Facebook Expects to Be Fined Up to $5B by FTC Over Privacy Issues
nytimes.com
nytimes.com
1) Prompting users to give Facebook their email passwords.[0]
2) Using that email access to "inadvertently" upload the information of their email contacts.[1]
3) Storing said passwords and others in plaintext. [2]
It's pretty impressive that a company could do something so brazenly malevolent and be confident that they will escape with no more than a fine.
[0] https://www.thedailybeast.com/beyond-sketchy-facebook-demand...
[1] https://www.theguardian.com/technology/2019/apr/18/facebook-...
[2] https://krebsonsecurity.com/2019/03/facebook-stored-hundreds...
in logs.
create_user('Bob', 'BobPassword123')
assert "BobPassword123" not in logfileI don't think it's trivial to guarantee non-existence.
I disagree in this case. Log messages don't spontaneously appear in arbitrary places. If the developers understand what their software is doing and how their systems are configured then they should know where to check for the logging messages.
That said, someone should have been watching for this stuff and failed to do so (or to exist), so I'm not excusing them - but this is not a trivial thing to protect against.
With billions of dollars and some the best software developers in the world (supposedly), Facebook should be able to figure this out.
Subject: Change Request
Body: I would like to log the body of authentication requests in production.
Subject Re: Change Request
Body: How will you ensure personal data is not stored that shouldn't be?
Subject: Re: Re: Change Request
Body: I will add configuration Y to logging system X.
You assert that it's trivial, yet you're adding more layers to protect against something like that from happening. It's the naivety that all problems are trivial is what gets people and companies into trouble in the first place
Reviewer: Does this have privacy implications?
Change1: No, Service X marks all PII before this point. Code X drops everything marked in this way.
Two years later.
Change N: Modify request structure for more optimal blah blah blah.
Now suddenly the changed request structure causes a regression in the PII detection which causes some logging of PII.
This shit is way more complex than "just stop people when they ask to log passwords".
What if there is a bug and some other function logs "[...]word123"?
Of course we (and they) should do it anyway, but it does often take an investment in making things testable.
This is the sort of thing that leads the HN crowd to sneer at the old, slow ways of the enterprise world.
What's to stop a malicious ex-lover from grabbing a FB password and reading that person's private messages? If FB didn't even know there were passwords in plaintext, they very likely weren't auditing log access as much as was needed.
[1] https://www.theverge.com/2019/3/21/18275837/facebook-plain-t...
I can't f'in believe I have to explicate such simple things to supposedly intelligent and thoughtful people
I think it would be way worse if we found out they were storing passwords were plaintext in the database in 2019. Even if the security implications are the same/worse, the policy/decision making of such a revelation would be beyond terrible.
edit: To put it another way, remote code execution flaws are terrible but they can happen. However it would be way worse if someone put in a static username/password backdoor. The security outcome may be the same but one is beyond terrible policy/decision making.
... for seven years.
Sorry, but it is like saying "there is no SQL injection, only bad input validation".
If Facebook devops engineers, who are probably among the best trained and highest paid on the planet, lack the same common sense for their users passwords... I can't even come up with an ending to this sentence that would properly express my emotions right now.
Well, fuck that and fuck me, those people are not idiots, they're criminals.
In other words, Hanlon's Razer doesn't say that there is no such thing as malice just that you shouldn't default to assuming malice.
Facebook is perhaps not out of the ordinary really, it's just another of a variety of businesses who have come to realize they hate having users. They just need their data. Vampires don't want human friends either, they just need their blood.
Like, if someone treads dog poo into my house on their shoes, it doesn't really matter if they did it by mistake, or spent ages walking around town trying to find some dog poo to step in before coming to my house; the effect is that there is now dog poo on my carpet.
We need to be more dispassionate when discussing these issues because otherwise threads like this descend into analysis of whether Zuckerberg/Bezos/whoever is a moral person. Which is a)probably unknowable and b)besides the point.
There is a problem here with a very big company that has more power than it knows how to handle, which can probably only be mitigated by breaking it up. That's all there is to it, really.
[edit] Just as an addendum, that's not to say that if the company has done something illegal, the people responsible shouldn't be prosecuted- they should.
Don't bend yourself out of shape. Actively, happily ignoring the evil you have caused and continue to cause is evil.
You can call Facebook a number of things from amoral to negligent or even criminal, but once you start talking about evilness you have to start judging their intentions and motives.
All of these things are no one's fault.
> Evil isn't about results. It is about intent and motive.
