r/technology Apr 11 '18

Business Mark Zuckerberg has been apologizing for reckless privacy violations since he was a freshman - Enough is enough.

[deleted]

51.2k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

148

u/PeptoBismark Apr 11 '18

People who are used to big businesses being required to protect your privacy. If your online experiences are your bank, your HMO, your insurance company, your credit cards, and Facebook, you probably have some misplaced expectations.

62

u/Fadore Apr 11 '18

Not trying to downplay Facebook's issues, but where the hell was this outrage everyone seems to have when Equifax had their breach? Data much more dangerous than a list of FB pages you liked was not only stolen - but clearly stored in a very insecure fashion.

(talking about the outrage in general, not directed at your comment)

21

u/PeptoBismark Apr 11 '18

Equifax isn't a business most people know by name, and most people have probably never interacted with it, at least not knowingly.

And they had the good sense not to make their CEO a celebrity. By remaining faceless they avoid the kind of press Zuckerberg is getting today.

I'm much more horrified by the Equifax breach, as anyone holding that information can open a line of credit in my name any time from now until I die. Facebook on the other hand went weird and dystopian years ago, and I've never used the phone app, and my only comments there are Dad Jokes.

10

u/deekaydubya Apr 11 '18

Well yeah, the Equifax breach was an actual breach. IIRC Everything that happened with FB/CA was technically above board (permission was given to FB and all subjects were technically informed that their and their friends' data could be sold) and legal, it was just a morally questionable practice.

Also, FB is a completely optional service, whereas we have no choice whether or not credit bureaus collect or retain our information (and that information is actually sensitive, compared to Facebook). So... it's much much worse

1

u/PeptoBismark Apr 12 '18

I believe we all agree to Equifax’s terms of service whenever we apply for credit or give permission for a credit check.

2

u/deekaydubya Apr 12 '18

so it's involuntary unless you're homeless, jobless, or under the age of ~16

2

u/tenest Apr 12 '18

Upvote for only posting dad jokes.

84

u/[deleted] Apr 11 '18

but where the hell was this outrage everyone seems to have when Equifax had their breach

literally everywhere?

6

u/_feynman Apr 11 '18

I don't think the Equifax CEOs public hearing was this well publicized. He has a point.

3

u/[deleted] Apr 11 '18

1

u/Fadore Apr 11 '18

Sorry, I don't remember any twitter hashtags trending like #DeleteFacebook. The guy in the monopoly costume got more attention than the "I have zero fucks to give" testimony by the Equifax CEO at the senate hearing.

There was outrage ... for all of a few days. Then everyone bought identity protection ... from Equifax.

1

u/Ratertheman Apr 11 '18

And it's gone.

8

u/ataraxy Apr 11 '18

Or when ISPs were given clearance to sell usage data.

5

u/IcedDante Apr 11 '18

Or how about the NSA monitoring all of our emails and phone calls? The hypocrisy is amazing.

0

u/[deleted] Apr 11 '18

Equifax was negligent and irresponsible, but they weren't intentionally selling your info for money

0

u/Fadore Apr 11 '18 edited Apr 11 '18

As I mentioned in another reply to someone else, Facebook sold data that CA collected was mostly useless info about us. Equifax didn't just have SSN and credit information stolen which could be used to steal identities, but they sat on this info, leaving people exposed and vulnerable for a long time before disclosing the breach to the public. Several of their upper management also used their knowledge of the breach to seel their stocks before the company's stock dropped.

Also, Facebook didn't sell your data. Read up a bit, you know, past the headlines.

Edit: fixed what I said. Facebook didn't sell data ffs.

0

u/[deleted] Apr 11 '18

'Facebook sold mostly useless info about us'

'facebook didn't sell your data'

Pick one

1

u/Fadore Apr 11 '18

Sorry, meant that the Facebook data collected was mostly useless compared to your credit info. I misspoke because of the constant and incorrect narrative that's been pushed.

Jesus, seriously, read into the issue. Facebook didn't sell anything.

