Facebook Is Giving Advertisers Access To Your Shadow Contact Information
gizmodo.com
gizmodo.com
Exactis Breach date:June 1, 2018 Compromised accounts:131,577,763
> Compromised data: Credit status information, Dates of birth, Education levels, Email addresses, Ethnicities, Family structure, Financial investments, Genders, Home ownership statuses, Income levels, IP addresses, Marital statuses, Names, Net worths, Occupations, Personal interests, Phone numbers, Physical addresses, Religions, Spoken languages
But, as someone who understands that not all people and companies use the same moral set as myself, this is why I've never set up 2fa using a phone.
Why should I give some company my phone number? Increasingly it's become a single point of metadata to uniquely describe myself (just as my email addresses have).
That doesn’t need to be the case though with just a little bit of effort and minimal cost. Use your own domain for email and set your account to be a catchall. Then use facebook.com@yourdomain.tld and your email address is no longer a cross site unique identifier.
If facebook was able to design and build this system, you can bet that other companies are doing this too.
9425ca8eb02d022309ec175a7067b1567a5f741ec7010cc1b5034287f9db6e2f
4d1c86b9f418c713e784760fea809e34418c2f13e993d907783572ecc2c9bb6e
I doubt it'd be worth spending the effort to target people with personal domains though, and it would have some negative effects, so your point is well taken.
They use it to match traffic across devices and IP addresses.
> pretty simple to crack unsalted hashes
Go ahead and rainbow table those hashes then. If you do it and are the first one to email me (email address in profile), I’ll pay you $100.
If you use the method described in the grandparent, you use a unique email address for every site (e.g site1@yourdomain.tld, site2@yourdomain.tld, etc). The domain will be the common part, which would be very hard for a company to use because most domains are shared between many separate users.
My if my site-specific email giqjtodvdksu@... has been getting spam lately then it is likely that either they sold it or they got hacked.
You mean a very small percentage of FB users do this?
The point being as parent comment said it’s not “a little effort and minimal cost”. Figure a $10-15 overhead cost for the domain and maybe $5/month/e-mail account? Effectively to minimize tracking on Facebook one would have to spend a minimum of $70/year?
It doesn’t seem like a great solution...go with a “free product” like Facebook in exchange allowing them to collect and monetize your data, only to pay to combat their business model? May as well offer a competing service that doesn’t track you, collect/monetize your data and pay say...half the cost of a domain and email.
> May as well offer a competing service that doesn’t track you
I would kill for that. But this day and age it would be hard. Also, even subscription services typically see fit to track you and serve you ads.
It takes a tiny amount of effort: you setup your domain with a wildcard so all you need to do to create a new email address is to use it. You could send mail to barkingcat@real.domain.for.394549.net right now, and it will be delivered to my inbox with no setup required.
It's also great in case you start spamming me. I don't have to struggle with your unsubscribe links, I can just blacklist all mail sent to barkingcat@real.domain.for.394549.net, and be done with it without any collateral damage.
I do and have done so for over 10 years. It’s been very eye opening to say the least to see how many sites have leaked my email.
unless sites smarten up and realize facebook@johndoe.com is the same person as pizzaplace@johndoe.com, especially when johndoe.com isn't a "common" email domain like hotmail.com
There's a lot more going on than linking email addresses.
(To save you a click, they look like aa_COMPANY+SHORTHASH@mydomain.com, with shorthash being based on COMPANY and a secret)
Downside is the address ends up absurdly long, and I’ve had to manually create some aliases for companies that won’t accept the plus.
I don’t recommend this setup, it’s kind of a pain to maintain, but I wish one of the mainstream providers would implement something similar.
I think I'll extend the latter (and reduce the required Spam score) before it gets sent to my inbox.
The reason I say it's something people should have expected is because if people were more critical of the things asked of them, then things like this would never get off the ground. Instead, because people do not seem inclined to naturally believe that corporations might have ulterior motives, such practice has become common place and on some sites even mandatory.
People worship at the altar of success, and there aren't many relatively new companies as profitable as FB. That's not to say that these companies don't spend significant coin in pushing their inane message of "we're connecting the world" wherever they can. And mass media for the most part go along with it, mostly focusing on the stock price, rarely bothering to examine how FB makes its money and what tradeoffs that comes with.
It is OBVIOUSLY for ad targeting, I think I mentioned it not even two weeks ago: https://news.ycombinator.com/item?id=18020177
But none of it is actually slowing FB down. Its biggest dip in value came from decelerating growth and spending to make FB more user-friendly, so there's a clear disconnect between shareholder incentives and those of the general populace.
On top of that, most people remain unaware that FB owns both WhatsApp and IG, and while the departures of their top brass have made waves in these circles, it's not a concern for most.
I don't see FB's dominance relenting any time soon, though I wish it would.
- not all people buying FB ads are experienced marketers
- companies throw tons of money at ineffective ads, that should be obvious…
- we have no idea what the ratio of "successful" to unsuccessful campaigns is
- even if that ratio is negative, Facebook is still one of the only remaining "games" in town, so people _will_ continue throwing money at it. “Least worst” is a fine and lucrative place to be in.
- can we just get over this idea of rational economies, by the way
- marketing is less of a science than a craft, and all the implications thereof
This is key and undermines a lot of rational arguments. People buying ads aren't reading HN and then making a buying decision based on the general vibe they get there. They'll buy based on budget. Budget is based on decisions made in a meeting a year or two before. Those decisions will be based on a strategy. For many that strategy is to the tune of 'I keep hearing about this social media thing that's supposed to be the future. I notice we aren't spending anything in digital. We need to buy more digital'.
If public opinion sours on Facebook it may be a while before we see a significant drop in revenues.
If you want to see how things work, start a small ad campaign yourself of FB. It's all about ROI, attribution, cost per action, super detailed targeting, etc. It's the opposite of "throwing money at it hoping that it'll work", unlike offline advertising or even traditional display ads.
"Sniper Targeting on Facebook: How to Target ONE specific person with super targeted ads" https://medium.com/@MichaelH_3009/sniper-targeting-on-facebo...