Exactly. Prioritizing profit at the cost of customers' well-being is a deliberate decision; if not, seeing that customers are harmed by your own, continued actions and doing nothing to change it is, to me, actively being evil. Your intent may not be exactly to harm, but you have no problem harming people to get there. There is no difference.
While I agree that it's useful to maintain some nuance in our perspectives, generally I think it's better to recognize and realign our actions, not definitions. It's the difference between accidentally hitting someone, and accidentally hitting someone and proceeding to run them over.
And to your example, I think we know most people aren't really aware of what is going on. Another group of people don't believe it at all, a combination of ignorance and poor government. We're all human; that means something.
Mark isn't trying to kill people. Mark _is_ evil, because he chooses to take actions that are likely to cause great harm.
No, but you would call it evil if someone repeatedly built rickety buildings in a hurricane zone or built structures out of dry wood and paper next to a forest at high risk for a forest fire, and then acted like they had no responsibility when the buildings repeatedly got destroyed by fires and hurricanes and people's personal property got lost forever or looted in the resulting disorder.
That's ridiculous, neither hurricanes nor fire possess free will. I bet you would call someone who intentionally starts those things evil, though
Unless you're an animist, I guess.
Trying to fit things into neat little boxes so you can apply words to them isn't particularly helpful. What Facebook is doing is some form of wrong. They aren't murdering children, but still, what they are doing is not good and they are doing it at a massive scale, so the harm is multiplied.
I think about this a lot with regard to Big Tech. For some companies it looks easy and obvious (e.g., Amazon spins off AWS). For Facebook is it really as obvious as "spin off Instagram"? I'm not really convinced of that. It seems like their power is so ingrained in Facebook itself that it's not immediately obvious what splicing off Instagram would do. What would we actually want to accomplish?
I suppose breaking off AWS might lower Amazon’s ability to subsidize an unprofitable retail business in search of market share, though that is probably a moot point now that Amazon is raising its prices in search of profitability and is likely to stop being the de facto online shopping destination now that other online retailers are also standardizing in two day shipping and easy returns (often easier due to providing return labels in the box).
Likewise for big companies. If a company is acting badly, you need to figure out if it was intentional. In both cases you seek damages, but your approach to making sure it never happens again will be very different.
That's like saying there's not a difference in involuntary manslaughter and murder.
There is. Intent is very important. That's WHY so many people focus on the intention.
The choice not to dedicate those resources up front was an intentional one.
But the point is that this assumes you're able to tell the difference between the two cases- intent is often a really hard thing to prove. And often discussions about whether Facebook acted in good faith when it did certain things neglect the fact that they made a big mess everywhere, that needs sorting out regardless of their intent.
It is and yet the legal system is busy with these sorts of proves all the time. e.g. if you have a professional insurance and caused some damage by mistake - that's covered, if you cause damage deliberately - it's not.
I think this is basic good that regulations- thoughtful ones- serv. Because if Facebook makes money by being evil, then their competitors will be pressured to do the same in order to stay in business. But by leveling the playing field you can help prevent these monopolies from getting so big and powerful.
We can't rely on businesses to act "morally." That ship has sailed. We have to compel them to behave, not by social shaming but by making non-compliance painful and repeated non-compliance an existential threat.
If a company makes an "innocent" unintentional mistake, it can be attributed in part to their choosing not to put resources towards detecting and avoiding that kind of error
It's hardly an accident at that point anymore, but intentionally or (intentionally) carelessly done. That's where we are with Facebook I think.
I disagree that it's likewise for big companies. Corporations like that don't really have intentions; every intention is fundamentally about profit. Profit is in fact both its intention as well as its reward/punishment.
It's really the only way to properly "communicate" with an entity like that. A corporation is not a human being. And just like it's not useful to try to reason with (or attribute human-like intention to) a cat, it's basically futile to do so with a corporation.
Any time that human-like reasoning seems to apply with a corporation, it really only happened because the reasoning happens to align with its profit intentions.
Edit: this is less true for smaller companies, but for a multinational it's pretty much a given.
Also, there's something in the way that large companies are structured, that actual accountability (like you'd find with humans or small groups) seems to disappear and slip between the gaps of hierarchy. Lacking accountability, attributing intent becomes guesswork.
Have to disagree with this; I am much more forgiving of accidental harm than intentional harm. And speaking of dogs, pretty sure my dog understands this as well, since there's barking if he thinks I did something on purpose but accidentally stepping on him doesn't elicit the same response.
My 9 year old son always rightfully claims that many of the harmful things he does was accidental. The problem is that he frequently leaves little margin for error in a lot of things he does. Follows his sister just a few feet behind his bike; of course your going to run into her if she stops quickly. Stacking your bowl, cup and silverware on your plate then bring it up one handed; of course they're going to spill.
