Facebook blocks Google Chrome extension for exporting friends
zdnet.com
zdnet.com
Disclaimer: I'm a Google intern this summer.
http://www.mattcutts.com/blog/backup-gmail-in-linux-with-get...
Also, Google throttles your downloads - on POP this takes the form of returning just a few emails per download. It took me about three months to have a full backup at home, and I'm a paying customer (~30gb of mail on Apps Premier or whatever they're calling it today).
How it works is you get all your contacts, and the data you're authorized to see. So, people who you're just following and aren't sharing anything with you, just appear as Google Plus links. People who have you in their circles and are sharing their email address with you will also have their email address attached.
Disclaimer: I'm bootstrapping OpenPhoto on Kickstarter
This example is even clearer. The app lets you export your friends' names and contact information. This isn't your information, it's your friends'. What if one of them wanted to take their phone number off the site? What if one of them wanted to hide their information from you specifically? If you've downloaded it already you're depriving them of the right to control their own data.
Clearly social networks should be required to offer some sort of friend list information for export. Maybe a bare list of user ID's is all that should be required -- the information about who your friends are seems legitimately like it's yours. Joining it against names and contact information is the potentially privacy-invasive step; that could be done online, under control of your friends, not you.
Consider how ridiculous that would sound if you asked "What if one of your friends had emailed you their phone number and wanted to remove your access to it (or had emailed you and wanted to remove your knowledge of their email address)? What if they gave you information in person and now want to hide it from you specifically?"
That's the mental model I, personally, use for social networks: any information you choose to publish on it is fair game for whatever your friends want to do with it (and they can do whatever they want with any information I publish on it). Anyone who does not want to be contacted (or have their contact information exported into other formats - such as the linking of name and email address which is required to email) should not make it available - there's no reason to publish an email if you don't want to be emailed, and no reason to publish a phone number if you don't want to be called.
Not if Google subsequently decide to make your information available more widely than it was originally, it's not -- and I would remind you that several of the Internet giants, including both Google and Facebook, have faced heavy criticism for deliberately doing exactly that in the not-so-distant past.
That would be a fine system -- where phone numbers and other means of contact can become invalidated if the owner wants them to.
If my number is listed in the 1995 local big yellow phonebook but then I choose to have it unlisted in the 1996 phonebook, is it wrong for someone with the older phonebook to have my phone number?
(Edit: To those downvoting, do you not like the analogy, or do you not agree with the ethical principle?)
The internet preserves those words in their original state, black and white, which makes them stick out against the shades of grey composing the background.
Even simpler...when your friends die, with them go the words you have shared. Not so with the internet. It appears to be immortal.
Because I demand the right to move phone numbers to my new phone, does not mean that I demand the right to sell your phone number to telemarketers or send your phone number to sex offenders. Doing things like that would make me a shitty friend. And being a shitty friend is totally unrelated to what websites/phones I store contact information on
And most of the people in this discussion are confusing the right to have an address book (which you control and to which only you have access) with giving someone else's personal data to Google (a global giant that would squish you like a bug if it meant a 0.001% increase in its data mining efficiency, with absolutely no loyalty to either you or the person whose data you are providing to it). Is that clear enough?
(Edit: And in answer to your other question, about which organisations I personally can trust, we have fairly strict laws in my country about privacy and data protection, which limit what any of these companies may legally do and give me various rights with regard to any personally identifiable data anyone holds about me. I don't think those laws go far enough, but IMHO they're certainly better than the free-for-all you seem to want. So I can have some confidence in how my data will be handled by any company operating in our jurisdiction, which immediately makes me more likely to trust them than US-based companies like Facebook and Google whose business models fundamentally rely on undermining privacy in ways that are rarely going to be in the interests of the exposed.)
If my friends have trusted me with their information they also trust me to make sure to keep it safe. What service I use to store my data should not be of any consequence for them. That is the same way with this Facebook exporter (BTW, the iPhone app allows one to sync contacts from Facebook to the iPhone address book, which can then get sync'ed to .Mac, Me, or the new iCloud, from there back to a Mac and then back up to Google), it allows the user to get the data from Facebook and store it in their address book. Instead of having to go through each entry one by one this plugin automates the process.
I don't see how my friends that clearly have made this data available to me (so I could contact them) should now have a say as to how and where I store said data. Just because I decide to store it in my address book on Google doesn't make much if a difference, if they didn't want me to have that data in the first place they should have A. never have given it to me, or B. ask me to please remove their information.
One more time, for the record: Your friend trusted you with their personal data, not Google. You may not personally have a problem with sharing your own personal data with Google, but not everyone is like you, and some people do. That doesn't mean they have a problem with sharing the data with you in the first place or that it was somehow unreasonable of them to give it to you.
