It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it.
For the FB employees reading this: what is your tipping point? Would you say no to that assignment?
It takes extra work to upload those contacts, which means several managers and developers decided to do it and then spent time implementing it.
For the FB employees reading this: what is your tipping point? Would you say no to that assignment?
- developer A is tasked to create the prompt to ask for username and password of the email account
- developer B is tasked to call some API to upload contacts from email account
- developer C is tasked to bind two functionalities.
Now replace developers with teams and you see how simple is for the average developer to underestimate the scope and the ethical bounds of a given task.
It's not news at this point to anyone working at FB what their leadership is engaged in, and what their work is being used to accomplish.
Perhaps several years ago you could claim some kind of ignorance.
That's no longer the case. You know who you work for. Own it.
Even at this point, you’re not getting a mass exodus of workers from Facebook. Those in there are choosing to be there at this point. Koolaid or not.
But you are right, scope creep in the “unethical” aspects and it can suddenly be “no one’s fault”. That isn’t a bad plan.
Indeed.
You’re getting paid 2x market salary (“market” here being non-Facebook and non-Google, which isn’t any better) and delivering services to people who voluntarily sign up ro them... I mean there are worse jobs in the world.
“That’s a really dick of an idea and I’m pretty sure it’s illegal. Exactly how illegal, I’m not sure. But I know illegal to some degree.”
“You live in a shit apartment because housing prices are stupid and makes your salary meaningless in this town. Here’s a wheelbarrow full of hundreds and we all agree it was an accident.”
“When do you need it by?”
Nobody will test this? No developer in team C will consider what they're doing?
return true;
Return true is tested to still work.
But seriously. There’s no accident in what happened. This is Facebook. Anyone who thinks Facebook isn’t morally corrupt probably also says “What do you mean Stalin wasn’t a pacifist?”
Unfortunately, this ha-ha-only-serious joke is least several decades old.
When FB stops giving them a check.
At least that has been my experience watching programmers at other companies. Unless ethically bound by regulation and law, few people seem to have ethics.
Or maybe their set of ethics simply differs from yours. It is very subjective after all
Methinks that was what the OP was asking -- what is the tipping point ? Having differing ethics is fine but one can't just lean on that as a crutch when one has none.
> Facebook told Gizmodo via email that in May 2016 it made a revision to the registration process, which originally asked the affected users for permission to upload contact lists. That change removed the opt-in prompt, though the company did not realize the underlying functionality was still operating in some cases.
It doesn't take a conspiracy to understand how a bug like that could happen.
It is difficult to get a man to understand something, when his salary depends on his not understanding it.
-- Upton Sinclair
"Mark Zuckerberg Promises That Misuse Of Facebook User Data Will Happen Again And Again" https://www.theonion.com/mark-zuckerberg-promises-that-misus...
"Facebook Employees Explain Daily Struggle Of Trying To Care About Company's Unethical Practices When Gig So Cushy" https://www.theonion.com/facebook-employees-explain-daily-st...
"Cash-Strapped Zuckerberg Forced To Sell 11 Million Facebook Users" https://www.theonion.com/cash-strapped-zuckerberg-forced-to-...
"New Facebook Feature Allows User To Cancel Account. ... The company later confirmed that account closures would not stop Facebook from continuing to acquire, permanently store, and sell all information about its current and former users until the day they die." https://www.theonion.com/new-facebook-feature-allows-user-to...
When every public-facing thing you build is centered on hoovering up data, you're going to have two broad classes of errors. Hoovering up too little data, which doesn't hit the news, and hoovering up too much, which does.
That said, when your "errors" directly line your pockets, you're not entitled to the benefit of the doubt.
That’s the initial asshole maneuver. There’s no excuse for Facebook to need that. Period.
2. CollectUserContacts(email, username, password);
It’s pretty hard for me to imagine that there’s some other function that just happens to coincide with accessing different email servers and collect past emails to collect the email addresses.
It was deliberate because of the work involved. The only investigators that think it’s accidental probably believe the internet is a small black box guarded by the “Internet wizards”.
> A Facebook spokesperson also told Gizmodo that a screenshot of the original opt-in prompt was not available.
I'm not a conspiracy theorist but if you're trying to claim you cannot capture a screenshot from any release meant to be shipped out, either you're crap at release management or are full of shit. Which one is it?
Also, even if we were to suspend logic and belive this was a bug, what's FB doing to correct it? Are they deleting all uploaded contacts and going to request for consent again?
FB is a cesspit. Get out of the company if you work there and get out of the platform in any case.
That doesn't strike me as especially unlikely, especially for a specific branch of the app codebase that would likely only operate with a huge number of other co-dependent codebases for backend systems that no longer exist.
With six months to recover code and build a non-live environment with all the dependencies could it be done? Sure. But that's not really within the scope of a journalist request.
At some point, it goes from "the occasional bug" to negligence at best, and hostility at worst.
There is a good chance that they didn’t know how their work would eventually be used. That’s the problem with big companies. Most people are far away from seeing the consequences of their work.
I have an open ended question aimed mainly towards founders. Would you have any issues in hiring a candidate with Facebook on their resume?
It also takes extra work to ask consent. You build it. You don't notice that your confirmation screen fails to trigger. You've just unintentionally uploaded a bunch of data without consent, when your intention was to do it with consent.
It's still pretty darn negligent, but it's easy to see how it could be done unintentionally.
Not really. Facebook is a bunch of autonomous services (registration, access, tracking, activities, etc.) accessing shared databases (chat logs, activities, media uploads, etc.) with some kind of automatic implicit and explicit ACL in place. The suggestion/contact service got access to data provided through the email-not-working-with-oauth-so-let-us-use-automatic-token-delivery-and-confirmation-by-accessing-user-emails because it was told a new source of contacts were available for those users. So, not a straight path.
Accident/Blunder > Evil.
Now. GDPR ? GDPR. And because of GDPR those things aren't supposed to happen in Europe.
As long as you don't see the evil being literally done ie in form or row of inmates being sent to gas chambers, there are almost endless ways to persuade yourself that all is actually OK and fine.