Facebook's internal controls and practices are insufficient to manage their business. It doesn't matter if they didn't willfully intend to do all of the shit they did. They did intentionally create the controls, practices, and culture in place that allowed it to happen.
Yes, but if someone treads dog poo into your house every day for a year, their repeated claims that it was a mistake every time are not going to carry as much weight. With FB we're not talking about a single incident of treading dog poo; we're talking about a repeated pattern of getting dog poo all over the place.
a woeful understatement, in my opinion; more like bulldozing manure into you and your neighbor's house.
I think in most of these cases the intent should simply unleash an additional charge or penalty - leading to the imprisonment of executives.
If my company accidentally does something extremely stupid or negligent, or against the interests of my customers, fine me enough to ensure I create systems and oversight to attempt very hard not to.
If it turns out I was doing so intentionally, lock me up and throw away the key.
So, whether it's your own two year old or a malicious adult, you think it's wrong to respond differently because they both produced the same harm?
So, are you saying that the malicious adult poo-tracker is being childish and should be treated with the leniency we afford to children?
> I interpret parent poster as trying to make a point about how we cannot tell anything about intent so we should judge on the action, solely.
Why on Earth do you think we can't deduce someone's intent? In the case I posited, you can know the intent of both the child (no malicious intent) and the malicious poo-tracker (malicious intent). In many other cases, you can also deduce intent from someone's behavior.
No, I'm not saying that. Take it easy bro. Why you all angry and shit?
People are realizing that social validation is becoming less validated by social media. (Lets remove the likes on IG!!). The people coming around now are sheep looking for the next wave of validation.
They can make money from contact lists, but IIUC the article said they didn't use the contact lists. Also, given that it only affected a couple million users (like 0.1% of their user base), the damage to their reputation would far outweigh any benefits of actually using those contact lists.
On the last item, the collection of email passwords, the only benefit would be if they actually use those passwords to get information, so the above point covers it.
Let me know if I'm missing something.
It's a bit like Exxon Valdez: they don't profit from spilling oil in the ocean, but they should still be penalized for cutting corners on safety.
My response to that quote is, to paraphrase Arthur C. Clarke: "Sufficiently advanced stupidity is indistinguishable from malice."
Some actions move into the criminal areas, like tricking users for passwords and phone number to then use that for other purposes to further their own agenda. That could indeed be seen as criminal I think.
And someone has to be held accountable.
I find that the people who use that quote are most often both.
https://www.linkedin.com/help/linkedin/answer/5204/email-pas...
> If your email provider doesn't support OAuth, you'll need to enter your email password before clicking Continue. LinkedIn will use your password only for a moment to authenticate your account. We don't store or save your email password during this process.
Facebook’s feature was similar I believe. Where they stumbled was connecting an email verification feature to the code written almost a decade ago for contact import.
What kind of a profile of me would they be able to glean from email? Whole thing feels so fucking invasive.
Shutting down these options, even if it is the right things to do for the users, is effectively increasing the barriers of entry and reducing the growing speed of new companies. The result is that those companies will maintain a dominant position on the market.
If they wanted to show proper contrition, they'd not only delete that information from their systems, they'd also remove all links in the social graphs that can be in any way a result of that information. They'd also take 100% of their revenue that was even slightly influenced/generated by the inappropriately gather data and send it out to the users whose data was copied without permission.
Also they should probably put together a legal team who will be ready to start handling the $150,000 per copied item that they didn't have the right to copy. :lol
>> “When we looked into the steps people were going through to verify their accounts we found that in some cases people’s email contacts were also unintentionally uploaded to Facebook when they created their account,”
Im struggling with the "unintentionally" part and to play devils advocate trying to figure out if it could be possible. Perhaps they had a service already that performed the login to upload peoples contacts on request and to save time reused this service to also verify the account?
[I meant this as a serious observation, linkedin was sued but I believe they only got a mild slap on the wrist]
You're under the impression that regulators are in the business of bankrupting companies.
All the instances you cited of Facebook's wrongdoing are not worth a $50billion(!!) fine. They just aren't.
Making it be 5% of profit and not revenue would make it hurt even less.
There was a stink about a car manufacturer and seat belts (I think) a few years back. They decided the cost of a few settlements for dead people was less than the cost of fixing the problem.
This is now, has been, and (unless we eat the rich) always will be the way it is.
If the settlement happens, I imagine this would provide some weight behind any class action lawsuit.
This bugs the heck out of me (in general, not specific to this case). What is point of letting them claim innocence? How does this benefit the consumer?
