Facebook Network Breach Impacts Up to 50M Users
nytimes.com
nytimes.com
> The first bug was that, when using the View As function to look at your profile as another person would, the video uploader shouldn’t have actually shown up at all. But in a very specific case, on certain types of posts that are encouraging people to post happy birthday greetings, it did show up.
> The second bug was that this video uploader incorrectly used the single signon functionally, and it generated an access token that had the permissions of the Facebook mobile app. And that’s not the way the single sign-on functionality is intended to be used.
> The third bug was that, when the video uploader showed up as part of View As -- which it wouldn’t do were it not for that first bug -- and it generated an access token which is -- again, wouldn’t do, except for that second bug -- it generated the access token, not for you as the viewer, but for the user that you are looking up.
> It’s the combination of those three bugs that became a vulnerability. Now, this was discovered by attackers. Those attackers then, in order to run this attack, needed not just to find this vulnerability, but they needed to get an access token and then to pivot on that access token to other accounts and then look up other users in order to get further access tokens. This is the vulnerability that, yesterday, on Thursday, we fixed that, and we’re resetting all of those access tokens to protect security of people’s accounts so that those access tokens that may have been taken are not usable anymore. This is what is also causing people to be logged out of Facebook to protect their accounts.
[1] https://fbnewsroomus.files.wordpress.com/2018/09/9-28-press-...
=)
No effort needed, if you click your Facebook bookmark, or follow a link or whatever, the browser goes "Oh, this is Facebook" and traps it inside the box with the rest of Facebook without any extra steps from the user. There's a cute blue "Facebook" icon added to the URL bar so you can see it's working.
(I mean, or, stop using Facebook, but for many that isn't a reasonable option)
If they'd done a proper post mortem and corrected the fundamental issue, and made sure it wouldn't have re-occured, this should not have happened.
There was a time where you could read other peoples' chats using this feature.
As every feature on FB needs to take "View as" into account when handling their own permissions, a lot of developers on FB's payroll get a chance to f'up. We are all humans, so the probability of this happening is very high. The impact (for the users) is also high, given that it's automated and concerns every user on FB equally.
When dealing with a very probable, high impact risk in a software project, considerable additional effort is warranted to mitigate that risk: in this case maybe taint checking and additional implementations of the same feature in different programming paradigms, to ensure the system is fail-stop.
But in contrast to airlines and railways, the interests of FB and their users are not aligned. For Facebook, this risk is not (or was not deemed to be of) high impact, so we did't get any of this.
Is it just me or does this sound like an terrible idea in the first place? Guess we can't know for sure, but why would anything unrelated to authentication generate access tokens?
That said, I've heard stories of similar bugs in the industry. The difference was that they were more shallow in the effort to reproduce; deep enough to get through QA but discovered quickly in production.
But honestly, Facebook has more resources to spend on security than any online bank. Banking security should be defense-in-depth: Strong first layer security, serious monitoring of suspicious activity & openness for reports by users, a certain level of manual approval of irrevocable transfers, a certain revocability of transfers that are able to be automatically processed, transfer size limits to deny one breach to have huge consequences.
And finally, a credible economic and legal system that ensures only a tiny minority of people want to rob a bank because there are much better options for making money, and banking regulations that leave the responsibility for security vulnerabilities squarely with the bank's shareholders.
Anyone can be owned with enough effort, so it's not just about creating software that's as secure as you can make it. You need to have sound policies as well.
Its so bad that for certain systems we check the origin of your connection and will only trust you if you've come from the DMZ rather than internal.
With that said, this is a bigger vulnerability precisely because Facebook is a free service - at banks, you need to be a customer with real-world identity to even begin to attempt to exploit this.
Set your preferences to show posts of your native language only, start poking around the timelines, and follow people who post something interesting. Follow, boost, reply, it only takes a few days before you have plenty of interesting content in your feed.
There's zero chance on Mastodon that you'll get caught up in a gigantic data breach like this. Probably less chance you get caught up in any kind of breach -- it's too obscure to be a target, plus the code is open source so many eyes on it, etc.
And you'll enjoy these guaranteed benefits, as well:
- No longer subject to the most sophisticated data vacuuming adtech in the world
- If you get bored/annoyed you can just take a break from Mastodon because it doesn't own your life the way Facebook tries to
Security through obscurity...
Open source != secure. I can guarantee that a hell of a lot more folks with a lot of security expertise have combed through the fb codebase than Mastodon.
...is not a solution by itself but is a perfectly valid part of a defense in depth strategy, for example running SSH on a port other than the default is a common and good practice.
> I can guarantee that a hell of a lot more folks with a lot of security expertise have combed through the fb codebase than Mastodon.
This is the same argument Microsoft always made in defense of Windows security back in the XP era. "We hire the best experts in the world so Windows must be fantastically secure." And Windows security turned out to be a train wreck. Now in Microsoft's defense it has improved considerably over the years, but Windows desktops still get owned far more often than Linux desktops do, for a reason that would probably apply to Mastodon today as well: not that many people use it, so it is not nearly as common a target for exploits.
I don't think I deserved downvotes for making these points btw, that button is way overused on HN.
This really depends on what kind of target you are. Are you a random person on the internet? Then making yourself a smaller target by using obscure services might help. Are you someone with sufficient value for a spear phishing attack? Not so much. “Sufficient value” might just be “you slighted the wrong person on the internet.”
There’s also a lot of trade offs involved, some of them less than obvious. For example mastodon servers may be run by a person/team who’s trustworthiness rating is harder to evaluate Tran facebooks. The server you’re on might by run by well-meaning but incompetent people. The server you’re on might have one participant that is a target of sufficient value for spear phishing and your data might be taken and leaked just to obscure the real target.
Nowhere on that banner does Facebook make it clear that there was recently a severe security issue that may have resulted in the loss of personal user information (Making it much less likely for the user to actually click 'Learn More'). It's misleading to title this with just "An Important Security Update" and make it seem like they've just updated their systems. No mention of the recent compromise until you click 'Learn More'.
https://www.facebook.com/help/2687943754764396?ref=comms
Which is the issue at hand.
Also, it's "100%" the banner I saw for several days last week. Make of that what you will. I didn't click it so I don't know what it pointed towards.
I just checked fb, and went quickly to my first notification. I didn't really register what the banner was until maybe a second after it loaded - at which point I had already clicked on my first notification. By that point, the banner is gone forever. I can't find any way to get it back.
It's so, so easy to miss this message.
CNN many years ago accidentally left some of their pre-written obituaries for (living) world figures publically accessible. https://en.wikipedia.org/wiki/List_of_premature_obituaries#T...
It's not uncommon. It's how you build "friendly" relationships with the media. I scratch your back, you scratch mine.
Actually, not "common" at all.
Obituaries for famous people are often done in advance, since everyone dies. It used to be one of the things that young journalists/interns did to cut their teeth.
But not every company has a massive security breach, so this was not pre-written.
It's not uncommon for big companies to fax (yes, fax) bad news to news organizations a few hours or days before posting it on their own web sites.
In the past, there would be embargoes on the information, but in the case of bad news, those are routinely ignored.
You should probably get on that.
I suspected there was a breach of some sort, when my tokens expired in three places simultaniously, this morning. First thing I did was search google news, nothing had been written yet. I wasnt sure they would ever announce it, probably depends on the scale.
There was a conference call with reporters about the subject, so the press release public release was not the first the NYT knew about it. They likely had an embargo agreement.
It's often in the interest of the reporter to agree to stuff like this since publishing security issues ahead of time can have serious negative consequences.
Source: I spent years at a national PR agency
Facebook wrote it. They called their friend at NYT and handed over the article - then mentioned they would be sharing it with other outlets later. [just my guess].
Noam Chomsky wrote Manufacturing Consent decades ago.
Read, you fools!
I am totally baffled in the post-fact world.
(No, it's not that it was just two devices - I had to log in four times just on my phone. Once for Messenger, once for FB itself; during each occurrence.)
oh boy, what a mess.
Well, when it doesn't have a security hole.
(Not to mention it's not really user impersonation, it's just filtering your profile page based on computed access level of one of your friends.)
