Facebook 'unintentionally uploaded' 1.5M people's email contacts without consent
businessinsider.com
businessinsider.com
At $40,000 per user per day [1], even at just one day of violation, that's a $60 billion fine FB should be liable for. "Under the settlement, Facebook agreed to get consent from users before sharing their data with third parties," so this seems to be EXACTLY in violation of that agreement.
[1] https://www.cnet.com/news/facebooks-ftc-consent-decree-deal-...
*Edit: on second thought, it should be even higher, as each of the 1.5M users had multiple contacts uploaded. So, for example, let's say 1 user had 150 contacts who were not part of the other 1.5M users who had contacts uploaded. That alone should be a violation of the consent rights of those 150 people, so $6 million per day. If every one of the 1.5 million people had, on average, 150 contacts exclusive of the other 1.5 million people who had contact info uploaded, that's a $9 trillion liability for one day of violation.
The FTC has been toothless on this for quite some time now, so I'm expecting no significant action as FB lawyers will defend that no one had data shared with "third parties," technically. Well, shouldn't my contact info shared by a friend with FB be a consent violation as FB is a "third party" from my perspective?
However, what Facebook did is far worse than violating that agreement. Facebook gained accessed to user data on third party systems, to which they should never have had access. They gained this (unauthorized) access (at best without clear consent) on a false pretense (disguising as security related requirement). Then they imported user data, with no relationship to their stated goal/requirement, into their platform.
Associative contact information is a highly valuable commodity to any company involved in marketing and social media. I've seen a lot of people argue how this could have been the result of a laps of oversight, but that sounds like arguing how a gem stone trader might have "accidentally" stolen a large quantity of rough gem stones, while claiming to not have known their value. Even if theoretically possible, it's extremely unlikely that nobody within Facebook knew/realized the value of this data.
Either way, Facebook gained access to highly valuable assets. Even in the unlikely event of sincere lack of oversight, it would demonstrate a level of incompetence that warrants them to still be held criminally liable.
Moreover, Facebook might actually have outright violated the Computer Fraud and Abuse Act (CFAA), in particular the "access in excess of authorization" part, but I'm not sure.
In December 2009, Facebook changed its website so certain information that users may have designated as private – such as their Friends List – was made public.
They didn't warn users that this change was coming, or get their approval in advance.
Facebook represented that third-party apps that users' installed would have access only to user information that they needed to operate. In fact, the apps could access nearly all of users' personal data – data the apps didn't need.
Facebook told users they could restrict sharing of data to limited audiences – for example with "Friends Only." In fact, selecting "Friends Only" did not prevent their information from being shared with third-party applications their friends used.
Facebook had a "Verified Apps" program & claimed it certified the security of participating apps. It didn't.
Facebook promised users that it would not share their personal information with advertisers. It did.
Facebook claimed that when users deactivated or deleted their accounts, their photos and videos would be inaccessible. But Facebook allowed access to the content, even after users had deactivated or deleted their accounts.
Facebook claimed that it complied with the U.S.- EU Safe Harbor Framework that governs data transfer between the U.S. and the European Union. It didn't.
While you can abstain, it creates all kinds of awkwardness that I'm not willing to deal with currently.
I know one FTC employee who worked on the 2011 FTC/FB settlement (which required FB to obtain independent 3rd party audits certifying their privacy program for 20 years...never mind the subsequent violations and settlements) is now “head of privacy” for a certain social networking company.
1. It occurred before certain important facts were known, and couldn’t happen again
2. It was an unfortunate lapse by an individual, which has now been dealt with under internal disciplinary procedures.
3. There is a perfectly satisfactory explanation for everything, but security forbids its disclosure.
4. It has only gone wrong because of heavy cuts in staff and budget which have stretched supervisory resources beyond their limits.
5. it was a worthwhile experiment, now abandoned, but not before it had provided much valuable data and considerable employment.
https://www.youtube.com/watch?v=zvNw0P5ZMbA
Especially since it comes up again in a later episode, with Humphrey discussing the ramifications of civil servants conceding the reigns of power to ministers who'd be under pressure to carry out voter demands.
Humphrey: "How would you feel if Radio 1 played pop music 24 hours a day? Or if they took the culture programmes off of television?"
B responds "I don't know, I never watch them"
Humphrey says "Well neither do I, but it's vital to know that they're there!"
While it was satire, the was a lot in it that could very well have been reality.
My primary criticism is that it didn't actually satirise the government's ideology or policies -- the main criticism was of politicans, civil servants, and interest groups like unions. These were actually in line with Thatcher's ideals and policies at the time (it's therefore unsurprising she said it was her favourite show).
I'm not trying to blunt any of their wit, just point out that (like most works) it had its shortcomings. It's unlikely the BBC would've aired it if it had just been a scathing ridicule of the PM at the time.
The workers (and thus the unions) were opposing government policies that were hurting them. Funnily enough (though unsurprisingly), strike rates as well as union membership fell under Thatcher because of her union reforms (which removed much of their bargaining power) -- and so the commonly held view of daily strikes in the 1980s (something Yes Minister capitalises on) isn't really an accurate portrayal.
