting ones own privacy. Also, the current theme of news regarding social media is that it's being seen as a threat to democracy due to the ease of massive manipulation through political propaganda. A huge attack! Threaten democracy and the people will hate it.
Facebook does have the network effect, so killing its network effect will be much more difficult.
Google have contributed to privacy issues, e.g. with poor permission management.
It's not a ideal solution however. If as a society we have decided social networks are important a not for profit, or decentralised federated scheme is probably the way to go.
Oooh if only Apple did "social" apps well; they are famously not-so-great at doing them, I'm not sure where that comes from at root though.
Shooting from the hip: Maybe their intense internal secrecy translates into a worldview where the hyper-focus on the 1:1 relationship with their customer obscures their ability to see how their customers (and potential non-customers!) could interact; might even be dangerous.
Is your friend into tech news a lot? If not maybe that's why it wasn't shown. The only people I know who care about this story are tech people.
Don't like CNN nor FOX but still skim them for news, articles not TV nor videos.
Facebook's revenue is almost exclusively from advertising. Advertising costs on Facebook depend on reach, PPM, and/or PPC. Facebook advertisers don't pay for "active users" or even "users" -- they pay for PPM/PPC. In other words, your data is relatively worthless if you aren't around to be targeted based upon it.
Despite having a profile, if a user isn't there to see the ads, that means less reach and fewer clicks. When advertisers realize the apparent ineffectiveness of FB advertising, ad rates will decline, reducing revenues for FB. It's unlikely FB would actually run out of money because with reduced scale comes reduced costs -- eventually the entire platform might be operated by Zuckerberg at at a WeWork rented desk after having laid off everyone else.
My point is that your data is pretty much useless if you aren't there to be exploited because of it.
Facebook and Google are huge really for one main reason -- self-service advertising. Some local bike shop can experiment with $200 in PPC super-easily. That local bike shop can't as easily run a radio ad or TV ad and measure the results as easily. So Google and FB have made advertising something that is accessible to those with both lower budgets and lower sophistication. The Coca Colas and General Motors of the world don't care about FB or Google at all -- they have the resources to sponsor the Olympics or national TV shows or pro baseball teams.
I downloaded my Facebook archive this weekend and it was a massive 12kb. I know entirely what it means to have a living account and not feed the beast, but I am also the rarest exception that disproves the norm. Deleting a Facebook account means the drug addict cannot relapse.
Advertising isn't the whole story by a long shot... hence CA / SCL Group (and whom else shall we add next?)
GDPR won't dent Facebook in the least. They'll bend where they have to, and no further. They'll pay occasional fines and that won't matter either.
If you take it to an extreme and the only thing they can do is show non-personalized advertising and do zero tracking, they'll still print billions in profit in the EU market. That's what owning most of Europe does for you. Their gross profit margin globally is just under ~87%. Cut that in half and they still have a very profitable business with margins comparable to Google.
Facebook could run entirely untargeted advertising on their platform globally and still yield enviable profit margins. Their platform is extremely tightly run on costs compared to most tech giants.
People talking about doom on this, aren't discussing facts or using logic, they're projecting a revenge fantasy out of emotion. It's driven by a desire to punish Facebook.
Living in EU, and I am thrilled at the party we will have, when 1-2 million people/facebook users will send this letter to FB [1]. I strongly believe that this will hurt them financially (where it actually matters/hurts).
I (try to) sinkhole every tracker, advertiser etc. on my PC and jailbroken iphone. I am sure that I don't block every one, but 90% is better than 0%.
It may keep me busy, but when I start receiving the answers that FB, Amazon, etc. have provided my data to XYZ broker, and then I will be more thrilled when I send THOSE guys the same letter.
Of course after every inquiry they will be receiving a "right to be forgotten" letter.
Hurt them where it does until they learn to respect people and not see them as items to be traded.
[1]: https://www.linkedin.com/pulse/nightmare-letter-subject-acce...
