Swedish Radio created fake pharmacy, reveals how Facebook stored sensitive data
sverigesradio.se
sverigesradio.se
- The Swedish healthcare company Kry has built a service for digital patient calls that has leaked doctors 'and patients' contact information to Facebook. https://sverigesradio.se/artikel/health-service-marketed-as-...
- The state-owned pharmacy chain Apoteket has sent detailed information about its online customers and their purchases to Facebook, Swedish Radio News can reveal. https://sverigesradio.se/artikel/pharmacy-passed-information...
Why the f** is everyone sending our data to FB by default? It's not enough to uninstall FB; you can't even go buy prescription medicine without them knowing, apparently.
From what I have heard, the FB SDK has a bunch of nice UI candy, so folks may have used it, just so they can get the nice splitscreen, etc. (UISplitViewController is a nightmare. I suspect that SwiftUI may have some improvements to offer).
I am sure they can still get some info and that some requests slip through but I wish them luck building a coherent picture of me by a few scraps of random info.
That story was like a Trainwreck of unbelievable proportions. One bad decision after the other.
Edit: apparentlt it was Computer Sweden: https://www.svt.se/nyheter/inrikes/2-7-miljoner-inspelade-sa...
2.7 million calls. 170000 hours.
Only hackers can do this.
The tools are built to make it as easy as possible to provide as much data as possible about the users. Whether it's nefarious is debatable, but FB should definitely have some checks and balances on what they allow to be stored on their own platform.
Ok, I'll bite: try to debate how it isn't nefarious, because I sincerely cannot think of an argument.
If you don't have superbowl ads money, or already have a huge following, data and A/B testing is probably the only way to be profitable while doing e-commerce on your own website
Those are tools designed to market products, not handle super sensitive data, it's kind of like using hotjar to record sessions on your (super confidential) website to find pain points and bugs, only to whine that hotjar stores data about your users actions, that's the entire reason why you're a customer.
I really don't get the fuss.
I don't even get the point of advertising pharmacies, you don't need medicines to be advertised to you, it's even crazier that a part of the price of your meds would be "facebook ads budget"
And tbh I have more trust in the reliability of the infrastructure behind FB ads than in the spaghetti PHP code written in 2005 by a contractor for those pharmacies, or in the windows XP/vista computers that their employees use.
If I had to bet on who's getting hacked, I wouldn't bet on Facebook.
And, user behaviour on a website can very well be confidential, for example they could easily track the cognitive decline of users over time as mouse movement gets more erratic and reactions slow down - super sensitive information if you ask me. The reason a person is a customer is because they might buy a thing, not to be analyzed.
Real or pulled from thin air?
"If I had to bet on who's getting hacked, I wouldn't bet on Facebook."
My getpawnd list includes: Adobe (billion $ company), Dropbox (billion $ company) and Linkedin (billion^2 $ company) - twice!.
The bigger the company, the bigger the payoff.
In which case it is nefarious to advertise that they do handle super sensitive data correctly. Which Facebook does.
> If I had to bet on who's getting hacked, I wouldn't bet on Facebook.
This is moving the goalposts.
Plus you'll find that many will vehemently disagree with you kind of accepting as a given that data should be handed to FB carte blanche. It's a dishonest to start with such an extremely debatable starting point.
I say why don't we give them jack (nil) and start the discussion then.
This argument is like in sports: Woe me I can't win a price everybody is doping!
You are comparing security in response to an issue about privacy. Facebook's security around data that they shouldn't have in the first place is irrelevant.
Additionally, even a contractor today still could not create feature parity with Facebook as they do not have the network effect of Facebook. That's assuming the company/contractor would even try to build all of it themselves.
Or is the advertising not for prescription drugs?
https://en.m.wikipedia.org/wiki/Direct-to-consumer_advertisi...
Then how did we manage to sell medicine or call doctors before this wonderful era of Facebook integration? Would without this Swedes simply go without healthcare?
They're just using the wrong tool for the wrong job for the wrong reasons, but it's not facebook fault in that case
I'm not entirely convinced of this personally, but it seems like a somewhat sound argument. I think that they know that it will inevitably be misused, and that they have enough incentive for allowing the misuse to continue.
Anyone who argues this should not be let anywhere near sensitive data.
From the point where your data is stored it's there for good. I think that's what they have proven, also, anecdotally, a googler friend told me well over a decade ago that they don't ever delete data. Which is not that surprising, since I, as a nimble private person, don't do either. So your data is there and it's there basically forever, you don't know what that data is and how that will be used in the future. Either by criminals who steal it or by the company changing policies or even the law being changed.
So I would say that even without bad intents, which I'm ready to believe not being there at the moment, collecting as much as you can and trying to filter out whatever someone thought of as being too sensitive is the exact wrong strategy. They should actively filter out everything except what they want to store specifically and they should claim what that is.
Other than that, I think completely blocking FB (and other big 3rd party) tracking is the way to go. It should be there by default in all browsers. There reason it's not likely to happen, is of course, that the most used browsers are all subsidized by the very companies that live off of data collection.
Maybe you have an 18% greater risk of default, if you visit sites about poker?
Only the big boys have tracking on all sites, so only they can report back everyplace you visit.
