How to Force Facebook into Handing Over their Secret Tracking Data
europe-v-facebook.org
europe-v-facebook.org
They delete sh*t, if you delete your posts they don't remove them from their databases.
This makes me really angry, there is a reason why i delete this stuff. I can't believe this, they have a responsibility.
Edit: WTF http://europe-v-facebook.org/EN/Data_Pool/data_pool.html#Mac...
This is maybe the most frightening: http://europe-v-facebook.org/EN/Data_Pool/data_pool.html#Mes...
There's a deep wisdom to the idea that one ought not put into words that which they wouldn't want the world to see... Once it's out of your head, your ability to control it diminishes if not outright vanishes... Just say'n is all..
It has yet to hurt me.
I would also make a very big assumption that the only companies who wouldn't do this are those run by developers or other people who have had experience implementing that sort of system.
There's nothing bosses love more than storing whatever data they can get their hands on, no matter how relevant it is, and how reluctant they are to actually delete it. Or secure it properly. Hell, it's just data, who gives a shit right?
I think that may be a view shared between developers who care about ethical practices, where our personal ideals and how we think we should respect the user takes precedence over the data collection and profit motive.
I think it's important to remember websites are dealing with actual people, who aren't a new commodity to be exploited for capital gain. Who aren't little mines full of precious data ready to extract at any cost.
Of course, none of this really matters. Whether you delete something or not, it will be routinely stored, over and over again, on some backup server. It's there forever.
For me, at least, it all depends on what 'delete' means to the user. There are some people out there that want 'delete' to mean "I don't want this stored anywhere anymore". There are other users that want it to mean "I don't want to see this anymore".
Unfortunately, people in both groups sometimes regret deleting stuff. Those in the first group accept the responsibility, however some people in the second group feel as though it's a problem with the system that they are using when they cannot restore the data easily. There are a lot of people that appreciate the "Recycle Bin" in Windows and never empty it.
Now, I've written a number of systems over time and I've implemented 'delete' in most of them. Sometimes I do an actual delete, sometimes I set a flag. It all depends on what I expect my users to actually want. It's got nothing to do with trying to exploit them for capital gain though, that's for sure!
I, however, do not implement an easy way to retrieve deleted data without going into the database or through an administrative interface with heavy auditing.
It isn't just about data mining for customer data -- it's about data mining for site usage and user activity. Using metrics off of visited web pages or tracking that way can be too convoluted when the KISS method is: flag it on the data side and you can interpret flow.
You can force local governments to expunge your data (it's not just off the records, it's forcibly erased).
I think this weight of eternal data is both unnatural and unsustainable. All living things die. Things that don't have a natural cycle of creation and destruction are abominations and should rightfully be feared (see Corporation).
People who will blithely click "Delete" — and then click "Yes" even though they don't mean it on the confirmation dialog that comes up — vastly outnumber people who care that an invisible copy of their content might be buried in some Facebook database somewhere. Next to the unintentional deleters, the second group looks like a rounding error. And that's not even counting people who get their accounts hijacked.
So I would say people who know users are more likely to go with the delete flag, since that leaves you an avenue to help the user who emails support with "I got really drunk last night at the wake and thought it might be funny to delete everything on my Facebook and now all my photos of my dead Nanna are gone."
What I would actually implement is something akin to the recycle bin in an OS. Flag something as deleted, ensuring it's no longer published in whatever form on the website. Optionally, delete it properly after a set period of time, or otherwise allow the users to manually perform that action.
In addition to that, log the delete actions along with the IDs of the deleted items. So if after all that the user regrets it and files a complaint, you can trawl through your backups to restore it.
Irreversible actions in the UI are bad. Having no choice but to tell the customer tough luck is bad. Deceiving the user is also bad.
Of course I'll concede my ideals are more compatible with the concept of deleting an entire user account, for example, as opposed to removing individual items associated with. But I don't think everyone else's intents are as pure as yours.