By laying criticism on one and not the other, Yes Minister showed their Thatcher bias. And it's not at all a stretch to say they had a Thatcher bias -- Thatcher herself said that Yes Minister was her favourite show. So while Yes Minister was very heavily critical of the civil service, they weren't fundamentally critical of the views of the government. Thatcher was very strong on civil service reform too.
(4) knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value
https://www.law.cornell.edu/uscode/text/18/1030
A criminal investigation into whether or not this was really accidental would be entirely warranted here. If there was intent to access this information without authorized access that is criminal.
I don't understand this. Claiming that something is an accident and not intentional usually isn't much of an excuse where it comes to the criminal acts.
>knowingly and with intent
Generally, civil law is better suited for this sort of thing, no matter how good a pitchfork feels in your hand. As but one of the reasons, the required standard of proof is much lower.
> Whoever ... intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer ... shall be punished as provided in subsection (c) of this section.
(The definition of "protected computer" encompasses any computer that is "used in or affecting interstate or foreign commerce or communication".)
Why? Nobody lost their contacts, so what’s the $ amount it cost them? Facebook claims they’re deleting them. If that’s true, then Facebook isn’t gaining from the contacts. If users don’t lose anything and if Facebook doesn’t gain anything, what is the monetary loss?
> especially at 150m user scale
Where’s that number coming from? The article talks about 1.5 million users.
> We could have all banded together and sold them, had Facebook not stolen them.
So while it’s entirely true that contacts should never be copied without consent, and that’s exactly what happened, I guess don’t forget that these users consciously gave Facebook their passwords. No matter how much I trust what someone says they’ll do, my email account password gives access to everything in my email account, I’ve always thought it was a terrible terrible idea to ever do it when connecting services together, for this very reason. I’m saying it’s partly the users responsibility, and the outcome here is predictable, because it has been predicted before by many people.
BTW, nothing stopping you from banding together and selling email addresses now, if you think it’s a good idea... the blip with Facebook is not in any way preventing that from happening.
There is a lot of legal precedence about social engineering and how to prosecute it, this would completely fall under fraud. If I ask someone for their password to perform some service and they then I copy all of their data, that is a crime regardless of how stupid they are.
This really doesn't matter at all in a case of fraud if you gave the password willingly, it is under false pretense. If someone asks me to give them something so that they can provide a service or take those things as an investment. I willingly give them those things yes, but we have a written, verbal, or implied contract that they will do and will not do certain things with that information. Failure to follow our agreement and instead robbing me is a crime.
Opportunity cost? If Facebook has these contacts now, then their third parties have them, so those contacts are no longer as valuable, if valuable at all.
> Where’s that number coming from? The article talks about 1.5 million users.
My bad, added two orders of magnitude by accident. I knew something was off there. Thanks for the correction.
We don't know that's true, I would be cautious about making assumptions. But, even if we assume it is, opportunity cost isn't equivalent to financial loss, so we can't say people lost money they weren't already making.
Anyway, I don't think email lists being sold has prevented email addresses from appearing in other lists. It's clear to me that nobody is tracking the value of my email address because marketers keep buying it over and over.
That said, from my point of view, I don't like the idea of selling my own email address or trying to extract money from it. I don't want that, and I don't agree with the idea of selling my privacy in order to battle my concerns about Facebook taking and/or selling my privacy. The selling of my privacy is the very thing I don't want to have happen.
Privacy is not a monetary value for me, it's something I value having, not something I value selling. I don't want it to be subject to capitalist thinking and market analysis.
What’s needed is serious privacy legislation, not creative reinterpretation.
Of course we need actual fundamental privacy protection.
The fact that Facebook put a system in place to obtain these contact lists is evidence on its own of their value, but that value could also be quantified without much difficulty.
The only real question is: was dropping the consent form without removing the feature an honest mistake or was it done because somebody decided it would result in a lower bounce rate and thus more money for Facebook.
Note this is not a state law as quoted, but it's the USC
(If Facebook changed its name to Lulzsec2.0 of course the FBI would be very interested in the situation.)
And while the previous commenter quoted the part of the CFAA that mentions fraud, fraud isn't necessary to violate the CFAA. All you need to do is exceed authorized access to any internet-connected computer. Is there any doubt that Facebook has admitted to doing that?
It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it.
For the FB employees reading this: what is your tipping point? Would you say no to that assignment?
- developer A is tasked to create the prompt to ask for username and password of the email account
- developer B is tasked to call some API to upload contacts from email account
- developer C is tasked to bind two functionalities.
Now replace developers with teams and you see how simple is for the average developer to underestimate the scope and the ethical bounds of a given task.
It's not news at this point to anyone working at FB what their leadership is engaged in, and what their work is being used to accomplish.
Perhaps several years ago you could claim some kind of ignorance.
That's no longer the case. You know who you work for. Own it.
Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not.
But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fault”. That isn’t a bad plan.
Indeed.
You’re getting paid 2x market salary (“market” here being non-Facebook and non-Google, which isn’t any better) and delivering services to people who voluntarily sign up ro them... I mean there are worse jobs in the world.
