TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

50M Facebook profiles harvested for Cambridge Analytica in major data breach

558 pointsby tsneed290about 7 years ago

29 comments

olivermarksabout 7 years ago
My problem with this &#x27;outing&#x27; of CA is that Facebook explicitly commercially exists to harvest user data for Procter &amp; Gamble, Johnson &amp; Johnson, Fidelity etc etc so they can profile us. A million dollars is chump change in the crazy US election game. This all seems overly selective - it&#x27;s ok for some people to profile but not for others. I&#x27;m not in favor of any of it to be clear but there is a definite political bias going on here. Let&#x27;s not forget FB itself has a formal political unit that exists to push propaganda in foreign elections, &#x27;stifling opposition and stoking extremism&#x27;<p><a href="https:&#x2F;&#x2F;www.bloomberg.com&#x2F;news&#x2F;features&#x2F;2017-12-21&#x2F;inside-the-facebook-team-helping-regimes-that-reach-out-and-crack-down" rel="nofollow">https:&#x2F;&#x2F;www.bloomberg.com&#x2F;news&#x2F;features&#x2F;2017-12-21&#x2F;inside-th...</a>
评论 #16607965 未加载
评论 #16608854 未加载
评论 #16608552 未加载
评论 #16607900 未加载
评论 #16608646 未加载
评论 #16608417 未加载
评论 #16609641 未加载
评论 #16608772 未加载
评论 #16607877 未加载
评论 #16607990 未加载
评论 #16608312 未加载
评论 #16607796 未加载
评论 #16607910 未加载
评论 #16609115 未加载
评论 #16609511 未加载
gfodorabout 7 years ago
I remember when the Obama campaign hired data scientists and used targeted social networking tools to pursuade voters who were on the fence and it was heralded as brilliant and the future of politics.<p>I worked for a company crawling Facebook data by creating viral apps the year the original API came out. By now I am sure this is done by many companies.<p>Why is any of this news? My understanding is that companies harvesting social networking data via viral apps and then reselling it to perform targeted voter advertising is literally a 10 year old concept. Were any laws broken here? Were there any techniques used here that were novel or done by one political party and not the other? Why are we talking about this one firm and not the many others that surely exist that are trying to do the same thing for &lt;insert political candidate of choice&gt;
评论 #16610288 未加载
评论 #16611122 未加载
评论 #16611761 未加载
评论 #16610219 未加载
评论 #16611154 未加载
评论 #16610496 未加载
评论 #16619260 未加载
评论 #16610992 未加载
评论 #16611391 未加载
评论 #16626212 未加载
评论 #16612220 未加载
评论 #16610691 未加载
评论 #16610325 未加载
heckanoobsabout 7 years ago
I used to make fb apps, any app gets full access to fb&#x27;s user graph as long as they request the relevant permissions.<p>Users don&#x27;t comprehend what permissions they are giving to apps they run. A quiz site getting full access is not surprising.<p>Once an app has any amount of access the only thing stopping them from harvesting their own clone of your data is an agreement in the ToS that you won&#x27;t store PII for more than x hours.<p>These rules are like the bare minimum to stop good actors. If you&#x27;re a bad actor fb does not do a single thing to protect users from you. As evident in this report fb is also not above blaming the users for the hostile environment fb created and placed them in.<p>There must be countless copies of harvested fb data out there. My employer at the time once realized we were accidentally storing some PII permanently in a derived field. If good actors can&#x27;t even keep above the law what do you think the ecosystem looks like in the shadows?<p>IMO we aren&#x27;t having the right conversation with fb over how they mistreat our PII and we should loosen the definition of that term when companies like the one in the article can infer our political preferences from the innocuous bits of our lives we tag on facebook.<p>We should be asking why even an authorized API that can&#x27;t stop you from copying the data doesn&#x27;t count as a systemetized data breach.
评论 #16609478 未加载
评论 #16609846 未加载
patjaabout 7 years ago
I was curious how the figure leaped from the 270k cited in the Facebook press release to this 50M figure.<p>It sounds like they never had full access to the Facebook profiles beyond the 270k who installed the app, but just harvested the friend lists of those 270k. This doesn&#x27;t give the app developer full access to the friends&#x27; profile data, but I guess once you have the network of friend connections you can use other public data sources to fill in or infer the gaps. And of course some of those 50M will have FB profiles that are fully public open books ready for anyone to harvest.<p>I will say as someone who has developed Facebook apps, the whole ecosystem is pretty much on the honor system for protecting user data. There are some seemingly random and capricious (and often erroneous) abuse detection algorithms, but once an app has access to user data who knows what they do with it and whether it was kept secure -- surely Facebook has no idea unless they perform invasive manual physical audits.