Ps: I am not a hater. I enjoyed FB until it started to try to manipulate me e.g. altering my timeline and showing me what THEY deemed is 'good for me' (profitable for them).
Pps: They make enough from advertising. It was excessive greed that got them to start the sell-out.
As someone who’s Jailbroken dozens of iPhones, I understand the appeal. That said, you seem to prefer privacy/security, and I can unequivocally state having a jail broken iphone is a huge step backwards on both.
Will Facebook even check or will they just play it safe and accept most requests?
So yes, it does matter, and them being compliant is a good thing.
Except they do care about their associations and brand management:
'At least three companies -- Sonos, Commerzbank (CRZBF) and Mozilla -- have pulled advertisements off Facebook after a data scandal engulfed the social network. Others are asking tough questions.
Unilever, which owns brands including Dove, Lipton, and Ben & Jerry's, issued a forceful warning to the platforms in February, saying they had become a "swamp" of fake news, racism, sexism and extremism.
"We cannot continue to prop up a digital supply chain which at times is little better than a swamp in terms of its transparency," said Unilever marketing boss Keith Weed'[1]
[1] http://money.cnn.com/2018/03/23/technology/advertisers-faceb...
We'll, they're contributing to this [1].
As much as they "hate" the platform, they still love the ad targeting it provides. They all do. Which is probably one of the only reasons these brands even bother.
They just can't help themselves when it comes to being able to push $X towards women only, in their 30's, who have small impressionable children at home, are affluent enough to buy expensive soap, etc, etc, etc.
[1] https://www.nytimes.com/2017/10/08/business/dove-ad-racist.h...
Many people didn't realize that we still living in a global society that pretty much made by many super large sized Black Pearl[0]s and Jack Sparrow(s) is the captain.
Dear Captain Jack is cool sometimes, and could bring you to the treasure, but you should never trust him that he will taking care of you. In fact, regardless what he said, he don't care about you even a little, all he care about is himself. If you fell off board, he will not bother to save you, unless it's out of coincidence.
So yes, you may follow him closely for an amazing adventure if you want to, but whether or not you will survive in the end, it's all depends on you.
[0] Yes, that pirate ship.
Plus, how effective is the advertising in motivating purchase versus sowing seeds of discontent?
It has utility, yes, but what the majority seem to consider, "not good".
Facebook's controlling minds don't care about you, they care about if there's reduction in profit [or profit generating ability].
Ok, fine, this is anecdata. But we're talking heavily tech leaning people and we didn't hear anything from them.
Nothing is going to come of this.
They'll probably be damaged if FB becomes a downmarket social network only used by those who are unsophisticated and unaware. It may not be apparent now, but it will be when some new product captures those users and starts building social momentum that FB can't counter. That's literally how FB got big, and I think they've only been able to so far prevent it happening to them because they've been allowed to buy their competition.
I posted this in another thread, but it's relevant here too:
Isn't this an Android issue? I mean, Facebook is collecting the data, but they're asking for it like every other Android app does.
As an example, iOS used to just show a dialog that mentions an app wants to use your location, and it was later changed to:
1. a dialog that asks if it's ok to use your location while "you use the App" with,
2. a required blurb by the app that specifies how it's used, and
3. a separate dialog for when the usage of your location also applies "even when you are not using the app", with a clear option to instead grant the permission only if the app is running in the foreground.
iOS also warns you when you use a custom keyboard if the keyboard wants "full access". And clearly explains this means it can "transmit anything you type, including things you have previously typed with this keyboard", including "sensitive information such as your credit card numbers or street address".
I quoted directly from the dialog boxes because I think the wording is well crafted to make it very clear for non-savvy users. Android on the other hand literally just asks you if you want to use Messenger as your "SMS app". This tells nothing to the user, doesn't inform them what data can be accessed, what can be done with it (can it leave the phone?), nor gives the user any further options.
