Unencumbered API access to the social graph is exactly what led to the Cambridge Analytica scandal, and promising to restrict API access was part of Facebook's settlement with the FTC.
Perhaps a "social graph" shouldn't belong to any company. The concept itself might be anti-privacy.
Perhaps it's time to move back to simpler things like OPML. (Which people seem more comfortable sharing freely - not sure if that's still a "social graph" tho.)
Perhaps specific relationship details shouldn't be housed in the social network - just the permission to follow.
Perhaps companies who house a "social graph" should be regulated - similar to what is done with medical data. It should be a toxic substance.
I just think we're a long way from doing this right and there are a lot of untried options - and I lack imagination as well.
Good riddance to them.
I’m surprised they don’t go after it as a violation of their terms of service.
Also, not asking right wing “news” orgs to be fact checkers or having GOP operatives override content policy team decisions regarding misleading stories that were reported by users would be another great way to reduce “propaganda”.
It’s not a technically unsolvable problem, it’s just one Facebook doesn’t want to solve. Don’t give them a free pass.
They are a multi billion dollar company, they have the all the ressources they need if they cared.
Which one is propaganda? The one you disagree with? The one that doesn't fit with your preconceived notions? The one that doesn't fit with your personality profile? Both positions? Neither position? Do we just shut down all thinking on the internet? Who watches the watchers?
> In the 20th century, the term propaganda was often associated with a manipulative approach, but historically, propaganda has been a neutral descriptive term.[1][2]
Letting people be mislead about vaccines harms people, letting people get brainwashed into mistrusting the legitimacy of their institutions harms people, letting people use their platform to incite genocide harms people.
They actually have metric to measure those things, it’s just that they prefer to dial down the heat, not kill it. It’s just too good for engagement.
Don’t “both sides” death and misery. It’s not a philosophy debate.
To be fair they are clearly fighting a delicate balance of censorship and community moderation. It's different from say a forum of yesteryear, because a forum can have a clear set of community values that should work for everyone.
Facebook and all social media is a single platform for many communities, and so given the new role of moderator they are in the impossible position of making a set of community values that apply to all communities.
I think the reason a lot of material isn't outright banned where you or I would see obvious misinformation or hate is because of this.
I urge anyone here to define metrics for harm reduction that are operationable.
If you get any far with that, then tell me how you feel if the tools that will achieve these operational metrics were inverted in their purpose.
If we're not okay with other companies having access then why is it okay for a single company to have that access? Do you know and trust every facebook employee including those that don't work there yet with your data? Do you trust that that data will be securely handled when the company is sold after declaring bankruptcy?
I think your objection is an accidental straw-man. I don't think it was intentionally made, it is a valid thought to ponder but it should exist independent of the question of sharing data.
Should Facebook have all the info your bank has for instance? Or auto mechanic, your realtor? This is a slippery slope of logic of shared data for all leads to.
Some of these "social graph" features will do things like link two people as friend suggestions if they both have your phone number in their contacts book, even if you haven't consented to Facebook building up some information about you.
This doesn't sound like willing access & knowledge of what information you provide to Facebook.
PS by fighting this point you’re merely pointing out that giving more businesses this data isn’t a good idea
It doesn't have to run on companies spying on their users either.
Sam Walton of Walmart would record everything about his competitors legally and illegally as well as clients yet you never see that in the news, why? Because it’s not sexy, it’s not about the internet.
This is why Equifax which was a much more horrible data breach isn’t thought about, yet everyone gets their panties in a bunch about Facebook
The ironic beauty in that would be awesome. Also, I'd kind of like to get it about myself for similar reasons :)
They had no real idea what else it would or is being used for.
Facebook builds shadow profiles on non-users and then fills them out with, amongst other things, data it gets from their actual users that they didn't no they were sharing.
This is particularly sneaky when Facebook has used dark patterns to trick app users into granting them permissions they don't strictly need for service.
The difference is that Disney grants license to its content after (potentially drawn out) negotiations and payments, while the typical Facebook users "Agrees and accepts to grant Facebook a worldwide license"
BTW it doesn't confer a license (mostly) to anybody else but normal users do not sue.
They have to monetize and I approve.
Hell I’m willing to bet if Facebook puts into their agreement that every photo you upload to their platform is partially owned by them then people will still upload photos.
It’s not the data that we find valuable, it’s the connections they make or will make, and to this company. Next time you take a photo and find it’s shared with not just Facebook but a whole slew of other companies you tell me if that’s the right thing to do.
The person above said “do you trust all Facebook employees” well you can make that blanket argument for every company in existence and giving more companies our data isn’t a good solution
I mean Facebook might perform facial recognition on your photos and infer connections to other people you didn’t explicitly tell them about.
