FTC Imposes $5B Penalty and Sweeping New Privacy Restrictions on Facebook
ftc.gov
ftc.gov
* Facebook is prohibited from using telephone numbers obtained to enable a security feature (e.g., two-factor authentication) for advertising;
* Facebook must provide clear and conspicuous notice of its use of facial recognition technology, and obtain affirmative express user consent prior to any use that materially exceeds its prior disclosures to users;
* Facebook is prohibited from asking for email passwords to other services when consumers sign up for its services.
This might, at first blush, seem like a win for users, but consider it from a different perspective.
When a settlement involves promising not to do a bunch of really, really bad stuff, that typically means the settlement doesn't have much bite. It's comparatively easy for a company to agree not to do egregiously bad things, and comparatively harder for it to agree not to do things that are still problematic, but less egregious.
These things that Facebook has agreed to not do are way outside the boundaries of ethical privacy practices -- but there's still a ton of gray area that remains unaddressed.
So from Facebook's perspective, this is probably a big win. The settlement allows the company to give the appearance of taking concrete steps to respect users' privacy. But what it might actually mean is that there were many other less egregious privacy violations that it was able to slip past the FTC's judgment.
This is exactly what made me quit Facebook a while back. Started to spam me with notifications when I only wanted to add a backup number.
oh wait theyre dealing ankind of drugs too . .
Whatever privacy review Facebook was undergoing like once a year was done by a private firm that Facebook could pick and then have to pay. So is it any wonder that those so-called privacy auditors have found nothing wrong with Facebook so far in 8 years? (even as the privacy scandals and Facebook's apologizing perpetuated in the media).
These types of settlements are a joke. There's zero doubt in my mind Facebook already has a plan for how to work around these restrictions and do 90% of what it's already been doing anyway.
As a side-note, does anyone still believe Facebook was genuine about getting Facebook female users' naked pictures "to protect them from revenge porn" genuine?
They've already lied about collecting the phone numbers and facial recognition as being used for security. And those were obvious lies to me from day one, too. Pretty much every new feature Facebook launches that seems good for users has an undertone of "...and this is how we'll track you now."
What they do is issue settlements, Facebook agreed to this fine, and to the conditions surrounding it, because if they didn't they might face hard, law based regulation from Congress.
The issue here is, the FTC process relies on good faith from the companies it settles with, and Facebook has repeatedly shown to be a bad faith actor in this regard (which is why its a 5 billion dollar fine to begin with)
The only way this is going to end is with very onerous regulation from Congress.
- Asking for email password: https://arstechnica.com/information-technology/2019/04/faceb...
- Targeting ads using phone numbers obtained through two-factor authentication: https://www.engadget.com/2018/09/28/facebook-two-factor-phon...
- Improper use of facial recognition: https://www.npr.org/sections/thetwo-way/2018/04/16/603056662...
>the FTC alleges that Facebook violated the FTC Act’s prohibition against deceptive practices when it told users it would collect their phone numbers to enable a security feature, but did not disclose that it also used those numbers for advertising purposes.
>The FTC also alleges that Facebook misrepresented users’ ability to control the use of facial recognition technology with their accounts. According to the complaint, Facebook’s data policy, updated in April 2018, was deceptive to tens of millions of users who have Facebook’s facial recognition setting called “Tag Suggestions” because that setting was turned on by default, and the updated data policy suggested that users would need to opt-in to having facial recognition enabled for their accounts.
But really, this is how organizations should be run: there should be a user-privacy-focused resource inside the company that can work with product to guide how features get implemented. (The same goes for accessibility, technical feasibility, and other things that product people aren't necessarily measured against.)
Facebook is not alone in misuse or wrongful use of phone number given for 2FA. LinkedIn explicitly requires phone number to be added on the profile to enable 2FA and makes the phone number visible by default to all the contacts, if you don't want your phone number visible; you'll have to loose 2FA as LinkedIn doesn't support authenticator or other alternate 2FA means(FB does).
I came to know this as after I enabled 2FA on LinkedIn, I started receiving messages from random people on WhatsApp whom I later found to be my LinkedIn contacts.
Here is a direct link: https://www.linkedin.com/psettings/two-step-verification
It really made me wonder what other shady stuff they might be doing with my and my customer’s data.