“That’s a really dick of an idea and I’m pretty sure it’s illegal. Exactly how illegal, I’m not sure. But I know illegal to some degree.”
“You live in a shit apartment because housing prices are stupid and makes your salary meaningless in this town. Here’s a wheelbarrow full of hundreds and we all agree it was an accident.”
“When do you need it by?”
Unfortunately, this ha-ha-only-serious joke is least several decades old.
Nobody will test this? No developer in team C will consider what they're doing?
return true;
Return true is tested to still work.
But seriously. There’s no accident in what happened. This is Facebook. Anyone who thinks Facebook isn’t morally corrupt probably also says “What do you mean Stalin wasn’t a pacifist?”
When FB stops giving them a check.
At least that has been my experience watching programmers at other companies. Unless ethically bound by regulation and law, few people seem to have ethics.
Or maybe their set of ethics simply differs from yours. It is very subjective after all
Methinks that was what the OP was asking -- what is the tipping point ? Having differing ethics is fine but one can't just lean on that as a crutch when one has none.
> Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases.
It doesn't take a conspiracy to understand how a bug like that could happen.
At some point, it goes from "the occasional bug" to negligence at best, and hostility at worst.
When every public-facing thing you build is centered on hoovering up data, you're going to have two broad classes of errors. Hoovering up too little data, which doesn't hit the news, and hoovering up too much, which does.
That said, when your "errors" directly line your pockets, you're not entitled to the benefit of the doubt.
That’s the initial asshole maneuver. There’s no excuse for Facebook to need that. Period.
2. CollectUserContacts(email, username, password);
It’s pretty hard for me to imagine that there’s some other function that just happens to coincide with accessing different email servers and collect past emails to collect the email addresses.
It was deliberate because of the work involved. The only investigators that think it’s accidental probably believe the internet is a small black box guarded by the “Internet wizards”.
It is difficult to get a man to understand something, when his salary depends on his not understanding it.
-- Upton Sinclair
> A Facebook spokesperson also told Gizmodo that a screenshot of the original opt-in prompt was not available.
I'm not a conspiracy theorist but if you're trying to claim you cannot capture a screenshot from any release meant to be shipped out, either you're crap at release management or are full of shit. Which one is it?
Also, even if we were to suspend logic and belive this was a bug, what's FB doing to correct it? Are they deleting all uploaded contacts and going to request for consent again?
FB is a cesspit. Get out of the company if you work there and get out of the platform in any case.
That doesn't strike me as especially unlikely, especially for a specific branch of the app codebase that would likely only operate with a huge number of other co-dependent codebases for backend systems that no longer exist.
With six months to recover code and build a non-live environment with all the dependencies could it be done? Sure. But that's not really within the scope of a journalist request.
There is a good chance that they didn’t know how their work would eventually be used. That’s the problem with big companies. Most people are far away from seeing the consequences of their work.
I have an open ended question aimed mainly towards founders. Would you have any issues in hiring a candidate with Facebook on their resume?
It also takes extra work to ask consent. You build it. You don't notice that your confirmation screen fails to trigger. You've just unintentionally uploaded a bunch of data without consent, when your intention was to do it with consent.
It's still pretty darn negligent, but it's easy to see how it could be done unintentionally.
Not really. Facebook is a bunch of autonomous services (registration, access, tracking, activities, etc.) accessing shared databases (chat logs, activities, media uploads, etc.) with some kind of automatic implicit and explicit ACL in place. The suggestion/contact service got access to data provided through the email-not-working-with-oauth-so-let-us-use-automatic-token-delivery-and-confirmation-by-accessing-user-emails because it was told a new source of contacts were available for those users. So, not a straight path.
Accident/Blunder > Evil.
Now. GDPR ? GDPR. And because of GDPR those things aren't supposed to happen in Europe.
As long as you don't see the evil being literally done ie in form or row of inmates being sent to gas chambers, there are almost endless ways to persuade yourself that all is actually OK and fine.
It doesn't make sense for people to trust the service at all unless you assume one of two things:
1 - Despite all the outrage on hackernews, and the NWT stories, our neighbours down the street and family members still don't know how Facebook works or what is done with their data
2 - They don't care about their data privacy. I've heard this claim many times, but the people saying it often change their minds when they read more news stories. I really do think people have trouble assuming the worst about the intentions of others and are inclined to be trusting.
edit: clarification
Its like that with skimming, lock picking, server security, infrastructure security, basically everything security related.
"People don't care about a problem initially, then when it becomes graver they start to care"
So normal, expected behaviour?
I'm going mental over the explosion of televisions in the last half decade which identify and report any content you watch on the TV by default, in exchange for 100-150 off the television (which was fluff to begin with... it's not a direct trade of $100 for your data).
I've set up about a dozen of these now for people and they just stare blankly while I try to explain what "Auto Content Recognition" means... Hello 1984.
And it's not just principles. The effects of Big Data are extremely tangible even if not to you in this particular time or space. Some feel the effects now, others will feel them later in life.
I'm worried my children or grandchildren could one day be denied healthcare or adequate education or loans or low insurance payments just because of my attitude towards my government and every other aspect of my lifestyle which gets swept up and analyzed by for-profit robot armies bent on achieving the Holy Margin.
