Facebook Is Using You
nytimes.com
nytimes.com
But- there is an interesting question in what is an appropriate use of our personal data w.r.t credit ratings, financial decisions, etc... Just like there are anti-discrimination laws that prevent mortgage servicers from altering policies based on race, perhaps there should be other walls to keep separate how our data can be used financially.
This is a question the NY Times should've posed instead of this clearly linkbaity uninteresting headline.
http://www.forbes.com/sites/kashmirhill/2011/11/29/facebooks...
HN Thread: http://news.ycombinator.com/item?id=3292225
"Facebook promised users that it would not share their personal information with advertisers. It did."
I wonder why so few news sites picked up on this.
We pay in our personal data (period).
They are using it for advertisements now, but they can use it for anything they can legally get away with.
While I'd expect most HNers to have made a conscious choice whether to trade their data for FB service or not, that's not something I expect regular users to do (I think they should, but that's another matter).
Anyway, here are some links and background if you aren't familiar with it. From http://freedomboxfoundation.org and http://freedomboxfoundation.org/learn
What is FreedomBox?
Email and telecommunications that protects privacy and resists eavesdropping
A publishing platform that resists oppression and censorship.
An organizing tool for democratic activists in hostile regimes.
An emergency communication network in times of crisis.
If you live near New York City, there will be a hack-fest February 18, 19, 20 (more information in first link above). I hope to see you there.One major worry I have about decentralized systems is crackers. It's hard enough to secure centralized systems using proprietary code behind firewalls managed by an army of experts. How can a decentralized system possibly avoid becoming a 0day distributed botnet?
I do not understand your concern.
Centralized systems are easier to crack, not harder. Proprietary code may or may not be easier to crack, but I'd lean towards easier. Distributed systems do not require you to not have firewalls. Distributed systems do not require you to not have experts managing them. Nodes of a distributed system do not have to obey the commands of other nodes or have a central control mechanism.
How would a decentralized system ever become a 0day botnet?
How do you address the problem of managing a fleet of 800 Million servers running in 800 Million homes? Who are the experts that manage this problem and who finances their work? Why would average Joe trust them with his data? What is the technical device through which they have admin access to 800 Million servers in 800 Million homes?
I don't see the 0day exploit window of one additional application running on local users' boxes to be much cause for alarm. Somehow we muddled through decades of Windows boxes with everyone joining the Borg.
That's why it's important to read HN.
Eben Moglen is one of the few lawyers I bother to listen too. It helps he has a CS background. Moglen did a talk at New York Technology Council & Internet Society, Friday, February 5, 2010 that outlined the idea behind the freedom box. I remember watching & listening to the recording just after the speech. It's worth the watch/listen to get the idea in full.
The idea in short, "Own your own logs". Third parties can't infer what they don't have. The talk is located here
- http://www.youtube.com/watch?v=kpHWnHxmnXg
- http://www.youtube.com/watch?v=QOEMv0S8AcA
or here for alternative AV formats ~ http://isoc-ny.org/?p=1338
Is it a social network? Twitter? Both? Something new? Why should I want to start using it, aside from claims of anonymity?
You shouldn't be. My values align roughly with that of the freedombox creators/developers but I can easily see this will have poorer adoption than other well-intentioned technology like PGP or gNewSense.
If you want a project of this nature to see widespread use it will have to be fun, usable, and pretty.
You are using Facebook, and Facebook is using you and your data.
"Using you" has a negative connotation, like a bad relationship. So what does Facebook do to "use you"? It shows tailored advertisements. By that standard, nearly every commercial entity on the web is "using you".
The article continues with non-Facebook-specific privacy issues, mostly focussing on law enforcement being able to access your data. If you got a problem with that you should take it up with your representation, not with those that simply comply with the law.
The problems with data aggregation are correctly identified, but not specific nor directly related to Facebook.
If an employer won't give you a job, because she found a drunk picture of you on your public profile, I really see only two people at fault: You yourself, and your employer (and maybe your local laws that allow for this to happen).
I think it is weak to point the finger at Facebook, when all they seem to do is facilitate you and others to give them data voluntarily.
It's likely they already give the government more data than strictly required; they've danced around the issue when asked if they voluntarily give data to the government, in circumstances that don't require them to do so (i.e. no subpoena, warrant, or other legal order). They could choose to do that with non-governmental entities too; for example, it might be lucrative to start an employee-screening service. Some of that could be risky PR-wise, but they need not publicly disclose it, and might choose to strike private deals with a few large companies for use of the data. They could even get some plausible deniability by doing it via an intermediary: Facebook licenses a data feed to a third party for analytics purposes, and the third party sells curated views on it to interested parties.