$5 billion is a lot, but Facebook is huge. Even considering, it's probably not pocket change for them, but they are getting a benefit from it for sure. They are buying public opinion.
"Look at us..we took a big fine and agreed to respect your privacy .. you can trust us now." It's essentially a very expensive ad, used to rebuild trust with their cattle; I mean users.
The FTC settlement indemnifies Facebook for "any and all claims prior to June 12, 2019"
"As part of Facebook’s order-mandated privacy program, which covers WhatsApp and Instagram, Facebook must conduct a privacy review of every new or modified product, service, or practice before it is implemented, and document its decisions about user privacy. The designated compliance officers must generate a quarterly privacy review report, which they must share with the CEO and the independent assessor, as well as with the FTC upon request by the agency."
I've never heard someone express the point you're making: can you think of any example where the PR impact turned out that way?
If they agree to not do bad things, then do the bad things, seems then we have a bad actor.
I doubt that any individual or lawsuit could affect this kind of change.
The only reasons these specific prohibitions are spelled out is because Facebook is known to have specifically performed these acts in the past.
The GDPR has it's flaws, but at last Europe has bitten the bullet and faced up to their responsibility to protect consumers and reign in privacy abuses. It's about time US lawmakers got their act together.
It does feel like they confessed and repented a few spectacularly egregious sins and bought a $5 billion indulgence for the rest.
they should get even stricter
force them to relinquish the absolute control of the founder/ceo, enable voting rights and more
investors are undiscerning and exchanges are not creating ultimatums for listing, so these founder privileges are only revoked after they mess up really bad which is cool
being fined 25% of annual profit (2018 $22.111bn) is probably not "a big win".
But yeah, the business terms of the settlement are surely inspiring a champagne toast back at HQ.
In fact you should probably subtract the direct costs to users, as there is already a mechanism in place for collecting damages, and any government intervention on this axis should go to something reminiscent of a victim's fund.
If I'm worried about Facebook's use of my data the answer is simple: stop using Facebook.
That's why I keep saying all the hypothetical privacy concerns with Facebook's Libra already are reality with the current financial system. Equifax also didn't get fined because of what they were doing, but because they were negligent in handling the data.
Having said that, given the importance of consumer debt in the US economy, credit bureaus are indispensable. They aren't going away any time soon.
What is happening to Facebook can be good for everyone. Because if the FTC cracks down on them then it sets a precedent to crack down on the credit agencies. Clearly people will go after them if that happens.
Sure, this should never have been an issue, but just because someone else is currently doing something doesn't mean that it ever was the right thing to do. Even if legal. Let's stop this BS "but they do it" and change the conversation to "they're doing it to, let's make sure they also are stopped."
I'm not saying "it's okay". It is what it is. I'm saying we're applying a double standard. It's like complaining about lighting a match in the middle of a wildfire.
> Because if the FTC cracks down on them then it sets a precedent to crack down on the credit agencies.
That makes no sense me. They can crack down on Libra for any number of reasons. They're clearly okay with what the credit bureaus are doing right now, why wait for Facebook to come along and do the same?
It's like complaining about lighting a match in a dry area while there is a fire somewhere in California.
FTFY
The analogy is bad because the match in the middle of the forest fire won't affect the fire. You're already engulfed in flames. What we're taking about is two different sectors. They are disjoint (unlike your analogy). But you can be in Oregon while it is dry and see that someone started a fire in California with a match and say to your friend "hey be careful with that match. That's how the fire started in California. We don't want that to happen here."
> That makes no sense me.
1) just because it doesn't make sense to you doesn't mean it's incorrect.
2) law works highly off of precedence. So one ruling affects new ones that come in. They keep try to be consistent.
3) just because people/laws are "okay" with something now doesn't mean it can't or won't change. In fact, I'd argue that's why new laws get made.
I obviously disagree. It's the essentially the same sector (consumer finance). Some of the involved companies (Visa, Mastercard, Paypal) are core players in that sector.
> 1) just because it doesn't make sense to you doesn't mean it's incorrect.
Indeed, it just means you failed to connect premise, analysis and conclusion to meet my personal standards for a sound argument. It might be incorrect too, but I'm not in the position to demonstrate that.
> 2) law works highly off of precedence. So one ruling affects new ones that come in. They keep try to be consistent.