There was a rather interesting example in Queensland ~two years ago when govt. health sector payroll data (from an outgoing system) was deleted due to privacy concerns, and then the replacement system mis-functioned (never really worked) and the entire state's health payroll information was lost. $200 million and counting to fix the lost data.
I have many times ran into a situation where having that deleted data either saved us from losing a customer or was used to show that our app was not mysteriously "deleting" their data.
And, when you click on the delete, should they erase the information:
* From the cache
* From the database (not only mark it for deletion)
* From the weekly/monthly/yearly backup
* From the old backup system that is not longer in use, and was connected to the old backend that is not longer in use.
And remember the man that gets his Flirk account erased by mistake. Luckily they got a secret mode to restore it. http://bindermichi.posterous.com/how-to-subdue-a-major-inter...
There is no necessity to change backups, just to remove it from the current database and when the last backup is outdated it is gone.
You can't come up with a realistic example that cannot be solved by 6 months old backups.
EDIT: That was just meant to be an example. I believe it's generally a good practice to use a delete flag as the default option (unless there are legal or serious privacy concerns), because it makes you sleep better at night. I don't know if it justified in this case, but I just wanted to point out that they did not do it just out of pure evilness.
Hell, my mail client has been doing that as long as I can remember.
My solution: mark the record with a 'deleted' flag, leave all the logical/structural data (user id, post id, etc.) untouched, overwrite/wipe out the post's content, on the webpage display "Post deleted" message. If you want to have an ability to 'unerase' things: mark as deleted, delay the purge.
Cache should be purged as well, though not necessarily in real-time. Backups issue is a complicated one - but is there any use of yearly backups in Facebook case?
That last one is scary indeed. People were arguing a while ago whether these companies should keep data only for 6 months, or for a year, or 18 months - but Facebook is simply keeping it forever. Even 10 years from now law enforcement could verify your Facebook data.
Facebook Timeline should give them a nice UI, too, in case you don't delete anything. But they would still want to dig deep. I wonder if Facebook built a special Timeline product for law enforcement to see everything about everyone. Remember when they admitted a while ago that they provide law enforcement a special software for the data? I wonder if the idea of Timeline for users comes from that.
Julian Assange was dead-on that Facebook is the biggest spying machine.
Reduces any qualms I might have about calls for Facebook to be regulated as a public utility, if it's actively choosing to act as an arm of the government anyway. Public utilities are actually, despite being much more entangled with the state in some ways, more separated from the state when it comes to law-enforcement. For example, the phone company can't just choose to record all your calls and give them to the police without a warrant.
Wasn't the Patriot Act recently renewed, where "recently" means "post-Bush"?
> If you want this fixed, it has to be fixed politically at a federal level.
And Dems, who voted for the initial version overwhelmingly, were uninterested in doing so when they held all three elected branches and that didn't change when they lost one.
So, yes, it's true that it was passed under Bush, but no one is interested in fixing it. (Yes, I'm ignoring Ron Paul and Dennis Kucinich.)
The question is if they have the ability/requirement to go sifting through the old backups for requested data.
http://gmailblog.blogspot.com/2011/02/gmail-back-soon-for-ev...
So this means that when I design the software for TrackMyEatingHabits.com, I should also be mindful to have a process (and data model) that makes it easy to locate this user data quickly, right?
Also, I should have in place processes to verify the identify of the requester too, right?
Or alternatively, I can just limit my market to the U.S.
To put it another way, are you worried if your US company breaks Chinese censorship laws? That's illegal in China. Are you worried if your company denies that the Holocaust happened? That's illegal in Germany.
You only need to abide by laws in the country you are in. Unless you have a EU server you don't have to abide by EU laws.
If you specifically target/advertize (e.g. with translated interfaces) your services to EU citizens, a judge might decide that EU laws apply to you.
Moreover a US judge might not care, but a French or German judge might decide he is competent (if there are good reasons to think the website is not US only).
Of course, if the company in question also owns a EU-based daughter company through which it operates on EU market (as Facebook apparently does), then that's a whole different ballgame.
So far no one send request for all their access log data, but that would mean, that we would have to go though billions of entries.