I mean that facebook might track your location and app launches and identify where you go on vacation and when you shop.
These are the kinds of thing nobody gave consent for.
The consent thing can both be good and bad, just like the invention of the internet and electricity before that. I’m trying to make that point that giving away your data is gonna be a commodity once everyone realizes they’re not a special snowflake
Check out LiveRamp for example; they literally scan in physical documents like car mechanic paperwork (seriously) and dropship them into S3 buckets to huge data brokers every day.
Take that and merge it with facebook’s social graph, how many ms you look at a photo on Instagram and how long you take to reply to someone on WeChat, and you have an awful lot to work with.
What difference does that make? Facebook almost certainly knows my banking information, without me giving it directly to them
Privacy is in the process of becoming antiquated. It is sad, but I think it is inevitable. Surveillance technology advances with technology in general, and counter-surveillance becomes more and more cumbersome. Eventually, we will reach a point where anyone can afford tiny stealth drones to watch what is happening in their neighbors' houses. The counter-measures necessary - hermetically sealed living space, faraday cage enclosure - are so burdensome that only people who currently live in bunkers will implement them for their living spaces.
If we accept that premise, let's think about what we are losing. In my understanding, there are two main reasons why privacy is so important:
1) Allowing individuals to avoid becoming targets of persecution for having some attribute. Targeting by oppressive governments for holding idea X, targeting by an evil megacorp for threatening to disrupt industry Y, etc.
2) Allowing individuals to avoid social stigmatization and shame for having some attribute. Getting caught eating one's boogers, viewing porn of people dressed up as pieces of furniture, etc.
For point 1, I think the real issue is imbalance of information. Schemes to abuse access to someones previously private information mostly wouldn't stand up to public scrutiny themselves. Unless, of course, you have some ultra-powerful organization like a well run totalitarian regime, in which case individuals by definition have no privacy rights anyways.
For point 2, I think shrinking privacy will seriously reduce the social response to this kind of information. "So what if I watch porn of people dressed up as furniture; you masturbate while dipping your toes in peanut butter! That's way weirder!" Sure, there are plenty of painfully normal people out there, but I think most shameful weirdness would become commonplace when the full extent of weirdness is out in the open.
All that being said, I do think anonymity is important, and can probably be preserved, as it is distinct from privately acting in physical space, or online while tied to some form of identity. Also, I don't want to argue against efforts to preserve and advance privacy for individuals for as long as possible. I just think that per point 1, we might want to devote effort to reducing the privacy of organizations to try to maintain parity of information access as our individual privacy slips away.
> The counter-measures necessary - hermetically sealed living space, faraday cage enclosure - are so burdensome that only people who currently live in bunkers will implement them for their living spaces.
There are a lot of situations we forbid activity that is difficult to prevent (and sometimes difficult to detect).
Whether trying to use the law to deter here is worthwhile, meaningless, or harmful isn't necessarily clear - but it deserves consideration in addition to outright prevention.
It definitely somehow limits their use, but anybody really interested is able to obtain them illegally, or produce them themselves.
I'm afraid the same will be true about micro-drones or whatever else the post suggests.
It's different from drugs in that one of the participants is unwilling, though I don't know whether that's a big enough difference - particularly given that that participant is also unwitting.
You can only briefly see which friends have also already signed up.
I'd say it's not ok, but people keep on giving Facebook all that information (and it's very tempting to do so). There are technical solutions which anonymize/privatize social network information, and then no entity has such access.
So while I value privacy, I'm not sympathetic to using privacy as an argument to restrict your own access to your Facebook data, for you to decide yourself on how that's shared. If you misuse your view of your friends' data, that's on you and up to your friends to punish/discourage you for.
Your sharing your FB friends data with third parties, could be seen by the friends as impolite or even hostile. It's a matter of trust between friends, not technical ability.
I'm not defending VK — it does some increasingly user-hostile stuff too after having been acquired by Mail.Ru Group — but you can still integrate it into whatever the hell you want with ease.
How would you know?
The worst thing to ever happen with that open data was that some debt collection agencies used it to threaten people and their friends, and I believe that's why those service tokens were introduced. And that story was rather widely publicized: https://www.the-village.ru/business/finance/217569-banki-pis... for example.
https://towardsdatascience.com/steeling-faces-for-investigat...
https://nakedsecurity.sophos.com/2016/05/02/facial-recogniti...
Facebook itself is a third party.
I think a case could be made that knowledge that <A friend B> belongs to A and B equally and that neither has standing to preclude the other from sharing that fact. Of course they could both mutually agree to such an arrangement ahead of time, but outside of such an agreement, I have a hard time seeing the case for "B prevents A from telling C that A and B are friends".