The fact of the matter is... ACLs are hard to get right. It's even harder when you have various roles that can be checked against the ACL (logged in user, batch job, logged in user impersonating someone, etc.) . But in the end, complexity is what's scary, not some feature that depends on complexity.
This sounds similar to different distros of linux. Some are security focused where nothing is allowed until it is explicitly allowed. Other distros try to be more "user-friendly" and pretty much everything is open.
Starting from a wide open starting point and then trying to batten down the hatches afterwards does seem to the harder way to do it, but that's exactly where FB is. They wanted everything open, and then had to decide to start limiting that data. FB was designed as a place to share info. If you posted it, you wanted to share it. I totally get that mentality. However, as devs, I can imagine that we have all built something that the end users use in a way not envisioned, and we've probably all had "you're holding it wrong" lines of thinking. Once you get to that point, you can alienate users by telling them to stop doing it that way or embrace what's happening, and then make it work for them. Seems like the perfect situation to where bugs can get introduced.
I guess even the best (at secure coding) sometimes mess up.
Have Amazon, Google, Twitter, Microsoft or Apple been on haveibeenpwned? That’s what I think of when I hear “big names”.
Yes my company benefits from it, but so do I. For instance, given a choice of trying to come up with an idea to learn about a feature of AWS and pay money for the resources I use, and take advantage of my work AWS (Dev) account where I am an admin, I would rather do a work related project where I have the resources and I don’t have to come up with an idea and I don’t have to pay for it.
What I don’t do is “signal”. I don’t stay at work late, I don’t send emails out after hours, and I pushback if they give me unreasonable deadlines.
On the other hand, say it would take me 50 hours and I knew I would have to work on the weekend because I’m not as experienced, but I thought I could still have it done by Monday.
I might be willing to volunteer, knowing it would take me longer but it would also be done on time. That extra 20 hours, I’m still working, committing code but zeal do trying to figure out the framework. I wouldn’t have a problem doing that because I am learning a new skill.
But, I wouldn’t work weekends to finish a project because I was given an unrealistic deadline.
The first scenario, the extra 20 hours benefits me and the company. The second, it just benefits the company.
In fact, I need permission from my manager's manager's manager in order to stay past 7pm.
This company believes in a strong work-life balance, and this is one of the ways it achieves this.
Also, it "changes the world" in good ways, not by "connecting people" through bogus data siphoning addiction traps.
Personally I strongly prefer no fixed working hours. If you want to work at night, so that you can do things when it’s light out (especially in winter), and you still get the expected results, what’s wrong with that?
Also, lone wolves working at night are harder to manage and communicate with.
Probably not fired. But the interior motion sensor alarms go on automatically at 7pm, which would probably alert the security guards that roam the campus.
When I first started, I came in too early once and set off the alarms. People were nice about it, but I was super embarrassed because I was a n00b.
Personally I strongly prefer no fixed working hours. If you want to work at night, so that you can do things when it’s light out (especially in winter), and you still get the expected results, what’s wrong with that?
I worked at a place like that once. When I was hired I was told I could make my own hours. I prefer to work early mornings, so some days I came in long before anyone else. A couple of times around 3am. But I always worked at least eight hours, and often more.
In my exit interview, my supervisor was rabid about how I wasn't a good fit because I "come and go as [you] please." She was so full of crap about other allegations against me that I didn't even have a chance to bring up that making my own hours was part of my employment deal.
Take those excited geniuses and have them work on preventing climate change from ruining all life on earth, instead of inventing new ways to profit off of people’s data.
Just because we have more "stuff" and more advanced "technology" doesn't make life more worth living. Happiness levels across society don't increase alongside productivity.
Okay. That's your choice. But having made this choice, don't complain when those of us who choose to devote more time to work receive greater rewards. There's nothing wrong with paying for performance.
I can’t stop my bosses from judging based on time spent working (which is silly, but hey, we’re all human), but I sure can try to stop my coworkers from subscribing to such insane work hours.
we're talking about Facebook here
If Facebook's a grind, then that's something the employee has to figure out.
> What, exactly, is wrong with the expectation that people make senior level eventually?
The problem is when you base too much on promotion systems and performance reviews, that end up as a form of bias and favoritism not closely approximating the truth. Some amount of people are doing useful work for you (like cleaning up after people you think are the high performers) that does not surface there, and when you crap on them, pass them up, bust their morale, make them afraid of their next review, etc., you risk losing their valuable contributions.
Modus operandi in these companies is to rewrite/reintroduce whole products instead of fixing bugs from already discarded people. So if you lose a critical amount of worn out higher paid contributors, you just make a V2 or introduce a new product with a completely new fresh team that will get discarded after another 3 years. This requires fresh supply of motivated and hungry people willing to take sacrifices and a much smaller amount of people willing to exploit that.
I can't believe people put up with this. I really hope you got paid for that time.
You see, the parent poster said:
> They got pushed to check-in code at 12a.m. for example.
This is ENTIRELY different than having you, overly excited about some project, deciding to work late and pushing code at 12am of your own accord. That's absolutely nothing wrong with that.
Now, if you are EXPECTED to do it, outside major emergencies, then you have a problem.
Unfortunately the number of lazy people far outweigh the number of hard workers.
My understanding of the "get promoted or leave" thing is "engineers hired as juniors are expected to get to mid-level in under 5 years (with a half-way milestone at 2 years)"; once you're mid-level it's up to you if you want to carry on climbing. Personally once I got there I switched to a "work more efficiently in fewer hours and keep the same overall productivity" approach instead of trying to get promoted into the senior levels, and that's worked out nicely so far :)
Train me, please.
It’s not a great practice in my opinion. But in practice only a small percentage of engineers fail to make the grade.
If you heard about the NCIX story where they basically abandoned their servers filled with users data (over 13 years of data) and someone scooped them up and tried to resell them on the black market, one could think that a similar fate is possible.
source : https://www.privacyfly.com/articles/ncix_breach/
Obviously if Facebook was going under it would probably trigger a huge legal process on how to handle the data but it clearly doesn't happen for smaller businesses...
Interestingly, Facebook owns your data. I believe if they wanted to, they could close the company tomorrow and put a facebook.tar.xz of everything they collected on archive.org or somewhere else.
(Except if a European office of Facebook did it, then the nationality doesn't matter.)
At least that written and TOS or so.
Your data is their primary asset.
And it won't matter because the data will be rolled over to drive ads on Instagram and Snap and other attention-properties.
Facebook is the IBM of social media. It's too big to die, and too big to do anything good.
I personally did not get any explanation as to why I had to log back in. It did surprise me to be logged out this morning and was wondering why.
It linked here: https://www.facebook.com/help/2687943754764396?ref=comms
I bet they're now really regretting keeping it around.
Did anyone else experience anything like that?
But does this mean most of the time that there was no active access token and she is mostly safe? (Excluding the windows of time where she was actively using FB) Do I have to take back all of my teasing?
They also disabled "View As" which is the actual fix for the time being.
Obviously, Facebook is an extremely complicated system. But I find it hard to believe a video uploading feature would impact 'View As'.
It's intuitively straightforward that modifying code for uploading videos could (read: not should) have authorization and authentication ramifications. One of those ramifications could then result in a vulnerability chain compromising user impersonation functionality.
I have seen far, far more incredulous head scratchers in penetration tests and code reviews. The interaction boundaries of, or middleware between, two seemingly unrelated systems is generally a good start to look for a security vulnerability.
I get this part. But why would it affect only videos and not other entities (photos, status etc.)? I would think creating (or uploading) any of the entities have the same authorization and authentication ramifications. What could be different for videos? Unless the privacy models are so fine grained that you can have different privacy settings for different entities (haven't used Facebook in years, so I don't really know). Your explanation makes sense, I'm just looking for a concrete example.
The problem is often that there are multiple sources of truth for who the user is. And if you have an impersonation feature, you by definition have two sources of truth: who the user actually is, and who the user is impersonating. It would just be a matter of a single mistake of using the wrong one.
Considering that "view as" requires your page view to render every control as the impersonated user but only when it comes to your profile, but renders all controls outside of your profile as the original user, I could see any engineering team dealing with some very carefully drawn and potentially confusing boundary cases.