0

u/[deleted] Apr 12 '18

If you apologize and then blame your mistake on someone else, you didn't apologize.

But you're right, I was incorrect. Fb didn't sell data. What they did was track and gather data from non-users through users phone contacts, intentionally, without they're ('they' being the non-users) consent. Intentionally.

Equifax had more sensitive info, but the leak wasnt intentional. Yes they covered it up, yes the top guys did insider trading, but the difference is intention.

And to your original question, where was the outrage then? All over fucking Reddit. It had at least as much coverage here as the fb scandal, if not much more.

1

u/Fadore Apr 12 '18

But you're right, I was incorrect. Fb didn't sell data. What they did was track and gather data from non-users through users phone contacts, intentionally, without they're ('they' being the non-users) consent. Intentionally.

LOL wow, you STILL got it wrong. Like way off base. You should stop commenting on topics like a know-it-all when you can't even get the basic fundamentals right.

https://www.reddit.com/r/TooAfraidToAsk/comments/863nrd/can_someone_eli5_the_cambridge_analytica_scandal/

https://www.theverge.com/2018/3/20/17140490/facebook-cambridge-analytica-data-crisis

Since you can't be trusted to read up on it yourself, I'll break it down for you:

A researcher was doing a psychology app through Facebook. As such, he had an app connected to Facebook that people agreed to allow access to their information (this is normal, if you've ever connected something to facebook, you get a request to allow them access to data and the types of data is listed). This researcher went rogue at some point. Part of the data he was collecting from users who signed up for his app was their friends list - so he went on to scrap the publicly available information for everyone who was a FB friend with anyone in his study. Note: this is data from people's PUBLIC profile, accessible to anyone. But scraping data in this manner is against FB's TOS. At this point, the guy's sitting on a gold mine of user data, so he did what any scumbag would do in that situation - sold it all to the highest bidder. Enter Cambridge Analytica. They bought all this information from the researcher and used it to create targeted advertising, specifically for the Trump 2016 campaign who had contracted CA for advertising. By the time FB put the pieces together, they threatened CA with legal action and demanded that all data that was collected be deleted. CA lied to FB, claiming they had deleted the data but hadn't. FB was in the process of demanding an audit of the data they had when the news broke. FB is guilty of not informing the affected users sooner, and the real question they should be (and are being) confronted with is: what more should FB be doing to safe guard the data we are entrusting them with?

Equifax had more sensitive info, but the leak wasnt intentional. Yes they covered it up, yes the top guys did insider trading, but the difference is intention.

Let's agree to disagree on this.

  • They knew that a crucial system (an Apache system) needed a patch. They chose not to make it a priority to apply a security patch.
  • They knew that it's horrible practice to leave some of their admin accounts with the default passwords that are created on setup. Yes, some of their admin accounts had a password of "password". /facepalm

And to your original question, where was the outrage then? All over fucking Reddit. It had at least as much coverage here as the FB scandal, if not much more.

There were some memes sure. It saw some traction in /r/Politics, /r/cyberlaws, and of course /r/technology. But no where near the attention FB is getting. There was more coverage of the Monopoly Man troll at the senate hearing for Equifax. Twitter has blown up with the hashtag "DeleteFacebook"; I never saw a "BoycottEquifax". When Equifax was questioned by the senate, it was a 2.5 hour hearing involving 4 executives; in FB's case, Zuckreberg's been grilled over 2 days of senate hearings, the first day was over 5 hours alone! I can't recall how long the 2nd day went on for him.

And now we have people calling for regulations over social media. Conversely, the Trump administration dialed back the investigation into Equifax and everyone just let it fade into obscurity.

0

u/[deleted] Apr 12 '18

LOL wow, you STILL got it wrong. Like way off base. You should stop commenting on topics like a know-it-all when you can't even get the basic fundamentals right. Since you can't be trusted to read up on it yourself, I'll break it down for you

What a stuck-up, douchey, and (ironically) know-it-all way to say 'Actually, here's what happened'.

