Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.
Facebook surely must be heavily fined and regulated for their misbehavior, because to fail to keep Facebook data safe is to put lives at risk.
So would you like a fine for your bugs? And note that contrary to other professions, software development doesn’t have generally agreed recipes for building bug-free software, so was that really negligence? Was it malpractice?
Being fined for a contribution to an OSS project would be terrible, wouldn’t it? And no, the size of the company doesn’t and shouldn’t matter in the eyes of the law, only the impact.
Also people uploading stuff on the Internet should really expect a best effort privacy. If you expect secrecy, then uploading shit on a platform meant for sharing is pretty dumb.
Note that I will blame Facebook for willful privacy violations. And I hope to see them suffer under GDPR. But a bug doesn’t fall in the same category.
How about a blog commenting system that leaks emails due to a bug, something like Isso:
Basically I don't like these arguments because it's about the company's size. Facebook should be punished because they are big, have a lot of data and we don't like them, right? No matter how you look at it, it's a Pandora's box.
Is this not how it works for every other industry? Up until the 2008 bank bailouts, that is.
So what should the penalty be for a 14 year old that contributes a bug into a project like Mastodon or OpenSSH or whatever, which then leaks the data of tens of millions of people?
All this would do is to have a chilling effect on the industry such that only big companies like Facebook will be able to develop critical software, due to being able to afford it. And yes, this happens in all the industries you're talking about. And it did not stop the market from crashing, it did not stop malpractice.
Also this regulation will probably not stop Facebook from lawfully violating privacy.
1. consumers want it
2. governments want it
The only thing regulation will accomplish is that only companies like Facebook will be able to do it. Yeah, big win.
I'm not a fan of the overregulation of industries like aviation, but consumer software has gone too far in the other direction and is long overdue for an adjustment.
We deserve it. Though of course others deserve it more.
The realm problem is the inevitable regulatory capture that occurs in every market with even an ounce of complexity.
Given the number of high profile breaches we see every month, I definitely think we're due for some consequences.
Does it ... kill people? Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death?
Yeah, regulation there definitely helped /s
Facebook asked users to upload nude photos. what if those get leaked and users commit suicide because of it? Would you (partially) blame facebook for their death?
> Does it enforce bad policies like the healthcare industry did for the past couple of decades, causing an epidemic of obesity, diabetes and heart disease, which are the top causes of death?
Genuine question but what policies are the reasons for the epidemic of the three death causes you just mentioned?
I missed that one. By now even lay people should know that's a recipe for disaster.
No, because doing nude pictures of yourself and then distributing them, no matter where, is just stupid. Parents should educate their kids to know better, or seek counseling if that mistake was made.
You're also talking of a hypothetical situation. When planes crash, people die, guaranteed. And yearly there are more than 100 plane crashes.
> "Genuine question but what policies are the reasons for the epidemic of the three death causes you just mentioned?"
The recommendation for a diet high in sugar, high in wheat and other grains, high in vegetable oils / polyunsaturated fats (e.g. Omega-6), low in saturated fat, low in dietary cholesterol, low in salt.
Children were fed in schools, diets were set in hospitals, foods where preferred in supermarkets according to these guidelines. That's not a debate I want to get into though.
Considering this article is about Facebook leaking 6+million photos to third parties, including photos that were uploaded but never shared, it's well within the realm of possibility that at least one of those millions of photos was a nude. In fact, I'd bet there were quite a few nudes in the leaked set. It only takes one more step to turn that hypothetical of yours into a reality.
BTW, how do you think anti-vaccination, healthy at any size, and minor attracted people ideas became popular? I specify those only because they are particularly heinous, but if you want official policy, just look at literally any election, though the 2016 US presidential election and the brexit referendum are the standouts in terms of memes.
I haven't seen any response yet. Does Facebook kill people, yes or no, it's a simple answer.
> "wasting peoples' time and/or money at scale is just as bad"
What?
> "how do you think anti-vaccination, healthy at any size, and minor attracted people ideas became popular?"
In that regard all Facebook does is giving people the tools to exercise their freedom of speech, possibly with an algorithm for that feed whose effects they couldn't predict, because it was built to maximize profits, not sanity ... and that will never be illegal ;-)
I understand some of the arguments that Facebook encouraged fake news, however speaking as somebody that was born in communism, I can tell you that fake news isn't new, it happened before WW I, it happened before WW II, it happened at the east of the Iron Curtain (at least) during the Cold War, and it happened just as well afterwards.
In my country distributing news via Facebook isn't even that popular, yet fake news is flourishing ... on TV. People are always looking for a scapegoat, for an easy answer, for an easy fix. It's only natural, but it doesn't make it right.