- marketing companies they ask to run Facebook campaigns for you may be as clueless as they are
Source: I used to work for one (we had separate development and social media marketing departments). People doing marketing had no clue about statistics, they just shoved random whale graphs from Facebook's fanpage panel into a word document and wrote narratives that suggested everything is peachy. Customers read those reports, and since they had no way or skill of reevaluating the results on their end, they were happy and willing to pay. I'm not even assuming malicious intent on the part of the provider - just general cluelessness.
I'm increasingly convinced a lot of marketing on the Internet looks that way. Neither party understands the real meaning of the results, but as long as the buyer is happy, money keeps flowing.
https://adage.com/article/digital/p-g-decided-facebook-ad-ta...
https://www.forbes.com/sites/joannmuller/2012/05/15/gm-says-...
The only type of ad that makes sense to me at all is one that educates someone about a class of problem and that there's at least one product (X) that can be used to solve this problem.
In many cases it would make more sense to focus these efforts on making stores more effective at presenting solutions and grouping related solutions in expected areas to improve the search effectiveness of independent agents that have black box algorithms and are outside of the store's control.
Attempting to modify said black boxes by an inundation of annoyances is ethnically wrong to me. (As implied above, when it ceases being educational it's increasingly likely to cross that line, particularly if the campaign is based on gimmicks or repetition to be effective in vulnerable population segments.)
When we advertise to raise money (for politicians) that provides a direct provable ROI and I can tell you nothing else has come close. Seems that is true for many corporations as well just look at FBs growing revenue. FB provides the tools to measure either a sale or the value of an app install over time the increased spend is proof of quality/value so clearly many others have also found success. I wonder who/what/how your campaigns didn't provide value?
What I mean is that we are comparing two different beasts, so I'm not sure "it happened to MySpace" is a good telltale sign of what will eventually happen to Facebook.
I've seen this a lot more in countries where internet access wasn't too common until the past 5-10 years and people didn't start out with a less centralized web before apps and closed networks gained popularity.
My partner isn't from the US originally and when I mention how obnoxious it is that Facebook is like the new AOL and I thought we were past this, she reminds me that it's all anyone back home uses for anything and they didn't have internet access back then.
To her and her friends/family back home, the internet basically is Facebook (and occasionally being forced to open their browser app to search for something if they don't just ask around on Facebook). A handful of other apps and defaults define the internet for them and anything else just sounds like too much hassle.
But it does mean that an even somewhat diligent antitrust enforcement could strangle them to death. They shouldn't be allowed to acquire their future competitors. If the US won't stop them, maybe European regulators can?
There definitely was a big difference between MySpace and the other social networks. Facebook ran well and worked. People forget the total shit show MySpace was in the middle of 2008. The site ran terribly, was getting hammered by spammers, and they starting covering it in banner ads. We didn't see a repeat of those problems with Instagram or Snapchat.
There is a coolness factor. It isn't as defined as fashion, or the latest hot nightclub, but it is there. That alone won't be enough to make the "next" Facebook, but I think it is the foot that gets stuck in the door.
Facebook might be able to acquire the next challenger in the US, but they will definitely fail to get it by EU regulators.
Networks are driven by positive feedback both going up and down. This sounds good, but isn't: the system and balance points are inherently unstable. Nothing succeeds like success, or fails like failure.
Nevertheless, your larger point holds, Facebook users are even less cool now than they were before.
I suspect Facebook knows this and will keep acquiring new platforms when they can.
Also, FB MAUs and DAUs are stalled [2], meaning users are becoming less interested in the blue website.
If anything, FB is closer to a 'boiling point' now than ever in the past.
[1] https://www.ispot.tv/ad/wUQP/facebook-a-little-closer
[2] https://www.businessinsider.com/facebook-maus-daus-stalled-u...
The MAUs and DAUs are more interesting, especially since younger people seem to be avoiding it entirely (although many are flocking to IG, so again, no loss for FB).
I would much rather see industries self-regulate. But I have big concerns about industries where people are mainly the product, not the customer. I think it breaks the key feedback loop that makes most self-regulation work: irritable users/customers.
For me America's best backup to irritable customers has always been class action suits. It allows aggrieved customers to band together and force accountability where otherwise individual harm would be too small to justify the costs of a lawsuit. But mandatory arbitration is breaking that too, and anyway doesn't work as well when users aren't customers.
So if we don't have user-fueled self-regulation, and we don't have class action, then I'm not sure what we can do short of government regulation. It's a last resort for me, but nothing else seems to have worked on Facebook.
I take everything Facebook has done that caused any level of public outcry as a guide book to design a better platform, likewise with Google. And I won't dive into the history or foundation of Facebook, however it's not surprising their path would lead to problems - and at indirect cost to society.
The problem is Facebook is allowed to buy rising competitors on its way down, thus prolonging its monopoly in the social media space.
A good real world example is Disney. Disney has been almost broke a few times over its lifetime, yet currently it's so huge that people believe it will never fail again.
Facebook have so much money in the bank, that the moment their primary model is no longer viable, they'll just go to market and buy up the next hot thing, and switch their focus there. They are like an unstoppable pandemic virus in this aspect.
In dystopian sci-fi novels and films, there is commonly the concept of 'The Company' who see-all, and control-all. It used to be that we'd predict it would be IBM, or Microsoft who would be 'The Company', more recently we'd say it would be Google. Currently however, it's more likely to be Facebook.
This is exactly why we shouldn’t worry about it. The company that we think is going to rule the world forever changes every ten years.
Which is the reaction most people will have, I'm guessing.
What are 2FA numbers in the context of ads?
I am not surprised. If you let Google autocomplete the search "is facebook o" for you, you'll find these autocomplete results in order:
1. is facebook owned by google
2. is facebook on roku
3. is facebook over
4. is facebook offline
5. is facebook overvalued
...
10. is facebook on its way out
Seriously, people? "Is Facebook owned by Google?". AFAIK most people have no idea what goes on with tech companies and they have no idea how much power they have and how they work with your data, or what personal data is even comprised of.— Facebook copied Snapchat's functionality on all their platforms.