Actually not a lot of people request their information anyway. It's sill better then the software patent situtation in the use.
I would suspect this means Facebook just simply did not provide it?
It might be possible to derive this information by linking on the IP address, but that isn't the same thing as a direct link at all.
If I view a profile on the mobile app or on the web page it is (presumably) measured the same, presumably in the application layer. That's different to recording the your id in the HTTP access logs.
I was in a band back then. Set up the page, tried to add my own band's music, and was told I had to provide valid ID first.
Additionally you should write in big letters over the scan "Request to access Facebook Data <date>", so that nobody else can use the scan of your ID-card for anything else.
The rest of the data, Facebook already knows (name, date of birth) or is useless (passport/ID document number).
Source: https://pim.bof.nl/gebruikers/geef-niet-meer-dan-nodig/ (Dutch)
This serves no purpose as it is trivial to 'shop these big letters out of the image.
I can't really imagine how you'd want to reconstruct that, and even if you could I'd hardly call it trivial.
http://www.dataliberation.org/
Or, from your Google+ page, click on your picture in the top right corner, then Account Settings, then on the new page click on Data Liberation on the left hand side.
A simple but perhaps inconvenient way to verify this is to be criminally prosecuted for something where your Google account is relevant. Google will hand over what they have to the prosecution, and as the defendant, you'll be entitled to see the evidence. (I've not tried this and don't recommend it, but do know someone that this happened to, and have examined the contents of the provided CD.)
DataLiberation is mostly a PR site, and it's main use is migrating what data Google feels is useful to you, not finding out what Google knows.
by @nextparadigms I'm thinking of quitting facebook
"If you are a resident of or have your principal place of business in the US or Canada, this Statement is an agreement between you and Facebook, Inc. Otherwise, this Statement is an agreement between you and Facebook Ireland Limited."
So if you're living in USA it seems like they don't need to comply with your requests.
Almost immediately I got an email saying that "Unfortunately, we won’t be able to respond to your email directly, as this form is only applicable in certain jurisdictions." Might try again when I'm back over Christmas.
Edit: On inspection of the Facebook T&C page, it says I'm contracted to Facebook Ireland, so I'm not sure what the email's about.
Related (well, maybe): You can easily download a copy of your Facebook data no matter where you are located, by logging in and clicking "Account Settings" > "Download a copy of your Facebook data". This will include all things like messages, pictures, etc., but I am positive that it isn't nearly as in depth as what is outlined in that article.
Wolves move in packs, too.
We have the right to use government to nationalize these programs if they are going to be so deceptive and intrusive.
Facebook falsely advertises their service as free. They don't tell their users that they are collecting unnecessary amounts of data to violate people's privacy, and that this data is payment for the service.
I really hope one day pg changes it so that all votes on articles and comments are publicly available, so that we can run our own analysis' using it. It would be interesting to see how much of the content on HN has become dominated by these employee rings over time.
If you're so out of the loop that you didn't know about f8 and 'frictionless sharing' then read up about those things and viola, you'll realize why these stories are all popping up the rankings.
FB is creepy and keeps getting creepier.
Keep your tinfoil hat on though if you want.
I also have only a passing curiosity of a desire to work for Google, no more or less than Facebook, Apple, Microsoft or any other large tech company.
However, I find it disconcerting how ALL companies seem to be edging towards creating and storing a mass of data about individuals without disclosing the entire purpose, what is held, or how to access it.
With that in mind, this is a great article/link. The Data Protection laws in Europe are wonderful, and they're there for a good reason (remember that Europe has been host to things like the Stasi).
We value our privacy, and we value our right to know what data companies hold about us.
So please step down from your soap box and ask yourself: Is there a real problem that resonates here? Is there a reason X stories are all on the front page at once?
It's nothing to do with employees waging a PR war or anything as petty... it's because even amongst very technical people there is a lot of concern about the direction things are going in, and Facebook (and sometimes Apple recently, though Google might trump them soon with Google Wallet) seem to be at the very front line of it.