There is no doubt that the public image about FB is significantly changing - a year from now things will not look better for Facebook then they are today, most likely worse I'd say. This is not something they can turn around anymore - the leadership is not making any learnings and repeats the same mistakes over and over again.
I'm pretty sure there are five year olds who have learned the magic phrase "I didn't mean to!"
edit - specifically, that mighty tome of great knowledge; 'Murphy's Law Book Two: More Reasons Why Things Go Wrong!', by Arthur Bloch.
I think you hit the nail on the head. Even on HN, it's not uncommon to see a few comments on each negative story about facebook accusing the media of a conspiracy against Facebook; claiming that the media is wrongly maligning Facebook who is merely the unfortunate victim of a series of coincidental accidents.
They have trouble accepting that a tech corporation like facebook actually might be rotten.
There is a certain amount of anti-silicon valley sentiment in the media and as a result there are a lot of stories maligning tech companies in ways that aren't always fair. Especially when the media companies are campaigning for some kind of problematic legislation that the tech companies are on the other side of and so will take any excuse to try to make them look bad.
Then there's Facebook, about which nobody has time to write a story maligning them unfairly because there is never that long between any of the stories maligning them fairly.
Probably because they work for an evil tech corporation as well (this is HN, where SV techbros hang out, so the probability of that it pretty high) and want to ease their cognitive dissonance.
Because there's a difference between "we screwed up and obtained this" and "we screwed up, obtained this, then used it. Hope our use didn't result in any problems for you."
Here’s an example page from 2011 talking about facebook’s old feature to import contacts via providing them your email username and password. This was at a point when many web mail services didn’t offer an OAuth API to do this, so it did make some sense at the time. It was still safer to do a csv export and then import, but much easier for users to provide the password directly.
https://www.techwalla.com/articles/how-to-import-contacts-to...
> Type your email address and password for the Web-based email or instant-messaging service that you want to import into the dialog boxes and click "Find Friends."
Just as with people, it’s sometimes difficult to judge them for a single act. Only by aggregating behavior over time can we learn of their true character.
And Facebook’s rotten.
I see other comments talking about personal responsibility, but in the case of FB the notion of a company selling their data is too abstract to clearly understand the risks/consequences for many. Should we put no responsibility on corporations to act civilly or at least legally? Should one not have a personal responsibility to engage only with corporate entities that behave civilly/lawfully/etc? I really don't understand this mindset.
Stop complaining, start taking responsibility.
So far as I can tell, this was Facebook exceeding authorized access to a computer system — at scale. If you or I did this, we’d be looking at felony charges.
For instance, if I had a friend whose job it was to design missiles that are used to bomb innocent people (Lockheed-Martin for instance) I would seriously reconsider my friendship with that person. Yes, it's "just their job" but choosing to have a job which requires having such warped ethics would make me reconsider whether I want to continue associating with them.
Nobody is forced to work at such companies. Yes, effectively all companies do things which we don't agree with on some level (unimaginably large amounts of tax avoidance being the most obvious example). But if a company's ethics are completely antithetical to your own, then I don't see how you could morally justify working for them.
(Obviously there are some understandable exceptions to the above -- the most obvious being that in the US employees are effectively blackmailed into working for their employer because they'll lose their heath insurance otherwise.)
I'm curious what part of the statement is important to you in making that decision though. Is it that LM is part of the military-industrial complex, full stop? That the weapons are used by the US military? That they are sold to and used by other governments? Would LM be acceptable if they created weapons that magically never harmed the innocent? What if they occasionally harmed the innocent but were always used by people with good intentions who were doing things you supported?
Never worked in that industry, just curious.
As for my personal view, it's fairly clear that Lockheed-Martin props up (through lobbying) and profits (through government contracts) from the US war machine -- which in turn has killed millions of innocent civilians. And then there's the contractors that Lockheed-Martin has provided to government agencies to further strengthen the surveillance tools of the NSA, CIA, FBI, and so on. So, I think Lockheed-Martin was a good example of a "clearly immoral" company.
EDIT: You changed your comment after I responded to it. I don't think the ethics of hypothetical magic missiles is a super useful conversation to have (changes in technology don't change our underlying ethics, they just change what ethical questions are being asked).
On the question about unintended consequences, obviously in wars you can't guarantee zero civilian casualties and innocent bloodshed is inevitable (though still unjustifiable). But the US is currently engaged in several illegal wars of aggression (which is a crime under international law) and clearly planning to engage in several more. Personally, I think the "unintended consequences are inevitable in war" defense isn't available to you if the war itself was illegal from the outset.
"Suppose you were bereft of morals, and suppose you were working at Facebook; but I repeat myself."
That stuff happens all the time at small companies. While it's certainly bad practice, it's often not evil intent, but just lack of technical skills (for the former issue) and missing sense for potential privacy issues (for the latter).
In case of a large company like Facebook, one could expect they'd have processes and education in place to prevent such incidents, but I guess this happened a while back when FB was much smaller than it is now.