I really can't understand why so few people in this discussion seem to understand the distinction. We have multiple Acts of Parliament on the subject here in the UK and an entire government department whose primary responsibility is enforcing the rules, so I'm clearly not the only one who gets it or thinks it's important. Maybe it's a cultural/generational thing, and the average person on HN just sees the world differently or something. Then again, the average person on HN today downvotes rather than replying if they disagree, based on my experience in this discussion and what's happened to several other people in other discussions I've been following, so things have obviously gone way downhill.
If you wish to not receive certain communications the way to do this is by screening incoming connections/contents. This works, unlike secrets.
Now, understanding that what you wanted to do (keep an email address secret) is a bad idea - it won't do what you want, you can see why those who understand don't care about this "privacy" - it isn't.
Claiming to authorize your email address being shared with CompanyX but not CompanyY is like saying "Here's my phone number, I'm only lettingVerizon subscribers know it, to keep AT&T from snooping on which of their users calls me." It's just nonsensical.
Do they own this data?
Think about this before you blame people who just try to find a way to reconnect with their friends (who are ok with being your friend on FB) on another Platform.
If you tell a friend e.g. your email address, you willingly give up the control you had over that piece of information, and accept that he now knows your email address. What you're expecting is that you can control when your friend forgets the information you voluntarily gave him. I doubt that's a legitimate expectation.
If you don't forget them between meetings you're trampling their right to a fresh impression.
If you remember that tune you're infringing on the RIAA's right to sell you another impression.
But that's not how information works.
If we pander to this mindset we're only letting them down when their illusion of control is shattered by the cold, hard, reality of cut-and-paste.
http://www.zdnet.com/blog/weblife/invite-your-entire-faceboo...
From there you can do what you want with them.
I would have hoped that data protection laws (I'm in the UK) would have protected this, since it provides me with access to my own data.
I'm not a lawyer, but I do spend a significant amount of time working with data protection and privacy issues in the UK. With my current understanding, I don't see how that could even possibly be permitted under the data protection and privacy laws here without the consent of those whose data you're transferring to Google+.
I suspect Google could get into trouble with the ICO (what, again?) if they are behind the plug-in, but if I were them, I'd be more worried about the European level privacy hawks. Here in the UK we're relatively forgiving, but Europe can and does slap down megacorps with significant penalties from time to time.
Even for that data, while the (British) law states that people must be able to claim the information stored about them, they have to submit a request, and the company is allowed to charge a small fee.
So, no, the data protection act isn't relevant.
This has been demonstrated a few times in court but I can't be bothered to dig around for references.
> The most important principle for Facebook is that every person owns and controls her information. Each person owns her friends list, but not her friends’ information. A person has no more right to mass export all of her friends’ private email addresses than she does to mass export all of her friends’ private photo albums.
> Email is different from social networking because in an email application, each person maintains and owns their own address book, whereas in a social network your friends maintain their information and you just maintain a list of friends. Because of this, we think it makes sense for email applications to export email addresses and for social networks to export friend lists.
Source: http://techcrunch.com/2010/11/09/googles-response-to-faceboo...
So the way they're construing this, contact information is not your data to begin with, but rather someone else's data which you've been granted (perfectly revokable) access to. I don't know if this holds in court, but I'm pretty sure no one will bother bringing this to court to find out.
You can play it out in court if the judge is favourable with this case: Since Facebook has allowed viewing emails for many years, there's a reasonable expectation that emails will always be there. By suddenly doing attempts to circumvent a tool, they could run afoul of; de facto false advertising (the author stated that the use was allowed since 2010) or anti-trust/monopoly laws by abusing their monopoly against new competition.
However, Facebook could whip out their ToS and point out that his extension is illegal as noted buried somewhere deep in the legalese. Or something else.
Even though I'm IANAL, this isn't clear cut to me either.
How is this any different?
Facebook's argument has always been that it doesn't think you have the right to export your friends' contact information (or at least, they're endlessly pondering whether you have that right). Which is a ridiculous argument, because, as has been mentioned elsewhere, they already allow Yahoo Mail users to do exactly that.
On the other hand the valuation is merely based on the fact that they are the "one and only social network". They are dependent on this monopolistic behavior or they are screwed and can forget an IPO.
Zuckerberg himself with this "i just try to connect people for the rest of my life" seems to be under this bias. He is no Steve Jobs who was able under almost any condition to create value.
This social network stuff has the biggest lock-in of all internet services, but he can't prevent people from moving by force.
I highly doubt that it is illegal, but it certainly breaks FB's TOS.
