Facebook fired an employee who was paid bribes to reactivate banned ad accounts
buzzfeednews.com
buzzfeednews.com
I'm confused. If anything, this seems to me like evidence that Facebook is holding people accountable for violating regulations on the platform.
> “For over four years, I have raised concerns to the [Federal Trade Commission] that behavioral advertising markets are rife with fraud – not just in the form of clickfraud but, exploiting the scale of large platforms, in scams and criminal schemes that directly exploit American consumers,” he said in a statement. “Because of Section 230, neither the victims of these schemes nor state [attorneys general] can seek to hold the platforms accountable for their continued facilitation of these frauds.”
Which suggests that he does not want to rely solely on Facebook policing itself for accountability.
How do you think mafia operates in Italy? They infiltrate their solders in every part of the government (especially local government), or even private companies where they have interests.
If they can't, then they bribe them.
In general, fraud against the company.
In this specific case, you might be able to throw in conspiracy to violate the CFAA.
Using new laws:
I would be perfectly happy to have a "corporate espionage/bribery" law that made it criminal to accept money personally to change your behavior as an agent of a company. I would prefer it if that law only applied when you and the company opted into it via a contract to minimize disruption to any existing schemes where that is considered acceptable behavior.
Even if it wasn't, that just means when drafting the law basic care needs to be taken. The same could be said for practically every law.
You are right, and this was more or less my point. Drafting a law is hard work - but the kind of handwaving armchair advice that you often see to "just make a law for this" does not recognise that it is very hard to do so. It's even harder to do it in a way that is right for everyone and with the political landscape being the way it is and lobbying working the way it does it's far from a foregone conclusion that such an effort will yield the desired result.
As for prosecution (whether civil or criminal) - I don't know, if there's a law that can enforce it, should that not be on the table? And if there isn't, then perhaps there should be?
(Yes, yes, it'd be hard to pass, but)
Likely the bad actors would still find a way around it, too. What's a little criminal collusion amongst coworkers for profit.
As much as I hate crowder for example, he ensured that most of his income comes from advertising his own store and products, so being demonetized for repeatedly violating YT policies didn’t actually cost him much.
What if this wasn't an isolated incident and only one that got caught? What if the person who took the bribes was part of a ring?
Corporations have a strong incentive to NOT root that out as it has negative image.
Isn't this the opposite of the corporate veil? The corporation is not being treated as a person, and the actual person is being held responsible.
The issue at hand is a) us knowing that fraud was perpetrated and b) appropriate jurisdictions being able to try that individual for fraudulent actions.
Neither is present today. Facebook polices its own employees and if those employees were important enough you'd bet they would not release that information nor hold those employees accountable.
So, you're describing the opposite...right?
What the "corporate veil" generally protects are investors -- only the actual amount invested is at risk, rather than more, or all, of an investor's assets.
The veil can also be used to shield specific executives, another common complaint.
But a third mode is when a sacrificial scapegoat, often relatively low on the hierarchy, is identified and blamed for problems. That shows up in government as well as the "one bad apple" excuse, which both fails to address true accountability and justice, and massacres the metaphore, which is "one bad apple spoils the barrel".
A lone actor should not be able to behave in such a manner, and is quite probably not acting alone. The oversight, detection, and cross-checks which should be required to be in place clearly aren't. That would include the individual's business unit and management chain, as well as the company as a whole.
Note that I didn't use the term "corporate veil", and I'm not entirely certain it applies here (see one definition: http://www.businessdictionary.com/definition/corporate-veil....), though in the sense of shielding the larger part of the corporation and individuals within it, the argument could be made.
Understanding business as a sort of "risk shedding engine" may help. The corporate veil is one mechanism for this, but another is the creation (or post-incident assignment of) what's effectively an ablative heat shield -- some component of the corporate structure, often a single individual, up to and including a CEO, though business units, subsidiaries, contractors, or largely-controlled corporate charities and trade organisations are also used -- which can be shed or discarded as needed.
So the "turnaround CEO", the management consultant organisation, the "rogue employee" (anywhere from the front line to the executive suite), the subsidiary, the spin-off, the "charity" or "trade organisation", all fit this bill.