Edit: just to elaborate, it's not just obvious impersonation contexts where this gets interesting. For example, linking your Humble Bundle account to your Steam account, or on Netflix which user you are vs. which email address is being billed. Many apps have a function to share some document using a one-time expiring token. If you're also logged in, then do you read permissions from the shared token or from your account? If you mix them, do you make sure anything that writes to this shared view can't touch your account itself on accident? We don't think about it much but I think you can see how these subtle distinctions are important when you are thinking about access control, and that makes it a breeding ground for subtle mistakes.
Trusting these entities based on their noble intentions today makes no sense to me if there's no legal agreement or regulation to restrain them tomorrow, when they get desperate.
No, not at all. Their positive reputation was in many ways unearned, and it's a good thing to be glad that their own actions and attitudes are finally catching up with them.
I hate that this has happened. The Bay Area used to be a place where working for the big, shiny company that makes your parents happy wasn't prestigious. It was safe. But taking a risk and starting something new was admired. The present state of affairs reminds me of Wall Street.
The tech industry, despite its shortcomings, is vastly superior to Wall Street in that regard. It's still a meritocracy above all else.
Plenty of smart people break into tech after doing something else for a few years. If you want to go into investment banking, you better come from a consulting or have already been working in finance. Your only last bastion of hope is to get an MBA and then join the rat race.
e.g https://www.slideshare.net/a16z/state-of-49390473/29-29Becau...
Outside the tech community, probably Amazon, Microsoft, and Instagram (most people don't know Facebook owns Instagram).
Are you saying the latter two don't do that?
Also, a bunch of recruiting venues exploited by Facebook are not that accessible to smaller startups.
E.g. one of the top previous employers for Facebook employees was Google (or some other outfit within Alphabet group, like YouTube). Most likely those people would've stayed at Google.
Another hiring source was university recruiting, which involves participating at job fairs at various universities, exhaustive days of back-to-back interviews, flying candidates for on-campus interviews, and eventually covering relocation costs (and potentially visas and immigration paperwork) for someone moving from Pittsburgh, Waterloo or Romania.
Would a smaller startup have the financial oomph to run a similar recruiting pipeline?
I know lots of people who feel they get and have got tremendous practical benefit from Facebook. It isn't "addictive" unless you use that term to mean anything some people make that other people enjoy.
https://www.ncbi.nlm.nih.gov/pubmed/28093386
"Our results showed that overall, the use of Facebook was negatively associated with well-being."
Naturally, even if this study is accurate it isn't definitive; the causation could go in the other direction, that the unhappy use Facebook more often than the contented. But it's still quite suggestive.
I saw this study referenced from this article: https://www.vox.com/policy-and-politics/2018/3/21/17144748/c...
Along with React, GraphQL and a bunch of other technologies with various degrees of popularity https://opensource.fb.com
Along with various startups building around the projects incubated at Facebook - Asana, Interana, Phacility, Qubole, etc.
Where B is the sum of the set consisting of:
-Breaking democracy in the US and the UK by being _the_ platform for disinformation.
-Disinformation assisting genocide in Myanmar.
-Use correlating strongly with poor mental health
-Manipulating behaviour to encourage poor attention spans for the sake of ad-clicking
-Constantly violating basic standards of privacy
-(I could go on..)
Oh wait, excuse my arithmetic. I forgot to add another JS framework like Relay to the LHS of the equation, that makes it a net positive from Facebook! :D
It is a problem inherent in the structure of most social media companies. And Facebook is the most significant social media company, and thus contributor to the problem.
Blaming facebook for "breaking" democracy in the US and the UK is ridiculous. I can't understand how this can continue being a claim remotely considered valid. I agree (or may agree, at least in part) on some of the other points, but not on this.
Claiming that Trump won just because of the russians putting ads on facebook is at least naive - and ignores the fears/actual issues a very big* part of the US population experience daily. Isn't failing public schooling a problem there also? Does that give us citizen more or less prepared to actually participate in democracy?
Politicians (of all sides) in the UK have accused the EU of being the root of all evil since they "joined", again and again and again: you lost your job? Blame the EU! We can't cut taxes? Blame the EU! You really want to blame facebook and NOT the politicians themselves because people voted for brexit?
If the Russians tried to manipulate (and for sure they did, oh gosh, I'm pretty sure the US and the EU states never do - or did - anything to manipulate elections abroad! Evil Putin, why you do this to us? :cry:) we rolled out the red carpet for them!
Democracy was broken because actual journalists did not do their job. Stop doing what they (may) want you to do, using social media as a scapegoat for their own (willing, sometimes, for sure, at least if you read what Chomsky has to say) MASSIVE failure of being the "champions of truth" they claim (and blindly believe - I worked on somewhat close contact with them for years, I've seen that) to be.
You don't think those technologies could have been developed by people at ethical companies, or even by the same people at ethical companies?
There's also financial support for building a community around improving the tech, by encouraging outside contributions via meetups, conferences, social events, better technical documentation, etc.
At smaller scale startup an engineer is surely welcome to work on his skunkworks project, but justifying expensive large-scale architectural undertakings on company's dime is problematic. Especially if a quicker fix is available and buys the company a chance to kick the problem down the road.
With that said, it's not impossible to build a major popular piece of technology within a small company (Joyent and Node.js being a good example), it's just harder.
This discussion is mostly irrelevant to the fact that this particular company is completely reckless and unethical. The technology they accidentally produce while building a dystopia to make people click on ads[1] does not justify anything.
So, yes, I believe they are trying to corner the market on the best programmers.
They may pay more, but they collude to make sure people couldn't leave without going far outside the bay. That's a monopolistic trait.
I agree they weren't putting a gun to people's heads but they were making the environment less available.
Google's goal: Organize all the information
Amazon's goal: Sell all the merchandise
-----------
Taken at face value, all those companies were/are all trying to make the world a better place in the ways available to them. But when the externalities of those goals affect other people, they will become hated. Everyone has a different opinion of what 'better' means.
Since giant companies are most able to execute their vision of better, they will get most of the hate from people who have a different opinion of better.
Looks to me like its all just a battle for power: People with ideas but lacking implementation and execution, vs Companies with ideas, implementation, execution, AND momentum. Let's not forget all the different forms of government either...
Google's goal: sell more ads
Amazon's goal: Sell all the merchandise... and ads
FTFY
All other news outlets: Make people click or view ads
Random-blog: Make people click or view ads
Free games companies: Make people click or view ads.
Internet businesses are a vicious circle of cash for ads. Ads are deeply embedded in the business model, but is advertising the goal of any of these companies?
I have a coworker that is jealous of me and my boss because we go at it, but we both know it isn't personal. It is about making the right call on a project. We each think we are right and just trying to make our point
So I think this thread is just more intense but there is no ill will
Oh, wait, it doesn't matter since they move heaven and earth to collect and store my data anyway, and of course I can't get them to delete it.
Seriously, fuck Facebook.
I might be way way off and I am (obviously) not a lawyer but interested in material about this.
I’m a EU citizen and I’ve always been intrigued by Estonia’s digital citizenship. I’ve only picked a few tidbits about how it works and they may be wrong, so take this with a grain of salt.
From what I understand, a digital citizenship is different from a normal citizenship. It allows you to, for example, open a company, but I don’t know if it gives you enough to make you a EU citizen. In Portugal there’s a bit of a kerfuffle about the Golden Visa programme[1] because it’s seen as a way to buy EU citizenship for cheap[2] and cause problems for nationals[3]. I’m not aware of the same happening through Estonia, so it makes it me think it doesn’t give you EU citizenship.
In addition, you have to actually go to Estonia to set up the digital citizenship; it’s not something you can do completely offline and be done with it.
Methods such as marriage are not that effective in Portugal, at least at the moment. I know of two people with legitimate reasons to get Portuguese citizenship and the process has been a chore, taking years.
[1]: https://en.wikipedia.org/wiki/Portugal_Golden_Visa
[2]: Yes, you need to invest, but you keep your investment.
[3]: House prices in major cities and surrounding areas are through the roof.
They were pretty clever, because they used proxies in my region so facebook wouldnt send me automatic warnings.
I can only encourage everyone to check their running Ads & campaigns and check the audit history log at business.facebook.com asap!
