Facebook's creepy privacy
jgc.org
jgc.org
I think this situation is like giving a friend your house keys while on vacation. You'd expect your friend to feed the dog, water the plants, and then lock up. Facebook is the friend that also takes the opportunity to rifle through your desk.
If you give up your password just because a stranger asks you nicely, whatever happens is your problem, imho.
The problem being described is a shady side-feature of this tool, where it apparantly stores all your contacts in your address book, even the ones not on Facebook, and when one of those email addresses ever pop up in the future, it is being re-used again. That isn't really nice if you're not up-front about it.
And you can't compare Facebook with a stranger in this context, it's a big company with a public image to maintain.
"If you give up your password just because a stranger asks you nicely, whatever happens is your problem, imho."
The problem being raised here has nothing to do with giving up a password. FB no longer has the OP's password, and cannot do anything password-related. The OP making a mistake does not give FB a free pass to do anything else it likes.
However FB got the OP's contact list, they're using it in a way that goes beyond what he understood they would use it for. That's a problem. And there's nothing you can do about it. Privacy statements are a joke, they're written in a way that gives the service maximum flexibility, they're long and inconvenient, and services will ignore them and then change them when it suits them. Privacy statement violations are likely ongoing as we speak, in every service of note. They will assume the wiggle room in the present, and brush off the challenges when necessary.
You should assume that any data you give to any entity will be used in ways that you did not consider and that may surprise or disturb you. By entity I include the entire spectrum from friend (low risk, except insofar as they save your data on a higher risk service) to corporation and government (high risk).
The more money a corporation makes from data, the more likely they are to spend the resources to use your data in creative and long-lived ways.
Then add in a corporation's parent/child companies and business partners ("... and our affiliates ..."), and business sales, and there's no way that you will ever be able to track or control your data.
The OP's problem was not giving up a temporary password, it was giving up data and expecting that it would only be used in the way he assumed. Even if he read the TOS he may not have been able to predict this, and there are additional surprising and creative violations of individuals' expectations of privacy waiting to be thought of; at best those violations might be tailored to the privacy statement in effect at the time, regardless of what the privacy statement may have said when you signed up ("... we may from time to time change these policies, and it's on your head to keep up ...").
But man that Facebook is cool.
I don't think this is necessarily true. In my experience most of these suggestions have come from friend-of-friend commonality. For example, two of the people you are friends with on Facebook are also friends with these people, so Facebook thinks you know them. Even if your thoughts on what happened in this case are correct, this kind of connection making, social graph building utilities if you will, are so fundamental to the purpose of Facebook that your objection seems odd to me. This kind of stuff is exactly why many people join.
The only interaction I had with them was via email (mostly for work-related questions).
This is one of the reasons why I would have never thought of trying to import my email account's address book.
I'm fairly sure that people are not thinking through the ramifications of giving _anyone_ else _any_ data online. This seems to be a similar learning curve as those who are finding their offline shenanigans haunting them later in online life.
And it seems quite a business opportunity to offer "reputation clean-up" services, maybe similar to the "credit clean-up" services existing now.
I am aware of an instance of a non-refundable charge of $1200.00 and the reply of "there is nothing we can do in your case."
Yep, unexpected. That's why I don't ever take up websites' offer to parse my address book.
I don't want to be the pedant who says "you should have read the privacy policy before you signed up," but you should just assume that any site like this is going to do all sorts of shady things with any information you provide, until you find evidence to the contrary. This kind of paranoia is absolutely called for on the web.
I'm not sure he received this suggestions solely on his emails contacts as I haven't allowed Facebook to access my email contacts and I could find most of them in my suggestions anyway.
I suspect that they also log when you view someone's profile and use this metric to offer better recommendations.
Anyone know more about how it works and what data they use ?
I'm sorry? Are situations requiring privacy getting rarer? I hope you can back that up with some kind of numbers, Slate.