评论 #16607481 未加载
评论 #16607835 未加载
评论 #16610179 未加载
评论 #16608396 未加载
loxiasabout 7 years ago
Minor point of confusion -- this article refers multiple times to a &quot;data breach&quot;. (<i>&quot;...one of the largest-ever breaches of Facebook data...&quot;, &quot;At the time of the data breach...&quot;, &quot;...first reported the breach...&quot;</i>)<p>As far as I can tell, there is no data breach, right? It sounds like CA got facebook data through an app they wrote, thisisyourdigitallife, which did some shady things.<p>Also, <i>&quot;The New York Times is reporting that copies of the data harvested for Cambridge Analytica could still be found online&quot;</i>.<p>The link is: <a href="https:&#x2F;&#x2F;www.nytimes.com&#x2F;2018&#x2F;03&#x2F;17&#x2F;us&#x2F;politics&#x2F;cambridge-analytica-trump-campaign.html" rel="nofollow">https:&#x2F;&#x2F;www.nytimes.com&#x2F;2018&#x2F;03&#x2F;17&#x2F;us&#x2F;politics&#x2F;cambridge-ana...</a><p>Anyone know what they&#x27;re talking about? I haven&#x27;t heard of any 50-million-profile data dump, and I really like collecting corpora...
评论 #16610572 未加载
评论 #16610549 未加载
ENOTTYabout 7 years ago
One thing other commenters haven&#x27;t mentioned is that Facebook asked the other parties to delete the data and promise never to use it again and the other parties even certified that they had done so, but the whistleblower is alleging they lied to Facebook.<p>Maybe that&#x27;s legally actionable.
urlwolfabout 7 years ago
OK, this feels like it will bring about the end. Of something. Facebook? Massive use of data for political campaigns? Anything?<p>If we keep consuming news like this, and do nothing, it&#x27;s going to scalate massively. Same way as when Snowden told people they were spyed on and they collectively shrugged and continued with their lives as if nothing had happened.<p>We, people in tech, have a massive moral burden to educate &#x27;normals&#x27; on the meaning of news like this!
评论 #16608088 未加载
评论 #16607966 未加载
评论 #16607998 未加载
评论 #16607924 未加载
734786710934about 7 years ago
This wasn&#x27;t a data breach, it was a misuse of data by a third party.
评论 #16607136 未加载
评论 #16607290 未加载
评论 #16607285 未加载
评论 #16607117 未加载
评论 #16608170 未加载
评论 #16611308 未加载
评论 #16607751 未加载
评论 #16607311 未加载
评论 #16607080 未加载
mcintyre1994about 7 years ago
I think I finally understand what the point of Facebook apps is and why they&#x27;ve always felt in some way dodgy. It&#x27;s been clear for years that Facebook apps can get your user data, and that of your friends, and that Facebook designed them that way and were aware of that. The Guardian article even mentions that one of the apps used by GSR to gather data for Cambridge Analytica triggered Facebook security protocols trying to pull too much data.<p>What I didn&#x27;t understand is why Facebook would grant this - maybe at some point they needed viral apps on the platform and giving user data away encouraged people to make them - but why did it still work a few years ago? But this article made it click: all you can really do to monetise or use millions of profiles of Facebook users is target them with ads, and Facebook is the only place you can target those ads effectively given Facebook user data, and the more data you have the more effective those ads are, the more you pay Facebook.<p>Facebook don&#x27;t sell user data, they&#x27;ve long said that - and it&#x27;s true. They sell the ability to target advertising to their users, and you can do that a whole lot better if you have their user data. So they don&#x27;t sell it, they give an API for their users to freely give it away, knowing that once you&#x27;ve done all your analysis on it you&#x27;ll conclude that you should spend money paying Facebook to actually deliver your messages to those users.
fjsolwmvabout 7 years ago
&gt; Facebook denies that the harvesting of tens of millions of profiles by GSR and Cambridge Analytica was a data breach. It said in a statement that Kogan “gained access to this information in a legitimate way and through the proper channels” but “did not subsequently abide by our rules” because he passed the information on to third parties.<p>This is exactly how Facebook was designed. You get a stupid quiz or photo frame in exchange for a copy of your friends list. It&#x27;s always worked that way, and it&#x27;s why Facebook OAuth was more popular than Google+ and other Oauth since 5+ years ago -- because app devs can make more money from Facebook OAuth since it comes with a copy of your friends list, so they prefer to integrate Facebook.
评论 #16607758 未加载
gaiusabout 7 years ago
Facebook: &quot;no-one herds our sheep but us, mmmkay?&quot;
auntienomenabout 7 years ago
So... If I were in Cambridge Analytica&#x27;s position, employed to influence the US election, one of the first things I&#x27;d do is match this data with any data I could find on voting patterns. Which reminds me, didn&#x27;t some of the Russian APTs hack into state voter databases?