That argument works the other way around too: It would be inconsistent to turn a blind eye to credit bureaus for all this time, but now that Facebook comes along, suddenly it's a problem? Why? Just because it's Facebook?
> 3) just because people/laws are "okay" with something now doesn't mean it can't or won't change. In fact, I'd argue that's why new laws get made.
Again, this argument works both ways. Just because people aren't okay with something doesn't mean it can or will change. You are not adding any new information to your argument.
That sounds like implicit permission at best.
This at best would qualify as implicit consent. Which is very different and not sufficient. There should at the very least be a big button you have to press for every agreement you enter into that shares data with credit bureaus that clearly states that you: 1) consent to sharing all of your transaction data with credit bureaus 2) are aware of the various ways the credit bureaus might use your information 3) are aware of the potential consequences in practical terms of how this usage might impact your life 4) are informed about the way the data is stored/who has access to it/what your rights are surrounding it
I would also like to see GDPR-style "right to be forgotten" laws that apply to this data.
It doesn't, I'm just using your umbrella term of "participating in the modern financial system". Read the terms of service you agreed to for the various financial services that you use. You'll find something akin to "we can share (aggregates of) your data with our partners". This is explicit consent.
> There should at the very least be a big button...
Fair enough, but I don't think it would really change anything. After all, what's the alternative to "participating in the modern financial system"?
If you don't want Equifax to have your private information, just don't participate in the modern financial system!
Don't forget to stop using every website that embeds facebook buttons (or block the scripts). It's not exactly easy to prevent facebook from gathering information either.
This doesn't stop them using your data obtained from other users.
I'm still happy to see our lesser enemies be curtailed.
Just as it bother's me that there are kids starving in africa... but I still donate to my local food bank. A worse evil doesn't mean we can't improve on other evils.
Remember when a gram of crack got you the same prison time as 100g of cocaine?
Is this a step in the right direction? IMO, yes.
To be clear, I dislike the FTC. But I believe power is corrupting in itself, so ipso facto the powerful will be corrupt or at least soon corrupted. That's why I want to see checks and balances. The guards of the guards... all lined up in a circle ideally. We aren't there, agreed. But I'll take any step toward that as a win.
FB allowed the exporting of all sorts of data, from your relationship status, demographic and contact information, information on employers, interpersonal relationship graph to companies who used it to mine information on you without your explicit knowledge (you could refuse them access, but as soon as one of your friends allowed it, your refusal became moot).
Then it built a whole bunch of tooling and ecosystem around this industry. Then it made a lot of money from it.
Then it played dumb. "We didn't know", "We don't allow it, even though we built tools for no other purpose than to facilitate it", and so on.
A little more nefarious than "your friends can tell someone you listen to this band".
It bothers me that Equifax exists and is as shitty as it is. But it doesn't bother me at all that intentional maliciousness is punished harsher than incompetent negligence. The degree of the crime matters, too, of course, but this wouldn't be entirely dissimilar to the idea that homicide is a harsher sentence than involuntary manslaughter.
https://twitter.com/chopraftc/status/1154010756079390720
One that stood out for me is complete immunity for for the execs for "known" and "unknown" violations:
"Mark Zuckerberg, Sheryl Sandberg, and other executives get blanket immunity for their role in the violations. This is wrong and sets a terrible precedent. The law doesn’t give them a special exemption. The settlement fine print gives Facebook broad immunity for “known” and “unknown” violations. What’s covered by these immunity deals? Facebook knows, but the public is kept in the dark."
It makes their jobs (LEO) much easier. They are not going to shit where they eat.
That's exactly the violations I figured they were getting immunity from. I mean, let's be real, they're not going to undo any of that, and they likely want to make sure that any new social nets set up the same facilities for them.
[0] https://en.wikipedia.org/wiki/Federal_Trade_Commission#Curre...
What stood out for me were the two dissenting statements by Commissioners Chopra and Slaughter.
https://www.ftc.gov/system/files/documents/public_statements...
https://www.ftc.gov/system/files/documents/public_statements...
Chopra disagreed with the decision not to charge the `bergs and noted that in the Cambridge Analytica case the former CEO was charged.
Slaughter believes that there was sufficient evidence to name Zuckerberg in a lawsuit.