No, I don't think Facebook is to blame for fake news, even if it might have contributed. Facebook can't be responsible for the poor education that people are given.
I'm grateful I didn't have to live through this as a teenager, it's a shark pool.
So how long do we keep pretending that allowing this to go on is a viable way forward?
[0] As in: Every rule was included because someone (nearly) died because of it not being there before.
Absolutely nothing wrong with that. If a small trucking company has a driver that speeds, that driver gets fined the same way a driver for a large trucking company does.
> Of course the fines have to be proportional to the number of affected users.
Of course.
The recipe for how a driver should not go over the speed limit is well known. Nowadays you even have the GPS apps alerting you and many trucks get monitored in real time from the dispatch center, drivers risking to be fired if not exactly on schedule.
Most software projects are greenfield ... people reuse previous work when available and for a good price, but all custom changes are greenfield.
Do you really think that the guy responsible for Heartbleed [1] was aware when he introduced that bug, just like a truck driver going over the speed limit?
It's really not the same thing, lets not pretend that it is and regulation in this field would have a chilling effect for open source or startups, because only big companies like Facebook will still be willing to develop critical software, which is definitely not what we want.
You're right. Look, software is complicated, and there's no way, yet, to make it bug free for any meaningful system. I get that. But at the same time, let's stop calling ourselves engineers if we keep hiding behind 'bugs happen'. We need to be a LOT more responsible than that. Does that mean regulation? If we keep going down the road we're on, yes. Because I gotta be honest, I'm tired of hearing, 'bugs happen' and I, the consumer, am the one who suffers.
I’ve worked in engineering roles where law made me potentially criminally liable for negligent handling of certain data. We took things more seriously than Facebook.
Not if your contribution causes harm. A fine would be a more than welcome addition to consumer protections.
Funny, because community-driven open source is the only hope for replacing Facebook with something that is privacy oriented.
However, there needs to be SOME distinction beyond intent, which is often impossible to discern.
I would agree regarding small companies, but I wouldn't put oss developers in the same boat, fining the entity that provides a service makes more sense. It doesn't matter if that service relies on OSS or not.
It's the company providing the service to the consumer who is responsible to vet the final product.
A OSS developer has no idea if her/his code is going to be used by a gaming app or by NASA for mission critical stuff and shouldn't be made responsible if a bug in the oss project caused a rocket failure.
Similarly a construction company providing wood (and that company isn't making any false claims about the level of quality): it should not be the company's fault if someone decides to use that wood for a bridge where concrete is needed. The bridge builder is responsible of picking a good material.
I agree with your post, but I tend to think of facebook's users as providing the product (their attention). If the consumer is a company buying advertising, then where's facebook's motivation to be careful with a user's "private" data?
Under GDPR, it actually doesn’t matter if you charge money for your product or not. If you process personal data, you’re responsible for it. This also applies to private people with no commercial interest who start to gather data from strangers (in exchange for some service or whatever).
Edit: The motivation should’ve been there from the beginning, if only for ethical reasons. Now the motivation is probably enforced by hefty fines.
Facebook‘s product is a platform. It can’t exist without users, and it can’t exist without advertisers (presumably).
Since both end users and advertisers are part of the product, the data of all of them needs to be protected. It doesn’t matter who the paying party is.
If you say I can avoid penalities by saying my services are "as is", what stops Facebook from doing the same thing?
Obviously, it’s still not clear for many people: All services that process personal data became more regulated through GDPR.
And yes, if any service loses its customers data, there will be a fine. The fine depends on many factors. And yes, even Mastodon.social or Gitlab.com (the service, not the OSS). The advantage of these platforms is that they actually don’t process that much personal data.
Behind any service is a legal entity that asks people for their data, to provide a service. These legal entities are subject to the same laws.
However, since the GDPR apparently determines fines on a case-by-case basis, they might give a low or no fine at all, if the service is non-commercial and had no intention to collect user data for commercial purposes. But the law still applies.
If you put a web service online that handles personal data, you must make sure to keep that data safe. It doesn’t matter if your service is free or not.
Turn this around: just because you as a user signed up for a non-commercial free service like Mastodon.social (the service, not the OSS you can host yourself), you wouldn’t want the admins of Mastodon.social to mess around with your data, no?
The post I responded to, I think, made a very good point about responsibility being on service providers rather than OSS contributors.
However, the wording about "providing the service to the consumer" seems a bit problematic; it leaves the door open to discussions about who the consumer is, and thereby who is accountable. I'm glad you brought up GPDR - it seems to take the right approach, with regards to protecting personal data no matter who's holding it.
That said, you and I can agree that FB sucks, and delete our accounts. It is up to other people whether they follow suit.