— Instagram and Whatsapp copied it too.
— Yeah, that's what I meant by all their platforms.
— They're owned by Facebook?
She uses Instagram and Whatsapp everyday!
No-one is forced to give all their info to fb. Better yet, no one is forced to use fb.. Of your using these services, and you give all your info to them, that's on you, not engineers just earning a check.
You are absolutely right this calls for nanny state involvement. This is precisely a case where the invisible hand of capitalism is impotent and government regulation is essential.
Last time I checked, Facebook did not offer free personal and company e-mail and collaborative office suite.
And where do you stop? Are all doctors working for big pharma related to opioid crisis complicit? what about people working for firms related to the financial crisis? engineers working for any company that suffered data breaches due to lax data security? what about engineers working for companies that haven't suffered data breaches yet but might have lax security? scientists working to certain biotech firms related to GM? engineers working for car manufacturers that cheated emission norms? engineers working for telecom/internet service providers that cheat users by throttling/net neutrality etc. etc. etc.
If any Facebook engineer suddenly acquired some moral sense, he should spend his time working to sabotage the company from within. Some have walked away; others have walked away and publicly spoken about facebook’s dubious culture.
Now it’s time to see some sabotage.
The problem with whistleblowing is that the consequences need to be more direct and actually leave a dent. As it is right now, FB can absorb pretty much any fines they're hit with.
I consider all of the energy being spent in the maintenance of facebook to be malicious. If a datacenter caved in because of a structural flaw in the building, then that’s a lot less energy going into supporting facebook. How many datacenters would have to cave in before they wouldn’t be able to recover?
https://www.businessinsider.com/cia-manual-sabotage-producti...
This is always the case when the general populace are not customers but products. It cannot not be the case.
There are actually ethical information dealers but they require you to pay them as you are paying your weed dealer.
They show ads based on search the content rather than via tracking.
The user data they sell to advertisers has a lot to do with your social network. Who you know, what their interests are, who they know, etc.
For Facebook to allow individuals to pay to opt out of their data being sold, it affects more than just that individual's data. I.e. it affects all their friends and friends-of-friends data.
I expect that the only way Facebook would be able to offer a pay-to-opt-out plan would be for everyone on Facebook to start doing, which would never work and they would never attempt.
I imagine the most we'll see in this direction is some sort of half-assed attempt where they offer to let you pay them money to stop some tracking, but still continue to most of it anyway.
I really would love to see advertisement companies that are less focused on tracking and more focused on ad placement that's relevant to the content it's going on, and hey sometimes there's no relevant ads for content and that's cool too, but at least show anything generic or close enough at that point. Also advertisers who don't do pop ups or annoying ads (that I swear could cause epilepsy on some users) are also good stewards of the online billboard market.
Problem is, it never stays ditched. It's always a slippery slope.
I just don't want to participate in this anymore.
Any company being truthful about what their customers want can't be tracking them 24-7 and sifting everything they type. Almost no-one wants that level of invasiveness. We just put up with it because there are no real (easy) alternatives or aren't aware.
Once there's money on the table, companies are going to take it and assume the number of customers who walk away aren't enough to offset the profits.
A focus on consumer rights, protections, and building difficult to defraud and difficult to exploit consumers systems is where effort needs to be spent.
* GNU Taler - A digital cash / micro-transaction system that hopes to be audit-able for tax and other legal reasons while still being anonymous for consumers.
Please read about privacy, verifiable in the right ways, and the "operational in 2018" claim
Based on what the OP is writing, the unique identifier foe the user can even be the IP address...
It's your choice to use the same IP address.
It's your will.
With a single device, it's fairly reliable to use a vpn or multiple vpn providers and only log in to each account when connected to a given vpn.
I used that foreign number to create my Instagram account and I've gotten the benefit of only being shown suggested accounts from locals from that country (zero people I know). Same goes for ads as well. Currently I keep it on roaming and actually use it to verify other online services that may stubbornly require SMS.
Might be worth a try for those of you looking to pseudo-opt-out of phone number tracking & recommendations on social media services that do this, if you can get your hands on one.
I'll give you an example of why it might not work. Since your phone has roaming, you happen to have it with you at work, or at a party, or at the library, or anywhere really. If even a single acquaintance of yours is "nearby", the information is leaked. If acquaintances seem to always be "nearby", children, wives, husbands, siblings, your info is DEFINITELY leaked.
If anyone is going to try to use this strategy for anything which might result in the loss of your livelihood, (eg - porn), please realize there are many, many, many more precautions you will have to take than are listed in oedfmarap's comment. If you just do what you see in that comment, you could find yourself without a job somewhere down the line.
[1] https://www.defcon.org/images/defcon-22/dc-22-presentations/...
[2] https://splinternews.com/facebook-is-using-your-phones-locat...
Within 1-2 days, Facebook recommended one of them as a friend - bear in mind I hadn't added any of them to Fb, so all it could have used was our location...
This happens to me often too, with much briefer encounters: mainly dates and meetups. Since I've shared similar amounts of time at the same restaurant with hundreds or thousands people with whom I had no interaction, many of who's arrival and departure times would happen by chance to line up with mine, they must be using something else. I also share a duplex-house and an office building with people who've never been inexplicably recommended on Facebook.
From these observations, I've come to think that location data has to play a very small role in Facebook's recommendation system.
Here's my best (but untested) theory to explain this: Your house-mate searched for you on Facebook, which triggered Facebook to think you might be friends.
I had watched it many many years ago, and I suddenly remembered about it while at my friends apartment, (which is in the same building). Now I searched it up on my friends computer which was logged into his gmail account. We watched it and laughed. However, an hour later, I was on my iPhone at home when it appeared in my related videos.
http://i.imgur.com/u31ZuWM.jpg
I refreshed and it was gone...
I know Zuck wants me to preemptively upload my nudes, but still.
Depending on the owner's security settings, Facebook will often suggest the profile of the person in the type-aheaded search results.
These are frighteningly common, typically enforceable in the US even for consumers, and typically enforceable in most countries for even small business customers (though rarely for consumers in much of Canada and Europe if the vendor has enough ties to the area for local consumer protection law to apply and you win the race to the courthouse).