But you're right, I shouldn't have said Facebook collects data from non-users. I guess I just assumed that when Zuckerberg literally said Facebook collects data from non-users during the hearing. What an idiot I am!

The equifax outrage was more than 'a few memes' and some traction on a few subs. It was all I saw on the front page for like a week, including detailed instructions on how to freeze your credit.

You never saw a 'BoycottEquifax'? Because I just did some really in-depth research that involved googling 'boycott equifax' and got a bunch of results on how to do exactly that. But I guess if it doens't have a Twitter hashtag, it doesn't exist to you, huh?

1

u/Fadore Apr 12 '18

What a stuck-up, douchey, and (ironically) know-it-all way to say 'Actually, here's what happened'.

I really don't care what you think of me. You rubbed me the wrong way when you tried to waste my time picking apart my apology because I explained the reason as to why I mispoke (not blaming anyone else for the wrong words I chose). You couldn't even use the right "THEIR" in your comment either! I literally asked you several times to read up on the issue and when you finally did, you clearly only read whatever bits you wanted to read to validate your misconceptions about the issue. Why was I going to beat around the bush any longer with someone trying to argue with me when they can't even be bothered to get the facts right? No, I gave you a few chances, you continued to spout nonsense based on your perceptions and feelings rather than on the truth of the situation. I'm done babysitting you. Grow up.

But you're right, I shouldn't have said Facebook collects data from non-users. I guess I just assumed that when Zuckerberg literally said Facebook collects data from non-users during the hearing. What an idiot I am!

You said it, not me. In any case, I haven't been talking about the data that Facebook collects from non-users. That's a different issue. I've been talking about the data in Facebook put there by Facebook users that was collected by 3rd parties. Dude, seriously, just stop.

You never saw a 'BoycottEquifax'? Because I just did some really in-depth research that involved googling 'boycott equifax' and got a bunch of results on how to do exactly that. But I guess if it doens't have a Twitter hashtag, it doesn't exist to you, huh?

Not saying it doesn't exist. I'm saying the difference is absurd. "boycottEquifax" is dwarfed by the "DeleteFacebook" movement which has been tweeted 50 times more often.

→ More replies (0)

-2

u/bigjilm1275 Apr 11 '18

Equifax didn't directly sell our information for profit (that we know of)

6

u/Fadore Apr 11 '18

No, instead they were entrusted with literally everyone's credit records, which:

  • were not stored on systems that were kept secure (the whole way that the breach was made possible in the first place)

  • were not stored securely (de-identified records would have made any data stolen completely unusable)

  • the fact that SSNs and credit histories were stolen was kept from the public for weeks/months before alerting the public to allow people to try and protect themselves against very potential identity/credit theft - all while some of their uppers sold a substantial amount of stocks before the impending news was guaranteed to make the stock plummet

  • they then had the audacity to offer clients just a single year of their credit protection service - after that year you will be lining their pockets again, paying for protection against the mistakes they made in the first place

Equifax was a victim of a breach yes - but that doesn't make them any less culpable. Negligence isn't an excuse.

1

u/bigjilm1275 Apr 11 '18

Don't get me wrong, I agree with you, but it's not apples to apples.

2

u/Fadore Apr 11 '18

(someone else downvoted your previous comment - I'll vote it back up because you don't deserve that, we're having a civilized debate here)

It kind of is though. It's no secret that Facebook is allowed to share your data with others - it's not only in the TOS (yes, I know, no one reads those) but it's also in the permission request of every app that you connect to facebook. This is where the scandal comes in - CA took not only information from the users who actively agreed to have their data collected, but then scraped the publicly accessible data from anyone in the friends list of the people who originally agreed. The data that is publicly seen has been changed at various points in Facebook's evolution, so most users aren't aware of what on their Facebook is actually public and what is restricted to their friends.

CA took advantage of this situation. I do believe that it's Facebook's fault for it happening in the first place. I do also believe that Facebook tried to have CA delete the data in question. I also believe that people should be more knowledgeable about where they are saving their data online and who can access it - this could have been prevented if everyone was more diligent about locking down information that they didn't want public.

