6 ms·
Facebook settles with FTC, under privacy watch for 20 years
- brown9-2 15y agoWow, this list is brutal: -In December 2009, Facebook changed its website so certain information that users may have designated as private – such as their Friends List – was made public. They didn't warn users that this change was coming, or get their approval in advance. - Facebook represented that third-party apps that users' installed would have access only to user information that they needed to operate. In fact, the apps could access nearly all of users' personal data – data the apps didn't need. - Facebook told users they could restrict sharing of data to limited audiences – for example with "Friends Only." In fact, selecting "Friends Only" did not prevent their information from being shared with third-party applications their friends used. - Facebook had a "Verified Apps" program & claimed it certified the security of participating apps. It didn't. - Facebook promised users that it would not share their personal information with advertisers. It did. - Facebook claimed that when users deactivated or deleted their accounts, their photos and videos would be inaccessible. But Facebook allowed access to the content, even after users had deactivated or deleted their accounts. - Facebook claimed that it complied with the U.S.- EU Safe Harbor Framework that governs data transfer between the U.S. and the European Union. It didn't.
- nextparadigms 15y agoI remember very well when the first one happened. It pissed me off because someone got to see some information I thought was private after I went to the trouble of going through Facebook's previous 50 privacy settings.
- freehunter 15y agoMy family had a major falling out with my father, to the point where myself and my sister had a restraining order against him when I was 7 and she was 9. I haven't seen him or talked to him in 16 years. After Facebook deleted my privacy settings, I had a message from him sitting in my inbox the next day. My sister called me, crying, because she had gotten the same message. Both of our accounts were previously unsearchable on the site, with all of our data being private. As soon as they rescinded that privacy, our father could tell what cities we live in (in one of our cases, a _very_ small town) and that she had gotten married, we both had changed our first and last names, and one of us had a child. He found me through my mom's friends list, he found my sister through my friends list. All of which were previously hidden. Nothing came of it besides an unwanted "please call me" message from him, but it's not a far reach from there to actually being located physically and confronted. We sent this man to jail and changed our names to keep away from him, and Facebook, in spite of their "privacy" settings, let him get a glimpse back into our lives.
- bad_user 15y agoShit, that sucks -- people are not yet aware of the damage the lack of online privacy can bring. And I fear that because of inertia, when the damages will become visible, then it will be too late.
- freehunter 15y agoI kind of wish the similar Google Buzz incident had gotten more press than it did. A boy who wasn't even in a balloon was on the news for days, but the case of a woman who was being harassed on Buzz by her abusive ex was lost in the public mind after a few minutes. Both the Buzz and Facebook cases were decided by the FTC very recently (the Buzz case was settled in October of this year). Perhaps we've reached a turning point in online privacy? But then, looking at things like Protect-IP and SOPA, perhaps the regulatory answer is to just do away with privacy altogether.
- click170 15y agoI wonder.. Could that have been their plan from the beginning?
- marquis 15y agoI would donate to your ACLU legal action against FB. I am consistently editing myself on FB, even in private groups, because of a sinking suspicion that with a flick-of-a-switch it can all be public.
- freehunter 15y agoI'm not sure that any laws were broken. It's not like we kept the restraining order active for 16 years, and his message wasn't really harassment, more like attempted atonement. At any rate, I do wish companies had to be held to their own site rules, legally. If Pystar break's Apple's TOS they get sued out of business, but if Facebook breaks their privacy settings they get a slap on the wrist from the FTC.
- jnorthrop 15y agoThis sentence: "including giving consumers clear and prominent notice and obtaining consumers' express consent before their information is shared beyond the privacy settings they have established" was the killer to me. It forces FB to much more transparent about what it does with data and could have a significant shift in its revenue model.
- grecy 15y ago> "...their information is shared beyond the privacy settings they have established" Face-palm. That's an oxymoron by definition.
- jnorthrop 15y agoNot really. If they provide clear and transparent notice to users on what they are doing with their data, then what they are doing is fine -- "caveat emptor."
