Facebook Ordered by Hamburg Regulator to Allow Pseudonyms
bloomberg.com
bloomberg.com
AND then they expose it publicly to anyone who looks up my profile, even when they aren't my friends.
AND this is all after me having disabled the "show birthday on timeline" and enabling every other privacy setting there was.
If there's one company using AI and data collection for evil, it's Facebook. Not to mention the years of silently disabling previously set privacy settings without getting the user's permission - e.g. the "show profile in search".
Insane. Facebook should be slammed hard by the courts.
- Easily deducing my approximate age from my Linkedin profile.
- Any of the numerous other private people data sources they have access to or have bought over the years. I'm sure my birthday and basic details are in some of those. It's impossible to get those all deleted once the information is out.
- Day and month are easy, because everyone wishes me happy birthday in the messages and wall posts. All that's remaining is the year, which could be easily deduced from Linkedin and other third party data sources. - Which I've mostly cleaned up now, until Facebook exposed it all again.
- I had a profile for a few months in 2005 before deleting it. Used a different computer, different location, different email and everything for this new one a decade later, but probably they've connected the identities. Looks like if you ever tell Facebook some private information, it's non-revokably theirs to expose to the world forever.
Facebook invests very heavily in machine learning / AI, and uses it heavily through out their platform. They collect and buy tons of data both on the site and from third parties. This deduction is trivial for them.
The bad part is not so much that they deduced these details about me though, it's that I specifically made it clear that I didn't want any age public, let alone the real age, and they exposed me anyway.
Facebook runs one of the top machine learning research labs in the world. They're among the most clever in this domain, by every possible metric. They've written extensively about how they employ machine learning across their entire product line, and are adding more constantly. They've acquired numerous ML startups and world-class researchers.
https://research.facebook.com/
https://research.facebook.com/researchers/1543934539189348
Respectfully, you're absolutely wrong, and I'm suspicious as to why you'd be intentionally spreading misinformation that they don't use ML/AI to fill in the gaps in their information about their users.
> "We strive to find ways to deliver more engaging content in News Feed, rank search results more accurately, and present the most relevant ads possible."
I think it'd be a pretty poor use of ML and AI to use it to try and guess the gaps in your profile, and then fill them in. Of course I'm sure they try and show you content and adverts based on what they believe your demographic profile might be, but these beliefs are purely internal to the algorithms that make the decisions as to what to publish - they aren't used to populate your public profile.
In fact, Facebook want the profile information to come from you and for it to be as accurate as possible - to help those algorithms. It wouldn't be sensible or useful to just set your profile fields based on guesses, no matter how clever the ML behind it. As I said before, I think people ascribe too much intelligence to the way Facebook handles personal information - it isn't magic.
Actually, the LinkedIn profile is the most likely, people often try these things, signing up and click-thru acknowledging everything without thinking, then never touch the app again. All I'm saying is that often what you think of as external is actually caused by actions you performed and then forgot about, or never really registered in the first place. Although, some of this may well be down to 'Dark Patterns'in the UX, which should really be investigated and changed.
I do have a FB connection to the place, though.
In general, I think most of the 'Facebook/Google have secretly stolen my personal data with intrusive sureveillance' anecdotes really are the result of someone clicking 'yes', 'yes', 'of course' without thinking when they first signed up, and giving access to their email addresss book or similar, then forgetting about it. They then get more privacy concious later, and suddenly wonder how all the information got there. And since they're privacy concious now they couldn't possibly have uploaded it, so it must be Facebook hacking them.
I've yet to see an actual documented and acknowledged example of a company like Facebook or Google doing the sort of intrusive data mining and surveillance that people accuse them of without the user's permission being given. It always turns out to have been provided at some point previously in the relationship.
1.) The Facebook and Google AIs are teaming up and following me and my friends and family around the web to see what we each had for breakfast.
2.) Facebook sort of tricked me into not clicking the button that said I won't not disallow them to keep all my personal information, and link it to my friends data too, if they can.