Yes, and at Facebook in the context of data gathering they seem to happen ALL THE TIME. So if they did actually care about privacy they'd make changes to curb these sort of "mistakes", but taken in aggregate the relentless "bugs" show a pattern of willful malevolence.
But it's been over a decade of these types of reports about FB and their behavior. FB should be asymptoting towards good ethical standards and software practices. These reports should be getting more and more rare.
Instead, they seem to be growing exponentially away from good ethics and practices [0]. It feels like it's getting worse, faster, not less worse and slower.
Here's a partial list : https://en.wikipedia.org/wiki/Criticism_of_Facebook
[0] Yes, I'm being a bit hyperbolic with the graph analogies.
You're joking right?
I think this company is inherently bad from the top and everyone working there is enabling them. Sure, it pays well.
Problem is, most bigger companies do bad things. See VW and the emission scandal and I hope Winterkorn and other top managers goes to jail for that. Also I'm biased, for me Facebook and Instagram are pretty useless, the only useful product they have is Whatsapp...
I mean, it's nice that they are deleting the information now, but they clearly did something wrong, and by basic standards, they should be punished. And the deleting the stolen information isn't punishment, and since they probably won't delete any new ad targeting information they gathered as a conclusion from the contacts, they are still profiting from it, so the punishment should be more then just a small fine (that I hope they get).
I'm just sick of them (and other companies) "accidentally" doing something wrong, and barely get a slap on the wrist.
How can you not mean to? It's one thing to say that, were it something tangible, like paper, "Sorry, mate. These pages snuck in with the others. Sorry about that. We'll pull it out. No worries."
Pulling contacts and uploading them is not a passive action but takes active action.
>and is now in the process of deleting them.
So, the question must then be asked: How do they differentiate the sources of contacts associated with an account, unless they're logging that, as well? If they're not logging that, then how are they, presumably, deleting those contacts?
Are we taking bets on Facebook being in the news again, in a months' or so time, for being found to not have deleted them? :)
Action such as "accidentally" asking for email passwords. It is quite remarkable how these accidents line up just so.
Grammar-checking programs should be flagging any use of "accident", "accidentally", "unintended" and "unintentionally" whenever they appear in the same sentence as "Facebook" and are not within quotes.
Indeed. Expect the next headline to be, "Facebook 'unintentionally failed to delete' 1.5M people's contacts, which they'd previously unintentionally uploaded".
They might want to overthink their motto 'Move fast and break things'.
It's my understanding that they used to do this entirely intentionally at one point via an "import contacts from mail" feature, then they dropped the feature and now when they added the "sign in with e-mail to verify your identity" feature someone reused the old code without being aware that it will also harvest the contacts and that they don't want that this time.
It's the opposite of "privacy by default", basically.
If that’s security, I no longer want to be secure.
If this is done in favor of the current government, then they probably won't mind.
If you're thinking Facebook is getting away with it, you're wrong.
Of course, they're mainly getting fined; if that isn't harsh enough punishment then I don't know what to do next, that's dangerous territory.
Another (which is merely me reading the law and therefore probably doesn’t mean what I think it does) is prison time and equipment seizure if a business engages in copyright infringement commercially.
Split the business into smaller, independent ones. We've seen this before. There's enough services hiding inside FB that treating them like a monopoly is not a terrible idea.
1.) The US FTC really needs to update its working definition of a monopoly. “Consumer welfare” is normally shown via price and since free services are always free, it’s a tough thing to argue.
2.) Facebook owns about 70% of the social networking space, and Google and Facebook have a virtual lock on online advertising. Moreover, through its share buttons, Facebook has created a web full of data gathering - the sheer amount of information they have makes them very hard to compete against. Add in some regulatory issues in the Instagram and Whatsapp regulations and there’s an image of a company that’s just about impossible to compete against and that has used its clout to bring net harm to consumers.
Facebook faces a small punishment or perhaps a public rebuke from some politician, someone from the company makes some lame statement about how they’re committed to do better, and then within two weeks another story comes out that demonstrates they don’t give a shit about their users.
Facebook has thumbed its nose at every single attempt to rein it in. The next steps are dangerous territory, but only for companies that behave in tremendously antisocial ways. It would be a net win for the rest of us.
> A quick Google indicates Facebook may end up paying 1.6 billion to the EU.
A slap on the wrist, Facebook had 8 billion in revenue Q1 2019. But first let's see if they actually end up paying that.
It's just like how banks change after receiving massive fines for their role in the crisis, money laundering, transacting to sanctioned countries (they don't really, aside from some minor internal processes to prevent the exact same thing from happening again).
Majority of apps are just spyware anyware.
It worked quite well for a long time, but tended to be quite a burden to maintain through OS updates. Starting with Oreo or so it no longer worked, but there was another similar module that had much of its functionality.
It could even go as far as exposing a subset of your address book to an app. So, for example, when I wanted to use WhatsApp I could just show it the 3 contacts that I wanted it to see.
The operating system should sandbox every app and by default provide it fake data for everything. The user should say what they really want to allow the app to access.
I eventually switched to an iPhone and just don't install many apps.
However note that this article is not referring to the Facebook mobile app accessing the mobile contacts -- this is about their service logging into a person's email service (like GMail) and downloading their email contacts.
