Direct mail marketers, since the 1980s, buy lists of huge swathes of Americans. These lists include full name, address, estimated income, political affiliation, companies you've worked for - and the records are pennies each.
Direct mail marketers, since the 1980s, buy lists of huge swathes of Americans. These lists include full name, address, estimated income, political affiliation, companies you've worked for - and the records are pennies each.
It doesn't contain my GPS coordinates over years.
It doesn't contain the list of my interests, based on my likes and the tracking of my web browsing.
It doesn't contain an analysis of the conversations with my friends and family.
It doesn't contain the pictures of my weekends and holidays, uploaded by other people.
It doesn't contain my face.
However it's still quite bad and such dataset shouldn't be available like this.
Which is nothing like using Facebook data to peddle false information through ads.
Facebook shouldn’t be allowing access to that kind of data in both cases, but that doesn’t mean what was done with the data is the same thing.
What happened was people installing a quiz app or game which requested unnecessary data access but collected profile data and then (against Terms of Service) provided this data to a third party.
I don't consider this Facebook selling data. And auditing this kind of behavior is incredibly difficult.
Don't install apps that request access to your data, especially if you don't understand who owns the app and what their motivations are.
What if a quiz app could not require so much knowledge about privacy by design? Facebook is responsible.
Auditing such process is a joke. No such audit will ever exist, as the results would be documented and leave a trail of misappropriation and abuse (of data). The only audits 'allowed' by the business would me the innocuous ITGCs.
I invite anyone from FB with audit related experience to comment (please use a TA account and be as vague as you can to prevent tracing).
Facebook build api and functionality that enabled data to be slurped, they also build how the warnings of what data is being exported to whom are displayed (or not).
Further more, since they control all the data in the first place it wouldn't be difficult for them to show a page that shows exactly which entity accessed what data they have on you.
Bottom line is that this whole mess couldn't happen without Facebook deliberately making decisions that enabled it.
And I know some of the smart people that worked there at that time. I don't believe for a second that nobody at Facebook had any idea what was happening.
Say a pretty basic personal information (address, income etc) cost a dime each person, it can get deeper and deeper until it is no longer worth any extra. 10 political opinion from this person? Interesting. Full reddit history? Maybe worth 2x the former. Facebook images? probably worthless. The point is that it quickly gets to the point where all of these information are noise and essentially worthless to an advertiser.
It is completely another story when you have people with authoritarian intentions coming in though.
The Nazi party went from ~2-3% of the vote to 37% of the vote in 4 years [0]. 5 years from 2-3% to the last election they had to contend with.
If the strategy is to wait for people with authoritarian intentions to come though before getting worried about privacy it will be far to late; things can go south extremely quickly. It is advised to stop the databases being developed before it becomes obvious that someone is abusing them.
[0] https://en.wikipedia.org/wiki/Nazi_Party#Ascension_and_conso...
Several reasons...
(1) Facebook/Alphabet have a lot more data. Leaking anything implies something about data security, which is scarier.
(2) Scale. Direct marketers in the 80s did use most of the techniques digital markets use, definitely in the early stages. The scale is totally different though. I'm pretty sure my city (dublin) produces more "digital marketing" grads than all engineering specialities combined.
(3) Power at Scale. Your address is not data, it's a datum. Your address, alongside lots of other data about your, alongside data about lots of other people... that's where data becomes powerful.
Prediction, in advertising, is the demonstration. It's responsible for most of FB's revenue.
Govs have done that many times, and they still do.
They build this sample data by compiling huge swaths of public records and buying private data.
Your political affiliation is not the worst of it, they can have the school your child goes to, the grocery store you visit, anything.
The worst really isn't the violation of privacy, it's the propaganda.
Most of the time the surveys themselves were meant to push information, the questions and answers were usually loaded.
Source: worked as a CATI technician, typist, and interviewer for a survey company in college.
And that's just official sources; when it's gathered via private questionnaires or inferred from other data, it's even less likely to be regulated.