Of course, it doesn't matter if you were just doing research for a paper, you now pay higher interest rares.
Banks also are one of the few places where your ID is 100% known upon login. So they are a perfect place to take loads of tracking info, and:
- link it back to your real ID
- your credit report
- your physical address
- your birth date
- things like home ownership
- all bills you pay
- using debit or cc, where you shop
They have an immense business model, where they link online tracking, to meatspace habits.
As well, since your bank often gives you points credit cards, and stores cooperate for fee discounts, often individual purchases are known.
In a sense, because "control the default" is a tactic engrained deep in the DNA of many tech giants. Control the default, and dominate the data. The default is the easy option in live, practical contexts. You have to actively pursue an alternative.
They're just in the same boat we're in. Data goes to data companies by default... anytime anyone does anything with data. If you use adwords, GA, FB advertising or whatnot... the default, ideal even, is that these get all the data. That way everything works best, and requires the least special effort and expertise.
Facebook's libraries do it, lazy people use them without thinking. Using software carelessly is extremely dangerous.
Or they're busy fighting each other over tvättstuga reservations?
Their modus operandi seems to be: wait for public outcry, then perhaps slap some wrists.
Politicians like big business.
Were people entering information somehow IN the ad, while still on facebook's page?
Not sure if they shut down the facebook pixel yet but I'm sure there is something similar around instead if they did.
My guess is that the 'ad' is has a 'sign up' where people can input information, which can be sensitive, that is capture for the advertiser. I could be anything i.e. contests, emails, whatever. The advertiser can get the data in a spreadsheet later.
If the company doing the ad is 'fake' then you have a CA like scandal possibly, where the fake company can sell that harvested data, some of it sensitive.
I think there are legit concerns here, but I mean, the companies could just as easily direct them to their own url and ask users to 'sign up', which would likely be beyond Facebooks purview to control.
So, even if you never ever had been even close to Facebook, Facebook could have the information that you just ordered some Emergency Contraceptives.
This is a massive GDPR breach of the site in question though. I really don’t fault Facebook much. Anyone who ever includes any FB script is reaponsible for exactly what it does.
Many people don't understand the implications of using FB scripts, whereas FB does.
For example, I don't think pharmacies should do any kind of advertising on FB, or do any kind of campaign tracking/conversion measuring etc on the same site they accept user data. As will all GDPR violations, if just a few large pharmacies were fined out of existence, I bet the rest would quickly fall in line.
This already holds for csam imagery.
Wouldn’t it be easier to just use an FB api to send one ping when a transaction completes, e.g with a campaign ID? Why would fb ever be uploading what’s stored in a form field that they don’t know what it means? It makes no sense?
Yes it's immensely stupid
Yes. And they are responsible for where that information ends up, regardless of how and where they advertise. So basically, anyone running any website at all should be really careful to not add any third party (e.g. Facebook) scripts to their page. I'd rather run a business not knowing whether my ad campaigns work at all, than run one where I don't know if I'm liable for breaking laws.
It's like visiting a physical pharmacy. In theory, somebody could be spying on the people who enter and leave the place, keeping a giant database with frequency, faces, etc. The question whether it is stupid to enter a pharmacy in person should be answered with: "No, we have laws that protect us against malevolent actors".
People do this in the US with Planned Parenthood clinics and parking 4K cameras outside/across the street and license plate recorders/scanners.
>The question that the reporters then asked themselves was whether or not Facebook even has a filter that works in the Swedish language. One of the pharmacies that Swedish Radio reported on say that they cannot find any warnings from Facebook on data transfers that have taken place. The other has not wanted to answer the question. According to state investigators in the USA last year, Facebook only filtered in English.
Wow, seems like this will have major implications under GDPR as well.
> Article 9
> Processing of special categories of personal data
> 1. Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
> 2. Paragraph 1 shall not apply if one of the following applies: […]
(https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...)
Also, as a country or nation state, if you do not curtail and prosecute these thieves of private data, then you show you don't care enough about your populace.
[1] I recommend using a combo of https://nextdns.io/
[2] Ublock Origin: https://ublockorigin.com/
[3] and No-script: https://noscript.net/
Quite literally victim blaming.
No. The companies are to blame.
The internet shouldn't be a bloody minefield that is impossible to navigate without a PhD in network security.
So I can't use a MacBook or iPhone? I can't watch Netflix?
Facebook Support is the biggest joke ever, even if you are a paying user of FB Ads. They can't or won't answer any question at all, and always reply with "We'll contact you soon to let you know if there's any updates".
It can't be tracking info, Facebook doesn't give access to such things outside the company, so the authors wouldn't have been able to confirm the records sent were still available. Also, technically the pharmacy wouldn't be sending those records, the fake user's browser would be sending them.
If I had to guess, the fake pharmacy created "Custom Audiences" -- lists of identifying info, like email addresses, that Facebook can use to serve an ad to a specific person-- and labeled them as people that had purchased some specific drug. You can name these whatever you want, and can read their contents.
API docs here: https://developers.facebook.com/docs/marketing-api/reference...
There's no complex tagging system, it looks like name and description are the only places where you could say this is a list of people that bought a specific drug.
Are they concerned because medical, or because facebook?
I don't thing I know anyone who would agree...