Now, those 122 friends are fully aware that their public email addresses and phone numbers are available to me. Those that do not want this, should not publish their emails or phone numbers or should not befriend me.
What Facebook is doing here is to make it hard to export my list of friends to other places, like Google's contacts or my own phone's contacts list or Google+ or whatever. I have to go over each of those 122 acquaintances and copy/paste their data manually.
What they are doing is definitely not illegal, but on the other hand I dislike Facebook so much that I'm willing to switch to a competitor that already engages in anti-competitive behavior by means of their near-monopoly, but that knows how to treat my own data.
The key here is that Facebook relationships are not people you trust. They are people you kind sorta know. That doesn't imply that they are trustworthy enough to hand over your personal information to do whatever they wish with.
Facebook can't protect you from every way your friends could mishandle the data you give them access to. If you don't want them to have access to part of your profile it's up to you to set your privacy permissions appropriately, and it's Facebook's responsibility to make that as easy as possible (which they haven't).
I don't personally use Facebook, having abandoned it almost immediately precisely because my friends were collectively volunteering all kinds of information that I considered private. Today, my friends know this is my view and it's not a problem, nor am I the only one of my group who takes this view. Obviously it took a while before my views became known, though.
In any case, this whole black-and-white idea that if you volunteer any personal information to friends on one service with privacy controls you might trust then that information is fair game for anyone to give to anyone else is just silly. If it weren't, Facebook themselves wouldn't have been pressured repeatedly into creating and maintaining all those privacy controls even though it's not really in their interests to do so and they've tried to reduce them again and failed on several occasions.
That's what I was saying: If you're going to let people see all your personal info, it should be people you would trust to use that info properly. Facebook stopping Google from importing your info but allowing Yahoo to do so won't protect you at all.
Facebook blocking one method for one company to import your data is not security; it's just corporate warfare.
Oh, I realise that. And I realise that some companies are necessarily going to get access to some basic contact information like e-mail addresses anyway if they are also in the e-mail business, because we all use mail services for e-mail to work. The fact that Google are in both the e-mail service business and the data mining business is an unfortunate coincidence in this respect, as far as I'm concerned.
I guess I just don't think it's healthy that in 2011, with all the data mining and all the poor security and genuinely harmful consequences of leaks going on, we still rely on things like unencrypted communication and centralised service providers who have direct access to personal data. We can do better now, and we would collectively be significantly safer and probably significantly happier as well if we did. Swapping Facebook spying on your entire life for Google does not seem like a particularly constructive move in that context.
This is one reason all personal communications over the Internet should long since have defaulted to encryption. I don't mind Google offering a useful service, but there's really no (technical) need for them to have access to all that data while they're doing it.
The unfortunate side effect of encryption is that it is not transparent, it requires users to be completely aware of what is and isn't encrypted and also to be completely aware of where their keys are stored and how they are treated. Defaulting to encryption would just make it so that the majority of the people are unable to communicate and or use the internet at large.
Most people do not use gmail with IMAP so suggesting client side is not going to really work. With encryption stuff like mailing lists will not work either, because you'd need to individually encrypt the message for each and every single recipient on the mailing list.
That's a load of nonsense. In the grand scheme of things, solving that problem is easy. We just haven't done it yet, because while Pandora's box is open, not enough people have yet come down with plague.
Sadly, that means things are going to have to get significantly worse before they get better. Still, as the ever-increasing leaks turn into more concrete problems like bad credit because your card was swiped, being arrested based on bad intelligence, or having your political career destroyed because the wrong private comments leaked out, sooner or later enough people with serious influence are going to get hurt for the situation to change.
we couldn't manage to devise a system where every user
has unique credentials to access sensitive systems
without those systems themselves being able to decrypt
the user's data?
In the case of the GMail web interface, which I can tell you it's better than any desktop client I ever used, no, it isn't possible.It isn't, because then Google cannot render email messages in the browser for you. And if it did decryption with Javascript, it's still their client and their client can still send back information about your emails to them.
Then you've got the problem of losing functionality. I love GMail because it does a good job of searching through my emails, or filtering them. And, ever since I switched to GMail, my spam problems are over.
Of course you could argue that with encrypted emails, spam is eliminated because you can just filter away messages for which you don't have a decryption key.
But this also represents a usability problem - getting the decryption key of every user that sends you email it's a PITA; and it would also prevent unsolicited emails that you do want (like old friends contacting you for the first time, or job offers).
Really, for encrypted email to work, you have to trust the client and it cannot be the default.
But yes, it's an usability nightmare now that everyone is using webapps. And even with native apps, having to copy the private key from your computer to your smartphone would be over most people's heads.
I don't really see the difference.