It is possible that Facebook fears Mark Zuckerberg being subjected to court-ordered discovery and put under oath. He came very close in a shareholder lawsuit some years ago and Facebook settled on the day before he was to testify.
I realize that misses FB willfully doing what they did and Equifax not intending to be hacked, but for me my consent is equal or more important than what the holders of the data did after they had it.
Let's say I send a saucy picture to a friend and s/he shoots it all around to show off his/her banging bodied boyfriend (that being the "profit" factor). Now let's say a stranger finds my lost phone, gets the picture off the SD card with intent to use it for some personal gain, and through some series of events that gets leaked. Who did worse, the friend sharing the data I gave to them, or the stranger who got it without permission? Missing from this is Equifax had a lot more sensitive information than I put on FB.
I honestly don't know which answer here is supposed to be the obviously correct one.
1) how can you give proper consent if it takes a great deal of expertise to understand what you're getting yourself into (never mind that complexity doesn't come across, but that's a good question too. About conveying complexity).
2) can consent even be given if we can't be fully informed? Or rather how informed do you need to be to give consent?
I just don't get the analogy.
Equifax compiled that information from vendors very similar to Facebook.
Frankly, I'm surprised and disappointed nobody here has started a class action to go after both Equifax, as well as the companies who shared my data with them without my explicit consent.
The issue is Equifax not being fined adequately. Let's maybe not use that as the bar?
Also, you seem to be OK with the idea that any company that gets hacked could be fined $5 billion. As being unhackable is an unachievable standard, that effectively means the FTC could bankrupt almost any company on a whim. That would be huge power in their hands and would not magically stop exploits from happening.
I think there's a big question about whether Equifax should have been fined at all. It would appear to either require mass inconsistency by regulators, or would put most US companies that rely on IT out of business.
> Are you assuming here that Equifax could absorb any size of fine?
Who said any size of fine would be appropriate? There is a lot of possible fine size between 500M$ and the max they could absorb.
> Also, you seem to be OK with the idea that any company that gets hacked could be fined $5 billion
Where did I say that? I am OK with facebook getting fined 5B$ in this context, that doesn't tell you anything about other hacks and other companies. I am also a little bit reluctant to call facebook's case a "hack".
> I think there's a big question about whether Equifax should have been fined at all. It would appear to either require mass inconsistency by regulators, or would put most US companies that rely on IT out of business.
You should maybe think outside of the tech bubble for one second? What you find apparently unthinkable is already in place in many other industries. Do you think there will be no repercussion for Boeing's crashes if it was caused by their carelessness? What do you think happen if an engineering company builds a bridge and it collapses because of a design mistake? Yet mistakes are human right?
Private data is something that should be protected. It is not as important as human lives, but it is very important. If you build a business around handling user's private data, but can't be bothered to properly protect them, then yes you should get fined heavily or even put out of business.
And just like in engineering there should be investigations into what happened to determine how much of it was pure carelessness and how much could not have been realistically prevented. In the case of Equifax, they didn't even bother applying security patches to their external facing software.
But despite how tempting it is to punish people who make mistakes, it's generally understood that incompetence is not illegal and should not be. Criminalising incompetence just makes everyone a criminal and hands absolute power to prosecutors and regulators: a scenario warned against many times by students of history.
I'm not disagreeing with this, but my understanding is that in the UK I'm always asked explicitly before sharing my data with credit agencies, and have been as long as I can remember?
This is actually the big thing here. Any disclosure or breaking of the data makes Mark Zuckerberg personally liable.
We'll see if that gets Facebook's attention at all.
The interesting part is in the write up from The Verge (https://www.theverge.com/2019/7/24/20707013/ftc-facebook-set...):
> "The settlement’s $5 billion penalty makes for a good headline," FTC commissioner Rohit Chopra wrote in his dissent. "But the terms and conditions, including blanket immunity for Facebook executives and no real restraints on Facebook’s business model, do not fix the core problems that led to these violations."
$5 billion of cost with shareholders' money. Not bad.
Facebook ceasing to exist is probably not a bad idea, but it's rather unrealistic.
"As part of Facebook’s order-mandated privacy program, which covers WhatsApp and Instagram, Facebook must conduct a privacy review of every new or modified product, service, or practice before it is implemented, and document its decisions about user privacy. The designated compliance officers must generate a quarterly privacy review report, which they must share with the CEO and the independent assessor, as well as with the FTC upon request by the agency."