Another aspect of this though, is "how much can A tell C about B without permission from B?" We know that IRL, people do get angry when friends reveal overly personal details about their lives to others, so this is definitely something to consider.
Agreed. And I am not arguing that it is, or should be. But the mere fact that two people are friends seems to me, at first blush, to be something that normally either person would be free to share.
I'm not sure how you got that from what I said above. Obviously there are such things. But I do think it's an open question to what extent we can compel our friends to keep things private. Of course if someone is really a "friend" you would expect them to keep confidences if requested... that's part of the definition of "friend" in my mind.
If the API is open and there's forced interoperability, the client device can call the service's API directly with the user's own credentials. No need for a third-party middleman, so no need to give a third-party access to the data.
It can work the same way IM applications like Pidgin work: one app, multiple accounts.
Why? If they shared it with me, that should mean they trust me to decide to whom I delegate the access no? I could as well just screenshot it and post it to twitter, what does make the social graph so special?
The point is to move toward standards around social data and then force the big tech companies to allow each user to export their own data, quickly, in these interoperable formats.
There is risk, but saying that users can’t be trusted with an API to their own social graph seems to be throwing the baby out with the bath water.
[0] https://www.healthit.gov/topic/health-it-initiatives/blue-bu...
The counter-argument to this is having the government provide the graph and an API to allow networks like Facebook connect to it. This should rightly terrify just about everybody.
I like the concept Diaspora had back in the day, it just wasn't workable really as your mum/aunt/non-tech friend wouldn't be able to understand how something like that works and would ultimately lose/delete/corrupt their tokens.
Multiparty secure computation is one possible way. There are a few, emerging implementations.
The problem is that if I export my social graph and share it with another company, it includes information about who my friends are -- at the very least, it shows that they are my friends. That violates their privacy. Maybe they did not want their relationship with me to be known outside the social network where they established it.
Example, you are chatting at a party with someone and they ask you if you know Bob since he works at your company. You say yes and you say you are good friends with him. You violated Bob's privacy here?
If the question were framed more like:
"Do you consent to sharing your entire address book, so that we can better market to you and your friends and offer targeted ads based on that data to our real customers?"
Would most people actually answer yes?
Presumably you would be granting this system access to this information.
>Would most people actually answer yes?
some people would, do they not have that option?
> To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller.
Laying out laws and regulations so the market works as intended (no doubt with adjustments on the way) seems like the far preferable way to ensure healthy competition than taking a hammer to the job site and hoping for the best.
If FB is doing anti-competitive things than disruption is needed. It's not meant to be comfortable.
Companies are really good at learning the playing field and then gaming it for their benefits. Tweaks to laws are often easy to work around. Disruption that stops an illegal monopoly is going to be uncomfortable. Especially at first.
But, it opens the door for the future in ways that aren't options today.
Absolutely. The same could also be said of the closest parallel of Facebook in history, the Bell System.
No, seriously, modern tech companies are an anti-trust challenge that was not truely forseen in existing anti-trust laws. That governments are now trying to find answers is a good thing.
That's what antitrust/monopoly laws do.
The Facebook purchases of WhatsApp and Instagram were not innovative and should have triggered antitrust at the time. There is no healthy competition when you buy Any worthy competitors.
How is the market going to fix that?
Besides... they will get to sell it, probably at a profit. They got to own it for 8 years, enjoyed the benefits of lowered competition. They will be fine. I agree that this should have been prevented in the first place, but we are where we are.
Controversially, I don't think ordinary rule of law can apply to FAANG-scale monopolies. There's no way to generalize rules, laws or industrial policies when the industry is "social media." Social media is (economically) mostly FB. Any rule, law or policy is basically regulating FB specifically.
Anyway, the danger of a hammer coming out is low. Even if prosecutors succeed, a cost-of-business fine is the most likely result. Even if they do spin out whatsapp & IG... that leaves facebook mostly intact.
I'd also note that the worst case scenario for overzealous trustbusting is basically nothing. At worst you kill FB. This isn't steel production or auto manufacturing. FB could be swallowed by a demon tomorrow and by next thursday any shortage in social media will be filled. We're not exactly short on the stuff.
FB bring in $80bn pa, but that's totally arbitrary to the cost of doing social networking. It could be done for $40bn or $8bn and I doubt the consumer would notice a difference. Again, this isn't auto manufacturing. A car company can't make as many cars with half the revenue. If one dies, we actually have less manufacturing capacity and we'll make fewer cars for a while. None of this applies to social media.
In the last paragraph, I was trying illustrate a point. With monopolies of the past, the primary concern was that the services continue to operate somehow. EG, when Bell was broken up, the danger was that phone/telegram services would be harmed. Before that, the danger was that steel production would be disrupted and downstream industries harmed.