This has very interesting consequences...
I reset his password and tried to close the account after he kept trying to access it by resetting his password again. Instagram support asked me to send a clear photo of myself holding up some random number to prove it was me. Nope lol.
Here's the issue with it. You might not give it but your friends would. Therefore, this strategy is pretty useless as network effects kick in.
Facebook will remove the phone number from your account when you do that. You can also use that to check who are your friend who gave FB your phone number.
Can you explain further how this will work?
I've never had such uncertainty about what a job would involve before - the "you find your match" sounded good initially, but in retrospect I'm wondering if I dodged a bullet - so hard to know.
That facebook is doing bad things because ads are their only real source of income is a problem because of the bad things, not the ads. At the time the primary concern was "what should facebook be doing about de facto empowering hate speech and (actual) fake news?" and that's a tricky problem that I don't think has a resolved answer, and I sympathize with those that empower communication and only later realize people have more desire to trash things than apply rational caution. Since then much more has come out about some FB practices (and Google), and the question of whether ads-as-your-primary-revenue-source is too much incentive to be "evil" is being implicitly raised, but is likewise not yet resolved.
That said, I do think there are lines to draw and lines not worth drawing. There's very few jobs that don't end up supporting bad things. I don't think it's right to pretend that if you aren't doing it directly that you AREN'T supporting such things...but I also think it's sometimes unrealistic to make your situation worse to deny an indirect support. Deciding where that line lives is an individual decision, and one I have to regularly re-evaluate. To expand my point in the previous post, the news coming out about FB practices definitely made me feel like I'd have been uncomfortable even if I wasn't working directly in ads.
I have always been suspicious of the aggressive "give us your phone number to secure your account" campaigns that so many sites/apps are running. And I think this is a HUGE disservice to users.
At first I was like, cool, companies are being responsible and encouraging good security practices, good on them. But there was something a touch too.. aggressive and "marketing-y" about it. It raised my spidey sense. Maybe the form and frequency and placement of them just was too familiar to previous campaigns to grab your email for "opt in" spam.
All of these companies should be shamed to high hell. Getting people to adopt 2FA is so important and here they are shamelessly exploiting it to market to you for undisclosed purposes.. well, buried in the privacy policy, but you know how that goes. The prompt is 100% about securing your account and nothing mentioned there about using it for targeting.
Seriously F these companies for breaking user trust.
ALSO: Did Zuckerberg lie to Congress?[1]
[1] https://techcrunch.com/2018/04/11/facebook-shadow-profiles-h...
In America (and most places), law normally lags quite a bit behind the events of the day. Standard Oil destroyed markets unchecked for several decades in the 1800s. No individual or company could withstand their market power. Then the government divided it into dozens of vertically integrated companies, which allowed for a wave of new market entrants, better deals for consumers, and higher standards of living for more people.
We are obviously at that breaking point now with the tech behemoths and their sprawling, impregnable market power. It is time for antitrust action against Facebook and the gang.
I'd argue that it would not -- 1,000 small Facebooks could still violate privacy. Creating privacy legislation is the only real way to achieve proper privacy guarantees.
Who wants a social security number when you've got someone's phone number?
[1] https://news.ycombinator.com/item?id=17515029
[2] https://news.ycombinator.com/item?id=14105696
This kind of thing has been going on forever, and I've told people this. 99% of people don't actually care, though.
Not for privacy, but to deny them revenue. I block Google ads on every single site I visit, period. I don't care if the advertising is non-obtrusive. If it's being run through Google, part of that revenue is going to fuel Google's tracking. I support creators directly instead. And if creators refuse to give me a way to support them, that's not an excuse to expect me to contribute to Google's bottom line.
Huge props to the people who are working on blocking trackers and protecting privacy. I'm very glad they exist, and I don't think their efforts are worthless. But, it is currently a losing battle to fight these companies on the privacy front, because the tracking model is so profitable that they will always be pushing more resources into it than we are. Collectively, the people fighting for privacy don't have enough resources to win.
But there's an easy, completely legal solution to that problem; the one thing companies haven't figured out how to get around is ad blocking. And a good ad blocker will block even native ads. For a company like Facebook, all of this boils down to getting you to click on ads. If enough people target that chokepoint, then the advertisers will start pulling out of the system, and there'll be less financial incentive for these companies to undermine people's security and privacy.
And we have evidence that this works. Even Google, which is the powerhouse for getting their ads to actually show up, is starting to devote more resources into trying to figure out how to stop mainstream people from installing adblockers. That's where all the autoplay stuff came from, that's where the acceptable ads initiative came from. They desperately want your roommate to say, "I'm not going to mess around with these weird Chrome extensions or whatever, that's too complicated. Chrome blocks this stuff itself, anyway."
Install adblock on every browser you get access to, tell ordinary people who aren't on HN to use it, and let the advertising industry kill itself. Make it very obvious to companies that buying ads on Facebook is a complete waste of time because even non-technical users just won't see them.
instead of deleting facebook (or not having it), create a shell profile, just enough for you family to pointlessly add. then subscribe the account with a service (aka The Idea) that simply post a once a month post on how to install ad blockers and such.
Which means Facebook has a shadow profile of you even if you don't use it at all: http://theconversation.com/shadow-profiles-facebook-knows-ab...
We should try to find one. I fully support the privacy fixes people are proposing. I think that's really important. But it's pretty obvious that Facebook is winning right now.
However, the only thing that Facebook cares about is getting you to click on an ad. So even if you can't stop Facebook from getting a shadow profile on you, at least you can make that profile worthless by blocking ads literally everywhere that Facebook can think to display them to you, for you and your family/friends.
And you can be public about it to ensure that when Facebook goes to companies and says, "we have all this data for your next campaign", somebody in the sales-pitch meeting raises their hand and says, "yeah, but nobody looks at your ads."
How would that work?
I doubt that holds in court, but as mentioned in the article, there are people in the EU who for months have tried to get Facebook to provide the shadow profile data on GDPR grounds, and Facebook has yet to allow it.
