Why does Instagram continue to store and use all of my contacts?
twitter.com
twitter.com
It should be clear to anyone here that the moment to act on this is before your contacts get copied, not trying to get them un-copied later. Think of it as a betrayal of your contacts, that you sell them out (then ponder the likelihood that none of yours have done the same, it's probably infinitesimal.)
Ironic, I know, but that's what it has come to. Welcome to 2020.
In the vast majority of cases I just don't need to call most people. I mostly stick between instant messaging and (during pandemic) video calls and (non-pandemic) in-person meetings and just avoid the awkward middle ground of audio-but-no-video phone calls.
The os would just pretend those contacts don't exist when all contacts are requested. There could be a checkbox to share protected contacts on the permissions prompt in case you're trying to actually export them.
GDPR is a good example of a law that the US sheepishly somehow chooses to obey EU law (wtf, why didn't the US obey the EU laws around recycling and energy and no free plastic grocery bags for the past decade? and all of a sudden they care about obeying GDPR?), but do Central/South American, African, Middle Eastern, and Asian countries take a crap about GDPR? Generally not. They don't care about EU law. It doesn't apply in their jurisdiction, and they are not sheep. That isn't to say privacy doesn't matter, it's just that the law needs to be locally implemented, not obeying some arbitrary EU interpretation of the idea that wasn't even discussed with them.
As such, I think technical approaches are generally superior to regulatory approaches in user protection. They apply across the entire world instantly.
Fundamentally, that's not a thing in the long term. Trust lasts until the next bad quarter if you're lucky, because ultimately a company will choose to abuse your trust rather than go under.
I don't want to come down too hard on companies here, they exist to make money, that's what they're for (and plenty of them provide very useful services).
But the concept of trust doesn't make a lot of sense here. The people that make up a company aren't constant, and if you do find a company with trustworthy employees, they won't take your data with them when they leave, they will leave it for the next person to abuse.
Trusting a company beyond what they explicitly promise (anything in a EULA-like document that says they can change things at any time doesn't count) is setting yourself up to be screwed down the road.
Off topic but: am I the only one who thinks video calls are awkward and the old-timey audio-only ones are preferable? I have a disdain for people walking down the street with their phone in an outstretched hand, having inane hour long conversations while virtual bunny ears, cat whiskers or horse heads adorn their faces. Not everyone wants to put on a performance every time they speak to you. Sometimes I just want to call and say hello without having to think about whether the shirt I'm wearing is cool.
I'm used to real life where you talk and see people, and the people you see are the people who can hear and talk to you.
With phone calls the existence of people around me that can hear half the conversation, aren't part of the conversation, and can't reply to the conversation, is utterly jarring and unnatural to me and I avoid it at all costs. I can't for the life of me answer the phone and be at ease when there is anyone else in the room.
I also find it really hard to comprehend everything someone is saying without body language. That is also super unnatural to me. I read faces a lot. I'm just used to real life I guess.
The issue is that some asshole had the genius idea of trying to monetize and spam the contacts once they were given and other assholes followed suit. I would never give the 2 way sync permission to some random app anymore and I almost never give the contact permission to bigger apps as well.
What I hope is that eventually there becomes some way to determine if my contacts also use an app without the app knowing they are my contacts nor giving up the information of contacts not on the app. That seems like a hard but not impossible task. Eventually I'd like there to be a safe way to return to the 2 way sync, but I'm not sure if that is even possible.
Anyone I consider a friend that I didn't meet online I will always have their phone number, even if that isn't my primary form of communication with them. A phone call will always go through without regards to any data limits and is less spotty in areas with bad service.
I'd love it to be a standard so that social networks could also be connected together in a similar asymmetrical way but that would require even more cooperation from people proven to be bad actors.
I'm very selective about who I connect with on social media, only close friends or relatives. But I have many contacts that I won't want any social media contact with at all. Former coworkers, ex girlfriends, professional contacts, etc.
In iOS 14, Apple (re)implemented a photo picker so apps don't need access to your entire photo library for you to upload a single photo. I'm hoping they could come up with something similar for contacts as well.
Never use an email user id you’ve given to other people
Never use a phone number user id you’ve given to other people
Try to only use app based 2 factor and not SMS based because you have to give it a phone number which they will untrustworthily reuse eventually to generate a social graph
This breaks the social graph
Facebook will ban you for this within 10 minutes, Instagram will not
Facebook topics aren't privy to a shared reality, this isn’t a mystery.