Facebook support sucks (also for business users) so dont expect to get your money back.
I was logged out of Facebook about 30 minutes ago.
Working for Facebook is a morally bankrupt position. If you are an engineer you have plenty of job opportunities available to you and there is no excuse for you to continue contributing your labor and time to a wholly malignant organization. At a certain point one has to ask how we as an industry will start dealing with those who continue to take a paycheck from Facebook even in the face of constant and horrific evidence of wholesale ethical violations and negligence.
Your point? Should we stop working in IT and go back to the fields?
Also, I fear that HN somewhat forgets the world is not SF, in Europe going to work for Facebook/Google/Amazon is a enormous bump (we're speaking 2-4x) of salary for many people, which in some cases means you can buy an house after 3-4 years even with the crazy rents back in your home country - and that's HUGE. Why should those people spend their time slaving as a subcontractor for yet another TLC/bank trying to squeeze their customers dry at the first occasion while getting 25% the salary and zero benefits? Are those less evil?
What needs to happen is that people keep applying pressure so facebook is forced to adapt its business model even if it hits their bottom line - which is already happening apparently.
So this is how we justify it now? “But it will allow me to buy a house in 3-4 years”?
I enjoy destroying the environment for future generations so they don't have it too easy?
The "justification" (if you want to call it that way) you are looking for is in the part you forgot to quote and respond to ;)
So I'm wondering (out of curiosity as I can't personally think of any) where in Europe is that happening?
Also EU != Europe
Doesn't improve the validity of the position though.
There are hundreds of more similar articles documenting hacking by China and Russia. The data breach at the parent of this article even is supposed to have been done by a coordinated nation states. How can a company ever compete against a nations resources? Expecting Facebook to magically secure themselves against attacks by a nation is wishful thinking. If you want to stop breaches like this, the nation's that are doing it must be held accountable. Facebook is an easy target, but that's just attacking the victim. China and Russia are much more intimidating but are the ones who are the true perpetrators.
This is a spearfishing attack... That's a totally different beast. Let me look at the gross mishandling of data that facebook had recently:
Remember the Cambridge Analitica scandal? That wasn't a hack. That was facebook deliberately letting apps access user data like it was candy, because that's what facebook does. It was done on purpose. Of course, they didn't expect someone to scrape the whole network at that scale, so it wasn't fully intentional. Still, it was absolutely gross negligence, and is absolutely a breach of trust that happened outside of external government interference: https://www.vox.com/2018/3/20/17138756/facebook-data-breach-...
What about the recent scandal revolving around the use of 2FA SMS numbers being used for ad targeting? Against, this isn't Russia coming in and hacking facebook. This is Facebook shooting themselves in the foot with a bazooka. They should have been aware that, when a user enters their phone number for 2FA, they expect it to be used for this feature and this feature only. Not for ad targeting, not for notifications. Again, facebook breached that trust. No outside interference, just facebook being either lazy, irresponsible, and incompetent around user data: https://9to5mac.com/2018/09/28/facebook-ad-targeting-2fa/
There are many other cases like the above. Facebook doesn't need china to attract hate. They can fuck things up by themselves well enough.
In my mind, FBs inaction in countries like Burma has caused more direct conflict/hate then most tobacco companies. However, if you look at the oil industry, its harder to draw a line... For example: Is the oil industry responsible for the bombing of Irak? The Government gave different reasons, but looking at current evidence for example, it just looks like pipeline protection.
So what i wanted to get at is that when a company gets to a certain size, it gets harder to separate government/ company involvement. At that point we need to look at how the company acts, and in this case, especially FBs, they are doing a horrible job (IMO) at actually standing up for their users, instead choosing to protect their business interests.
(While this is their supposed purpose as a company, there exists people like myself, who believe the current model of stock sponsored companies are the wrong way to do business).
Just a FYI: This is more a rant then anything, Im tired of the BS that these huge companies are producing and selling as the solution to humanities issues. Personally i hope that this current system fails for something better, however, personally i have not thought up anything much better atm.
"Nation states": The bad guys, usually China and Russia, sometimes Iran.
I'm pretty sure we'll end up discussing the various shades of moral bankruptcy soon enough though.
Yes. Most of the large and powerful organizations have severe moral problems, almost all of them due to violations of a simple rule: $ < Values
"Love of money is the root of all evil."
We all have choices. We all make decisions.
I would go even further and say that people who ride Uber or buy from Amazon are moral cretins.
Alright then, where do we draw the line? Can I go buy a person? If not, can I invade Sudan?[1]
> Ethical consumption is a dead end.
Should we give up even thinking about it and just do whatever is most convenient?
Will that solve all our problems?
You know Amazon treats its employees like disposable shit. If you buy from them anyway you are putting your self-love above the love you should have for the folks working there. You know Uber is extracting value from their drivers[2] and will discard them without compunction when the robots come online. And they killed Elaine Herzberg. If you ride Uber you're rewarding them for all this and putting your self-love above the love you should have for those folks driving.
I'm gonna keep fighting for what I think is right. That means telling people that they are moral cretins when they are blithe about it. (I don't think violence solves anything, but a good rant can shake up a body's thoughts. I have friends that shop through Amazon and ride Uber and I don't chide them too harshly or often.)
Working at FB or one of the other emerging technocracies isn't an instance of "Never let ideological purity prevent you from effective action." It's a case of putting money above core values, or not having those values in the first place, or simply not paying attention.
If you're going to be a Morlock at least be a self-aware Morlock, eh?
> You can't even buy slavery-free clothing or food reliably.
You can try.
If you don't even try you're a moral cretin.[3] It's a common malady in this empty and abortive age.
[1] One of the few places where outright slavery still occurs in modern times. If that's not grounds for attack what is? Oil?
[2] "They don’t pay the cost of their capital. The wages they pay to their drivers are less than the depreciation of the cars and the expense of keeping the drivers fed, housed, and healthy. They pay less than minimum wage in most markets, and, in most markets, that is not enough to pay the costs of a car plus a human." https://www.ianwelsh.net/the-market-fairy-will-not-solve-the...?
[3] "Origin Late 18th century: from French crétin, from Swiss French crestin ‘Christian’ (from Latin Christianus), here used to mean ‘human being’, apparently as a reminder that, though deformed, cretins were human and not beasts." https://en.oxforddictionaries.com/definition/cretin
Between you and me, I pulled a muscle in my neck/shoulder this morning and I've been in a devil of a mood all day. I'm not trying to make excuses, I shouldn't have taken out my bad mood here. Today's B.S. is not indicative of my best efforts.
HN is an incredible forum (I interacted with Alan Kay the other day!!!) and I'm ashamed to have added such counter-productive negativity. It won't happen again.
I'm sorry for being part of the problem today. Have a great weekend.
Yes, it's an horrible world. I know, I'm saying that it is, I agree completely. What's the alternative? We blame people that work in other companies and claim we are honest and pure? Do we say that since there are X layers between us and them then we're fine? :)
Whew! It's not just me? That's reassuring (As in, yes, there IS a monster on the wing of the plane, but that's so much less scary if you see it too. Little Twilight Zone reference there.)
> What's the alternative?
I don't actually know. However...
Bucky Fuller calculated that we would have all the technology we need to supply our needs globally for everyone, if only we applied it efficiently, by sometime in the 1970's. We have arguably already passed that point, meaning that our problems today are not physical, that they are just psychological (or moral or religious or spiritual if you prefer.)
Starting in the mid-1970's a kind of effective cybernetic psychology has been developed (under a kind of trade name Neuro-Linguistic Programming) that provides simple algorithms for correcting a great deal of malfunctioning psychology. (Be aware that the Wikipedia article for NLP is crap, it's haunted by skeptics. I can vouch for NLP. Not only is it grounded in hard science, I myself was cured of serious debilitating depression. I owe my life in a sense to NLP.)
To sum up, we have the technology to supply our needs, and the technology to overcome our psychological problems, so I think it's a matter of A) dispelling ignorance of the possibility, and B) logistics.
Tag, you're it.