It seems like Facebook can afford to stall, they've got more knowledge and power than a single EU citizen can have, so I'm sure they know what they're doing.
----
To be honest, I think Facebook is in breach of _multiple_ GDPR articles _simultaneously_ here, which is quite a feat in itself.
They're in breach of:
- Privacy by Design (a.k.a. Privacy by Default)
- Right to Access
- Right to Be Forgotten (which is older than GDPR..?)
- Data Portability
Then again, Facebook is not alone. I'm pretty sure there are very, very few companies on the web that are not in breach of GDPR at least in spirit, if not in letter.
There's a zero chance that holds in court. If it were possible to have a negative chance it would have a negative chance of holding in court.
Data protection does not in any way relate to "ownership" of data.
If the data are personal data then you are forbidden from processing that data unless you have one of seven lawful bases enumerated in the GDPR, and where the data are sensitive then those bases are reduced further.
Under GDPR, the company I just gave that information to doesn't have your permission. So, let's say that later on, you go to the company and say, "hey, delete any information about me." For them to comply, they can't keep on syncing your contact information in my address book, right?
I guess, how does GDPR handle a situation where a separate customer is going to Facebook and saying, "hey, let me put in that I'm X's cousin"? Should Facebook block that person from specifying the relationship in the UI? Or would that just fall under "essential for business"?
Personally, as long as the user has an opt-out and opt-in options, I don’t think ad targeting is necessarily an unethical pattern, the blurring lines of ads and recommendations would be actually a pattern that users might like. Would you rather use Netflix or Spotify without recommendation engine?
Needless to say, Facebook's goals and incentives are very different.
But on Facebook people go for socialising, and not to get personalised ads.
Anyway, I still upvoted your comment, because it's interesting to read what someone working at FB has to say on this.
[0]: https://readwrite.com/2012/12/11/why-are-dead-people-liking-...
EDIT: Images seem to be missing from the original link, so here is an archived version: https://web.archive.org/web/https://readwrite.com/2012/12/11...
The space of phone numbers is small enough that this is not a significant consideration.
Hell yes.
Related artists per track, that would be more, than enough.
> Would you rather use Netflix or Spotify without recommendation engine?
100% yes.
Personally for me the term "personalisation" is becoming a dirty word and I am becoming uneasy when I hear it mentioned in design docs and product launches etc. I dont want to see what some algorithm thinks I want to see. Instead I would prefer to see the real, unfiltered, unfettered data. I think the whole Fake News outcry started me thinking about it in a more deep way.
Imagine if you went into a fancy restaurant for some special occasion and the waiter took a look at you as you walked in and brought you a "special" menu based on some decision they made silently in their own head about what they think you want. Rightly you'd want to see the full menu and not just what they think you want to see. Sure I'd welcome them pointing out some highlights on the menu, but I'd apprecaite seeing the whole thing before making up my own mind.
As a result now I use DuckDuckGo exclusively and have Firefox set up with Google Container[1] to keep the Google cookies separate from everything else (I dont use facebook at all so their cookies are entirely blocked as 3rd party) as well as the usual uBlock Origin, privacy badger et al. I am even toying with the idea of moving away from my gmail that I've been using since 2004/05.
1 - https://addons.mozilla.org/en-US/firefox/addon/google-contai...
That's also a corruption of the meaning of "personalisation." Personalisation is about me making choices to adapt a product to my preferences, it's not about the product making choices about how to interact with me.
Real personalisation would be having the (sticky) option to shut the algorithm off and "see the real, unfiltered, unfettered data."
Somehow, the knowledge that the efforts to tie every trace of my existence together to help marketers target ads to me are done in a cryptographically secure fashion is not entirely comforting.
In general, I have been unimpressed with recommendation engines of any sort. Spotify can't suggest music I'd like worth a damn, and it's working within a relatively specific domain. Whatever fractional gains in ad relevance are currently obtained from this aren't worth the privacy invasions needed to obtain them.
It's not even cryptographically secure, a phone number is like a 10 digit number that isn't even completely random because of area codes, trivially brute-forceable.
Lol! Phone numbers have less than 40 bits of entropy, it's trivial to break those hashes.
Facebook would be unable to contact the user via SMS, they would have to issue a token via WWW or app and have the user text that to a specific address from the corresponding phone number to achieve phone-based 2FA. This might even be a third-party service to deny FB any direct access to the phone number.
The verification channel might become a phishing target via spoofed FB pages or apps, though that would be moderately expensive and of limited use. An attacker might request FB login credentials (the actual verification would not), might acquire a phone number (generally, though not always, a non-critical datapoint), and would still be denied account access via 2FA without further compromises, say, social-engineering the phone account (a proven risk, though expensive at scale).
Tildes.net uses a similar mechanism for recovery email addresses.
I'd rather it didn't have a recommendation engine. I'm fed up with it trying to get me to watch something else - I'd rather it just stay out of my way.
A 10-digit number is only 10 billion possibilities, much less if you consider that they aren't completely random and have area codes, etc.
You can probably brute-force a hash of a phone number in seconds to minutes _on a CPU_.
Facebook app abuses your phones internal Contacts API.
Effectively, you are linked and your main Facebook account is known to be a pseudonym already
That seems like a lot of effort for no real payoff.
At least I can see some of what Facebook has about me instead of none.
Maybe I am completely wrong about this, but I'm pretty convinced that almost all of the ad spending for that feature would have reached Facebook's coffers anyways had it not been available.
And the sad truth is that the vast majority of people will not be deterred by, be aware of, or even understand the fact that Facebook is abusing their phone number in this way, so as far as Facebook is concerned it's a small bump in the long road to increased profitability.
Sure, but the same is true about negative headlines, the effect is just more difficult to quantify.
Maybe it's a general world view problem within Facebook, but usually these things are the result of one overly ambitious person or group optimizing the singular bonus metric of their own little fiefdom at the cost of corporation-wide commons. Big organizations need to be extremely vigilant in their defense against internal foes who won't blink an eye costing the company billions for a gain of millions add long as the latter will be attributed to them while the former won't.