I know Facebook privacy is the hot-topic right now, but my problem with this is there's lots of other apps that can and probably have used these permissions too, and are probably storing this information. This is the opportunity to put Google under fire for their terrible Android permission system, which extends to random games asking for full phone access and a myriad of other sketchy things, but by focusing on Facebook this opportunity is being lost.
The concept in medicine is that consent for treatment is done in a simple way that encompasses things that are commonly an issue (but often a minor inconvenience), things that are rarely an issue but are disastrous, and things that might specifically be an extra-big issue for the patient (i.e. damage to fingertip sensation for a typist, or something like that).
This gives the responsibility of getting the salient issues communicated to the person requesting consent - forcing it to be phrased in an understandable way. I see some companies are doing a summary of the terms and conditions (seen it with Virgin and Google), which is welcome, as long as they are including what is common and important in that summary and not hiding things in the T&Cs.
Assumed consent of an ignorant party is effectively no consent at all.
I remember when Google and Microsoft changed their privacy policies 2-3 years ago to become much more generic and "unified" - as in they could now use your data however they found fit from across all of their services and products. Great piece of PR that "unified" trick, though, so props to the PR team, I suppose.
The tech media mostly treated it with a shrug even when there was something that sounded quite suspicious in there, and had a tone of "yeah, but that's probably just used for X, and it's unlikely Google/Microsoft will use it for other nefarious purposes. It's just for legal reasons, you see."
No, those provisions weren't put in there "just for legal reasons" and they were put in there on purpose because they were meant to be used. Also, if they put it in there "for legal reasons" it's also because they intend to use it and need the legal cover. It's weird how the media took out exactly the wrong message from it back then.
It also bares repeating, because the media didn't cover it much back then, and it was quite a sneaky thing for Google to do - Google changed its privacy policy to no longer keep your data "anonymized." Many people even on HN like to defend the companies' data collection "because they anonymize it", which in itself has always been a joke, as studies have proven, but they no longer even do that:
https://www.extremetech.com/internet/238093-google-quietly-c...
They have done great things in that regard by pushing the whole industry forward
The problem is that very few people cared.
So even if people start leaving facebook in mass, it will just start all over again with another bad actor.
How many tons of people are leaving Facebook now?
As another example, if you translated tete a tete into "head to head", those actually have slightly different meanings in English. Tete a tete translates idiomatically to "one on one", a private meeting of the minds, while "head to head" is a direct--usually public--confrontation or encounter, as one might find in a sporting match.
Do I do it right ?
You could think of English as a contest between other languages, to see which one can get the biggest share of the etymology. French is one of the leaders. A lot of the core words come from Norman, but modern terms, particularly those drawn from cuisine and fashion, have made it in as well.
I found French class hard growing up. Until I realized that this "latin" language had as much in common with English as it did my two romanance language.
unless they want to prevent this from happening in the long run?
Even that is dubious. Law is interpreted by judges for this exact reason: people pushing it to extremes.
The legal system (at least in US and EU) needs to catch up to this, but it does. In the EU, the GDPR [0] will require "freely given, specific, informed and unambiguous indication of the data subject", which is a lot more than Facebook's claim of having "permission". We will see how judges interpret that.
Judges are getting more tech-savvy, and I think lawyers are also getting better at explaining the deceit. There is hope, the question is how long it will take at this point.
I'm not so sure about that, but that's what courts are for.
If the pop-up does not adequately convey the consequences of agreeing, it cannot reasonably be considered a form of consent.
Just wrote about it here: http://www.tnhh.net/posts/shitty-by-default.html
What the legal precedence is for UX patterns considered deceptive enough to be intentionally malicious?
The best I could find was a settlement with linkedin in 2015: https://www.fastcodesign.com/3051906/after-lawsuit-settlemen...
Unfortunately, there's also the little matter of EULAs.
California is a two-party consent state for recording, and it's not an unreasonable stretch to say this should also include call metadata. If one party (i.e. Me) opted out, and someone else didn't, they now have a log that I didn't give them permission to make.
I think this is probably the most strong case users will have against Facebook, and I honestly think it's a pretty damned good one, but IANAL, YMMV, etc.