For CEOs, see Albert "Chainsaw Al" John Dulap (obituary: https://www.nytimes.com/2019/02/05/obituaries/al-dunlap-dead...), or Martin "Pharma Bro" Skrelli. An argument could be made that many major politicians operate in this mode -- the argument might be made for a Boris Johnson, Mitchell McConnell, Fritz "The Senator from Disney" Hollings, who serve as the public exposure of their respective interest groups. "Trade organisations", particularly with an enforcement arm, such as the MPAA, RIAA, and BSA, largely represent firms in the cinema, music recording, and software industries, respectively. Various "think tanks" such as those in the Atlas Network (https://www.atlasnetwork.org/partners) allow specific interests, usually business, industrial, and generally the wealthy, to engage in activities at a slight distance. Many of the Atlas partner organisations are strongly associated with the Kochs, Scaifes, Bradley, Searle, Walton, DeVos, and others. (See: https://www.sourcewatch.org/index.php?title=Atlas_Network https://www.sourcewatch.org/index.php?title=State_Policy_Net..., and related articles.)
In this case, Facebook are avoiding corporate liability, legal risk, and goodwill erosion by blaming a "rogue employee". That strikes me as an incomplete fault analysis, and one that's overtly and obviously self-serving to Facebook, its management, and shareholdes. Most of which are synonymous with Mark Zuckerberg.
1. I'm still working through my thoughts on this.
2. The key point is not "corporate veil" but "legal and operational concept of corporate structure as a risk externalisation engine".
Under that second, the "corporate veil" is a part, but not all, of the externalisation mechanism. And would make the short response to your reframing: "No".
More subtly, it's not essentially necessary for the externalisation to be a deliberate strategy -- a conspiracy -- though that probably is often the case. There are emergent phenomena a and behaviours, and given that risk externalisation is, in both the short and medium terms, generally, profitable (that is, it decreases costs and increases revenues), there's a natural self-selection among firms, managers, and behaviours toward such structures and behaviours, and those who follow them, consciously or not.
If you're looking at specific legal or risk concepts, you'll probably want to examine the notions of moral and morale hazard, attractive nuisance, negligence, malfeasance, and the like. The notions of willful ignorance and motivated reasoning as well.
These issues get less play than they should, and comprise a major weakness to the market-capitalist model. Though of course they're also present in other organisational models of central control. Organisational models which are immune or resistant to centralisation and concentrations of power, ownership, and/or control would probably fare better, though these are difficult to arrive at and sustain.
The reason this challenges the general notions of markets includes both generally understood principles, and possibly some that are novel, or at least less considered:
- Moral and morale hazard -- changes in behaviours based on a changed individual risk profile. For a discussion see: https://www.investopedia.com/ask/answers/032615/what-differe...
- The correspondence between wealth and power, best captured in Smith's uncharacteristically suscinct quip in Wealth of Nations: "Wealth, as Mr Hobbes says, is power."
- The dual problems of principle-agent and regulatory capture. Though often viewed independently, I see these as largely the private- and public-sector variants of the same underlying behaviour: individuals acting for personal gain rather than institutional benefit. Corruption generally.
- Classic informational asymmetries: At a given point in time, two (or more) agents having unequal amounts of information concerning a transaction or state of offairs. Akerloff, "The Market for Lemons".
- Temporal informational asymmetries: The development of fuller understanding, particularly as concerns unforseen consequences, emergent phenomena, or latent (as opposed to manifest) properties or aspects, over time, to all agent (though also often with an imbalance between agents). Robert K. Merton, etc.
- The risk-immunity of size. If an organisation has both resources and cost or operational structures to survive negative circumstances, then in a period of contraction, less-capable organisations will fail whilst the larger survive. Size does not always correspond to the capacity to absorb risks, but often does.
- Motivated asset inflation or value assurance. The tendency of those holding some valuable or income-generating property or system, to seek to further appreciate its value in ways that reduce social wealth growth. Bernhard J. Stern's "Resistances to the Adoption of Technological Innovations" (1937), and NIMBYism, are key examples.
- Various blame- and liability-shifting practices, including as described above. NDAs, non-competes, anti-poaching practices, and the like, would be others.
- Practices generally seen as immoral, unethical, or illegal: coercion, product bundling and tying, exclusive dealing, product dumping, and the like.
Sorry that's not a short answer, though I feel it's more accurate.
That risk should include personal responsibility. As long as the only people who suffer meaningfully are normal ICs, customers, and small shareholders there’s no actual reason for the boards to change behavior. Fines are passed on as increased costs (PG&E), reduced wages (every company), etc - I’m sure once individual executives can be sent to jail for allowing criminal acts the behaviour will change. (Until they buy a law to remove their liability)
You're asking for government mandated bureaucracy. Here's how I've seen this play out in the context of the world's largest bureaucracy, the Department of Defense.