I uploaded a subset of my contacts to IG pre-Facebook acquisition, must have been ~5 years ago, and to this day I get follow suggestions (that I've never clicked on) which one would have no reason to believe are good unless that data was retained (e.g. for contacts who are not "mutually well connected" with other people I follow).
https://gizmodo.com/facebook-is-giving-advertisers-access-to...
https://play.google.com/store/apps/details?id=com.cklee.cont...
Haven't tried this app, and it may be more horrid do install an app but the only other way I was thinking was manually via CSV and generate it with dummy data from some other misc data on the web....
I should do it actually. It helps break the addicting nature of social media apps and ruins the networking effect.
--
https://code.lardcave.net/entries/2012/04/22/135057/
This is really cool and covers the exact issue, but with resolving it by creating TWO contact books!
Outlier rejection of completely random data for these sort of graph-connected networks is exceedingly easy and unlikely to screw up their algo.
But... for how long do you have to keep the fake contacts and whatnot?
The interpretation of GDPR by certain companies is that when someone requests "data deletion", they are to delete the association of the data points to "known identifiers" and are not required to delete the data itself. As the user has decided to disconnect their association, the data remains in the hands of the organization for analysis, look-a-like modeling, etc etc.
Scenario 1 - Insta didn't fully delete the associations according to policy and thus one of their processes is still linking the contacts. Scenario 2 - Even with disconnected data associations, the ability of Insta to re-identify you was too easy and thus the contacts are showing up.
Either scenario shouldn't be viable under GDPR. If you're in the US, you're SOL (CCPA isn't as robust as GDPR and focuses more on 'data sale' and less on data privacy & protection).
Longer story: I went to create my first ever WhatsApp account after I was invited to a friends group chat. I downloaded the Android app but, being aware of Facebook apps' thirst for slurping up all your contacts, I made sure to repeatedly deny contacts permission even though the app was annoyingly insistent that it needed to have it. I only wanted to access this one group chat so I didn't see why it needed it. After maybe 20 minutes in the group chat Whatsapp permanently banned my account. Appeals have been denied. I have now been unsuccesfully trying to convince the group of 30+ people to switch to a different platform so I can participate :(
If they had a policy of banning everyone who doesn’t allow access to contacts, I wouldn’t be allowed back in the chat.
It's a much easier sell, I think. Plus it's definitely more secure than Whatsapp.
If Instagram/Facebook/Whatsapp have ever had access to your contacts - even inadvertently - you essentially can't undo this.
Of course you could take a similar argument or stance when it comes to desktop, and indeed, just look at all those CPU vulnerabilities. I think technology is at a really sad state. Most things are closed source (what does your keyboard do?![1]), and we have no goddamn way of knowing what is happening behind our back unless someone reverse engineers it, but the fact that it has to be done is an issue to me.
[1] https://thehackernews.com/2017/11/mantistek-keyboard-keylogg... or https://security.stackexchange.com/questions/158805/how-to-d... but yeah you could just search for it. Regardless, besides the point. :)
I wish the US had something similar at this point.
From a security and privacy standpoint I think it’s got great potential but there are too many open questions about enforcement and it muddies actual compliance.
[0] - https://iapp.org/media/pdf/resource_center/CCPA_GDPR_Chart_P...
could go either way tbh
The definition of negligence is that it isn't malicious.
My point is that, if you ought to have done something, and you didn't, you're culpable. And I would certainly use the word "malice" (in the everyday sense, not in all legal contexts) to describe someone who knows they are cutting corners that might have damaging consequences, but cuts corners anyway. I think it's malicious to harm or endanger other people to make a buck.
don't let individuals off the hook just because they work for a particular company. if that company operates in bad faith, its employees do too.
You're going to see both good and bad Facebook engineers.
Hanlon's Handgun.
Hanlon's Razor is absolutely valid.
That said, I'd posit that stupidity isn't accidental and shouldn't be excused. Rather it should be stomped on just as hard as malice since, as others have pointed out, the effect is the same.
People have reasons for acting incompetently - often those reasons are because the system is set up to enable that, in one way or another.
And it's most often the case that system has been set up intentionally in that way (or has been manipulated to get that outcome) - there's malice in the organisational big picture.
The effect is the same and the cause is the same as well.