You should change this.
preventing impersonation is literally the only reason I have an account, since I cannot trust facebook to handle this for me
I'm pretty sure you can do good even within facebook, doing your utmost to keep the company accountable (from my experience in another big corp, we don't see 1% of what's happening inside it, and how many people are facepalming - and we'll never know if many things were just humans being stupid or actual calculated decisions). You can also keep your guard up from outside and force facebook to fix itself (obviously, as much as its business allows) from outside, for example pushing it to hire more moderators and get as better so to prevent things like myanmar from happening again.
What I'm saying is that it's impossible (and in my opinion, pointless) to claim moral superiority and to accuse people of being morally bankrupt because they work for corp X.
There are plenty of companies which can't easily be categorized as having significant negative effects to the world. You can work for a "bad" company but consciously constrain your work to a business unit which improves customers' lives.
What you're using is false equivalence. You know what the worst thing for the environment is? Being born. Why do people insist on living when everything is bad? Reject the notion that you're powerless to change things.
Its like, "Doctor, why dont we just apply pressure on the tumor until it starts to grow at more reasonable rates!".
No. When you find cancer, you try to eliminate it.
Facebook is exactly this -- cancer. They have been aggressively monopolizing software for socializing so that they can arrive to the dominant position they are in now.
Until Facebook becomes more transparent w.r.t how they use the user data and until Facebook gives users autonomy -- they need to be regulated. We need to define constraints regarding how they present and manipulate user data and interactions.
Not the OP... But no... Just stop working for morally bankrupt companies.
There are enough consulting jobs, to say nothing of current and future startups around (including your own if you create one), to not need to work for them.
> What needs to happen is that people keep applying pressure so facebook is forced to adapt its business model even if it hits their bottom line - which is already happening apparently.
Then again, would-be employers saying loud and clear that they won't hire people who worked for morally bankrupt companies is a potential answer too.
If software engineers pushed hard to consider that working for them was a dead-end job rather than something very desirable, then maybe they might end up attracting less talent and go bust eventually.
On your deathbed you'll only take a single thing with you. Not your house or family; not your wealth; only whether what you did with your life was worth it.
A very very few, like Alfred Nobel, are lucky enough to see what their contemporaries thought about their lives before they passed away and got to adjust. You probably won't.
While Google and Amazon both have their ethical problems and serious anti-trust issues, Facebook is in a league of its own. The complete, cavalier disregard for the consequences of its own actions as long as they get theirs is utterly unconscionable.
Unlike Google or Amazon, they add nothing of real value to society to balance the abuses they bring with them. All their labors are geared towards extracting the utility of other creators (their acquisitions like Instagram or WhatsApp) or to suck the time and attention out of people through addictive mechanisms. If Facebook disappeared tomorrow a hundred federated online platforms to function as generic address books and life-updaters would crop up over night, and just about every one of them would be better.
You would have to look at lines of business like Big Tobacco to find another field of similar moral perfidy.
Maybe, but at least Facebook doesn't actively try to manipulate you into believing that they're the "good guys" and "not evil". That's why, after all, my level of respect for FB is still a lot higher than for Google.
They don't? News to me.
> They don't? News to me.
News indeed. Being good IS their mission statement. "Facebook's mission is to give people the power to build community and bring the world closer together."
Hah, good one!
But just in case you're serious: Did you see Zuckerberg's Senate hearing?
but I'm also hoping that it breaks apart and we find a better way then invading peoples privacy to monetize platforms
Facebook is more like Big Tobacco. They're purely malignant, continuing solely through adversarial relationships with their users meant to foster addiction or control the revenue streams of key industries like media and news. They're pirates. What benefits they provide, they have only ever made worse than other services and tools that predated them.
>but I'm also hoping that it breaks apart and we find a better way then invading peoples privacy to monetize platforms
Amen to that. Treating attention as a form of currency has been utterly corrosive to society.
I work at a big tech thing. But these also do a lot of good.
Facebook keeps me more connected to old friends and family than ever before. It facilities communication and organization of events that would far more time consuming to do without Facebook. I hang out with loved ones more, because pinging them is on Facebook is easy.
Sure, Facebook could be better. IMO ads in messenger is a cheap move, that won't play out well. But Facebook could also be a lot worse than it is.
You're not going to rebuild the world from scratch. Nothing will ever be perfect -- but don't let that get in the way of better. Why not make it better from the inside? How is that not ethical?
People who work for known unethical organizations are hardly celebrated so these are poor attempts at muddying the waters and distraction.
The bottom line is if you can't behave ethically you can't expect ethics from others in society. If 6 figure earning engineers can't exercise ethical choice then who can? Its incredible given the level of discourse how anyone can expect any ethical behavior from the poor and starving and yet we do. The double standards and greed from educated classes is stunning.
going to work for Facebook/Google/Amazon is a enormous bump (we're speaking 2-4x) of salary for many people, which in some cases means you can buy an house after 3-4 years even with the crazy rents back in your home country
Ah yes, the ends justify the means.
Hahaha, thanks, that was a good one.
Minimizing the damage of collecting that information is maybe not directly evil, but helping kick the can down the road to the point where facebook is so deeply networked in our society its unremoveable doesnt seem like a high horse to be riding on.
Or, have the former earned a monopoly on the latter/our-species?
And unfortunately Hillary Clinton did it to Putin first, probably using similar methods.
The parent poster is calling on them to do just this with regard to Facebook.
There is nothing wrong with that call, and it doesn’t impugn your friends unless they ultimately fail to re-evaluate the company.
What about those who argued for React to move to a more reasonable license? What about those who pushed for open sourcing code and hardware in the first place?
Companies at the 25k+ employee size are complex, often internally-disagreeing enterprises. Code may be pure, but resource allocation (programmer time) is political.
Of the recent Facebook news (e.g. shadow profile and 2FA phone numbers being used for ad targeting)... "we had bugs in our code" is by far the least ethically problematic.
I think that is clearly a fallacy.
Nobody is arguing that every individual within Facebook is an unethical person.
The argument is that the overall project is unethical and the ethical people within it should take that possibility seriously.
For more philosophical background on this idea:
And is ridiculous, for anyone who's worked in the real world.
We all make ethical compromises, and have worked for companies that made ethical decisions we didn't agree with.
That was the crux of the Nuremberg Trials: what portion of an endeavor's ethical decisions can be assigned to an individual.
The answer was "more than none, but less than all."
Can you quote anything at all from this particular thread that supports this statement?
It’s clearly the position you are trying to refute, but I think it’s a straw man.
That said, at least you are in the domain of agreeing that working for Facebook is an ethical compromise:
“We all make ethical compromises, and have worked for companies that made ethical decisions we didn't agree with.”
Once again, your position seems to be to try to erase the distinction between Facebook and any other company. The Nuremberg trials demonstrate that this position is not tenable - we don’t erase the distinction between the Nazis and any other government.
The argument here is that by now there is enough evidence that this compromise is too much, and that ethical people who work at Facebook should consider that.
Being an ethical person doesn’t imply some kind of mythical ethical purity. It implies that you care about ethics.
The original parent comment of this thread...
> Said this yesterday in the other Facebook thread, and I'll say it again.
Working for Facebook is a morally bankrupt position. If you are an engineer you have plenty of job opportunities available to you and there is no excuse for you to continue contributing your labor and time to a wholly malignant organization.
As to your comment...
> The argument here is that by now there is enough evidence that this compromise is too much, and that ethical people who work at Facebook should consider that.
The argument in this thread is not that people who work at Facebook should "consider" that, but rather that anyone who continues to work at Facebook is no longer ethical.
It's not a straw man if the very first comment proposed exactly that.
Which is a sort of absolutism that I'm taking issue with. I'm sure there are parts of Facebook that are wretched hives of scum and villainy. I'm sure there are parts that would make my and your employer look terrible, ethically comparatively.
So maybe we should use a bit finer brush when tarring people. That seems like a fairly modest proposal to me.
The poster you quote believes that Facebook is clearly immoral, and to continue to work there is indefensible.
Have you considered that this might be true?
Now perhaps you don’t think it is true. That would be my guess based on your positions in this thread.
A non-absolutist position would be to say ‘Facebook as a whole isn’t that bad - here are my reasons...’
Whereas your actual position is ‘nobody can make valid ethical statements about organization above a certain unstated size’.