Either way, if you're still using the Facebook app after this has come to light... you're probably setting yourself up for a world of pain. Even if you don't delete Facebook outright, the risks of having their terribly coded app on your phone vastly outweigh the benefits at this point (you know, if you didn't delete it when people realized it decreased their battery life by 10-20%, or that it asked for every permission Android had an option for, with no way to tell Android to restrict access back-in-the-day...)
Yes. It is an unreasonable stretch. Cal. Penal Code § 632 prohibits "eavesdrop[ping] upon or record[ing] [a] confidential communication." There is no set of circumstances in the history of telecommunications where seeing your itemized phone bill is the same as eavesdropping.
I understand you feel violated. You should. What Facebook did is vile. But that's not a reason to throw due process out the window.
If a law said i couldn't "record your visit to a shop" and I shared commercially that you "went to the shop at X time and stayed Y minutes" even if I didn't record the details of your purchases, or what you were wearing, or whatever, it would still appear to be a contravention of the letter of that law.
It is very unreasonable. All modern phones automatically keep a log of your phone calls (call history). Should I ask for the consent of anyone I call or delete the phone call from phone history immediately after, otherwise I face criminal penalties?
It was required in 8.0 to tell the users that they're collecting this data. So the question is, did they collect it before 8.0 w/o permission?
https://developer.android.com/about/versions/oreo/android-8....
People simply do not care about their privacy if its in conflict with convenience. It has been common knowledge for years that Facebook will directly use that data against you and still people, completely aware of this, didn't care.
The only thing that made people care about their loss of privacy was a change in fashion. A new trend. Somehow, now, it is suddenly bad where before it wasn't. I simply cannot find the words to blame Facebook for this.
Also, Zuck arguing he has your consent is like the spouse saying "You mumbled 'okay' when I badgered to take pictures of you naked! That's permission!". Also Zuck saying it's secure is like your spouse having those pictures in a Windows share in his frat house but telling his frat bros "tell me that you agree not to look at those pictures." (More like your spouse saying the small print says he's allowed to distribute those pics to other people, but only if they promise not to misuse them...).
> People simply do not care about their privacy if its in conflict with convenience
is only partially correct.
So far I have been able to distinguish these kinds of people:
- people unaware
- people aware that try their best to keep privacy (if they are on facebook, they limit their usage - more or less like "lurkers")
- people aware and still posting stuff on FB/giving some permissions and they still do "something" (a bit more than lurkers above)
- people aware but "I don't have anything to hide", yet still unaware of the full potential of lack of privacy and they post whatever they want
- people aware and educated about privacy and "I don't have anything to hide" (yes, they do exist) and they still post whatever they want
> I simply cannot find the words to blame Facebook for this.
I have to disagree here as well. There are certain things which I agree with you on, e.g., this feature was enabled by default, because users want to have more convenience. Indeed! However, what about last week's scandal with Cambridge Analytica? And what else aren't we aware of? I am trying my best not to connect these two facts, yet, it seems there is a pattern when it's about user data => who cares, they don't know what they want.
This isn't news to me. Any data submitted by a user to Facebook is forever surrendered to Facebook who then owns it. Facebook can do whatever they want with their property.
The only surprise there is that users so happily agree to this madness only to be shocked by the result. What did they think was going to happen? Still, I don't blame Facebook for this.
It reminds me how people (Twitter addicts) were shocked at this website 10 years ago: http://pleaserobme.com/
https://techcrunch.com/wp-content/uploads/2018/03/opt-in_scr...
The no button is barely recognizable as button. But the No button is barely recognizable as a button and it and the explanation are gray on white, while the Yes button and misleading title are much more emphasized. And even half the explanation is bullshit like "better experience for everyone". Plenty dark UX in my book.
(Though I assume a lot of people would have agreed to this, even without the dubious UI)
Is that consent? Do you have a hard time finding the words to blame the malware creators?
It's not great, but it's a little better than you suggest.