My mother, for example, does not really understand that websites are run by individual entities. There's one "internet" and all websites are kind of like a strip mall under general management, so in her mind if one page on facebook askes for a password to read my email, how is that any different than reading my email on on the yahooo page. All she knows is Facebook, an "official" website asked for a password.
And that, including me not paying attention, is how all my e-mail contacts got an email from facebook where I invited them to FB. That wasn't the intent!
Also sad is the fact that BlackBerry already had a fine-grained permissions systems pre-iPhone days, but it took iPhone and Android many many versions and years before they built such privacy controls (but yeah "We care about our costumer's privacy" - Apple). And Google didn't even care about privacy back then I remember the Google Maps app for BlackBerry just prompts you "Please give us all the permissions we want or this app will just exit now." on startup, when you've denied it a permission or two.
It turns out that some people genuinely are forgetful enough that if they told their iPhone Bob's number, email address and shoe size in 2016 and then in 2019 their phone finds out that phone number is registered for Signal, they will conclude that the phone must have learned Bob's details from Signal, which in turn stole them from Bob as part of some nefarious plan.
You can't do anything about this, it's like the Spam problem. If you send ten million very, very useful emails that are genuinely valued by every human recipient, hundreds of them will be flagged "spam" because Humans aren't very good at this sort of thing. They press the wrong button or they've been using "mark as spam" because they thought it's "mark as read" or they meant to mark the one below it, or above it.
I remember signing up for facebook when I was in high school, and I probably would've provided my email password if facebook asked for it...as an adult now I wouldn't provide my email password to anyone, of course.
I myself have had trouble figuring out whether certain dialogs were OAuth dialogs or just skimming my password, and I've been in web software for 20 years. A layperson has no chance.
It's incredible that the banks tolerated this service even though they told their customers to not to give their credentials to a 3rd party. Or not just banks, how about the German Federal Office for Information Security.
I wish the bank would just block accounts who they detect used the service with an error like "We think your credentials have been compromised" (then again the stupid customer will think it's the bank who got breached). Or give them a fine of e.g. 100 Euro for breaching their user agreement. Then again, this would lose them so many pissed-off customers.
P.S. As you seem to be a non-native English speaker, the word you wanted to use was "scrapes" not "scraps".
This is almost non-existend for personal banking. First and only case by now I’ve encountered was in Czechia:
I know this isn’t a contest, but I always felt LinkedIn was twice as scummy as fb.
This practice opens up a significant potential for abuse and should be illegal.
Your online banking is known to be verified, therefore another company can piggyback on that verification.
I was having discussions with FB recruiter and some of their senior managers. I just informed them that I won't be pursuing that anymore.
FB engineers who are on HN: why are you still there? You can make similar money at several other companies without sacrificing your soul!
The tech industry worships money and those who make it, and there are plenty of engineers who'd take the FB compensation package in a heartbeat, regardless of FB's public image problem.
This idea that the public will act together morally to stop corporate malfeasance while sacrificing their good fortunes isn't that realistic. Look at the FB shareholder situation. Lots of shareholders are angry at Zuck but can't do anything about it. None of them seem particularly interested in selling their shares because they don't want to have to pay for his bad behavior.
... this does not need to happen. Plenty of other companies in the Bay Area pay as well as FB, but without the heartache.
Engineers aren't going to start quitting en masse until their compensation is threatened (i.e. the stock irreversibly tanks). In order for that to happen, shareholders need to stage a massive sell-off, which won't likely happen soon due to FOMO.
Google collects significantly more data than Facebook, and has a sordid past with sexual harassment and inappropriate relationships. Lyft, Uber, and AirBnB have openly flouted regulations, and that doesn't count Uber's other scandals. LinkedIn grew by emailing everyone's contacts without their permission (if you think what FB did here is bad, LI was far worse). High frequency trading and other fintech companies engage in front-running and derivatives trading that may be contributing to market volatility and systemic risk.
Comparably paying companies pretty much all have questionable histories.
Meanwhile, Mark Zuckerberg has committed to investing in improving Facebook even at great expense (don't believe me? look up what triggered the nosedive in Facebook's stock last summer). Do you think Facebook will improve more if conscientious engineers left the company?
I'm not so sure. Certainly Google, Amazon, et al are just as bad as facebook.
This has been asked before on HN. The genuine answer is some combination of:
* criticisms of FB are wildly exaggerated. This takes many forms, but in this particular case I think it’s the issue of attributing to malice what’s best explained by incompetence. Somebody probably just reused some old email importing code without understanding it thoroughly. If you know anything about how FB works, that’s infinitely more plausible than some shady conspiracy to unethically harvest the contacts of a small percentage of users for a slight improvement in ranking or targeting.
Facebook is not some well-oiled machine, it is a jumbled mess of thousands of junior engineers, perpetually barely avoiding collapsing under its own weight.
* People inside FB generally believe, whatever they think of Zuck, that he doesn’t just outright lie about verifiable facts. The entire code repository is completely open to all employees. If adding this feature really was malicious and FB’s response is an outright lie, somebody WILL find the commit and leak it.