- rhizome 15y agoNo, it just means that changes to privacy that affect existing data should be announced beforehand. However, I doubt that they'll tell you which data will be affected. Have fun scrolling through your entire FB history to update permissions!
- Silhouette 15y agoThe trouble is, it only "forces" Facebook to do anything if there will be meaningful sanctions if they don't. They've just been found, in a formal investigation, to have broken numerous fundamental privacy laws across several continents, and been punished with... absolutely nothing, as far as I can tell. All this has done is teach them that they are above the law and should feel free to continue doing whatever they like without regard to the consequences for the hundreds of millions of real people who are counting on them to behave responsibly.
- felipemnoa 15y agoThis seems to be a first warning. It seems like next time they will not just get a warning, but who knows.
- d_r 15y ago"- Facebook represented that third-party apps that users' installed would have access only to user information that they needed to operate. In fact, the apps could access nearly all of users' personal data – data the apps didn't need." Privacy/ethics issues aside, from a pure developer standpoint, isn't this just a feature? Where do we draw the line between functionality and privacy? User A allows user B to see her data via "Friends only." User B runs app X, whose functionality includes interacting with friends. Let's say it shows on a map where each of your friends lives. App X can see the said data for the purposes of providing functionality. Yes, I know that by strict definition this conflicts with "friends only." You now have "friends and the application executable code only." But how is this different from, say, Gmail auto-scanning my e-mail to show ads? Is it because I trust Google and don't trust $random_fb_app_developer? Likely one concern is that this third-party developer can disrespect (or actually, not even know about) that "friends only" setting and inadvertently make the data visible to other parties. (Disclaimer: Don't get me wrong, I loathe/distrust most FB apps as much as the next person. Just trying to think from an honest developer's shoes here.)
- Bud 15y agoPrivacy/ethics issues aside, from a pure developer standpoint, isn't this just a feature? Where do we draw the line between functionality and privacy? This is a reasonable question. Where I personally would draw the line is, "functionality" implies to me that the app would only access user info when it needs to do so for some FUNCTIONAL purpose. If the app does not need the data and is not doing anything legitimate with it, then obviously, the user's privacy should be respected and said info should not be accessed.
- brown9-2 15y agoIt ceases to be honest when you incorrectly tell users that the apps "would have access only to user information that they needed to operate".
- rhizome 15y agoNevermind how they would go about determining and implementing that boundary logic.
- sunchild 15y agoWhatever trouble Facebook has with the FTC, it will face roughly 300 million times that trouble in Europe, where the rules are much more strict, and the data protection authorities have much greater power to act on behalf of the general public and individual interests.
- Vivtek 15y agoThat whole using-personal-information-to-burn-people thing is still (barely) in living memory in Europe. There have been riots in Germany over the government trying to take a census - with good reason. Privacy is more important than a lot of shallow people imagine.
- sunchild 15y agoWell, the U.S. has its own history of people who shoot at census takers, and so on. From a legal perspective, the EU and member state implementing laws are: (1) more protective of the individual over the corporation than US laws, and (2) fairly onerous and expensive for companies to comply with. In fact, compliance is a kind of red herring, since many of the data protection rules in place are ambiguous or nonsensical. Personal privacy is basically a global policy experiment at the moment.
- anigbrowl 15y agoTrue, though I have to admit that Neelie Kroes seems to have plenty of both executive authority and the willingness to exercise it in a muscular fashion. It helps that the EU privacy protections are closer to the constitutional than the legislative level.
- anigbrowl 15y agoUsers of Facebook will, of course, be able to sue the company and cite the FTC findings as corroborating evidence.
- gyardley 15y agoI never understood why bodies like the FTC rely on 'independent, third-party audits' for enforcement, since they end up making the entire action pointless. The independent third-party auditor will give Facebook a stamp of approval, both in the next 180 days and every two years thereafter, because the independent third-party auditor wants the repeat business. Same thing goes for any regulation that depends on a third party, really. I mean, over the last six years how often is a 409a valuation not to the board's liking? Somehow, magically, the auditors collect their fees from the company and then independently deliver an acceptable answer. Might as well not have the regulations - or just fine the company something meaningful - instead of engaging in this goofy kabuki theatre.