Not sure if any of that will happen, but there doesn't seem to be much stopping it. The privacy policy is not that strong to begin with, and can in any case be changed at any time with retroactive effect (at least in the U.S.; they would have more trouble in Europe).
This kind of discrimination is difficult to prove. If I'm hiring and have a large enough labor pool (say, retail in an area with high unemployment), I can apply this to each resume that comes in, never responding to those who didn't pass the test.
Anyway, using Facebook as the lead and straw man is flamebaid but, hey, it reached the top of HN.
I don't think its unreasonable to want some assurances that my creepy neighbor can't purchase my web history or FB data. Less facetiously, at the very least, I should be informed when an adverse decision has been based upon this information and should have a chance to review it periodically.
Here are a few examples:
> In Europe, laws give people the right to know what data companies have about them, but that is not the case in the United States.
This sentence primes the audience for a discussion of the laws, but that anticipation is never fulfilled. The article jumps to a new topic immediately.
> Ads that pop up on your screen might seem useful, or at worst, a nuisance. But they are much more than that. The bits and bytes about your life can easily be used against you. Whether you can obtain a job, credit or insurance can be based on your digital doppelgänger — and you may never know why you’ve been turned down.
Yes advertising uses the same 'bits and bytes' about your life to determine targeted ads, but you can't co-mingle the idea of advertising and the drastic case of being turned down on insurance because of a Facebook posting you made.
The premise of the article is that Facebook uses you, in that they use your personal data. It's true, but they use your data for advertisement and not for the other more troubling purposes the article talks about.
The author appears to want to set up a slippery slope argument by saying that simply because a market exists for personal data beyond advertising, then Facebook will either (a) sell their corpus to those companies that already provide the service or (b) start providing those services themselves.
It's possible, but there's no evidence suggesting that it is occurring already or is likely to occur in the future---businesses don't enter new industries merely because they can; there's always a cost to diversifying and for Facebook the cost of selling user-data to let employers make hiring decisions is the loss of their dominance in social networking. Once its known that the information you give you Facebook can be used for more than advertising, people likely will stop giving that information. Facebook can make a one-time sale, but loses on the chance to continue reaping ad-profits.
Why would they kill their cash-cow and core business just for dubious short-term gain?
Secondly, I guess there's a fine line between "stereotyping" and statistics, isn't there?
Thirdly, the author looks at some of the worst offenses of this type of mining and seems to extrapolate it as the norm. FUD mongering.
If you've not ever worked in the media it's easy to underestimate the lengths they go to to work out who is consuming what and how to better channel ads at the lucrative targets, or how astonishingly detailed their information actually is. Your cable provider is probably far more evil than you imagine.
More to the point, companies that draw the wrong conclusions from data they have – changing credit limits without merit, targeting ads wrongly – will not be helping themselves.
And it goes without saying, for me anyway, that putting information online means putting it online. I don’t assume that Facebook’s interests are mine.
To me, the definition of “my data” is not claiming ownership of bits on FB’s servers. It means that if it’s on the Internet, it’s because I put it there, caveat emptor.
I don't support the implicit assumption that it is better to err on the side of leniency when it comes to credit provision. Inadequate information was as responsible as lack of oversight for causing the financial crisis. Racial discrimination is also a flawed analogy -- that was a case of using traits that had no bearing on credit risk to calculate a deliberately false appraisal, whereas using data on online activity is far more akin to the practice of requiring bank statements.
Granted, mistakes could very likely be made, but so far the author presents no evidence that using such information is any worse than other means of estimating credit.
you grant us a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use any IP content that you post on or in connection with Facebook
Though it's an interesting point; the Facebook ToS are a pretty weak way of effecting a copyright license, even worse than a click-through EULA.
I'm guessing they wouldn't be dumb enough to do so, but it'd be interesting if they tried to exploit that license grant to its maximum potential. For example, a number of musicians, and even major labels, post music videos on Facebook. If we take the terms at face value, that means Facebook gains a transferable license to use that music video, worldwide and royalty-free. So they could, for example, sublicense the video to be used in a Levi's television advertisement, without the original artist being paid--- if this license really does what it claims to do.
Copyright for databases or collections of data is variable, depending on the legal framework where you live.
