Facebook bans researchers who were investigating Facebook ads
dailydot.com
dailydot.com
>Facebook moved to penalize the researchers in part to remain in compliance with a 2019 data privacy agreement with the Federal Trade Commission, in which the company was punished for failing to police how data was collected by outside developers, Clark said. Facebook was fined a record $5 billion as part of a settlement with regulators.
That's a reasonable explanation for their action, right? Even if it's not 100% true, if you're a manager at Facebook, and the situation isn't 100% clear cut, you're still going to act, so you can show it as an example the next time the FTC tries to fine them.
And they did offer an alternative:
>Clark said Facebook offers targeting data sets for political ads, and has suggested the NYU group use that information.
I believe it is reasonable for FB to react to scraping under the current circumstances. But it seems equally reasonable for the researchers to go with the data collection approach they chose.
Facebook also goes after other browser extensions that scrape data, not just researchers: https://www.zdnet.com/article/facebook-sues-two-chrome-exten...
and that is the gist - is your browser a part of the FB platform or not (the situation of ATT network and the telephone and even just the phone book). FB behaves like it is and like as a result they have control over it. And them getting their way means we ultimately lose very important area of general computing. That has been already happening as unapproved ways of calling web APIs have been met with responses from C&D all the way to criminal prosecution.
That's insane. Why even have a web API if I can't make HTTP requests to it? Why do I need "approval" to do what their own javascript does?
It’s kind of like asking “what’s the point of letting me into your warehouse if you didn’t want me to take the compressor that was in there?” but you signed a contract not to take the compressor before they gave you the key to the warehouse.
I should be able to create my own user agent for a website if I want. I should be able to replace their web application and non-free javascript with my own software.
FB is totally free to ban you..
I mean they're a gussied up advertiser, of course if you mess with their "engagement" or bottom line they'll ban you. It's like the "rubber hose crypto breaker" XKCD.
We ought to add another party: the public. Perhaps data should be able to be used for the public good, and we should be able to participate in deciding what data is collected and how data is used.
In this case, having data about what ads are seen, by whom, and why they see those ads, seems like it could lead to us better understanding how FB and other companies algorithms are segmenting the population and how certain ideas proliferate within those segments. This seems beneficial to the public, since as we've seen over the last 5 years or so, these platforms and the way they choose what information we see can have drastic effects on the economy, politics, etc. If I had a choice, I would choose to continue collecting data about the behavior of advertisers and the platforms that serve them for that kind of analysis. But we don't have a choice, because facebook "owns" that data.
A number of people in this thread have referenced Cambridge Analytica. When Facebook does choose to share data with other parties, we have no say over what data is shared with them or what they may do with it. We don't even get a choice in how Facebook internally uses our data. Instead of democratizing the decision of what data is collected and how it is used, the FTC applied the rules of private property and fined FB for lack of privacy.
The public got nothing out of that situation. Facebook now is more defensive of their ownership over our data, which also precludes us using it for the public good.
Regulation of broadcast was justified on the basis that the airwaves were a scarce and shared public resource. In looking at a coherent, pragmatic, and equitable basis for regulating online content and surveillance, the notion of a common public good and interest might be a good anchor.
In discussion, the notion that public awareness, attention, mindshare, and understanding are themselves a common good ... gets to some interesting (and yes, scary) places.
Interests in privacy, concerns over widespread or highly targeted manipulation, and similar concerns could possibly form the basis of coherent limits on tracking, surveillance, and "information sharing" on individuals and groups. Open, transparent, and ethically guided research ("who decides" being university and professional ethics review boards, as is presently largely the case in human-subjects research) could be excepted, but would require those components.
Acadamic use vs commercial use is a separate topic too imho.
And irrespective of this opinion, CA backfired spectacularly on them, so it's not totally unreasonable for them to enforce that right.
The whole point in the project is to make the scraped data available to anyone and everyone who is interested. They publish this data via a public database. This is articulated very clearly at the top of the Ad Observatory project page.
"Ad Observer is a tool you add to your Web browser. It copies the ads you see on Facebook and YouTube, so anyone can see them in our public database."[1]
The Ad Observatory project collects the following:
"What we collect
The advertiser's name and disclosure string.
The ad's text, image, and link.
The information Facebook provides about how the ad was targeted.
When the ad was shown to you.
Your browser language."
Additionally the code for the browser plugin is up on github[2]. How much more transparent could they be?
[2] https://github.com/CybersecurityForDemocracy/social-media-co...