The first is holding a different opinion. The second is an absolutist claim.
Another counterargument could be like the Nuremberg defenses that you have already mentioned - I.e. Facebook is that bad but there are good people there who don’t realize that, or who think they can change it, or don’t understand the consequences of the orders they are following etc.
But that’s not what you are saying - you are saying that nobody should claim that Facebook is that bad.
You seem to think that Facebook is no different from any other employer, but have offered no explanation other than to suggest that not all steps taken by all employees are calculated to be evil.
It’s perfectly reasonable for others to think that Facebook is so obviously corrupt that to work there is morally bankrupt.
Perhaps it is.
I sincerely hope your friends will be more successful. But I doubt it.
Can you go into your argument for that?
Which large companies are morally worth getting our support?
So they are certainly engineers at Facebook doing very questionable things - but not all of them.
In general: the more influence you have (via code you write or otherwise via power you are aware you have over people), the more you become ethically accountable for your actions.
What that's too much? Moving jobs is sooooo much easier, what with changing your healthcare, benefits, probably taking a paycut, losing all the friends and acquaintances you've made, no problem man.
And we all know Facebook is the only Pure Evil company in the valley. You could get a job at Google and work on censoring search results for the Chinese government. I hear MSFT is in good graces these days with hacker types, unless you don't like the idea of supporting the Military Industrial Complex, and certainly they would never become as anti-competitive as they were in the 90s if they found themselves in a monopolistic position again. Or you could always work for any number of startups that sell hype, bullshit, and vaporware to get VCs to part with their money.
Really if you don't quit your Facebook job and #delete your account you're really no better than Mark Hitlerberg at this point. And you can't hide, we'll find you, and "deal" with you (I hear Twitter mobs are good for shaming these days).
Full disclosure: The company I work for does some small contracting work for Facebook, so I guess I'm on the list.
But why? Use of the platform is entirely voluntary. Beyond that, what are they doing besides targeting ads at people based on pretty basic info that those users (almost entirely) provided to Facebook of their own free will. Yeah, I know they were found recently to be using "shadow contact info" to target ads. But even that study seems fairly contrived- they had to upload an entire organization's private data without their consent just to prove the point they were making in the article. But even if we all agree that that's bad, so what? Okay, so if they stop using MFA data and shared contact data not necessarily shared by the users to target ads are they suddenly not evil? My guess is that most people would remain unconvinced.
I think there's some part of society that just hates the idea of advertising of all kinds. They think they should be able to move through life without having information foisted in front of them without their consent. That's a fine view, but the reality of our society is that it relies on businesses being able to sell and they do that largely by advertising to consumers. I also think a lot of the lament comes from the idea that using these platforms is a waste of time, which obviously is more of a personal value judgment call.
But above all this, I believe Facebook is hated because it's powerful. But it's powerful because people the world over use it and use it a lot. And that doesn't seem to be changing at all based on Facebook's last several earnings reports. People seem convinced that everyone should agree that Facebook and targeted advertising is evil and the use of the platform isn't worth the trade-offs. And yet people don't care. That stubborn fact. People just simply do not care about having their phone numbers, ages, political beliefs, genders and interests used to target ads at them. Lots of people can't wrap their minds around that fact- that not everyone is so concerned about using that info for ad targeting. Some fraction of the active FB user base probably does care- but not enough to delete the app and stop using it. "Your actions speak so loudly that I cannot hear what you say."
No it's not. Do you know Facebook creates shadow profiles of you by tracking your online activities?
Even if you discount that, what about when all your friends use Facebook? Then you are going to be forced into a situation where you either use Facebook or stay disconnected from you friends.
How would they do this if you never visit the site or download the app? If you're referring to the use of a pixel, compared to the full-fledge use of cookies used by other ad networks (the Gizmodo article from yesterday itself noticeably had ads all they way down the page based on sites I'd recently visited), surely that alone doesn't make FB evil relative to other advertisers?
what about when all your friends use Facebook? Then you are going to be forced into a situation where you either use Facebook or stay disconnected from you friends.
Why are you forced to use Facebook or be disconnected from your friends? You still have texts, email, Twitter and phones. I know a few people (admittedly not a lot) that refuse to use Facebook. They complain occasionally because they believe they are missing out on seeing photos or something, but nothing to the point where they are in the dark. I think the use of Facebook is a convenience and each person has to weigh their values against what they know Facebook does. But let's not elevate what Facebook does beyond the level of displaying ads for money and crossing ethical boundaries in some instances about what data they use to target those ads. Based on some comments you'd think they were proactively trying to destroy the world.
Your friends install the app on their device. They provide access to their contacts. FB slurps in all of that data. For every person in the user's contacts, FB compares that info to their records. They update connections where found, and start new records when not found. So they now know your name/email/phone number/physical address info depending on how detailed your friend's contact was about you. I haven't read anything if the user has added your picture in their contacts if that's something FB can read as well, so they could know what your face looks like. They are now tracking you, and you've at this point never joined FB. One day, you decide to join FB, and you're presented an option to connect with people FB thinks/knows you know. Oh, and now that you're a user, you don't get to see that info that they had been making on you before you signed up either.
To me, this is the most evil part of the scheme.
I'm definitely not giving Google a pass. I just didn't mention them ;-) Google Analytics, Fonts, whatever are just as bad, to me. I as an unsuspecting web user have my browser tracked from web developers using some free tools. I have no idea that it is occurring as a viewer. If a website puts in FB's like buttons, it is visible to me, and being in the know, I understand the repercussions of that site's decision. GA, Fonts, etc, are completely hidden from view. This is why I've used NoScript/Ghostery/etc throughout the years. It started with ads, but now I'm more concerned about these types of scripts.
Facebook SDK is used in more than 40% of mobile apps. Devs do it for analytics and ads. The feature is called Facebook Audience Network.
Being human is a morally brankrupt position. Accumulating wealth is a morally brankrupt pastime.
If you want to be a morally pure human, starve yourself -- that's the only way.
And again I say to you: It is easier for a camel to pass through the eye of a needle, than for a rich man to enter into the kingdom of heaven. --Matthew 19:24
As an adult, I heard someone talk about one of the gates in the wall to Jerusalem was named the "eye of the needle" because of its shape. If a camel was loaded up that exceeded a certain height, the camel could not fit through the gate. It was this situation that the biblical passage was supposedly referring. So as with most things, context really helped. </random_tangent>
I could be totally wrong, of course. Maybe they started naming holes in dilapidated walls that to bring tourists/pilgrims.
Did a quick google for pic examples; https://patmcinerney.wordpress.com/2014/06/30/the-church-of-...
But, I do know that working for companies that are funded by advertising makes me feel uneasy. I know because I've worked at one or two. I also know that the company I currently work for charges our customers for the services provided, and I know there's a consensual quid pro quo in every customer agreement. I also know we don't track our customers beyond their consent. I would hope if my company ever started doing that I'd speak up, and if things didn't change I would hope to have the fortitude to leave and continue to speak up outside of the company.
I also have no doubt that my day to day work is automating away someone's job, somewhere. Where someone used to make a good living, my code will run instead. People might not get overtly laid off because of my code, but there's no doubt people who use my company's services hire less people... it's kind of the point. I definitely think about the moral implications of that. Sometimes I'm not super comfortable with the hypothetical effects of my code over a long time period. Even if I contribute less than 1% to my company's service, if my company's service saves our customers on average the equivalent of one salary a year I've been responsible for the, at best, lack of creation of hundreds of jobs. In a different world someone fed a family, bought a house, and lived a life with one of those salaries, and now that opportunity is forever gone. Sometimes that's a hard thing to grapple with, and I really hope that I'm not contributing to negative economic trends that hurt a large majority of the world's populace while enriching myself. Chances are I probably am, though.