Let's say the law requires someone in a powerful position, like a VP, to approve the un-ban request so you can hold someone "accountable". The following chain of events will occur:
1. The VP will be inundated with un-ban requests and become increasingly annoyed at requests that should obviously remain in effect.
2. The VP will delegate a subordinate to check that each request is sufficiently nuanced to require the full attention of the VP.
3. Repeat steps 1 and 2 until you reach a management level that's too over-burdened to add another review layer. You should have 2-4 layers of review at this point.
To properly route a request, each layer queues the request and runs some cheap processing and sends it up the chain where the process repeats. We can borrow some concepts from networking to model this process:
- buffer bloat: queues are typically unbounded in the real world. Requests are rarely dropped. Instead they accumulate.
- back pressure: the VP goes on vacation. All requests will pile up at the previous layer.
- latency: certain days have exceptionally high latency, notably Saturday, Sunday, and most parts of Friday.
- network partitions: often the transport layer (usually an intern to shuffle paperwork) will become unavailable as the scheduler (boss) repurposes the intern to higher priority tasks.
With a bit of tuning, a well-established bureaucracy can increase latency from minutes to months per request.
What appears to have happened at Facebook wasn't bribery, but potentially fraud, misrepresentation, or a form of rebate.
And whilst Facebook may not be a notional public utility, its role and behaviour (as well as intentions) make it all but that.
Reminds me of this Parks and Rec!
Now if it was $1M bribe and I was on h1b visa I am fine. Otherwise it is losing deal.
It's seen as sufficient, often, because:
(1) even if a civil cause of action is available, the cost of litigation far exceeds any plausible benefit to the company, and
(2) The company can't direct criminal prosecution and the high bar of proof and other competing prosecutorial priorities mean even if the conduct the company believes occurred which justified the firing would also be criminal, it often won't meet the criteria a public productor will apply before prosecuting.
> There are so many situations where the payoff is still much higher even if you get fired.
Maybe, but that doesn't mean that there is a correction to that circumstance which doesn't itself have social costs that outweigh it's utility.
"if this guy already was taking bribes, why should we give him access to critical system $SYSTEM when he may sell that knowledge to others?"
What incentive is there for this company to continue to behave, now that you have been pacified with this token gesture? Laws are stronger incentives because even though you still can't see what the company is doing, they are a real deterrent. Because the company knows that a disgruntled employee might one day blow the whistle if they carry on as before...
This would have more weight if Facebook had discovered this on their own, but it was an outside investigation that uncovered it. Firing people once they are outted by an external agency is pretty weak accountability of their platform. And note that this was a contractor so should have had higher scrutiny than a full-time employee, but I know from personal experience that it's often the opposite - the contract company signed a contract saying that they'll abide by all of the rules, so no need to monitor them, after all, they signed a contract.
A company spokesperson confirmed that an unnamed worker was fired after inquiries from BuzzFeed News sparked an internal investigation
“Ya,” Burke replied, punctuating his message with the sack of money emoji.</Quote>
Heh, amateurs. Let me tell you guys a story from my country, from 90's. So in those years cell phones started to become the norm. You know, those Nokia brick types (which had like 1 week of battery in them before requiring charging) but the service was like this. You would call your contact then around 4 or 5 rings will give you plenty of time to close the call, and after that a voice mail message would inform you the contact was not answering and inviting you to leave a message. Problem was that if you went that far, then you'd pay for those seconds when the automated voice mail be initiated just like if your contact would've answered. So far so good. But one CEO of a cell company decided he wanted money. So randomly, he would enable the automated voice mail message to enter just after one ring. Now, individually that was not expensive, around few cents for each subscriber, but on the whole network this would mean for every hour this trick was pulled the company would win one million dollars (yes, you read that correctly).
The number of subscribers and frequency of their calls required to achieve this in the 90s seems difficult.
And not ten of millions, just ten is enough. Call your family and few friends under this trick and oops, you're good to pay an extra dollar at the end of the month.
As a side anecdote, cell companies started a war among themselves with different features to lure customers from one network to another, and one of those features was at one time that initial 3 seconds were free, and after them it kicked the normal fees. So here I was a student in University campus and absolutely every single student had a cell, but you'd call your friends something like: "Hi X, it's me Y" and click, close the phone. Then call "I need this course" and click, close the phone. And so on and so forth until you'd finish your conversation. And at the end of the month when cell company was issuing the bill, you'd receive a very thick envelope that would have like 50 pages in it and the majority of it would read like this for each row: <destination number> - <begin time> - <duration> - <price>, where <duration> would be something like 1 second or 2 seconds, and <price> would be "free". It didn't last, cause companies understood they were losing money by printing those pages so it was a feature for like couple of months, but oh boy that was fun. Good times.
