7 ms·
> From the inside it might look like there’s a lot of effort put into something like this, but from the outside it’s clear it’s nowhere near enough. I actually
by panic 5y ago
> From the inside it might look like there’s a lot of effort put into something like this, but from the outside it’s clear it’s nowhere near enough.
I actually do believe it. The thing is, no matter how much work the privacy people put in, it will never be enough to solve Facebook's privacy problems. The problems are fundamental to the way Facebook works as a product.
It's a pattern you see in many places:
1. Identify a fundamental problem your organization causes.
2. Form a team responsible for fixing this problem.
3. Make sure this team is organizationally separate from the teams actually doing the work.
4. Give this team lots of resources and have them share whatever progress they manage to make.
What will happen is that this team will be able to make some improvements. Whenever someone criticizes you, you can point to these improvements and say (completely honestly) that the team is doing the best they can. Meanwhile, the core of your organization is protected. Any changes that would threaten the processes that sustain the organization itself can be written off as unrealistic.
EDIT: I should add that this pattern can appear without any malicious intent -- it's natural (though perhaps naive) to think a "privacy team" is the right way to solve privacy problems in one's organization. But we owe it to ourselves to be honest about what is really happening. Not just for Facebook's sake, but also for the sake of any organization which models itself after Facebook. Without an understanding of how this stuff works, organizations will end up reproducing Facebook's fundamental problems (privacy and otherwise) while believing those problems have been solved.
- deleted 5y ago[deleted]