However I am certain of a couple things. The mass collection of billions of people's information is putting upon yourself an incredible responsibility that I find hard to justify. This wasn't by accident, this wasn't dumb luck, this was a purposeful attempt to amass and control power. This power isn't inherently good or evil itself, but even in a vacuum one has a right to be suspicious of such power. Fortunately we don't live in a vacuum and over time Facebook has shown itself to not be a good steward of the power it's created. I have no doubt there are plenty of ethical people that work at Facebook, and there are definitely plenty of ethical, smart people who work in Facebook infosec. I don't blame them for the data breach. I blame the creator of this Pandora's box, I blame those who willingly continue the abuse of this power, I blame those who purposefully profit off the abuse of this power, and I blame those who refuse to realize that they will not change an organization that refuses to change. Until the use of Facebook's data is no longer rewarded with massive amounts of money Facebook will continue to collect and sell this data. The incentives are very clearly aligned. Working there, no matter your intentions, cannot change these incentives. I'm not saying everyone at Facebook is evil, but if the hiring reputation is true they are too smart to not understand these things for much longer. Facebook will continue to be morally bankrupt until its power is abolished or democratized, and since a Pandora's box cannot be closed I'll settle for democratized.
Look friend. If I lose my job, you aren't going to do anything to augment my lack of income. You're not going to do anything to provide health insurance. And you're not going to do anything to help me find new employment.
There is no "We".
Here's an idea. If this topic is something that you feel is important, then perhaps you can set aside half your income to a general fund to help provide benefits for employees who leave facebook for morality reasons. Maybe if it gets enough momentum others will also provide funds. Given enough time perhaps this will help the "industry" to become more ethical.
You know what's not going to convince anyone to leave facebook now? Trying to setup some sort of ad hoc lynch mob to "deal" with people who are trying to pay a mortgage.
gots ta pay the bills yo.
That’s not how you change the world.
Facebook offers a service that people wants. A service that is not morally bad, if any connecting people is a positive thing.
The monetization of that business is what has proven problematic. As it is offered for free, it is people's privacy what is being sold.
Who should solve it?
The problem with "just don't work for Facebook" is that it shifts the responsibility to policy companies from governments, that have the power and resources, to individuals that have not. Of course individuals have a moral responsibility, and that is why whistle-blowers are so important in all industries.
But it is the government that has the responsibility to assure that the industry remains a positive force in the country. Tech giants are a new phenomenon. Regulations have not still catch up with its problems. But governments around the globe need to shape up and get up to the challenge of letting companies offer services that people wants and needs while minimizing the harmful impact that some business models have.
If you do not like the ethics of the company that you work for, change jobs. You are going to be happier. But that is not going to make the company more ethical, if any it is going to be less ethical as people that worries about such things move out.
People also want heroin. That doesn't mean it's actually a positive thing in people's lives. If anything the evidence is mounting that it is negative, e.g.: https://hbr.org/2017/04/a-new-more-rigorous-study-confirms-t...
I mostly agree with the rest of your post, though. I believe it's possible, though very rare, to work at Facebook and have a positive impact.
And there's definitely a total mismatch between regulation and the realities of big tech companies. I'm skeptical of government regulation solving privacy issues specifically (I think that stems more from a widespread cultural misunderstanding or unawareness of privacy concerns) but maybe it's needed for other ways these companies are negatively impacting the world.
Do you also suggest that someone should no longer be friends with anyone who uses that Facebook platform and is 'the product'? What about that? That is support as well. Right?
With as big as Facebook is, a lot of people (the majority?) are not directly connected to all the crap you see in the news. Sure, you can say they contribute to it, and you'd be totally correct...but Im sure what they see is a bunch of smart people working on cool technology with a good salary and free lunch.
So yeah, its probably "morally corrupt", no denying it, but so's the majority of companies that hire more than 50 people, one way or another. You have to work somewhere.
Then you have people who are trying to do the right thing from the inside. I knew someone who worked for Google purely to try and change its culture. The paycheck probably didn't hurt. There's a lot of these people.
If you look outside the Bay Area, I’m sure you will find people who desperate enough and would sacrifice any sense of morals they have for a $100k job.
It’s as simple as that.
The issue is that there is not a 'universal' set of morals for tech people, especially as tech has started to become a more accessible profession. I'll agree, personally, that the ethics of working with FB may have issues, large ones at that (Rohingya comes to mind). But, and correct me if I am wrong, are you are advocating for a medical board/ the bar / ASME / professional engineer type of organization? Generally, those organizational types also have ethical issues too, but they tend to be a lot more nuanced and not as glaring.
From the press release[0] posted elsewhere in this thread
Now it's 28th, meaning that they've disclosed the breach within 72 hours, as requested by at least one regulation (Article 33 of the GDPR).
That's clearly not even half a week.
Fun times.
1) I was logged out randomly of messenger on my iPhone for the first time ever, i think a week ago. Like messenger completely reset for no reason, and i had to put in my cellphone number again. I don't know if this has to do with the breach. Also i received several snapchat 2-factor codes without requesting them on my cellphone.
2) If the message history has leaked it will absolutely unimaginable consequences for many people, myself included. Nothing incriminating but enough to make me paranoid and make loads of people shameful, loose their partners, loose their friends, loose their employment, have their reputation tainted forever. It's absolutely insane if it shows up in an indexed fashion somewhere. Black mirror is becoming real.
3) For the first time i am actually thinking about seriously migrating from "all corporate services" - and only searching through TOR through VPN on duckduckgo if i have to search for something personal.
4) I will probably forget all about migrating to privacy oriented services in a few days.
5) Living these days can make me slightly paranoid, a new feeling i guess, that has not been experienced by most humans before. The feeling of being watched constantly, of being potentially revealed in some vague fashion. A strange and unhealthy feeling for sure, no matter how banal your life probably is to the rest of the world. Now everyone knows how it is to live in eastern germany under STASI, or like in Iraq or Syria before the breakdowns, - just potentially worse if these leaks get real.
I think "privacy" is a basic human necessity right at the bottom of the Maslow pyramid even though a common trope in pop culture is that privacy is a new phenomenon.
I think that is utterly wrong, a tribe back in the days was like an organism, an extension of the self, that also required privacy from other tribes.
Regardless of who requires it, right from the earliest, animals and humans have been hiding them selves both from predators and from their prey. Later the mammalian brain extended this need for privacy as a basic necessity in the interaction in basic civilisation, from politics, to civic life, in family life and in war. It's all a game of showing and telling.
This vague fuzzy paranoid panopticon feeling is devastating.
6) In a few years neural nets will trawl the net and run stylometric analysis - everyone will be ranked and have complete psychological profiles created, all their whereabouts will be mapped completely by inference, you will know everything everyone has done for the last 20 years in complete detail including their desires and emotions. Lol
I had to log back in and so did 6 out of the 8 people I've asked so far. Purely anecdotal, but it just seem unusual that if only 5% of accounts are affected that so many of the people I talk to would be potentially affected.
What an ass. It's simply amazing that he makes a statement like that when Congress hasn't bothered to "stand up" to Equifax, Experian and TransUnion yet. Not once. Maybe look into protecting privacy and security of people period, FB and social media are but one component of that.
You have facebook being this huge target for attacks and you combine that with 10,000 engineers with likely not a lot of security training.
Even a single point of failure could compromise the whole site, what are the chances that no one makes a mistake?
Its like the bigger your company grows while still having a single product, the higher the probability something like this happens...
Or Instagram has great messaging, and if you’re brave oculus can do great VR chat!
* CSO * VP of security * CEO/CTO
https://www.theverge.com/2018/8/1/17640852/facebook-cso-alex...
"But for certain types of posts on users' timelines, such as prompts to post happy birthday greetings, the video uploader function was shown as active."
I wonder if FB reset all political buyer accounts too just to be safe?
Edit: Same on my PC. Still logged on.
My frist thought was that I must've had turned it off at some point, but I just checked and that isn't the case.
Some users are reporting that they are unable to post today’s
big story about a security breach affecting 50 million
Facebook users. The issue appears to only affect particular
stories from certain outlets, at this time one story from The
Guardian and one from the Associated Press, both reputable
press outlets.
...
The situation is another example of Facebook’s automated
content flagging tools marking legitimate content as
illegitimate, in this case calling it spam.
https://techcrunch.com/2018/09/28/facebook-blocks-guardian-s...They may have fixed the "bug" now.
You’re joking, right?
do you have a good link for this?
