Facebook's Email-Harvesting Practice Is Under Investigation in N.Y.
bloomberg.com
bloomberg.com
The market just does not care; it's time regulators and law enforcement started to.
[1] https://www.barrons.com/articles/facebook-stock-is-up-becaus...
The fines need to be bigger.
For FB this is the nth time. I don't even know what n is anymore.
On the other hand, if the fine is % income or anything but % gross receipts, then of course the system will be gamed endlessly by accountants and lawyers to show the smallest possible net number. The end result might be worse than a fixed fine. So % of revenue it is.
GDPR, 4% of Global revenue and your Directors can be barred from operating in the EU.
Will Germany actually take a swing at Volkswagen? Will Germany try to go after those that defrauded the government with cum-ex-trades?
Everybody vs banks regarding the Libor scandal? Sure, they paid some fines, but the fines were far below the damage done, and it appears to still have been a good investment for the banks, that is: all in all they made money, fines included.
Crime does pay at that level.
That's not something US specific, I believe.
Yes, large corporations can get away with much more in other countries as well, but rarely by outpaying their opponents.
(Yes, the US does have some new problems with private laws being passed, where the public is not allowed to know the law itself - and this opens up huge scary things. But that is not what is being discussed here and I don't believe is relevant.)
Yes. 100%. "I was just following orders" is not a valid excuse, ever - Nuremberg is the obvious extreme example, but it's true everywhere.
When the orders are to do something that is plausibly legal, and you have good reason to believe that it is in fact so, "I was just following orders" will probably work in most jurisdictions.
If it's either obviously illegal or it's clearly at least dodgy and they didn't get explicit confirmation from the project lead, "following orders" is not a valid excuse.
To take the VW case as an example: if your project lead tells you to implement a way to recognise test conditions and adjust the performance to reduce emissions, that is dodgy af and you should at least get confirmation that this isn't illegal (i.e. that it's not intended to cheat on certifications but maybe just for certain internal testing scenarios). In the end the entire chain of command that led to this being implemented is guilty, but if the person implementing that behavior knew what they were doing was illegal or at least suspect and they didn't get confirmation, they're still guilty.
How do you expect the developer to figure out its illegal when a team of lawyers couldnt?
Facebook claims to "value privacy" (and some devs have even told me that they value it "more than any other company") but their actions consistently show either neglect or outright abuse.
Should a developer be punished for implementing something illegal that the legal team signed off on and that wasn't obvious illegal? No, because the legal team is supposed to take the responsibility and if it wasn't obviously illegal the developer had no reason to assume the legal team was lying.
Should a developer be punished for implementing something obviously illegal even when the higher ups say "don't worry about it"? Yes. If your boss tells you to rob a bank, you still go to prison for bank robbery.
For everything in between: whistle blowing is a thing. If you suspect something fishy is going on, document everything, raise concerns and report what is happening.
Also if you are a well-paid employee in a position where you can easily find another job in the industry, speak up to your superiors and refuse to be complicit. Organise.
> A Facebook spokesperson said before May 2016, it offered an option to verify a user's account using their email password and voluntarily upload their contacts at the same time. However, they said, the company changed the feature, and the text informing users that their contacts would be uploaded was deleted — but the underlying functionality was not.
I doubt it was an engineer who deliberately removed the text but kept the contact import functionality.
Engineers who make mistakes that harm people are still responsible for the mistakes they made. You cannot just claim "it was a bug" and get off scot free if your code harms someone or otherwise breaks the law. Also there's no need for this sarcastic tone, "have you never..?"
> I doubt it was an engineer who deliberately removed the text but kept the contact import functionality.
Why would you doubt that? I personally think that situation sounds quite likely. But either way we're just speculating.
Also, don't ignore the part of the parent comment that discusses the manager's (and implied other decision markers) that result in the decision being made to make an illegal change to the code.
Engineer, or manager, or QA assistant - someone or some group of people will have made the change. And "oops that was a bug" doesn't count. Corporations and their employees must be held to the same laws and standards to which the rest of us are held. "Ooops I didn't mean to do that" doesn't fly as an excuse to break the law.
The problem though is that software engineering doesnt require any licensing requirements, etc. so one can always refer to incompetence being the problem (ooops a bug) and might get away with it.
Someone who works at FB even came out and said so:
"Remember, what Facebook is doing has never been done before. There are going to be mistakes."
https://news.ycombinator.com/item?id=19321420
So yeah, I think what that person is saying should be translated as:
"Please don't think twice about punishing rank-and-file FB engineers. We are so competent, all our mistakes have only been intentional ones."
There doesn't seem to be any debate that Facebook broke the law - just debate about what the punishments should be.
The FB/Zuckerberg combination is almost unique in terms of (1) market cap, (2) the controlling ownership he holds, and (3) behaviour of the firm.
Facebook is reputedly pedalling furiously behind the scenes to prevent Zuckerberg himself being charged. Whilst saying almost nothing about the fines. That says everything about where they see the real danger.
