If they drill too deep they'd need to face very uncomfortable questions about other platforms too, e.g Palantir (Thiel was right there lurking ;)). Facebook is the Internet in many countries (making them less resilient and even more prone to meddling than the US). And so looking at it from the IC perspective FB is too big to fail:
- Remember Palantir worked with CA on the Facebook data it acquired: https://news.ycombinator.com/item?id=16690721
- Remember how confident in May 2016 Thiel was of a Trump presidency and when he openly started endorsing Trump? Was he operating with more knowledge than available to the general public: http://fortune.com/2016/05/10/peter-thiel-trump-delegate/
- His $1.25 million donation in October 2016 seems even more interesting now: https://www.nytimes.com/2016/10/16/technology/peter-thiel-do...
- Leaked Palantir Doc Reveals Uses, Specific Functions And Key Clients https://techcrunch.com/2015/01/11/leaked-palantir-doc-reveal...
- This is who runs PRISM: https://talkingpointsmemo.com/edblog/is-this-who-runs-prism
Oh and Palantir enables Immigration Agents to Access Information From the CIA: https://news.ycombinator.com/item?id=13895827
Also more uncomfortable questions: https://twitter.com/RidT/status/983789426340921349
We got a demo of Seisent, since bought by LexisNexus, mid-2000s. Our use case was to uniquely identify patients to improve record matching across heterogeneous databases.
Back then, Seisent was just based on publicly available data. It spanned all of North America, The Caribbean, and a good portion of Central and South. In those regions, every single person has been unqiuely identified. Easy to do thru process of elimination with that much data.
When shown my own data set, everything about me was right there. Everywhere I've ever lived, worked. My entire legal trail, like mortgages, marriage. Seisent even inferred my ex-wife's affair (FOAF).
Seisent sold their tech (big graph database, query language, some gear) to the NSA. Who was able to add non-public data. Like phone records, electronic transactions, etc.
That was 10+ years ago. Now I imagine they're slurping data up globally.
Siesent, Palantir, Facebook, Google, Amazon, Apple, etc effectively know everything about everybody.
I assume foreign efforts are doing the same.
I'm sure they have a lot of data, but like anyone else, it's dirty data, and it's difficult to draw meaningful conclusions from it.
PS- One of Seisent's selling points was helping to solve cold cases. The successful example I remember was matching MOs from a set of crimes in multiple areas and then identifying all the persons matching the profile who could also be in those areas at those times.
How about a single targeted advert for a product I want to buy? (Note: products I already bought and then start seeing tons of advertisements for don't count)
> PS- One of Seisent's selling points was helping to solve cold cases.
Did it actually help solve those cases? I haven't heard of any dramatic drops in unsolved murders, or huge numbers of cold cases being closed.
If they really do "effectively know everything about everybody", they're keeping damn quiet about it.
Yeah, Thiel is more conservative than most big names in tech, but that's not surprising given that Palantir started focused on the national defense space.
Oh, and "PRISM"? Yeah, that's just a data importer. Completely separate from the secret CIA project, it's just a classic naming conflict. It was originally named "Palantir Data Importer" or something of that ilk, but Palantir loves fancy names, so re-branded it Prism (which is actually a clever name, as prisms takes white light and separates it into colors, much like the importer takes unstructured or semi-structured data and separates the entities and relationships).
Source: Am former Palantir engineer
https://www.washingtonpost.com/news/the-switch/wp/2018/04/10...
SEN. MARIA CANTWELL (D-WASH): Thank you, Mr. Chairman.
Welcome Mr. Zuckerberg.
Do you know who Palantir is?
ZUCKERBERG: I do.
CANTWELL: Some people refer to them as a Stanford Analytica. Do you agree?
ZUCKERBERG: Senator, I have not heard that.
CANTWELL: Okay.
Do you think Palantir taught Cambridge Analytica, as press reports are saying, how to do these tactics?
ZUCKERBERG: Senator, I do not know.
CANTWELL: Do you think that Palantir has ever scraped data from Facebook?
ZUCKERBERG: Senator, I'm not aware of that.
...
CANTWELL: Have you heard of Total Information Awareness? Do you know what I'm talking about?
ZUCKERBERG: No, I do not.