* Even if FB is doing harm, on balance the good it’s doing is greater. It has made communication between humans easier and lower-friction which has many upsides.
Part of this is that all the upsides are concrete and obvious (people fall in love on Facebook/IG/MN/WA, they stay in touch with friends and family, they run a business, etc). Whereas the downsides are abstract and hypothetical (maybe someday someone will use Facebook’s collected data for some nefarious purpose).
* Even if all of the above is false and FB really is harmful to the world, the situation certainly won’t be improved by thinking people quitting, and leaving the company totally in the hands of yes-men who drink all the kool-aid.
* Criticisms of FB are not exaggerated. In this case, FB stole 1.5 million creds, then used these creds to harvest user data (nobody actually wants to give this data away, it was taken by force). If an individual did this, they would be in prison. FB gets away with it... again..
* People inside FB are a cult. It has been shown that MZ will lie about verifiable facts, even to congress! Its wilful suspension of reality for the sake of a huge paycheck. ... "when his salary depends upon his not understanding it!"
* FB is doing harm, and Its not on balance greater. Its divisive, promotes untruth, gives a voice to those that really shouldn't have a voice, spreads misinformation, promotes hate and dismantles democracy. Not to mention... Ostracization? Murder? Genocide? Exactly how many FB whistleblowers have existed in history? Is this worth it so people can share cat and dog pictures, and stolen memes from other media? I'd say, no.
* One of the most troubling moments in my recent history was visiting India, and seeing how FB is so influential in general discourse. I had people tell me great, unjust untruths like they were facts -- "I read it on facebook".
* If FB has no users anymore, it has no advertisers, it goes away. Better for the world!
FB is arguably the most destructive force of the 21st century. We will never be free until we shake its iron grip on humanity.
I am quite capable of making similar sums outside of Facebook. In fact I plan to leave soon for reasons that have nothing to do with ethics, and I don’t foresee myself changing my opinion once I’m no longer an employee.
Now to answer your specific points:
* Facebook did not steal credentials. They were willingly given.
* “Nobody actually wants to give this data away” how do you know? Do you have polling data on this? My personal belief is that most people don’t care at all.
Also you’re completely ignoring my assertion that it probably was just an accident. Hard to argue that something was “taken by force” by accident.
* Can you give me some examples of Zuckerberg knowingly lying about objective, verifiable facts to Congress?
* Well, your guess is as good as mine whether it’s better or worse on balance. My intuition is that it’s better. You haven’t really argued against this, just given some examples of the worst possible downsides and asking if they’re worth the most trivial upsides (conveniently ignoring the real value of communication tools in people’s lives, which has nothing to do with dog pictures and memes).
In my experience, FB isn’t divisive at all. I use it to talk daily to people who have become very close friends and who live in a different city (my home town). Without that connection, I would be extremely lonely.
* I’ve heard plenty of people in the US tell me great, unjust untruths like they were facts. They saw them on TV or heard them on the radio.
* As for FB being the most destructive force, I think you’d have to give that title to climate change, resource depletion, terrorism, and war.
* "Wallet inspector". I don't think the authorities would let you off if you claimed to socially engineer (steal) someones wallet. People wanted their FB supplied dopamine hit, and handing over email creds was the only thing in their way. It is coercion.
* Another FB meme -- 'people dont care so we can do what we like'. People lack the specific understanding of what they give up. It is coersive to take advantage of people like this. We talk of informed consent. FB existence is reliant on action without informed consent. https://news.gallup.com/poll/232343/worries-personal-data-to... recent poll showed 55% of users are concerned about FB selling there data. That's a majority. I think society is growing wiser in time. My hope is the social climate matures to understand what the individual gives up by using these services.
* MZ lies to congress: "we don't sell data to anyone." Mental gymnastics to make this true. Its the entire business model of FB, selling user data to advertisers -- sure, its not the raw bytes the user uploaded (however, they provided lots of record data to 3rd parties). The social graph is data, user data, and it is sold to advertisers, integration providers, hardware vendors, etc etc. How is MZ not a liar about privacy, again and again?
* I am ignoring your assertion it was an accident. Stealing credentials isnt an accident. Full take logging (capturing creds) on your HTTP gateways is an accident (kinda). Deploying credential stealing walls is no accident. Deploying code that uses these credentials to harvest address books is no accident. Its a chain of malicious actions. Cannot be an accident.
* We have legislative and industry standards for Radio and TV (aka legacy media) to ensure that untruths don't get very far. FB, not so much. Yes, all media can be a source for misinformation, but FB really is king here.
* I dont use facebook and am extremely lonely.
* Point taken, there are worse things in this world. But to me, this is the most visible, and most actionable, today.
Thanks for engaging. I don't really know why I decided to write all of this, but Im feeling mad over this credential harvesting. Its yet another strike.
Best of luck with your career outside FB!
the code to implement that functionality didn't come from nowhere
Later when login with email was added, the same event was sent but whomever added the event didn't know it would case the upload of contacts.
That doesn't mean it wasn't shoddy craftsmanship, bad architecture, bad QA and probably bad communication later on, but it could have been by mistake (at least at first).