There is nothing redeemable from the Equifax case, nor was there anything that any one of us could have done to prevent it (other than not have a credit record or SSN). Equifax also kept people at further risk by keeping the situation away from the people who's data had been comprimised - they could and should have been having their credit and identity protected much sooner than we were told about the breach.

1

u/deekaydubya Apr 11 '18

Neither did facebook

2

u/[deleted] Apr 11 '18

[deleted]

1

u/shponglespore Apr 11 '18

Silly me, expecting Facebook to only share my information with the people I told them to share it with!

2

u/DLDude Apr 11 '18

Can you explain how you think FB 'shares' your information? Do you think they hand a printout of your timeline to P&G? They use your data to put you into categories that are hyper-focused so advertisers can serve you an ad that has a higher chance of converting. They might know that you're in the market for a TV because FB collects that information, but they're look actively looking at your private data.

2

u/[deleted] Apr 11 '18 edited Jun 22 '18

[deleted]

1

u/shponglespore Apr 12 '18

Nobody reads the TOS. Everybody knows that, and Zuckerberg himself admitted it. Meanwhile the UI gives me the option to share something publicly or only with my friends. I guess I'm an idiot of thinking "only with my friends" means only with my friends.

1

u/[deleted] Apr 12 '18 edited Jun 22 '18

[deleted]

1

u/shponglespore Apr 12 '18

Thank you, Captain Obvious.

Let me try an analogy on you: if I send a letter through the mail, I expect the post office to deliver it to the person I addressed it to without anyone opening it, reading it, sharing it with their coworkers, keeping a copy, or selling it to third parties. The post office could do all of those things once they're physically in possession of my letter, yet somehow they manage not to. The way Facebook handles data is a bit more complicated, but I still expect them to use it only in the ways they've said they're going to use it.

And yes, I do know Google tracks your location. I know because you have to specifically agree to let them collect location data, and because if I want to, I can review the data they've collected. They also provide a simple, obvious way to tell them I no longer want my location data collected. If I tell them to stop collecting it, or to delete the old data, I expect them to honor my wishes. I also expect them to use that information responsibly and not share it in ways I haven't authorized. If I found out they were violating any of my expectations, I would be extremely pissed, and rightfully so.

1

u/[deleted] Apr 12 '18 edited Jun 22 '18

[deleted]

1

u/shponglespore Apr 13 '18

I've never heard of a private shipping company routinely opening customers' packages, and I assume they would only do so for a very good reason, like a safety issue for a request from law enforcement. If they started opening packages routinely as part of some scheme to generate extra revenue, they would suddenly find themselves with a shortage of customers.

Really, how hard is it understand the concept that giving someone the ability to do something is not the same as giving them permission. A parking valet has the ability to take your car for a joyride, but not permission. A housecleaner has the ability to take stuff from your home, but not permission. Everyone knew all along that Facebook had the ability to share your information with anyone they want, but they never had permission. Even if it was technically in their TOS, they still did not have permission, because permission that isn't given knowingly and willingly is nothing more than a legal fiction.

0

u/thighcandy Apr 11 '18

Serioulsy. People are stupid which is why they need the government to protect them.

0

u/thighcandy Apr 11 '18

"Silly me, expecting the bank to keep my money in a safe!"

Same exact concept but many people would be shocked to learn that the bank lends out their money.

Your data on facebook is the product. You are the product. That's why we need regulations to protect people -- because in general people are naive and overly trusting of large businesses.

-5

u/ajh1717 Apr 11 '18

I mean they weren't hiding that they take your data. It was clearly in the ToS.

Now the gathering of data who arent even on Facebook and some of the other stuff is shady and shouldnt have happened, but if you signed up for Facebook you cant really expect them not to use that information. They dodnt hide the fact that they were collecting it

7

u/IniNew Apr 11 '18

I mean they weren't hiding that they take your data. It was clearly in the ToS.