CANTWELL: Okay. Total Information Awareness was, 2003, John Ashcroft and others trying to do similar things to what I think is behind all of this — geopolitical forces trying to get data and information to influence a process.
So, when I look at Palantir and what they're doing; and I look at WhatsApp, which is another acquisition; and I look at where you are, from the 2011 consent decree, and where you are today; I am thinking, “Is this guy outfoxing the foxes? Or is he going along with what is a major trend in an information age, to try to harvest information for political forces?”
And so my question to you is, do you see that those applications, that those companies — Palantir and even WhatsApp — are going to fall into the same situation that you've just fallen into, over the last several years?
ZUCKERBERG: Senator, I'm not — I'm not sure, specifically. Overall, I — I do think that these issues around information access are challenging.
To the specifics about those apps, I'm not really that familiar with what Palantir does. WhatsApp collects very little information and, I — I think, is less likely to have the kind of issues because of the way that the service is architected. But, certainly, I think that these are broad issues across the tech industry.
> ZUCKERBERG: No, I do not.
Hard to believe someone who has spent the past decade looking at how to monetize data has never heard of TIA.
Your average Ivy League CS grad is familiar with the bottom-line summary of what Palantir does - all the claims about secret projects aside, they do give tech talks and put product demos online. Zuckerberg is claiming he's not even familiar with that stuff?
"Going to tweet out amounts received by each Congressperson from Facebook since 2014 as they speak in this hearing"
https://twitter.com/sarahjeong/status/984075571981266944
this is worth gold!
That's the point.
Imagine the result of all this is a piece of legislation that doesn't hamper Facebook in any significant way but imposes large fixed compliance costs on tech companies.
Facebook is huge, they pay the costs without even noticing. People who want to dethrone Facebook, or replace it with some decentralized alternative that actually protects privacy, are killed in the cradle by the new fixed overhead.
Facebook gets what they want and the Senators get to look like they've done something, meanwhile nobody pay attention to the fact that the same Senators are about to get a load of campaign money from Facebook.
I don't follow you, how would a decentralized (and presumably non commercial) alternative be affected by this?
Besides the fact that legislation is typically a local affair Facebook would have an advantage versus another commercial player, and whoever wrote the law would most likely focus on those aspects that would have an impact on such players as well.
So for a non-commercial, decentralized and/or federated alternative this would be a huge boon, rather than that it would be killed in the cradle.
Are you anticipating a specific exemption for non-commercial operations? That hasn't been true historically.
For example, the notice and takedown rules in the DMCA require you to register an agent with the copyright office. There is no good reason for this when you have the info listed right on your site, but it makes a great trap for the unwary for anyone without the resources to hire a lawyer to tell them that, and causes grief for distributed networks where it isn't clear who should have to register and it almost certainly isn't the case that every participant actually has. Because the law came about as a negotiation between the big players with nobody even considering how it would affect small businesses and individuals or network architectures different from the then-dominant ones.
Or the regulatory nightmare in finance that has successfully destroyed a huge number of small nonprofit credit unions, or the medical industry where none shall enter without an entire law firm on retainer, etc.
People have just gotten used to it so they don't see what's missing. The idea that any individual or even pair of individuals could conduct a medical trial in today's environment is quite ridiculous, so nobody expects it to happen and then no one is surprised when it doesn't. But that was once the source of most of the progress in modern medicine before it was de facto prohibited by law.
It may be true that federated systems won't be affected because of a lack of enforcement, but that's cold comfort. Plenty will opt out of a system where they have to break the law in order to operate, even if the law is almost never enforced. And laws that everyone violates but are almost never enforced are inherently dangerous because they give the government a pretext to go after whoever they want for unrelated and pernicious reasons.
A little antitrust enforcement certainly wouldn't hurt -- stop letting Facebook buy its competitors. More competition would do two things. First, less people on each network, so less impact for each mistake. Second, more competition creates market pressure. It's much more problematic for Facebook to be able to do this and get away with it because they have a monopoly and users have no alternative, than for them to do this and lose all their users to a vibrant competitive marketplace, serving as a lesson to anyone who would do the same thing.
It also wouldn't hurt if the government would just overtly support decentralized systems. The internet itself, The Tor Project and most of the other decentralized technologies we have all came out of government research grants. Which we don't do nearly as much as we used to in this space.