I've never knowingly provided my cell number to facebook, as I don't use facebook as an o-auth provider so I consider 2fa as less important that my privacy in this case.
They can read your number there.
I'm fairly accepting that every android app asks for "permission to read ..." permissions, but I don't want them to be so proud of this that they present their information back to me.
That's what is so creepy about Facebook, they've lost sense of what is normal, so they don't hesitate to show off how much they know.
I'm sure Google knows a lot more about me, but they have the sense not to parade that fact back to me unless I specifically ask.
Same with LinkedIn, who installs this crap? And why?
Of course, there's plenty of other crap on my phone that I've installed and is exposing me...
For me Facebook is a necessary evil. I'm not willing to miss the family trips that only get planned there so I just attempt to minimize damage.
Maybe what's normal has changed out from under you.
The permissions include:
Device ID & call information read phone status and identity
From: https://support.google.com/googleplay/answer/6014972?hl=en Device ID & call information
An app can access your device ID(s), phone number, whether you're on the phone, and the number connected by a call. Device ID & call information may include the ability to read phone status and identity.
Which returns "null" unless the operator actually stores the phone number in the SIM so it can be read from there (also it can be modified to be anything). While technically possible, I have not seen it in practice for long time (since 2010 or so).
On iPhone it's not possible for an application to obtain the phone number[2]. There was a semi-hack doing so and Apple rejected the applications off the store and closed the loop. (reading SBFormattedPhoneNumber)[3]. In 2013 there was another exploit to obtain it but it has been addressed as well.
[1]: http://developer.android.com/reference/android/telephony/Tel... [2]: https://www.google.com/?gws_rd=cr,ssl&ei=GNa4Vc3ODuxxxxrQCg#... --it's google search with the reject terms [3]: https://www.cocoanetics.com/2009/11/forbidden-fruit-apple-ap...
Personally I have not seen an EU provider storing a real phone number there.
and the number can also come from a friend phonebook within one of the aforementioned apps
I'm a product even without having signed up.
EDIT: Shouldn't I have some kind of say in that?
'Shadow profiling' ought to be 100% illegal.
They have no business propagating that information any further than the profile that supplied it.
The genius part of it is that people maintain their own personal dossiers on themselves. Who would have ever, in their wildest dreams, been able to think of a future where an authoritarian regime has gotten its citizens to keep their own files on themselves. It's bonkers.
There used to be an assumption that a national, let alone global surveillance state would have been impossible due to the sheer workload of maintaining dossiers on everyone, who would have thought that is totally irrelevant because people are more than willing to self report.
> How can a government have jurisdiction over this?
Because the government can decide that demanding a driver's license is illegal because it is an unreasonable burden on users, simple as that. German law states it must be possible to use a service anonymously or pseudonymously "if it is technically possible and reasonable". Whether it is reasonable in this particular case is for the courts to decide. (cf. Telemediengesetz, http://www.cgerli.org/index.php?id=51&tx_vmdocumentsearch_pi... )
Alternatively, they can try to hit Facebook's ad sales in Germany, but that's likely to run into common market rules around trade barriers.
Anyway, does Facebook actually enforce this? I have never shown any ID to Facebook, and I see plenty of people not using their real names (typically they use derivatives or add a screenname as a middle name, rather than being totally pseudonymous).
The result of the real name policy, outside of taking away individual privacy, has been the shutting down of accounts, forcing people to provide identifacation, phone numbers, etc, to prove you are you, and insisting that the name matches the legal name. Some people never really seem to be able to unlock the original account (or don't want to give facebook ID)
Around a year ago, many of my friends were in a "Gay Pride 2014 parade" group. Over two or three days, everyone in that group with a fake-looking name was reported. A little later, everyone who had 'liked' a local gay nightclub page was reported.
The obvious conclusion was someone with an agenda was searching particular groups for people to report.
Facebook has offices in London and Hamburg so "operating out of Ireland" is a bit of a stretch that seems to work with tax authorities, but may not work with other law enforcement.