Which begs the question, how do you structure your organisation such that a foolish developer that only barely understands the change that they are making can't write code that makes arbitrary queries to particular data sets in unapproved contexts?
To access the user's data, your developers should have to intentionally crack the user's password. And if they attempt to do that they should be fired.
Obviously this is not how Facebook works, but ideally it's how the thing that replaces Facebook will work.
E.g. Google Drive, which claims to take privacy seriously and also encrypts your data. But the data is not encrypted with a secret unknown to the server. How should my family members differentiate between the encryption Google claims it has and client-side encryption? For them it's all the same.
Maybe we need some commonly understandable name that a regular user can look at and know that this software is data-agnostic.
It's an organizational policy, procedural, ethics and legal question - not a technical one.
They should have feature reviews before the code reviews. The feature review panel puts bounds on what the code can do.
Not really. You have to fall back to those things when a good technical solution isn't available, but sometimes it is.
Suppose you have a car, and four children. You can enact all the laws and policies and procedures you like, you can lecture the kids not to misbehave a thousand times. But the most important thing you can do, if you really don't want them out joyriding in the street, is to not give them the keys to the car.
Anyway, from my experience people do the stupidest/reckless things despite being told not to, just because there is no fear of backlash. Holding people liable for their actions could be a start, but who wants that?
Also, don't hire foolish developers in the first place. Policing around pebkac is hard.
Yes they did. I remember people complaining about it many years ago. Here’s a page from 2012 describing it I found using google advanced search: https://smallbusiness.chron.com/import-email-facebook-44162....
> When you create a Facebook page for your business, you can import your email list of contacts directly into Facebook. From there, you can suggest your Facebook page directly to your customers. Facebook can interact with a range of email providers and only needs your email accounts's username and password to import your contacts.
Here’s another from 2011 https://www.techwalla.com/articles/how-to-import-contacts-to...
> Type your email address and password for the Web-based email or instant-messaging service that you want to import into the dialog boxes and click "Find Friends."
If the full scheme of Facebook's business strategy (and other companies' as well, for that matter) were clear enough, a mass exodus would take place.
I'm still hoping a mass exodus takes place some day, or at least, like Roger McNamee has suggested, log and data deletion is enforced in some way.
This has to stop. Even if there is some temporary outrage, these companies remain unaccountable and get away with whatever they want.
From now on, I think I'll stop replying to emails provided by companies whose trust I've long lost and use only Protonmail's encrypted link feature.
I'm just a mess without my morning coffee. If I don't get a good cup of joe in the AM I could do something reckless and random... like violate the privacy of millions of people! OOPS!
You know what I'm talking about! Right! ... right? ...
Don't give access to your contacts, location, emails and photos to not just FB, but also WhatsApp and Instagram. If you must use them, try doing so from incognito browser windows. Facebook has proven time and again it cannot be trusted.
Facebook knew exactly what they were doing but they're playing dumb because it's less insulting to the recipient that way and they feel that will minimize the response.
Publishing mailing addresses worse since that is a physical location in addition to being mail location.
Once the e-mail address is validated, is there any further need for a valid e-mail address to continue using FB?
Historical fact: Going back to the days when a university address was required, if the user created her Facebook account while at university and her e-mail address later expired when she graduated, FB did not disable the account.
Unless one wants to get notifications and other FB crud via email, AFAIK there is no need for a working e-mail address to use FB.
I wanted to create a FB account while giving as minimal data as possible. While it's possible to create an account using temporary emails / temporary phone numbers, FB eventually asks you to submit more details.
This includes clicking verification links, uploading your photo, providing phone numbers etc.
Even when I managed to do all these (using fake data), my accounts got disabled in few days.
PS: when I used my email id associated with my FB account deleted back in ~2012, I found out it wasn't deleted. FB asked me to recognize pictures of my friends. So I believe no detail that ever passes the event horizon of facebook can ever leave it.
https://nordic.businessinsider.com/facebook-old-posts-mark-z...
Right now I can find just about anyone’s email, seed them with an ad pixel, show them hyperpersonalized landing pages and follow them online knowing exactly who they are, allowing me to tailor ads to individual level.
If that doesn’t creep you out, what would?
WhatsApp on iOS recently updated, and now will only show phone numbers for contacts UNLESS I upload my contacts.
In the UI if I click on a number it will take me to the profile where I can see that users name ~Tom, but wow, waddamove... Have we reached the point where FB can't make any more money until they go deeper or is this just drag-net "data is the new oil"
Furthermore it won't let you start a chat with anyone unless it can access your contacts to find them. However there's a great little app on F-Droid called 'Open in Whatsapp' that lets you start a chat with any arbitrary phone number.
(Facebook Asking for Some New Users' Email Passwords)
> You accidentally, expertly, carefully took the entire top off of that tower?
They trick you to get your password, then steal your contacts. Seems like typical malware.
The BS you refer to is his creation, not some accidental thing that happened to occur in his company without his intention.
"Dumb fucks" wasn't just an episode, that's his character.
He'd probably be a good friend of Martin Shkreli if he wouldn't care that much about what others think of him.