Facebook has to _document_ what they're doing in the privacy world. They have to prepare a report of what they did, and be willing to share it, and accept the consequences (which they already effectively do, just more opaquely).
At no point does the compliance officer have to _approve_ "how they handle privacy data any more", nor the independent assessor, nor the FTC.
They still have complete control over how they choose to behave and steer. They just have to report on it.
The FTC settlement indemnifies Facebook for "any and all claims prior to June 12, 2019"
At some point, wouldn't it be simpler to have the same policies globally? Or is that too simpleminded?
But maybe that doesn't apply as much to online stuff. Because marginal cost isn't so sensitive to volume.
>Facebook is prohibited from using telephone numbers obtained to enable a security feature (e.g., two-factor authentication) for advertising;
>Facebook must provide clear and conspicuous notice of its use of facial recognition technology, and obtain affirmative express user consent prior to any use that materially exceeds its prior disclosures to users;
>Facebook must establish, implement, and maintain a comprehensive data security program;
>Facebook must encrypt user passwords and regularly scan to detect whether any passwords are stored in plaintext; and
>Facebook is prohibited from asking for email passwords to other services when consumers sign up for its services.
This is great! What do we need to do to get this to apply to other data harvesting companies like Google and Microsoft?
That applies to Google and Apple, no? To apps in their stores.
Why are they storing passwords at all? It's not necessary for authentication. They should only be storing a hash, or better yet a public key derived from the password on the client.
I question your distinction. Toxic behavior is largely caused by people not caring about harm caused to others.
I think we all agree that Facebook takes really good care of their employees and keep them happy, whatever it takes. That doesn't prevent the company to produce a product that is toxic to humanity. It is of course difficult to see that when you are extremely well paid and your salary depends on you producing that product.
Zuck: I have over 4,000 emails, pictures, addresses, SNS
[Redacted Friend's Name]: What? How'd you manage that one?
Zuck: People just submitted it.
Zuck: I don't know why.
Zuck: They "trust me"
Zuck: Dumb f*s.
One reason Facebook came to dominate over older social networks was that they provided much, much better user privacy controls, they were better at keeping fake users off their networks and they kept the site more secure. Before Facebook social networks didn't have APIs and thus didn't have permissions - everything just scraped the (always public) profile pages.
Moreover many of the things they're being rapped for here aren't even betraying user trust. I believe the only time they've ever asked for passwords for third party services is to import friend lists. That's a useful and optional feature. If a mail provider doesn't have an OAuth style API, how else is it meant to work?
I know everyone has decided it's cool to bash Facebook because they're big and use advertising. But when I look at the actions of the FTC here, I wonder how on earth such trivial things turned into such a huge fine. Advertising doesn't kill anyone, and targeted advertising is much preferable to the noisy punch-the-monkey type of barrel scraping ads the internet used to be filled with. If they use a phone number to better target ads to me (presumably regionally) how is this any different to using my IP address? At worst it means I see more local businesses. Yeah, if they'd had some small print somewhere, a few people would have cared. Most wouldn't and we know this because they use WhatsApp which already gives Facebook your phone number. Big deal?
I just can't get worked up about these trivial "evils" that mostly exist for my own convenience, or which are irrelevant given the set of services me and all my friends use i.e. Facebook gets the same data anyway voluntarily. Why am I the only one?
He WAS the CISO for Facebook during all the biggest scandals. He WAS the person responsible for overseeing all of this.
He decided conveniently to exit Facebook once the bad press came over and now he is trying to play the "expert card" on everything related to security and democracy. It's really a shame that we don't keep him more accountable.
Should we expect to see some of these prohibitions generalized to more companies?
* Facebook is prohibited from using telephone numbers obtained to enable a security feature (e.g., two-factor authentication) for advertising
* Facebook must encrypt user passwords and regularly scan to detect whether any passwords are stored in plaintext
* Facebook is prohibited from asking for email passwords to other services when consumers sign up for its services
Yeah, I'm honestly surprised that one wasn't already illegal.
"Americans are biased toward thinking of bad things as being already illegal, always illegal, illegal by definition and by nature and in themselves. If the thing that Facebook did was so bad, then it must have been illegal, so there is no need for a new law against it. At most we need a settlement with Facebook clarifying exactly which things it did were illegal and specifying that it won’t do them again."