Facebook is a monopoly in a marketplace of extreme abundance. We have lots of social media, messaging, photo sharing, etc. There is zero danger of shortages or meaningful "consumer harm," regardless of what happens to FB.
Even if antitrust does harm FB, the only stakeholders at risk are FB employees and investors. There is no systemic risk, downstream risk, consumer risk. All the risk is contained within FB.
This doesn't mean FB should be killed. It does mean that the scale tips strongly towards antitrust. On one side, we have a lot of risk. On the other, very little.
Isn't this also true for Facebook itself as related to how dependent they are on revenue and at what cost that comes to the users who help generate it (by being presented as "eyeballs" to the advertisers)?
We used to let kids play with dry cleaning bags, until we discovered they were idiots and can suffocate on them.
The realization today is that parents were the actual idiots, not the kids.
If what's being said is that those investments are important and necessary, then we should be looking for reasons to sustain them that aren't just about validating the continued existence of a monopoly.
This organization itself is disruptive. As interesting as it is to discuss the potential costs and benefits, there's been a very real cost to society for these issues. It makes no sense to wait for further damage reports if that's at the cost of further damage. It's simple cost vs benefits really. Also I thought disruption was a good thing..?
Downvoted so I'll just add one more thing; this isn't a conversation that is new. I'm coming to this with that context. Do I want them to fail? No. The desired outcome is that they will self regulate. But if not, there should be competition. Monopolies naturally have negative side effects, that's why we try to avoid them.
No password access, login through SMS which can be intercepted, no 2FA, no access from another device while you phone is dead, compresses video to 2 pixels, no real crypto auth to speak of.
It does not seem to have any features that are better than Signal, telegram, messenger, or a dozen other apps. Why is it worth any awards or special consideration, besides being popular?
You're not wrong about any of this, but that final phrase weighs far more for most people than anything else. It is a communications app after all, and is only useful if there are people to communicate with.
I posted this elsewhere but I think Ben Thompson gives a very deep analysis of the issues in the competitive landscape here:
https://stratechery.com/2017/manifestos-and-monopolies/
The summary would be something like "any acquisition of a social network by another social network is necessarily anticompetitive and should be banned, or at least have the presumption of being illegal".
The only way that there can be a true competitor to Facebook is for a smaller social network like Instagram, or WhatsApp, or TikTok, to not get acquired and to grow until their userbase is bigger.
Zuckerberg understands this well; you can read his emails where he openly admits that buying Instagram is about preempting a competitor:
https://www.theverge.com/2020/7/29/21345723/facebook-instagr...
The money quote from Zuckerberg:
"There are network effects around social products and a finite number of different social mechanics to invent. Once someone wins at a specific mechanic, it’s difficult for others to supplant them without doing something different.”
“One way of looking at this is that what we’re really buying is time. Even if some new competitors springs up, buying Instagram, Path, Foursquare, etc now will give us a year or more to integrate their dynamics before anyone can get close to their scale again. Within that time, if we incorporate the social mechanics they were using, those new products won’t get much traction since we’ll already have their mechanics deployed at scale.”
I think you can apply the same argument to WhatsApp; by purchasing a rival social network, they prevent it from being a competitive threat.
End-to-end encryption in a proprietary app is a joke. "Please trust us we encrypt your messages".
But it was pretty good before they bought it, too. And widely used, IIRC was clearly the biggest in some parts of the world.
In short, their implementation allows to change the encryption keys of users without their consent to arbitrary, known keys. The protocol won't re-encrypt sent messages, but there is nothing in the protocol forcing the app to show a notification that your encryption key has changed, which amounts to a man-in-the-middle attack. Any subsequent messages sent or received using that encryption key will be exposed to the attacker.
Encryption keys are managed on servers controlled by WhatsApp.
Disclaimer: I personally know nothing about beyond the posts in this thread.
Did you click through the link at all?
It's curious that you are using a new account with a gibberish name to make all these claims.
Facebook either buys or crushes all competition which doesn't have billions of dollars to push back.
Since the function of the government should be ensuring the best outcome for the majority of the population and what facebook does makes things worse for the majority, it makes sense to take action here.
Now their tracking pixels can't see you.
I agree that tech is the wrong place to be solving this problem, but it can work in a rather cludgy way.
Any ideas where to go for similar functionality that will be supported in the future?
These are not the creations of Facebook or Google, any more than Anemometer (1) manufacturers should own the shipping forecast.
(1) The spinney half-ball things that measure wind speed.
I am sure people have thought about this.
All the Government needs to do is to enforce compliance to such standards.
the main economic value of it is to serve ads on Facebook dot com. that's it. that's how they make 100% of their earnings.