We could also roll back some of the existing bad laws -- like SESTA -- that are already making it harder for small players to compete.
Companies like Google and Facebook have effectively turned the web into "the internet" for the vast majority of people. Even e-mail has essentially become "the web" for most people thanks to services like gmail capturing so many uninformed and unsophisticated users. IRC, too, is mostly lost to services like Slack.
Corporate interests have mostly erased the concept of an open, decentralized, multi-protocol internet from the public consciousness.
I can see this becoming so bad that the only way to communicate freely would be to tunnel our stuff through TLS on port 443. (That is, doing what looks like HTTPS.)
That is definitely not the result of a lack of regulation. The networks doing that are predominantly not public networks like Comcast, they're private internal corporate networks. The issue is they're a large enough minority that they can't be ignored. But that can't be fixed with regulation of public networks.
In fact, it's caused by certain regulations and pseudo-regulations like PCI-DSS, which require the default-deny policies you're referring to.
When my relatively small company announced that they were installing a Palo Alto firewall and that everyone needed to install client side certificates in order for web browsers to continue working, it set off major alarm bells in my head that led to one conclusion -- "No more non-work related web browsing at the office. No exceptions."
Most of my coworkers (albeit mostly those in support and not developers, but still people at least somewhat familiar with the way computers work) only cared that they'd still be allowed to visit Facebook during the day.
I was assured that "nobody was actively looking at employee web traffic" but that doesn't matter. They didn't even think it was a big deal to put this new monitoring in writing until I made a big stink out of it, and they added this to the employee handbook:
>Each of these communication avenues are subject to monitoring by the IT Security Manager, a supervisor, or the President. When using any of these communications, be aware that a business record is made, which is retained by the company and becomes the company's property. This business record may potentially contain sensitive personal information related to the sites you are viewing and into which you are logging on, including user/password information. If you do not wish to share such information, it is suggested you do not access those items using [employer]'s network.
The web has always been a bit contentious for instance the browser wars are still being fought in some way even today. The problem is that the web is where developers were able to build without concern over who the powers that be even were but now the web has been turned into a creepy surveillance machine.
Our current president even paid Cambridge Analytica to socially engineer all of us. Turns out the tricks that hackers used to employ have been appropriated for use by the web monopolies. I can't think of a way in which this turns into anything good for the average person.
the scourge of p2p protocols
Scourge? Which of the peer-to-peer networking protocols is a scourge?Surely, you aren't suggesting p2p itself is conceptually an abomination in general?
There was this thing called "newsgroups", some day before my time. Wasn't the web.
IRC is still a thing. So is XMPP. Isn't the web.
I'm not sure what you mean by "internet without people". There are plenty of people outside of HTTP.
But yes, as much as I love the web, it's funny how people forget (or never realized) there are other protocols.
The regulations should be non-technology specific. Simply it should provide rules about customer/user data. Even if I use pigeons. (But not RFC 1149.)
For example if I log into the Facebook business manager for a company I can see tons of data on Americans but not nearly as many details for Canadians, it's because of these laws. The new E.U. laws are even stricter with regards to personal data and how it's used, no matter who you are.
Why there is no demand for this level of protection in the States by its citizens and representatives is crazy.
Anyone who expects goodwill from Facebook, Google or any company is seriously misguided. Privacy laws need to be in place, actual laws that are bound my the federal legal system, and not just state regulations.
The U.S. is culturally much more opposed to government interference in citizens' interactions, compared to Europe. The U.S. started as a rebellion against an authoritarian government.
I suspect this is because a lot of the first Europeans who migrated to North America were the self-reliant type who actually would flourish best if left alone. What we see as help or protection, they see as interference. (This doesn't explain Canada. Inexplicability is one of Canada's many charms.)
You may not believe that if you live in Myanmar or Kenya. Large amounts of behavioral information in the hands of the wrong people can absolutely be a life or death issue.
Smaller organizations would have a much harder time complying with legal changes that significantly erode the Safe Harbor provisions of the DMCA that make platforms not responsible for the actions of their users.
Not only that, laws have a tendency to set a particular model in stone.
The model large companies use is to collect everything they possibly can and then use bureaucratic processes to control access.