The Schleswig-Holstein data protection authority lost a case against Facebook in 2013 because the court ruled that Germany didn't have jurisdiction. However, the Google Spain case last year changed that pretty decisively. It's difficult to see (after Google lost before the CJEU) why Germany should not have jurisdiction in this case.
How can a government have jurisdiction over this?
By the existence of a law proclaiming so.Also, in this case it was not the government but another organ of the state, unless you refer with ´government´ to any organization of public law.
In many jurisdiction there are restrictions and rules for businesses in place. For example, often you can't restrict purchases of your product based on the customers skin colour.
In Germany privacy is fundamentally more valued and protected than in the US of central-north America. For example, under german law you have the right to get virtually all information a organization is keeping about you, why they are keeping it, where it is from, how they use it and who they share it with. The organization is obligued to comply without financial compensation [1]. Furthermore, there are broad cases where the deletion of the stored information can be demanded [2]. Information about people may not be stored without the technical necessity for the service or without the explicit consent from the affected persons. As soon as the consent is withdrawn or the data is not any more needed to offer the service, it must be deleted.
Facebook collects and keeps data about people who do not have an active account. That is not allowed in Germany. To put it blunt; in its current form, Facebooks practices are illegal under german law.
Germans don't want anybody to collect data about them, and made laws against it. Ironically, they still use Google. I guess most simply don't understand the implications or don't see practical alternatives.
I hope this elaboration makes the situation more understandable.
Indeed, in Section II, Article 7 rules are laid down [1] which Facebook is violating, for example with shadowprofiles.
[1] http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX:...
No, you've got that backwards. Jurisdiction is what allows the government to make a law in the first place.
"Territory within which a court or government agency may properly exercise its power"
The only problem would be enforcing the law. As Facebook has offices in Germany and targets German customers that shouldn't be too hard.
If you read the page you linked closely (and remove all the US specific stuff) you see that it really only talks about of enforcement not lawmaking. Your own addition
> Jurisdiction is what allows the government to make a law in the first place
can nowhere be found on the page you linked.
There are a lot of laws in the books everywhere in the world that are usually not enforced because you can't. Germany (as well as many other countries) has laws regarding human trafficking that apply to anyone everywhere in the world. Would you argue that this is not a law? If that's the case we can agree to disagree.
What you are calling ’law’ I would maybe call ’enforced law’ or ’enforcable law’(by whom?). Well, whether the rules in question are of this kind is what will be found out in court.
The only problem would be enforcing the law. As Facebook has offices in Germany and targets German customers that shouldn't be too hard.
It is an interesting question if Facebook requires your real name to function properly and if this decision would hold in court, but it is in principle covered by law and I imagine the fact that facebook and other social networks have worked without these rules before might work against facebook here.
IMO this ought to be a global rule. It's completely unacceptable to have a private company arrogating to itself the ability to "out" you at its convenience.
Fuck contracts. It's wrong.
Just don't give Facebook your real name, then they can't tell anyone your real name. They might deny you service, but they can't 'out' you.
As with Linkedin, that's not sufficient. Other people can tell them your name.
And it sounds like German privacy law prevents requesting identity documents (which are, after all, government issue) when not actually required for fraud prevention. Theoretically US law has a similar rule about social security numbers but it's not well enforced.
I was working for BT at the time and the briefing we got on use of NI numbers was very clear that break these rules and your ass is fired - it was stronger worded than the don't look up the queens private telephone numbers one we had.
Or more broadly, how can a government have jurisdiction over anything, or anyone? The answer is fundamentally: by force.
For example, if I point a gun at you, I've just established the same kind of "jurisdiction" over your wallet. Because otherwise you'd just refrain from giving it to me.
But isn't it great that a "privacy watchdog" is limiting the privacy invasions Facebook can inflict on us, while surveilling us themselves, and funding their operations with money that's forcefully taken from us? It's like, heart-warming!
(They've established "jurisdiction" over our incomes!)
Aren't this claims funny?
It is not my fault hat almost all the people doesn't agree with your libertarian fantasies.
Ad I said, your libertarian claims are very funny. Out of reality, but funny.