That's one way to encourage people to use 2FA App, I guess.
They also refuse VoIP numbers for authentication.
I.e. if you switch from using a 2FA phone number to using the app do they stop using that phone number in your facebook profile? And your shadow profile?
>>(Albeit, the company only added the ability to do non-mobile phone based 2FA back in May, so anyone before then was all outta luck.)
Yes. Yes. We did: https://www.theverge.com/2018/2/16/17022162/facebook-two-fac...
So either they lied in February or they have changed their minds. Either way, I think there is value to bring this very similar discussion back to our minds.
I wonder if Facebook acts differently for European users?
Plenty of other online and offline ways to connect with the people in your life.
The government should have bigger fish to fry than trying to regulate the distribution of information that you have and continue to willingly provide to a company. If you don't like it, sure government could jump in and make Facebook just how you like it, or you could delete the info you don't want them to have. The later sounds easier on everyone.
There are some things users/people did not sign up for and cannot (reasonably) opt out of that still harm them. This is what regulations are for.
Unfortunately, whether you created a profile or not, you can't just "not use Facebook" with their whole shadow profiles.
Sure, they aren't (currently) pumping waste into the environment. I'm not saying those things aren't important, but I do think we're going to look back 10 years from now and wonder how we let Facebook even get this bad.
Not that I allow any advertising here, mind you - everything is blocked at the router (ipset [1] comes in handy here), at the client and in the browser. This works at home as well as abroad since I route all my data through a VPN (OpenVPN) terminating at my router.
Drawn to its logical extreme, you don't need regulation to be protected from racketeering if you run a restaurant either, you can just hire private security and arm yourself.
(Security Keys are actually way more anonymous than I'd even thought possible until I understood how they work, if you know Susie uses the same key for DropBox and GitHub, and you suspect Susie also uses this key for the account NumberOneSecretTrumpFan on GitHub, and then you steal all the account credentials from GitHub somehow, this doesn't end up being enough to verify that Susie has the same key as NumberOneSecretTrumpFan, nor is it enough to sign into Susie's DropBox account, and unless GitHub's data includes the backup passphrases or whatever it's not even enough to sign into GitHub as Susie, NumberOneSecretTrumpFan, or any other Security Key user...)
This last time, they crossed a line: they pre-filled the field (I do NOT have this set up in the browser), meaning they already figured out my number (probably by scrubbing some friend’s phone) and just want it confirmed. To hell with that. I would not be surprised if every spam call in existence can be traced to Facebook.
Phishing ads on FB may be less obvious than sending them a phishing link over e-mail.
As part of the Facebook family of companies, WhatsApp receives information from, and shares information with, this family of companies. We may use the information we receive from them, and they may use the information we share with them, to help operate, provide, improve, understand, customize, support, and market our Services and their offerings. This includes helping improve infrastructure and delivery systems, understanding how our Services or theirs are used, securing systems, and fighting spam, abuse, or infringement activities. Facebook and the other companies in the Facebook family also may use information from us to improve your experiences within their services such as making product suggestions (for example, of friends or connections, or of interesting content) and showing relevant offers and ads.
Bizarrely, whilst general everywhere else, the policy specifically calls out banner ads to make it clear that they won't use them until they do, at which point they'll stop saying they don't:
No Third-Party Banner Ads. We do not allow third-party banner ads on WhatsApp. We have no intention to introduce them, but if we ever do, we will update this policy.
https://www.whatsapp.com/legal/#privacy-policy-affiliated-co...
I wonder how do they come up with this kind of language? Do they write a short text that gets filtered several times by multiple teams of lawyers and comes down to this? I cannot honestly imagine a sane human being writing such intricate bullshit, even on purpose.
You want to use facebook to get in touch with friends? We all now know that you will be targeted by ads customized with every piece of information that you reveal (and some bits that you are not even aware you are revealing...)
Assume that an extra layer of security is also costing you some privacy. Interesting dilemma...
Will our kids resent our posts?
To many people it is more like a place, and places are free. Sure, technically you can buy a place and own it and charge for access, and technically somebody owns almost all places you might care to go to, but mostly we think of them as free.
The fact that it costs nothing, monetarily, to access… that very thing often makes something seem like it has no cost.
All ads are not free, all advertised products already include the cost of advertising in their price.
So everybody are paying for those "free" services whether they use them or not.
I use 2FA on sites that support TOTP.
>things i have see flying by are crazy
I think we are at an impasse. Most in the know do not share this opinion.
If you're implying that "most in the know" think FB is much worse than competitors or even other IT companies, we do indeed disagree. Sadly that is not something we can argue here, because if you are in the know you cannot share examples :)
I don't understand -- especially in this crowd -- how this is even a question, at this point, nor why anything related to this fact even warrants discussion any more, given the knowable ubiquity of the practice. I guess the only thing left is figuring out a novel way to capitalize on it, like the Gold Rush.
would be happy to see this discussion split into an Ask HN: or other, I think this topic should be debated quite a bit more than it is with the goal of attaining real results on fixing these issues.
unfortunately I do not think that more people doing that will solve the root of the problem... only try to treat a symptom.
If enough people decide to turn their backs on FB (or any other company doing things like this), there will be a market for better solutions.
It needs time.
Nothing is free.
Facebook continues to do good for people. Twitter as well. These are invaluable communication channels for many people.
I imagine this problem will get fixed about the same time my physical spam mail stops arriving. I'm not holding my breath, given that I can _say_ something to my wife in the privacy of our own home and get a cold call or physical mailing about it a few weeks later.
I try to encourage people to pay for the services they believe in. Whether you love or hate Microsoft for $6.99/mo you can get Office, (decently private) email, cloud storage, and Skype. Hate Skype? Don't blame you but from there you can get a phone number that you can give out and keep your personal number just for family/emergencies.
This sends a powerful message to folks trying to build a better mouse trap. It is _very_ hard to produce a free service that competes with these folks but if we show we're willing to pay for privacy then maybe we'll start to see competitive innovation in that space again.
Now that I have a family it inspires rage that my phone rings constantly from spammers and I might ignore a call that's time sensitive and important.