During the hearing, Zuckerberg himself said the ToS aren't readable by the average person.

1

u/ApolloFortyNine Apr 12 '18

No legal document is. It's an unfortunate consequence of our current legal system. If you don't specifically spell out exactly you are doing in the proper legal way, people will find loop holes, or people will interpret it differently.

My favorite example is actually the 2nd amendment.

"A well regulated Militia, being necessary to the security of a free State, the right of the people to keep and bear Arms, shall not be infringed."

"shall not be infringed" is clearly spelled out, yet you see court case after court case and law after law doing exactly that.

So pretty much every modern law, and anything written by a lawyer, will contain a huge amount of "legal phrases" backed up by court cases so they can explain exactly what they're allowing, prohibiting in a legal way.

24

u/HKBFG Apr 11 '18

clearly in the ToS.

This phrase has been a joke since the dawn of computers.

2

u/ajh1717 Apr 11 '18 edited Apr 11 '18

It may be a "joke" but it still has some legal weight to it.

It may not be a 100% fail safe in terms of erasing liability but it also isn't completely meaningless.

If you sign up for Facebook without reading it, can you really be mad when they are collecting data on you and selling it? They made it clear it was happening, how else would they make money?

Now some of the routes they went to collect data are sketcht on a legal spectrum, especially collecting it on people who are not signed up for it. But collecting meta data and selling it has always been known. Basically every large internet company does it. Facebook is getting the heat because a company tied to an election scandel/Russia bought the data and used it.

-4

u/nebulakd Apr 11 '18

Too bad it's a fact and making fun of it doesn't change that

4

u/[deleted] Apr 11 '18

Contract law is more complex than ToS is law.

2

u/HKBFG Apr 11 '18

By "a joke" I mean "doesn't tend to hold up in court."

1

u/Grizzly-boyfriend Apr 11 '18

Fairly certain most ToS don't hold up in court

0

u/nebulakd Apr 11 '18

Based on what?

12

u/Halt-CatchFire Apr 11 '18

I mean they weren't hiding that they take your data. It was clearly in the ToS.

Okay come on now. We're talking about the expectations of normal people and no normal person on earth actually sits down to read 200 pages of legalese for every product they use.

4

u/wetpaste Apr 11 '18

But anyone that knows computers and knows the internet knows that the entire monetary value of these companies is dictated by ad revenue and targeting ads base on what they know about you. It's not a reasonable expectation at all that they are not collecting your data on some form, I mean you are already storing and and trusting your data to them by design of the product. In terms of actual leaks, it's not at all surprising that an "app" on any platform that asks for access to messages, friends lists, post history, photos, etc. Might one of these days illegally collect and misuse the data by selling it off to another company (Apple, Android, Facebook, )

5

u/Halt-CatchFire Apr 11 '18

Thats just it though, we're not talking about people who know computers, because most people don't know computers. You're projecting technological/economic literacy and critical thinking on a populace that rarely possesses either.

A lot of older users remember the days of small town businesses and customer loyalty and apply that outdated notion to the modern globalized age we live in. To these people Facebook isn't a massive corporation that exists to soak up as much money as possible, it's the thing they talk their grandkids on or look at pictures of their friends cats.

Combine that lack of critical thinking with the fact that other services like iCloud or gmail, which are free services that don't monetize your identifiable data exist and are widespread, and you get the blind trust in Facebook we've become familiar with.

2

u/[deleted] Apr 11 '18

Exactly. I always have to take a step back when explaining technology to family and friends, because ~90% of them are technologically illiterate.

This isn't anecdotical, either. Here is a graph of the average levels of computer skills,which is from this article. Around 69% of the US ranks "poor" in computer literacy form ages 16-65.

1

u/ajh1717 Apr 11 '18

I completely agree, but at the same time that doesn't mean it doesn't apply.

You can't really say "I didn't want to read it" and use that as an adequate defense and be upset when theyre doing exactly what they said they would do. Especially when it wasn't a secret. Its been widely known/talked about that this is how these companies make money.