I can see occasional exceptions where it's clearly a case of misunderstandings so you don't want to bring down the full hammer...but I honestly can't remember more than one such case where someone DID acknowledge wrongdoing.
The title of this post/story, should be "Facebook Expects to be Fined Not More Than $5B by FTC," because a $5B fine would be extremely not-painful; there would be zero deterrent effect from a fine of this size.
It changes the evidentiary basis of future claims on related grounds. The admission opens them up to other legal risks outside of the current dispute.
Maybe European regulators want to slap them for the same fact pattern (same facts, different jurisdiction). Maybe a class action is put together (same facts, different plaintiffs). Maybe they have an HR suit for unlawful termination from one of their security guys claiming he was fired for disclosing a vulnerability (related facts).
Etc.
Well that's interesting...citation? I thought not admitting any wrongdoing meant that you didn't admit it, meaning that there'd be no lower bar for anything, related grounds or not.
After all, the insiders most familiar with the matter are those deciding how much to set aside for its eventual resolution. There are rules for how to account for the inherent uncertainty, and massively underestimating the loss would just set them up for new trouble, i. e. a shareholder lawsuit.
Is this actually meaningful to any company that isn't IPOing or releasing new shares? I am not pro-facebook by any means but it's not clear this means much aside from how much their investors like them, again of questionable value as the majority of votes are privately held by Zuckerberg.
https://www.ftc.gov/news-events/press-releases/2011/11/faceb...
Now of course this is not to exonerate Equifax whose entire premise rests on safeguarding sensitive information. From the consumer side, the 2 incidents are equally bad.
https://www.bankrate.com/finance/credit/what-your-identity-i...
And gmail credentials:
https://www.popsci.com/technology/article/2013-07/how-much-y...
Is this a joke? You are not Equifax's customer and they do not need your trust. Their entire premise is selling information about you, to people who do not trust you. Securing your data is something they have to do for compliance, not a core part of their business.
Also, people use FB by choice today while something like Equifax is forced upon us given institutional structures. So it is unclear why Facebook is more wrong than Equifax.
The Equifax matter is far from over, they are being investigated by: 48 state Attorneys General offices, the District of Columbia, the FTC, the CFPB, the SEC, the Department of Justice, other U.S. state regulators, certain Congressional committees of both the Senate and House of Representatives, the Office of the Privacy Commissioner of Canada, and the U.K.’s Financial Conduct Authority.
Not to mention they made a recent SEC filing acknowledging they expect fines from FTC and CFPB.
Facebook made ~$7B net income in 2018. Am I supposed to believe that $5B fine isn't going to affect them at all?
What about ethically?
How much do you think Facebook would have earned if it acted responsibly?
Once you add punitive damages, I don't understand how you could possibly think $5 billion is anything less than an order of magnitude off.
Considering the fine seems to be primarily based on something they stopped doing in 2014, yeah, I think they'd have easily earned $167 billion without doing it.
So in fact, Facebook is paying billions because they made a bad decision when choosing to grant access to data for research. That’s a lot of money. I think if you’d asked what a likely fine was when the story broke, people would have guessed a few million dollars.
For clarity, Facebook didn't "choose to grant access to data" specifically to Cambridge Analytica. It used to be the case that Facebook's API would let the client app see all the information a FB user could see once they authorized it, including information about their friends. That's what CA exploited.
No, they didn't, it's around $56.3 billion [0].
[0] https://www.macrotrends.net/stocks/charts/FB/facebook/net-in...
>5 billion is ... an order of the magnitude off
So you're saying a 30% of their income came as the result of illegal activity? That's a pretty strong statement to make. What proof do you have of that?
Do you want to punish Facebook for doing things that are legal (but arguably not ethical) or do you want to punish them for doing things that are illegal? The former means you're essentially advocating for an ex post facto law and it's easy to understand why some people would see that as not fair.
On one hand, we (as a society) want it to hurt, to cause the company real pain. On the other hand, we don't want to actually destroy the company. This leads to a "cost of doing business" problem, where evil practices become a preferred path for management, if evil is sufficiently profitable.
The underlying problem is that corporations are NOT people, whatever the law says, and the corporation itself has no inherent ethics or morality. The fire doesn't choose to burn the forest, it just does.
edit: I suppose the problem in part is society. We see a beauty and symmetry in capitalism, so we assume beautiful == good, a philosophical failing going all the way back to the ancient Greeks. Just because it's beautiful and useful doesn't mean it's "good" in a moral sense.
That said I think they finally get that, after a long period of total denial. Not because of the fines and regulatory action which have come too late, but just from all the unintended unignorable consequences that have pilled up.