Suppose that there actually is a group within the government that's genuinely trying to protect us. Even so, the organization they'd be protecting us from is the exact same one they're part of. How does that make sense?
It's like there's a pack of wolves next to a herd of sheep, and one of the wolves is like: "Guys? Guyyys? Can we just not eat them please?"
In reality, governments are hell-bent on monitoring everything we do, because that's a great way to cement their power over us.
Dictators don't arrange elections, and the most productive slave is one who thinks he's free. That's a large part of why the whole world isn't under complete tyranny right now. Try protesting anything any government does though, and the response will be tear gas and batons. That shows exactly how many fucks they give about our well-being or wishes.
(Recent examples: Hong Kong, Brazil, Venezuela etc)
It's their country, not Facebook's.
Facebook should really not try to make the same mistakes as G+ in that sense
I don't think any of the German Facebook friends I have use their full real name, and some of the pseudonyms aren't even that real-enough sounding to German-speakers.
Facebook would be making the same mistake as Google if it did allow pseudonyms.
In England you can use whatever name you like, as long as you don't have the intent to deceive. (This is tricky with doctors and banks). So, legally, I could be "Bob Smith" and "Ann Jones" at the same time. Why does Facebook get to tell me that I only have one name when my government is fine with me having multiple names?
Because Facebook isn't your government. It is a non-government entity with a very specific vision. If it finds that the use of fake names hinders the experience of other users and there by Facebook Corp., it should be allowed to require real names.
Other than for a small number of reasons due to protected groups, businesses generally have the right to refuse business to anyone for any reason.
Do I think Facebook should be allowed to block black people? No.
Do I think Facebook should be allowed to block pseudonyms? Yes.
I've never tried to use a false name, but it probably would be easy for many things (utilities, local government) but difficult for others (bank account).
I don't have a FB account for quite some time now, but yes: Every contact (right - let's be honest: 80% of my contacts or more) obscured their name. Some just changed a little thing, like using a handle instead of the first name. Others did the ~useless~ reverse-the-last-name thing. Some people mashed up their names by - for example - translating parts of it to English (name contains 'rot', translate to 'red'). And quite a number of people just used insane (if you're German, and not the clever/good insane) puns/references/crap as name.
The real name policy is already a failure. Not trying to enforce it, or - more correctly - not being allowed to enforce it, is a step forward.
And it's very annoying for everybody else. It defeats the entire purpose of Facebook when I can't find my friends.
If _your_ friends don't pick their real name, take it up with your friends? What kind of attitude is that, really?
"I cannot find my friends if everyone can pick their name on this platform, hence this is very annoying". What?
We're talking friends here. Ask them: "Hey, are you on Facebook?" (reasonable question in my social circles, implying a yes is baaad) and follow up with "What's your name/can you add me as a friend?". Solved. They're your friends, after all.
Why should I force my friends to do something they do not want?
Talk to each other like, you know, people who should actually add each other on fb
When I'm on HN I'm building up a professional reputation, so I use my real name (or at least an easily searchable abbreviation of it) here.
Why would it be a mistake since it is a pretty common use pattern despite the rules Facebook tries to impose?
I can also flip your argument and say that why do people who use fake names want to impose themselves on Facebook? They could just as well abide by Facebook's guidelines or just not use it.
I really wish I could assign them aliases I know them under rather than what name or gender they feel like this month. Steam does that and it's very useful.
How did they know her real name?
That way, it can create 'shadow-accounts' for people that don't have yet a Facebook account. So when/if that person finally creates a Facebook account with some data tying him/her to a shadow-account, Facebook can directly propose relevant contacts and already knows a lot about that person, including his/her real name.
Just assume that anything that you entered on any website, or that you mentioned directly or indirectly to anyone on Facebook is available to Facebook.
In the creepiest of worlds I imagine this: on a non FB website with a FB "share" button on it, I congratulated a friend on her birthday five years ago. When she gets a FB account for the first time tomorrow, Facebook already has her shadow account with good Guesses of her details, including the birthday and real name.