And, in those days if you didn't press the 'end' button to terminate the call, regardless of the other party hanging up, it kept an open line. I remember my dad getting several hundred dollar bills related to saying 'bye' and tossing the phone onto the passenger seat.
says the parent post.
> A company spokesperson confirmed that an unnamed employee was fired after inquiries from BuzzFeed News sparked an internal investigation. The employee in question was based in the company’s Austin office, according to information obtained by BuzzFeed News.
The article doesn't say exactly [0], but potentially a BF reporter might have noticed that scammy ad accounts that BuzzFeed previously reported on [1] – which FB then banned in response – were inexplicably active again. But why doesn't FB have an internal flag/bit for these egregiously scammy ad accounts (and their unique identifiers) in their systems? A flag that would trigger an automated notice/audit when that account was reactivated for any reason, by any employee?
[0] It's possible the article under discussion was completely sparked by insider leaks to the BF reporter, e.g. "chat messages obtained by BuzzFeed News". I'm just saying that it's possible that the rogue activity potentially seems to have been observable by any outsider, i.e. completely observable and preventable if Facebook had proper access control.
[1] https://www.buzzfeednews.com/article/craigsilverman/facebook...
> "If you're an SRE, for instance, on Gmail, you will have access to mailboxes because you may have to look into the databases," the former Google SRE—who did not work with Barksdale—explained to us by phone. "You'll need access to the storage mechanisms," he explained, pointing out that in order to determine the cause of a technical issue with Gmail, an SRE might have to access emails stored on Google's servers to see if data is corrupted.
I'm assuming in the years since, Google's SRE have mechanisms in place to audit and log the use of sudo-level access and powers. Twitter, on the other hand, seems to not have implemented this, at least as of 2015 [0]
I can imagine FB having decent auditing and logging when it comes to internal access of private data of user accounts. But not when it comes to ad accounts, considering the level of scammy activity these ad accounts had when BuzzFeed News reported on them [2]
[0] https://gawker.com/5637234/gcreep-google-engineer-stalked-te...
[1] https://news.ycombinator.com/item?id=21467921
[2] https://www.buzzfeednews.com/article/craigsilverman/facebook...
In this case, it was a "contractor". Next time, it will be an "intern" etc etc.
... as another example, Indeed does not action/review companies that have been flagged as having inappropriate postings (i. e. MLM scams) as long as they have actively billed job postings.
This is evidenced by the fact that when such a company removes their automated payment and/or pauses all job listings, all the flags then get reviewed and actioned (speaking from personal experience - not MLM, but commission based job listings).
FB is a dumpster fire.
Kind of depressing to think that a non-zero number of people are making decisions about financial management based on facebook ads.
Obviously they perceived the risk as low.
Why do people break the speed limit on wet roads just to get home a minute sooner, when they could slide off the road into a ditch and never make it home at all? Obviously, because they think that won't happen.
It's another argument, but I think it's on Facebook entirely that they don't pay their employees enough, keep them happy enough, to prevent this sort of thing from happening. When you leave content moderation to your lowest paid employees, you are only encouraging people to figure out how to game the system for more.
I cannot tell you the amount of frustrating time we had to spend to chase Facebook to stop banning us because of an algorithm that thinks the belly buttons and the ladies in our ads resemble adult ads (it's not in any way nsfw, it just shows more skin than usual because that gets interested clicks)
Sometimes I wish there was someone to talk to at facebook to make the automated process less painful, but we are in an Asian country with no facebook representative.
The scale of this problem is too big for transparency. Hypertargeting of advertisements should just be illegal.
If you want ad-supported businesses to go away, invent a convenient way for me to pay Google 1¢. (Convenient as in, I don't need to create an account with a password.) It's extremely difficult, both for technical and legal reasons.
So, the problem is not how to create the infrastructure for micropayments, but rather that explicit charges would be very high - the effective cost of browsing the commercial web is about $6/hr, which is about twice what it cost in the mid 90s to use AOL.
I'm not sure of all the implications, but I think this should substantially change a person's views.
http://www.ard.de/ (and satellites: NDR, RBB, SWR, MDR, WDR, BR, hr, SR, and RB, because reasons)
And similarly...