The model small companies and individuals use is to minimize the data they collect and use technical means to ensure that the company has no access to the customer's data at all. This obviously tends to be more secure.
But if the bureaucratic process is required by law regardless of whether it's really protecting anything, the more secure model becomes impossible -- you have to collect all the data because it's the only way to make enough money to pay for the bureaucratic overhead.
There have been a zillion startups that have had collecting user data baked into their business model.
And they can rot like Facebook. Nobody is trying to save them. The problem is you're destroying anyone whose model isn't that.
Come on this isn't a game of semantics.
Edit: I can only speculate as to why people don't like this, but in case it makes a difference it's intended only as historical background for people who missed the start of the experiment.
They can't do whatever they want. So long as the Internet is free from overbearing government restrictions and the ISPs aren't segmenting it (locking users into restricted sandboxes), you can go wherever you want without using Google search, or shopping at Amazon, or using Windows, or using Chrome, or using Facebook, or shopping on eBay, or paying with PayPal.
The only real limiting premise as it pertains to the Internet, are the ISPs and the backbones.
So long as you can get on a free Internet, engineers can perpetually build their own new products at will, crafting new tech universes that didn't exist before. They have been doing that non-stop in every category for the last two plus decades since the Web took off.
Don't like Chrome because it managed to acquire 99% of the market? Fine, spin up your own clone and put it out there. Or use Firefox or Edge a dozen other lesser used competitors.
Don't like Go or C# or Java? Fine, use one of 37 other languages.
Don't like Google search? Fine, use Bing or DuckDuckGo or a dozen other less well known search engines. Build a new one maybe, nobody is stopping you, maybe it's time for a new search paradigm.
Don't like AWS? Fine, use Hetzner, or Digital Ocean, or a dedicated box provider, or Vultr, or Linode or Google Cloud, or Azure, or build your own new competitor.
There are vastly more options today, in essentially every way, than there were in 1995 or 2005.
The free Internet has worked extraordinarily well. It has never stopped producing alternatives, and alternatives have never stopped existing. The only thing that can crush it is government regulation, specifically if they fuck that up.
We most likely will not see any trust-busting as you're describing here. We'll more likely just see more side-effect legislation like the net neutrality repeal or FOSTA/SESTA that will just consolidate power for a few parties and the government at the expense of small businesses.
Sounds like a libertarian conspiracy theory to me, especially when we still don't know what these hypothetical regulations would look like. For instance if they make it easier to access your data, download and delete it they might somewhat weaken the lock-in effect of Facebook and level the playing field somewhat.
Beyond that and even if they make it slightly harder to build a social network in the future it doesn't mean that a reasonable amount of regulation is not worthwhile. If you want to start a bridge-building company you'll have to abide by a massive amount of rules, yet I'm not really sure I want to let the "completely free market" decide what a safe bridge looks like.
I'd call it skepticism or pessism at worst.
Doesn't mean that we shouldn't be very careful about what comes out of this whole discussion and maybe make our voices heard if we deem it unfair or ineffective but we're not there yet.
Can you name a piece of US federal legislation regulating a major industry passed in the last, say, 30 years, where this was not the case?
Well actually...
https://en.wikipedia.org/wiki/List_of_defunct_automobile_man...
Notice the number created before vs. after 1967, when the feds started passing vehicle safety regulations.
Also notice how many of those created after 1967 (e.g. Geo, Saturn, Hummer) aren't actually independent, they're just retired marks of the existing incumbents.
Because the safety regulations are designed for huge companies. The companies literally provide cars to the government to be crashed for testing purposes, because destroying a few cars is nothing to Ford or GM.
https://www.usatoday.com/story/opinion/2014/09/17/ralph-nade...
Regulation can be awful or insignificant.
My state requires strippers to fill out a license and pay 50$. Changed nothing.
However, my state also requires you to put down 1M to start a bank. Thats definitely regulatory capture.
Its too soon to know whats going to be required of data. Databases might become significantly worse to program and require teams to maintain at government standards.
No benefits at all, really?
Remember pre-regulation leaded gasoline and cars without seat belts?
I dont know the history of leaded gasoline, but I worked in safety, and car companies were definitely moving toward safe vehicles.