Microsoft compromises the security and privacy of all of their online services, including Skype, Outlook.com, and Hotmail: https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...
A much better alternative is to give your money to independent telephony providers that run on, and support, Free Software: https://jmp.chat/
And if you're not willing to delete your account just yet, switch your profile pic and cover photo to messages saying you're planning on using Facebook less or eventually deleting your account.
If enough people do that, it adds a social element to the exodus. Just deleting you account makes it poof out of existence without a sound, and most of your FB friends won't even notice.
Unfortunately, it seems like that's becoming more and more common these days.
It doesn't help that legislators wouldn't have the foggiest clue about some of these issues^, so there's no impetus from the legal community or political arena to make changes, while nefarious companies are doing whatever the hell they like.
I deleted FB years ago, and this infuriates me to know they might still be trying to sell my information based on contacts and what I share with them.
^ Actually, they've recently tried to pretend they are above the law of mathematics, so...
FB and similar surveillance shops thrive because people let them. People let them, primarily, because humans instinctually follow a safety-in-numbers model - FB just couldn't be that bad, or someone would have done something about it. That is likely the most clever/evil hack - FB flips this instinct on its head.
So keep telling people the truth about FB. It is a tacky AOL 2.0 panopticon optimized to manipulate you in the name of your friends and family. The company routinely lies about their practices, the CEO gives all appearances of being an untrustworthy weasel, and they're more interested in growth than the damage (up to and including facilitating mob violence!) they're doing.
And: the net is a big place. FB is a big corner of it, but unless you'd also think living inside a Walmart is a great idea, there's a lot out there that you're missing.
It took years, but I've gotten some family members to stop using them.
I changed my number 3 years ago but I still keep my old number active because it occasionally gets calls or text from past contacts.
I actually assume that they violate GDPR, but GDPR gives users a sliver of chance to fight back.
Bottom line, Facebook will devalue you as a human and invade your privacy in any manner possible for as long as it can withstand legal pressures and get away with paltry fines. Obviously, all these measures are to provide users with a better experience. That's Facebook's DNA.
With these upcoming incarnations I'm not sure I want to use it, and I'll be looking for a simple IM application which just charges a simple fee for service.
Lujan: Facebook has detailed profiles on people who have never signed up for Facebook, yes or no?
Zuckerberg: Congressman, in general we collect data on people who have not signed up for Facebook for security purposes to prevent the kind of scraping you were just referring to [reverse searches based on public info like phone numbers].
Lujan: So these are called shadow profiles, is that what they’ve been referred to by some?
Zuckerberg: Congressman, I’m not, I’m not familiar with that.
[1] https://techcrunch.com/2018/04/11/facebook-shadow-profiles-h...
I bet plausible deniability is that they call them by a different name internally.
Information brokers are so sketchy – it makes me so sad that the coolest tech companies are also some of the sketchiest.
Do you remember back when the internet and web were all so full of promise? Instead we got tech behemoths that would put Standard Oil and AT&T in their day to shame.
Sometimes it seems like the “Default deny” security concept needs to apply to Internet companies. Instead of having years to screw with data and the Internet until told “no”, how about every idea they have is illegal until it can be proven through thorough review that it might be valuable?
This doesn’t surprise me at all. Facebook has been bothering me for YEARS to enter my mobile number for “account recovery” purposes. My email is fine for that.
Now Facebook is recommending pages and friends to me who I only am connected with on Instagram. Not to mention Facebook notifications are now integrated into IG. I wouldn’t be surprised if these were the final nails that made Kevin Systrom leave.
When data collection and advertising companies such as Facebook (and Google) push a feature actually beneficial to users so aggressively – such as 2FA – during the sign-up process; you'd have to be naive to think it's for your benefit.
It's not 2007 any more... tech savvy users should know better than to trust such organisations with any scrap of additional personal information than absolutely necessary.
Advertisers can specifically say that they want to advertise to a phone number THAT THEY ALREADY HAVE, (READ: THE ADVERTISER ALREADY KNOW WHO YOU ARE). And Facebook will display that ads to the Facebook account that use that phone number in their shadow contact info.
At no point does advertiser have access to which Facebook account that is.
> Please don't use uppercase for emphasis. If you want to emphasize a word or phrase, put asterisks around it and it will get italicized.
What will it take for some prominent VCs/Investors to just come together and create a fund to fund FB replacement? If done right, they will make a killing (from a returns perspective).
https://www.youtube.com/watch?v=SIoAX5bI6S0
edit: typo
Security Keys are better here. The security key can prove to a site that its the same one as before. "Before what?" Well that's up to the site. In most cases it's going to register one or more keys when you sign up to the site, and then check you still have one when logging in. This is completely useless for everything except the one thing it's intended for, a Second Factor during login.
I try and evangelize Signal over WhatsApp and most of my friends won't budge. I deleted my Facebook four years ago, and as a result I have lost contact with a lot of friends.
That there is this artificial world where people can arbitrarily keep in contact doesn't make that sort of non-interaction of occasionally commenting on or liking posts normal or better. It certainly is easy though to search for someone you knew ages ago, add a friend, have the five minute conversation of what's been going on the last five, ten, twenty years and then never really talk again.
In this regard facebook isn't the problem, and your preferred platform isn't a solution. The problem is people.
I have letters I treasure and will keep to my death. Emails? Not so much. The impression, the personal touch is missing. We as humans notice that sort of thing even when we pretend its all the same.
(I'm sorry, not trying to be needlessly pedantic - I had to re-read to understand your meaning.)
Why didn't the author use Alice and Bob?
I feel helpless, even though GDPR is in place.
That’s their business model, it’s what they do. If you use it, treat all data as public. Otherwise, don’t.
In the end I gave Goog even 2 of my numbers because I am scared as hell to lose access to my account. I got my Gmail account when it was in 'innvite only' so it is my main account for long time. Have to move out of it soon.
How many of us use 2FA on our Google accounts?
https://www.wired.com/story/why-zuckerberg-15-year-apology-t...
Perhaps Move fast and hurt people would be more honest. I think it's rather catchy.