评论 #16608181 未加载
shiftfocustimeabout 7 years ago
I think it is much more important to focus on an investigation to make clear to the public how this data was used. That i think will lead into a much more interesting story. No one seems to want to go there and i don&#x27;t understand why. Maybe because a lot of its clients are political parties&#x2F;political individuals around the world and they do not want to be ousted for using &quot;public opinion manipulation technology&quot; on a wide scale.
评论 #16608470 未加载
dawhizkidabout 7 years ago
Think about all those apps where you connect your bank account via your online banking creds that have full access to everything you buy.
评论 #16609098 未加载
ceejayozabout 7 years ago
I wonder how many of the &quot;see what you&#x27;ll look like when you&#x27;re 80&quot; and &quot;find out how you&#x27;ll die&quot; quiz apps are doing this behind the scenes.
评论 #16607336 未加载
评论 #16607147 未加载
评论 #16607177 未加载
megousabout 7 years ago
Whistleblower&#x27;s account suspended.<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;chrisinsilico&#x2F;status&#x2F;975335430043389952" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;chrisinsilico&#x2F;status&#x2F;975335430043389952</a>
andy_pppabout 7 years ago
This kind of work combining propaganda and disinformation with AI models and feedback into them to get a progressive change of belief is fascinating. I think of this as the first of many wars democracy will fight against AI and we are currently loosing.<p>This comment is from the “Duped” article that has a different headline and more detail.
trhwayabout 7 years ago
For example, &quot;Weev&quot; got 3 years for downloading ATT user data. I wonder whether Bannon&amp;Co would get anything ... So far it doesn&#x27;t look like FB makes any push for CFAA case here. I wonder what would FB do if instead of Bannon it were a nobody like the above mentioned &quot;weev&quot;.
myth_busterabout 7 years ago
50M doesn&#x27;t strike much in FB scale, that&#x27;s until...<p><pre><code> At the time, more than 50 million profiles represented around a third of active North American Facebook users, and nearly a quarter of potential US voters.</code></pre>
评论 #16610052 未加载
svbillabout 7 years ago
Nothing new about Campaign Data companies. In fact knew of a South San Francisco company called &#x27;Campaign Data&#x27; in the &#x27;90s that ran a SAS on DECUnix. They collected voter registrar data from counties for targeted voting campaigns. Usually for passing more restrictive laws or raising taxes. Like raise property taxes for schools; send flyers to renters with kids and send nothing to homeowners with no kids. It was always in a way, unfair and evil.
allthenewsabout 7 years ago
Let&#x27;s be realistic here. This headline is nothing but partisanship. The only reason this is exaggerated as a &quot;data breech&quot; is because of the connection to the Trump campaign.<p>The real scandal is that such data is so easily harvested and freely available.<p>I&#x27;d be interested in seeing how much of facebook&#x27;s data repository was used in targeted political ads by all parties. Including Russian agitators who have been shown playing both sides.
评论 #16608542 未加载
评论 #16608430 未加载
aetherspawnabout 7 years ago
I hadn’t thought of it like this before, but from a political POV everyone’s vote, whether they are a dole bludger or a quantum physiscist, are worth the same. So really, to win an election .. take that as you will. Identifying these people is a very profitable area.<p>Interesting side note .. in Australia we assign school funding based on the highest education received or wage class of the parent (classes A, B ... E or such).
inetknghtabout 7 years ago
1) Facebook collects and builds a profile about you 2) Facebook allows third parties to target advertisements based on the profile 3) Advertisements are tracked 4) Browsing habits and advertisement tracking reconstructs who was targeted
muddi900about 7 years ago
ITT: people who did not read the link Astrotrufing and conservative martyrs bleeding all over the site.
dretaabout 7 years ago
Why bother protecting any data, if you can put a footnote in your ToS.
whiddershinsabout 7 years ago
I don’t understand the use of the word “breach” in this headline.
hux_about 7 years ago
Can&#x27;t wait for Sheryl Sandberg to write a new book now on garden soil or something.
评论 #16608124 未加载
matchagauchoabout 7 years ago
This is hardly news... Facebook ads cannot target specific <i>users</i>, they only target audience <i>segments</i>.<p>It&#x27;s actually far easier to create ads targeted at segments with likely political beliefs, and Marketers have access to aggregate numbers of niche segments today.<p>There&#x27;s no need to scrape people&#x27;s profiles or get down to the individual level.
评论 #16622209 未加载
MechEStudentabout 7 years ago
China has more. They have enough that this is a drop in the bucket. While they might be as blatant and ineffective as Russia by interfering with an election, they want a low profile and to maximize capture of revenue, so they are more about making money than trying to put feces on the face of the American political process.<p>You people should pick your battles. It would help if you knew the battlefield first.
评论 #16608935 未加载
评论 #16608426 未加载