"Auto makers, who have been fighting the introduction of air bags for nearly a decade as too costly and only marginally effective, have gone a long way toward their goal of bypassing the federal regulations. "
http://articles.latimes.com/1985-02-19/news/mn-546_1_seat-be...
From 1990:
"But the history of catalytic converters reveals another side of Detroit. The industry refined the technology only after Congress imposed strict limits and deadlines and foreign car makers threatened to develop cleaner engines."
https://www.washingtonpost.com/archive/politics/1990/03/26/a...
From 1985:
"The American Petroleum Institute, a trade group, said that the refining industry had been making efforts in anticipation of today's rules to ''insure against future supply disruptions.
'But the announced lead-reduction schedule will create a substantial problem for the refining industry in providing motorists with adequate quantities of high-quality gasoline at reasonable costs,'' the institute's statement said."
https://www.nytimes.com/1985/03/05/us/epa-orders-90-percent-...
What is the ask here? A ZIP with all your information? A JSON file with your friendship graph? How would that be readable to most people? I doubt that Facebook's data structures are so portable that they could just be placed into another social network? Even assuming you have the data, Facebook's value is in the IP and ML algorithms. Facebook sure as hell isn't giving those up.
Even assuming all that, how does it take us further forward than what we have now?
There's a lot of arguments to the effect of 'something needs to be done' but not much detail on what an alternative looks like.
Making scraping of your personal data a statutory right, including the building and distributing of tools for it.
No need to force FB to publish anything, just prevent them from blocking anyone who uses a tool to scrape their own data through the regular UI. This should draw the boundaries of responsibility in the right place.
This would allow e.g. a “messaging” bridge which automatically interfaces with the messages part of the site, and bridges it to any tool (or API) you want. At least per user per account. This would force de facto federation without putting a burden on FB.
The disingenuous loophole the government is so fond of whereby you sharing information with a third party suddenly negates ALL expectation of privacy and 4th Amendment protections is a farce. Signing up for Facebook should not be a "first sale" of your personal information or right to privacy.
Of course, no tech company that has ridden the free ride of harvesting personal data would be on board with ANYTHING like that.
They can keep their IP and algorithms if they want, but if I don't consent to the fruits of my existence being fed through them, then that is where it needs to stop.
No company should feel safe with involuntarily increasing a user's digital footprint. Period.
That covers not asking to and being explicitly told not to. A person has an inalienable right to maintain final authority over their digital presence. The only exception that makes sense to me is for the press. Though I haven't thought that implication through completely yet.
If something needs to be done let's at least give one chance to the people who seem to be trying to do something.
Do you run your own company and find the regulations dont require you to hire a multi-thousand dollar legal team at every turn?
Are you an internet user that thinks that what the government says wont be exploited?
I worry that my kids will be unable to start businesses due to regulations, or rather their friends wont be able to start businesses. I am a top 4%er and I'll simply pay for the legal teams needed. I know my competition making 40k/yr cannot.
> Are you an internet user that thinks that what the government says won't be exploited?
Nope, I'm a normal person, not actually a strawman. As long as there's government, it will be exploited; but, you're throwing out the baby with the bathwater by arguing that because people will exploit loopholes, we should eliminate (all) regulations. Instead of supporting a representative that tries to eliminate two regulations for every new one, how about supporting a half-intelligent representative?
You're worried people won't be able to start businesses? Where is Facebook's big competition? Can your kids' friends start a business now to compete with Facebook? No -- so why are you worried that they won't be able to do something in the future that they can't do now?
I disagree with this. I think at the current time they can.
In any case, the reason they might be able to at the current time is the blood in the water from the "reasonable regulations" people.
What??? I watched most of it, and while Zuckerberg agreed that legislation in some areas are needed, he was quite clear that most times that he does not think legislation is the answer. He said that they would internally implement things.
Multiple senators kept trying to get direct yes/no if he would support such regulation and he would say "I look forward to my team discussing that with you" when they wanted hard "yes" that he would champion regulation.
So I don't understand your post at all...
As for stifling competitors, Facebook actually benefit from a free-for-all Internet because they can watch trends and identify what needs to be done to capture each successive generation of users, slowly folding them into the big Facebook family.
I don't like the company but I don't think they want to lock the Internet down . I reckon they know that will just lead to something really disruptive and destructive that they won't see coming, like some app that spreads by sideloading.