[1]https://mashable.com/2014/04/30/facebooks-new-mantra-move-fa...
Oh the irony.
Zuck: Yeah so if you ever need info about anyone at Harvard
Zuck: Just ask
Zuck: I have over 4,000 emails, pictures, addresses, SNS
[Redacted Friend's Name]: What? How'd you manage that one?
Zuck: People just submitted it.
Zuck: I don't know why.
Zuck: They "trust me"
Zuck: Dumb f*cks
https://en.wikiquote.org/wiki/Mark_Zuckerberghttps://gizmodo.com/facebook-is-giving-advertisers-access-to...
The actual story is FB enriching your profile with shadow contact information about you when you or third parties provide it with details it wasn't aware about yet. For instance when a friend of yours has your landline number in their address book and gives FB access to the latter; or when an advertiser provides FB with the same as part of targeting an ad campaign.
> Later he learned that elsewhere in Facebook, there were “plans and technologies to blend data.” Specifically, Facebook could use the 128-bit string of numbers assigned to each phone as a kind of bridge between accounts. The other method was phone-number matching, or pinpointing Facebook accounts with phone numbers and matching them to WhatsApp accounts with the same phone number.
> Within 18 months, a new WhatsApp terms of service linked the accounts and made Acton look like a liar.
Companies like this, and Facebook in particular, are desperate to connect identities. Phone numbers are an incredibly useful way to do so. Most people only have a couple of them, their re-use rate is slow, they get entered into forms all over the place, and they're usually valid (because they were provided as a primary method of contact).
In this case advertisers have an identity (and phone number), Facebook wants to match on that value. They're going to do it any way they can.
It may not be ethical, but the carrot is right there and it's naive to think you can give them your identifying number and they're going to turn a blind eye to it.
Edit. Also this [1]. Does GDPR suddenly open the door for sharing this data "legitimately"?
[0] https://www.ft.com/content/951d650e-abf5-11e6-9cb3-bb8207902...
[1] https://www.theguardian.com/technology/2018/mar/14/whatsapp-...
Which furthers my point, that Facebook will jump on any carrot in front of it.
It's a shame the EU didn't punish them more severely over that, because they were basically already using the feature without mentioning it in their ToS for almost a year, if not longer.
I thought they were taking pains to limit the ability to directly target individuals. They limited audience size to at least 1000 people previously when doing regular targeting.
How is it that I've never heard of custom audience until now?
Custom audiences though, is why FB are profitable. The platform before those tools were intriduced (5-8 yes ago) made a lot less.
"Similarly, individual employees, managers, and directors are liable for their own malfeasance or lawbreaking while acting on behalf of the corporation, but are not generally liable for the corporation's actions."
from https://en.wikipedia.org/wiki/Corporate_personhood#Case_law_...
I don't think GDPR has any tooth in this.
And, during at least one of those periods in history, the US was not content with superiors claiming ignorance of any wrong doing either.
> I’ve been trying to get Facebook to disclose shadow contact information to users for almost a year now. But it has even refused to disclose these shadow details to users in Europe, where privacy law is stronger and explicitly requires companies to tell users what data it has on them. A UK resident named Rob Blackie has been asking Facebook to hand over his shadow contact information for months, but Facebook told him it’s part of “confidential” algorithms, and “we are not in a position to provide you the precise details of our algorithms.”
I imagine that to prove it, you'd have to make several accounts, with several phone numbers, and somehow demonstrate to a judge that the information leaks through. Not an easy task.
1. Ask for the judges phone number 2. Register new account with judges phone number (clean browser, no friends added or pages liked) 3. See friend recommendations from the judge in this new FB profile.
I also said before that this is exactly why Facebook wanted to "verify people's faces for security purposes", too. It just seemed so obvious to me that Facebook would use security as an excuse to get people to put their own 100% accurate face scans into Facebook. It's also because Facebook used the same excuse with the shadow tracking (it's for your own good!), which is as ridiculous as Google claiming Analytics is for website visitors' own good.
Wait. You think Apple is selling your phone number to advertisers?
Apple is making it easier to use SMS 2FA in iOS 12 (automated copy paste)
However Apple itself doesn’t use SMS for 2FA.
As for Apple they had your phone number since the launch of the iPhone (!). Never needed 2FA to know it.
And no, Apple isn’t selling your phone number.
Until they have bad iphone sales.
Given Apple's less than stellar track record toward developers, employees, and customers, Apple will do things for Apple.
There are also extrinsic benefits outside advertising. Apple, for instance, is also a member of PRISM and one can only imagine how many other surveillance programs across the world that remain classified. Companies are undoubtedly 'compensated' for their involvement in these programs, and the more information they have and can gain - the more valuable their participation would be seen as.
This conflict of interest is why I think we will never see any sort of significant guarantee of privacy at the federal level in the US. The more information companies obtain, the more information the government has access to.
[0]: https://www.quora.com/Which-is-the-best-app-in-Android-for-b...
Not excuse this behavior in the least, but robo calls in general are a solved problem for me.
But more importantly, increased robocalls seriously means more life interruptions. Work nights? Sleeping while sick? That phone still rings, and there are many reasons to leave the sound on. Direct to voicemail simply doesn't really solve all the issues.
Didn't live in a mobile service area either, so no mobile too. Some parts of that were really good. :)
Anyone with kids.
Anyone who works as a B2B customer contact.
* Be in the US, get your mobile number years and years ago and it has the area code of where you lived at the time.
* Move somewhere else, keep the mobile number.
* Now you get 4-5 robocalls per day spoofing numbers from "your" area code and calling at reasonable hours for that area... which are not reasonable hours where you now live.
And if you say "just turn on do not disturb", remember some folks have to be on call for their jobs, don't know in advance what numbers the pager alerts will come from, and so have to leave the phone open to ring from whoever calls. Which will be robocalls with "helpful" offers at 4AM.
What I would love to see in a future mobile operating system is the ability to say "block all calls from this area code unless they're in my contacts".
Anyone who runs a small business?
http://www.nbcnews.com/id/21458486/ns/business-us_business/t...
Thanks, Sprint!