I quit using Facebook because I realized it's actively unhealthy for me, and I've been "healing" since. They don't want the dribble of middle class tech nerds leaving the platform to become a flood.
It would be bad for investors, but... would it be that bad overall? I guess a replacement could theoretically be worse but they would have to commit to that ideal and not be dissuaded by the fate of their predecessors
But as I suggested earlier, we're still stuck with a society where a lot of people, perhaps even a majority, find corporate capitalism to be morally righteous, not merely elegant and effective. Corporate life is more sacred than human life in our world, sadly.
Honest question: What gets negotiated in this kind of settlement? What leverage does Facebook have in this situation to say, "no, that fine is too high"?
"No, that fine is too high. We'll settle this in court(s) since we think we can do better."
Now the FTC is facing a potentially big delay and a risk of no fine if the courts eventually hand Facebook a favorable decision.
The risk is much higher than that. There's a risk that a court rejects the entire justification for the fine greatly reducing both the ftc's ability to impose future fines and their power in general.
I'm not defending Facebook, but I feel like whenever a huge financial instiitution does something, they're treated as a protected class, but other companies get hit pretty hard (justifiably)
That could also just be the angry techno-cynic in me though.
https://www.sfgate.com/business/networth/article/When-govern...
Put it another way: if you took all of the daily market cap changes of FB's stock, but added -1% to one of them, could you pick out which one it was?
Having had days where NW changed by entire year's salaries, I can say it makes a huge difference to how you see it.
And it's not a lot.
Given this effect, Facebook has an incentive to 'low-ball' their estimate.
holy shit
For instance, if the FTC was going to be happy with say a $4bn fine, this tells them that FB is happy to pay $5bn.
The only reason I can think of is that FB is quite sure the fine wouldn't be less than $5bn (maybe FB is asking for significantly higher), and they are trying to price-anchor it. Maybe this is a way of telling FTC that FB will accept something close to $5bn without any lawsuits or other appeals, don't try to negotiate more?
(and one that is smart as to how to approach it, given Facebook's network monopoly. I.e. it should allow you to "use Facebook" in the same way I "use Yahoo mail" when I communicate with a Yahoo mail user from my Gmail account)
You're using an internet that came from government funding, btw.
Really, isn't running one of the biggest companies ever created a better retirement hobby than collecting stamps?
He also pledged to donate all his wealth along with Bill Gates and Warren Buffet
> I would guess because he truly cares about making the world more open and connected and issn't in it for the money.
It's more likely that he just likes being powerful and in charge of something big. If he just "fucked off and retired" the power he'd wield would be much less.
Then, when your children are all grown up you can get around those promises you made to the pesky public about not giving your privileged children billions of dollars by simply making them life-long directors of your charitable foundation.
Besides, some of the most evil and warped people in history were convinced they were somehow making the world better even in the face of overwhelming evidence to the contrary.
We call these people ideologues and fundamentalists.
More than that, treat email just like password. That means, force users to change email regularly so that it's not leaked.
We need a better email system.
This is a material but hardly back-breaking fine.
The best part for FB? Two years from now FB will say to FTC, "you already fined us once...the largest fine ever blah blah blah"
Jail time for lawbreaking executives needs to happen. The financial penalties do not dissuade bad behavior or act as a deterrent, so the same crimes will continue to be committed.
Are there any peer-reviewed studies looking at deterrence of financial/tech/privacy crimes in the modern era? I would expect that in every case the penalty is lower than the profit, making it a continued incentive to break the law.
The only thing these people value truly is their time on this Earth to be free and breathe fresh air. If they risk jail time when breaking these laws, I think we would see a reduction in intentional and repeated lawbreaking by large corporations.
FWIW, FB quarterly profits Q1, Q2, and Q3 2018 were 5.1, 5.1, and 6.9 billion, respectively: https://www.statista.com/statistics/223289/facebooks-quarter...
You'd have to be caught going way above the limit to be fined above 1 month of pay, but it's possible.
I'm sorry, but this shit isn't going to end until the U.S. actually punishes white collar crime. Fines _do not_ work.
There's an element of intent that might be hard to prove. Intent is legally defined as "the decision to bring about a prohibited consequence." If you know your actions will result in prohibited consequences and take them anyway, you are deciding to bring about a prohibited consequence.
Conspiracy might fit, too. You've got 2 or more people intentionally agreeing to these practices that they know will result in identity theft and then taking action to put those practices into use.
I guess they'd have to start with somebody who provably had their identity stolen as a result of the practices, though.
A fine is not enough in this situation ...