Before Mark Zuckerberg (and possibly now Google), we didn't really have anyone abusing personal data to such an extent that what they are doing is clearly, to the average person, wrong. Dumping toxic waste into waterways/letting it reach the groundwater is probably a similar example.
Every now and again an individual, company or industry comes along who is callous enough to make money off the things that surely must be illegal before and until they actually are.
The campaign finance laws in the US are a joke and it would be easy for them to bribe politicians with campaign assistance.
A good way to put it is that the stock price would not have changed by more than a few percent today anyway, but in a world with no fine the starting price would have been higher. And in a world where we see more and more 5 billion dollar fines, they'll be less and less shrugged off as one offs even without increasing penalties.
A fine of a size that exceeded their free cash ($40 billion) would have given FB a huge incentive to clean up their act. A fine of this size is nothing but a toll to pay.
> Any false certification will subject them to individual civil and criminal penalties.
Facebook is required to _report_ how they handle privacy data. They can choose what that handling looks like. They just have to accurately describe that. The false certification is related to materially false statements in the _reporting_. How they handle privacy data is still up to them (albeit potentially subject to future sanction if problematic), but this definitely does _not_ state that Zuck will be subject to criminal liability for future privacy problems.
It is also sad that Facebook is still seen as a somewhat prestigious employer. Some of my friends still brag about working there as if it was the pinnacle of their tech career.
Most (all?) federal fines are this way, although if they specified that some of the total were to be used for direct compensation to victims, then that could be included in the total as reported by the media but obviously wouldn't be spendable by Congress.
I can't point to a case where that's ever happened, though, so the answer in practice is "the US treasury".
> Following a yearlong investigation by the FTC, the Department of Justice will file a complaint[0] on behalf of the Commission alleging that Facebook repeatedly used deceptive disclosures and settings to undermine users’ privacy preferences in violation of its 2012 FTC order. These tactics allowed the company to share users’ personal information with third-party apps that were downloaded by the user’s Facebook “friends.” The FTC alleges that many users were unaware that Facebook was sharing such information, and therefore did not take the steps needed to opt-out of sharing.
So does this settlement correspond to that complaint? I'm guessing that it must. But then, that means that the FTC negotiated the settlement with Facebook based on an unfiled complaint. That rather implies that Facebook had some influence over the complaint.
I guess that's not very different from plea bargaining in criminal cases, however.
0) https://www.ftc.gov/system/files/documents/cases/182_3109_fa...
Has this happened to anyone else? Is there anything I can do besides creating a new account with the right email address?
So does this in theory apply just to the data of FB users who are American citizens (although I guess practically it may not be feasible for FB to treat non-American user data differently)?
Provide easy means for users to permanently delete all information, posts, comments and messages, as well as a setting to automatically expire and delete all if the above as desired. This should include backups.
If by external backups you mean my cousin copying one of my photos and saving it or something like that, sure, I take your point. However, I think you understand exactly what I mean. There's a massive difference between that and Facebook having an entire record of my life, complete with tags, pictures and classifications, all of which I have exactly zero control over.
And, no, social media does not exist to facilitate law enforcement investigations. If that is their primary purpose they need to disclose it. It so happens that it can be used that way, but we should not pass legislation based on the possibility of law enforcement using these databases to effectively spy and reach for people's private information.
Cautionary tales abound, incuding:
Gonna make so much money robbing these banks.
Edit: yep, lots of them.
net profit.
And accounted for over the last few quarters already.
Probably an unintentional but more accurate representations than what they had in mind.
Then again, if they take it out of circulation, maybe it is a net gain for everyone?
Props to the FTC for the size of the fine and the detailed explanation, not so good that the perps get to walk - again.
So, basically free.
> Facebook monetizes user information through targeted advertising, which generated most of the company’s $55.8 billion in revenues in 2018
Thus, all the money they make. All of it. The FTC now takes a small portion.
See Facebook care. (not)
If you think the government ought to just ban Facebook, sure, whatever, but that's not the FTC's job.
5B is one time 25% (or 9% of 55.8B revenue) tax. It's a far cry from a joke; certainly it's higher than AZ or other members of FAANG pay, while not outright terrible.