I do agree that fines are overused, but I don't think there's reason for sending anybody to prison on this case.
Could you imagine the absurdity of them passing down a verdict of “and they shall be fined a billion per month until their stock price falls by at least 10%!”
If a punishment no longer deters bad behavior, then it's no longer a punishment.
The problem isn't how open they are, it's that most people don't understand what the harvesting means. Facebook could have asked for the sacrifice of the firstborn and people would have snapped it up on the prospect of a few likes on their fake online alterego. It's human nature and the HN echo chamber exists far outside that normalcy. Most people don't "get it" (through no fault of their own) and that's why it's dangerous [edit] and effective.
From what I read FB had a "bug" where the feature was not removed properly, so the text about harvesting was removed but by "mistake" the harvesting code was left running.
At least that's the story I've heard about why this was an "honest mistake".
Besides Facebook I can think of LinkedIn and Mint as two big examples of SaaS that ask for 3rd party passwords. Mint is even getting your banking information, whereas LinkedIn and Facebook were just doing contact import.
And of course before the era of SaaS giving applications passwords was normal, e.g. putting your email passwords into an email client like Eudora or Thunderbird. It only really becomes questionable in SaaS where the passwords inevitably end up on a server somewhere subject to a data breach, or, in Facebook’s case, misuse by another piece of its own software.
> A Facebook spokesperson said before May 2016, it offered an option to verify a user's account using their email password and voluntarily upload their contacts at the same time. However, they said, the company changed the feature, and the text informing users that their contacts would be uploaded was deleted — but the underlying functionality was not.
> "Last month we stopped offering email password verification as an option for people verifying their account when signing up for Facebook for the first time. When we looked into the steps people were going through to verify their accounts we found that in some cases people's email contacts were also unintentionally uploaded to Facebook when they created their account"
so Facebook discovered this bug in an audit of its code, fixed it, and planned to notify everyone who was impacted.
I can give a dog walker or cleaning personel the keys to my apartment, still if they steal stuff and I have evidence they will be prosecuted. It's not a bug that they don't have business ethics.
BTW, just in case you are unaware, Equifax got away with this hack with zero fines in US.
Most of the other Facebook data breaches where they didn't secure data accordingly would compare more to what you refer to.
This case is different though as Facebook performed unauthorized actions on email accounts, basically breaking in.
A bug is a bug. Whether it allows a hacker to sneak in to steal all your data or whether it allows a company to collect data it wasn't supposed to (as in this case Facebook specifically mentioned that it didn't turn off the feature though it intended to).
What you are describing here is in fact a lack of action, or a lack of change policy (to cause such action). That's not a bug. A bug is unintentional behaviour of some code, not some folk who've said they'll do something, but then don't.
And as for whether the original behaviour is/was a bug is also a point of contention too: that's a lot of willfully bad behaviour that's got chained together somehow to do what it did, then reviewed, signed off, and deployed — that's quite some 'accident' — I write code, and to me this whole thing just smells of a cover-up (by FB calling this a 'bug', when it very much looks to be otherwise).
I doubt it, so it seems that we're just bickering over whether the accidental removal of the message is considered a "bug" or a malicious act by some engineer to trick users into sharing their data because they (and their company) lack business ethics.
Which is more likely?
Maybe a complete engineering stop for a few months, and development of new practices and processes.
Similar to what Microsoft did with Bill Gates Trustworthy Computing memo which led to the creation of the Secure Development Lifecycle is something Zuckerberg should order to do.
https://www.businessinsider.com/facebook-uploaded-1-5-millio...
I remember maybe 8 years ago it was here on HN that a company was found to be doing this and it was shocking to some. But an executive of that company showed up here and said that "everybody does it" and it's "standard practice" and for some years after that anyone complaining about the practice here was not only downvoted but sometimes warned by our glorious compromised moderators.
In my opinion the practice of contact list ransacking should never be allowed, is clearly unethical, and anyone defending it is an enemy of humanity who should be locked away in order to protect society.
Sidenote: I bet you could make a business out of tracing derived data to comply with lawful orders.
(Just hearsay, not affiliated with Palantir in any way)
The US government has always controlled the internet. It just made the strategic decision that having a 'free speech' platform accessible to the thought leaders of the 21st century between 1980 and 2010 dealt more damage to its enemies than to itself.
Now that the internet is reaching the majority of people it's gotten worse, more regulated and less free. One only need to look at the 2016 election with it's 'fake news' and compare the US reaction to that of, say Iran in 2009 and see very little difference in rhetoric between the two countries.
https://eu.democratandchronicle.com/story/news/politics/alba...
TLDR Scammed consumers twice, gets to keep doing what it was doing.
"Charter and the Department believe that this action is an important step forward" indeed
Well, put like that, it sounds just like they did it as a planned A/B test strategy (like they do to trial other features) — and, personally, I believe this to be the case.
Deploying such code/functionality is hardly an accident/bug.