Remember, this is a company headed by someone who captured failed login passwords and used them to hack the email accounts of a journalist writing an anti-FB article. Yes, that was a decade ago, but that is a serious, criminal low.
http://www.theamericanmirror.com/flashback-zuckerberg-used-l...
'Facebook is clearly aware that losing its chief security officer and dissolving its dedicated security team, in the middle of all that’s going on, is not a great look. So many of the company’s statements today are clearly designed to address obvious concerns that arise.
“We expect to be judged on what we do to protect people’s security, not whether we have someone with a certain title,” a spokesperson said. In another statement, Facebook said it is “investing heavily in security to address new types of threats” and that its new security structure has “helped us do more to keep people safe.”'
Source: https://www.theverge.com/2018/8/1/17640852/facebook-cso-alex...
Essential infrastructure describes "assets that are essential for the functioning of a society and economy" [1]. Not things that can cause a lot of damage. Bombers aren't essential infrastructure. Facebook is non-essential.
Nuclear missiles themselves aren't critical infrastructure, but you better bet the launch systems, and specifically the security of those systems, are utterly critical to society's continued functioning as we know it.
If you destroy Facebook, Google+ gets some more users.
Edit: people take my comment to mean it won't be a big deal. It will be. However, not on the same scale of taking out the power grid, or the water system, which would lead to hundreds or thousands of deaths. Facebook is not critical infrastructure.
With that said, is it perhaps possible that some people might view this as subtly distinct from power plants, hospitals, roads, and ISPs? Those are what are generally considered "critical infrastructure".
I understand the point that you don't need facebook the way you need the ability to feed the people in the cities (and thus need roads and power plants). If facebook disappears, life will go on. But as long as it exists, control of it is critical like control over power plants.
In the sense that it's an immediate need for the continued basic functioning of the state, it's possible that there may be some distinctions that could be drawn. Some might opine that these are the distinctions that matter for the designation of what is and isn't critical infrastructure.
As that comes into place and use, how many companies are going to be basing their pricing -- their entire product offers, in light of the availability of this information, this "score" (and all the categorization behind it) -- upon it?
Bingo. Critical infrastructure. (Like it or not, for some of us.)
[0] https://science.ksc.nasa.gov/shuttle/missions/51-l/docs/roge...
FWIW though, investors can be fooled.
There is lot of misinformation about the Stamos debacle on all sides.
A true statement is that Facebook's security teams have been shifted around in several reorgs. A false statement is that Facebook has dissolved its security teams. The latter is a mischaracterization of the former, because while some security staff have left Facebook for a variety of reasons, the company is not deliberately reducing its security staff nor encouraging their departure. It still employs a huge number of engineers specializing in every major domain of information security.
If you'd like evidence that Facebook is expanding its security presence, you can take a look at its careers portal. It's aggressively hiring security staff in satellite offices that previously weren't focus areas for security engineering.
In my opinion, Alex Stamos' company memo gives a clearer picture of what's happened in Facebook's security org recently.[1] You should read that in addition to media reports.
______________
1. https://www.buzzfeednews.com/article/ryanmac/facebook-alex-s...
[1] https://www.c-span.org/video/?451963-1/google-apple-amazon-t...
This is code for "this is much worse than we are telling you now, we just can't reveal it all at once".
I dislike Facebook as much as the next person.. but I have to say, Facebook Ads are a goldmine if you know what you're doing. It's not going to be that way forever.
https://Qbix.com (see the video)
On the other hand, I feel like I’m shamelessly promoting/shilling my own company.
How to do it in a classy way? I really believe that there is a problem people are not recognizing enough to do something about it (Diaspora and Mastodon and Solid are exceptions).
And I spent the last 7 years and $700K of our company’s profits solving it. So it’s now solved. If Mastodon is “a decentralized Twitter creation kit” where you own your own data, then Qbix is a “decentralized Facebook creation kit” where you can assemble social apps from a growing marketplace of reusable components, some of which don’t exist anywhere. Here for example is a Group Rides plugin that basically makes a social Uber, and ANYONE can have it on their OWN social network:
OK, but we are perfectionists and are spending months polishing “the other 90%” so it’s not a flop when we release it to the public to create their own facebooks. We need really clean onboarding and measure engagement metrics and fix bugs etc. It took 7 years thus far.
For example this was last year, we are way more advanced now:
So, advice would be appreciated from people who have successfully done before. Maybe contact me (qbix.com/about has my email link). How do we get the story out there that Qbix is being built to FIX the underlying root problem of decentralizing social networking, so people’s data isn’t in one place?
Please if you have some knowledge about this, take a look at the above videos and let us know what advice you have to get stories actually published.
PS: one more thing, we managed to get tons of inadvertent press back in March including BBC and Newsweek, which you will find if you search for “calendar mining” or “qbix calendar”. BUT when I reached back out to thise journalists to cover an actual story of Qbix is actually doing, none of them replied. Many of them just want to break the sensational controversy because that brings notoriety. How do you make them write about SOLUTIONS to problems?
You only get one chance to make a first impression. I'm afraid the first impression I got means I'm unlikely to return. I suspect the same applies to all those who took a look in March.
What makes it dated specifically? Versus let’s say https://joinmastodon.org/
Also did you visit from a mobile phone or desktop?
3D strong blue and green spinning globe. 3D logo, hard (high contrast?) RGB values. Child's drawing header looks like a hospital. Mission statement not at all aligned with what your comment says. Empowering people page, weird lego photoshop. More strong RGB icons.
>We build apps for all kinds of communities.
I assume this is an app building consultancy from this statement. Nothing about decentralization. Way too much text on the page (for people like me who cbf to read). Are you trying to get people to download your group / calendar app or build apps on qbix? Choose a goal and optimize your copy for it.
Mastadon - Single page layout. Clear missions statement (Social networking, back in your hands). Flat (material?) icons. Single, fixed width column of text. Lower contrast color scheme.
Good news, you're not just imagining things. It feels exactly like that to the readers as well.
Now you have 50 million people's data for sale. Are you in that 50 million? You don't know or you will never know.
Connected incidents - British Airways Data Leak, Equifax, Uber Data Theft Cover Up, Air Canada, T-Mobile, Dixons Carphone......how many such. All of them soon will be available for sale, with no one to blame for.
I don't think there has been much stopping these companies selling the data up to this point. That's been the issue with Facebook and others, they have happily sold peoples data with little legal protection for the people whose data they sell. There is no crime in just selling the data within the US so your theory doesn't hold up.
Never attribute to conspiracy that which is adequately explained by incompetence.
BTW there are people who need data, not just people within US.
https://www.nytimes.com/2018/09/26/world/asia/trump-china-el... "Mr. Trump did not suggest that China’s behavior was on the scale of Russia’s sophisticated campaign of manipulating social media and the release of hacked emails during the 2016 presidential election."
https://www.rappler.com/technology/news/211276-facebook-twit... Sen. Richard Burr, R-N.C., the chairman of the Senate Intelligence Committee, opened the hearing by citing the promise of social media before adding, "But we've also learned about how vulnerable social media is to corruption and misuse. The very worst examples of this are absolutely chilling and a threat to our democracy."
Already, Russia and Iran have sought to interfere by passing themselves off as American groups or people to shape the views of American voters, say lawmakers and technology executives. Facebook, Google and Twitter together took down hundreds of accounts tied to the two countries last month, a move that prompted Burr to open the hearing Wednesday by expressing fear that "more foreign countries are now trying to use your products to shape and manipulate American political sentiment as an instrument of statecraft."
Cambridge Analytica - Worked with some Indian Political Parties or the Government itself too.
Lawmakers aren't limited in the questions they can pose Facebook and Twitter. Sandberg's boss, Facebook CEO Mark Zuckerberg, faced questions in April hearings that extended far beyond the reason the hearing was called: Facebook's entanglement with Cambridge Analytica, a political consultancy that improperly accessed 87 million users' personal information. Sandberg could also face questions on Cambridge Analytica.
You should try and change that. Best to deal with the actual verifiable ills of the world, without causing misdirection and making up new ones
https://www.telegraph.co.uk/technology/2017/07/03/googles-de...
“Facebook Is Giving Advertisers Access to Your Shadow Contact Information”
Source: https://gizmodo.com/facebook-is-giving-advertisers-access-to...