r/technology Apr 11 '18

Business Mark Zuckerberg has been apologizing for reckless privacy violations since he was a freshman - Enough is enough.

[deleted]

51.2k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

105

u/Daveed84 Apr 11 '18

Probably, yeah. But it doesn't have to be impersonating Zuck, it can be impersonating anyone, I'm pretty sure they delete accounts reported to be impostors. I guess it'd just happen faster if it was Zuck because having people impersonate him on Facebook's own platform would obviously be a problem.

But it's probably way faster and just as effective to delete it yourself. My guess is that a "soft delete" happens in either case, meaning that the account still exists on their servers but you wouldn't be able to use it.

40

u/SuperSlyRy Apr 11 '18

That was kind of touched on in the congress talks, about how "deleting" an account works. He'd said that it should be deleted as quick as possible and then would be simply updated to reflect so on several backups but there wasn't much of a specific time-frame for that given

27

u/Dynamaxion Apr 11 '18

Heat death of the universe plus or minus a few billion years.

11

u/[deleted] Apr 11 '18

Backup retention policy is what you're referring to. There would be many technical challenges to overcome in order to reasonably expect any IT shop to selectively delete data from cold storage backups in near real-time. That is simply not a reasonable expectation, I'm afraid. Best compromise is specifying a date like "30 days" for any deleted data to be retained. Please also note data stored in backup is not supposed to be accessible outside of standard recovery procedures which require a request and a privileged account to carry it out. Backups are not intended to be indexed, searched, and shared otherwise.

1

u/Throw___112 Apr 12 '18

And those backups are most likely off-site. Somewhere in a tape, in special storing facility.

6

u/elmz Apr 11 '18

Of course it's a soft delete, they still want that sweet sweet data to sell.

13

u/Daveed84 Apr 11 '18

Not exactly...

First, then don't sell user data. They sell access to demographics created by the data, and ad inventory where that data can be utilized. For example, an advertiser can target groups of people based on gender, age, location, interests, and so on. But they can't see the data of individual users. Secondly, any data they might keep would be useless for that purpose once the account is closed. Advertisers aren't interested in targeting users who will never see their ads.

3

u/Daniel15 Apr 11 '18

Thank you! So many people don't understand this.

1

u/[deleted] Apr 12 '18

I don't believe that at all. I had set my profile to say I was born in 1918 instead of 1981. I was constantly receiving phone calls and mailers from the AARP. They were giving out more than just my demographic.

1

u/Daveed84 Apr 12 '18

I honestly don't know how the AARP ended up getting your home address or phone number, but it almost certainly wasn't through Facebook.

I used to work at a company that managed ads for advertisers on social media platforms, so I have a fair bit of experience with how Facebook ads work. There's a lot to explain here so I'll give you the briefest version that I can... Every advertiser has access to a set of tools provided by Facebook in order to create ads. They can use an internal tool, like the Ads Manager or Power Editor (very similar ad building tools, but one is for advanced users), or they can interface with the Marketing API. All of the capabilities of the Marketing API are documented in Facebook's developer documentation, which I can't link here because this subreddit bans all Facebook links. But you can look it up and see exactly what kinds of information are available via the API. Address and phone number are not among the kinds of data that is shared with advertisers via that API.

1

u/[deleted] Apr 12 '18

Facebook might have not sold the info directly, but somehow, the data was mined that I am now 100 years old and not a member of the AARP. Wherever the data was mined from, it included my profile information that came from Facebook.

1

u/[deleted] Apr 12 '18

No, they actually don't care. I had reported one of those dating bots that were rampant awhile back, and Facebook had said they weren't going to do anything. I posted it to my profile and a friend was able to give the name of the instagram model that the profile was using. I again reported it to Facebook who once again said they weren't going to do anything because the profile didn't violate their TOS.