Of course it’s much easier to blame muh Russia than it is to blame Facebook, who created the platform and by definition set its boundaries. They literally gave all the information to Aleksandr. All he did was read their documentation and query their API endpoints as designed and officially documented.
He literally followed Facebook’s instructions to get the data they offered to him. And yet here you are using weirdly ethnic overtones to denigrate him as some evil hacker that victimized Facebook by pilfering some nebulous “private” information that Facebook worked so hard to protect.
It’s the same reason Fox News says “Alexandria Ocasio-Cortez” instead of the more common “AOC.”
> It’s the same reason Fox News says “Alexandria Ocasio-Cortez” instead of the more common “AOC.”
Wouldn't you expect a news organization to use the full name for a politician instead of a colloquial term, regardless of how they feel about them? They don't say RBG either for Ruth Bader Ginsburg, despite the fact that Internet conversations use it heavily.
I know this is a radical viewpoint these days, but it turns out that not literally everything is about race.
And there's no guarantees with any data. Facebook itself can't be trusted to not have leaks. Two years ago, data from 500m profiles was leaked, Zuckerberg's own Facebook id, mobile phone number, and other information.
Individual users:
1. May not be aware of how data are being used. (In fact this is a virtual certainty.)
2. Don't appreciate the immense power of data in aggregate. (Something that is close to Facebook's key commercial advantage.)
3. May be exposing data on other users, who are not participating and/or don't consent to particupate in such data hoovering.
I'd argue that Facebook can also make exceptions, and that good-faith, well-reviewed research projects, particularly those aimed at independently assessing manipulation and propaganda efforts on the platform, are a case I'd strongly recommend. But to say that Facebook has no right or obligation to decide is false on its face.
As a business, making a business decision, they'll want know "can this come back to bite us" (and they will miss many of the ways that might happen), and, how much will this benefit us either in money or in facilitating new ways of making money with the new information.
My reply to that addresses some of your concerns as well.
TL;DR: the call is not entirely Facebook's to make. Perhaps not at all.
Understandable that any entity that bypasses their API/consent flows and collects a user's data would be a big no, regardless of what their intended use is.
Personally I don't think access should be given based on assumption of the query's intention (daily browsing vs scraping data for analysis authorized by someone), but like r/w/x and user group, i.e. if you can view, then you can view and record. Otherwise either no access granted, or burn after read.
However, your principle argument that there's a difference between Facebook serving pictures to friends and massive, automated serving of pictures to bots and scrapers. I understand that there's no good way to differentiate, and that the bits that are sent over the network are the same regardless of who is consuming them, and that my friends have the technical capability to upload the images elsewhere.
But just as you get different outcomes between one situation with an individual policeman watching traffic, pulling over reckless vehicles or tailing a suspect vehicle with a known license plate and another compared to a network of automated license-plate readers and speed cameras tracking the city-wide movement of lawful and criminal people alike, you get different outcomes when you differentiate between bots and live users.
Generally I agree and understand FB's position. But isn't all of the data from Ad Observer publicly available?
why they were targeted for the ad.
How is that determined exactly? Does the clientside download details like that, for what purpose?Haven't used FB in ages but I assume it's like "why am I seeing this" hint in youtube recommendations (which usually says "because you watched video x").
>Facebook defended the action Wednesday, saying: "We repeatedly explained our privacy concerns to NYU, but their researchers ultimately chose not to address them and instead resumed scraping people's data and ads from our platform," a spokesman said.
The ethical complaint is that they accessed data without consent:
> "Facebook defended the action Wednesday, saying: "We repeatedly explained our privacy concerns to NYU, but their researchers ultimately chose not to address them and instead resumed scraping people's data and ads from our platform," a spokesman said."
There shouldn't be a worry about what the researchers are going to do with the data because they make it public.
[1] https://www.reuters.com/technology/us-lawmaker-says-facebook...
Thanks for the downvotes appreciate it
I imagine you're getting downvotes because you need to expand on this.
What specifically is NYU doing correctly that Cambridge Analytica was doing incorrectly?
> “By suspending our accounts, Facebook has effectively ended all this work. Facebook has also effectively cut off access to more than two dozen other researchers and journalists who get access to Facebook data through our project, including our work measuring vaccine misinformation with the Virality Project and many other partners who rely on our data. The work our team does to make data about disinformation on Facebook transparent is vital to a healthy internet and a healthy democracy.”
So, what's the issue?
Facebook just submitted this ad to me. I don't know why, they "trust" me. Dumb idiots.