In the EU, there is some protection but it requires either creativity going into the compilation, or the work done to create the compilation must exceed a certain threshold:
http://www.esa.int/esaMI/Intellectual_Property_Rights/SEM2M2M26WD_0.html
http://en.wikipedia.org/wiki/Database_Directive
In the U.S., there is no protection for a compilation of data just because you put work into the compilation: http://www.bitlaw.com/source/cases/copyright/feist.html
In any case, the basic pieces of information about you are not copyrightable, even in the EU. They have adopted privacy laws to deal with personal data.There's been some discussion on HN about copyright of public transit schedules, I believe in Australia and/or India.
At the heart of the problem is that the sharing of data is assymetric, which will prevent market forces from weeding out services that don't put a premium on ensuring their data is even accurate, let alone whether their conclusions are sound. In other words, I have no idea who is sharing what about me, or how it is actually affecting the decisions being made around me. Employers, banks, etc, don't do a post game wrap up where they show you the data mining services they use, and what they say about you (relevant aside: when I get these data mining pitches emailed to me, where did they get my email, and why do they think I may be interested in these services? I have no way of knowing). I may be able to curate my facebook data, but I can't curate an augean stable of ever changing services that I don't even use, or know exist.
Facebook does nothing to violate your privacy. The FBI intentionally spying on you without your consent or knowledge IS a violation of privacy.
This article does not really reveal anything that has not been already well documented, and most likely on the NYTImes.
But as these stories become more commonplace and the general public becomes informed of the true Facebook, I'm wondering if there will actually be people that care.
I can see as the kids that grew up on Google and Facebook become older that the idea of "privacy" becomes more obsolete and that they inherently trust the algorithms because they have always worked for them in the past.
I'm not saying that I agree with this and that I hope this is how it turns out, But maybe The Zuck is right after all.
I think there has to be a price to pay from the data aggregator side if they want information associated with my 'real' identity.
If you're actually concerned about people destroying your data after six months, why are you giving it to people lacking such an agreement?
As to your question, I use FB fairly cautiously and I'd also rather not exclude myself from a social forum which friends prefer to use.
What I'm suggesting is a simple compromise, rather than give social networks an unlimited license to my data I'm happy to give them a more limited one.
Which of course raises the question, what is the intended purpose of a facebook user…?
Anyway, one way Facebook could do this is by upselling to an account where you have access to a database table or key-value file (or mixed) showing you all the data they have about you (not necessarily use). They could further upsell you on using your data for a particular function or not using your data for a particular function, showing you the documentation to the various functions in question. e.g. an option called "Send to credit agencies" (which you can pay $5 to turn off) when expanded highlights the particular data or sections of the data it sends to which agencies. Indeed, there may even be code it can take the docs from:
/**
* Sends user's Account Data (username, full name, address if provided, etc.) and a credit score estimate determined by @See otherfunc to EquiFax.
*/
function send2equifax($account_data) { }
Or, you know, something simpler like how oAuth permissions are granted. But considering the likely target market for significant data restriction upsells, customers are probably pretty technical and can handle the specifics.Seriously though. Facebook is a for profit company. I don't really think thats wrong or even ambiguous?
FB is an awful, monstrous growth on society. I'm sorry if this sounds like an over-reaction, but its pure, undiluted evil. Its reach is just way far too pervasive and the tracking on non-members is just plain illegal as far as I'm concerned. Unfortunately, people seem to have come to believe that society couldn't exist without it.
I'm (vainly probably) hoping that the flotation will, ultimately, be its downfall. Even existing toothless Regulation might scupper its share value enough to make it an obvious bubble investment -- and people might wake the fuck up and start to remember the real value of money, people and privacy again.
I can think of many things I'd apply that label to (Such as DHS, the republican party, ACTA), but applying that to a service that people voluntarily sign up and use is a bit absurd, don't you think?
This just in: Advertising companies track people. Film at 11.
It's possible to completely avoid facebook and their tracking with the most minimal of effort. I wonder when we're going to stop seeing these breathless "zOMG EVIL!!1" rants against commonly used services and stop diluting the meaning of the word "evil".
Showing you advertisements is not "evil". Using cookies is not "evil".
Don't you get that?
I find this kind of response unfathomable.
Cookies and ad-based tracking have been around for years. I find characterizing that behavior as "evil" is patently absurd.
So no, I don't "get" that. I don't see what you're so up in arms about.
People reserve that type of speech for concentration camps or mass graves, not a social networking site where you can poke your friends. Please read up on some history and get some perspective