- JonnieCache 15y agoDon't the credit rating agencies work the same way? The companies being rated pay the agencies, not the companies that want to know the rating.
- chalst 15y agoThey do. Their value is unclear. Accountants supposedly are employed by shareholders, but in practice are employed by executives. This makes auditing problematic, but it does have some value. The bigger problem there is the big four's oligopoly: they are too big to fail.
- JonnieCache 15y agoThought so. Why do people insist on inventing wacky conspiracy theories when the scam is right there in front of them?
- philwelch 15y agoHow are the big four all "too big to fail" when not too long ago they were the big five?
- chalst 15y ago
- state_machine 15y agoThe best part is when you get to the footer and see: "Like the FTC on Facebook".
- jpdoctor 15y agoUtterly inexcusable. Someone (several someones really) at the FTC should lose their jobs over that. When O when will we get regulators with some distance from those they are regulating? (I'm looking at you SEC.)
- hexis 15y ago"When O when will we get regulators with some distance from those they are regulating?" Oh, that's an easy one.
- jpdoctor 15y agoSadly, you're right.
- jrockway 15y agoThe government needs mindshare and advertises just like any other entity. Just like people use Facebook to tell people not to use Facebook, the FTC may buy or use services from companies they are taking legal action against. That's not an endorsement of the practices they are fighting against; it's simply how businesses work. Facebook is where the people are; if you want people to hear your message, you take the message to Facebook. It's especially relevant in this case since their work directly benefits Facebook's users, so it would not make much sense to not have their message heard there. Also, they settled and all is good between the FTC and Facebook.
- MartinCron 15y agoShould government agencies who regulate telephone services not use telephones?
- shibboleth 15y ago
- arthurgibson 15y agoSpecifically, under the proposed settlement, Facebook is: "barred from making misrepresentations about the privacy or security of consumers' personal information;" Is this implying companies are allowed to lie? Seems redundant.
- freehunter 15y agoIt sounds to me like they're just reiterating the law that's already in place, highlighting that Facebook has been violating it.
- johnthedebs 15y agoI think what it means is that, in this case, the FTC gets to watch and make sure Facebook complies. If they don't, they get penalized for it. FTA: The proposed order also contains standard record-keeping provisions to allow the FTC to monitor compliance with its order. and then further down: Each violation of such an order may result in a civil penalty of up to $16,000. I really hope that's up to $16,000 per person for each violation.
- deleted 15y ago[deleted]
- tbrownaw 15y agoMy employer handles insurance claims. I have an email sitting in my inbox right now, explaining that if we get a certain thing wrong it will get us fined up to $1000 per claim per day until it's fixed. Not because we screwed up and got in trouble, but because that's just how things always are in this industry. So no, I don't find that unlikely at all. In fact it not being per person is what would be absurd.
- seiji 15y agoThe next site-wide privacy snafu will cost $11 trillion dollars.
- rhizome 15y agoThis just means that Facebook privacy changes will have the imprimatur of the FTC from now on, which FB paid for with the airing of a little bit of dirty laundry. The fix is in.
- jellicle 15y agoSo the penalty for ongoing repeated lies and fraud is.... nothing. Zero. The FTC has investigated, and the settlement is zero money and zero penalties. Not one dollar. Whew! I'm glad they were punished! They won't do THAT again! The U.S. is really in late-stage empire breakdown. I don't think there is any significant enforcement of any laws whatsoever against companies and people that are reasonably well connected. The only thing keeping the society from total breakdown is inertia.
- daenz 15y ago> The only thing keeping the society from total breakdown is inertia. I know, society is breaking down, kids are getting more disrespectful, things are more expensive, the end of the world is upon us, etc :) You taking your lifetime to come to a realization about the state of the world does not make the realization less true before you had it. It's a memory glitch. Jump back 100 years, it's the same shit.
- JonnieCache 15y ago>Jump back 100 years, it's the same shit. Yep. Jump back 100 years, and you're in the breakdown of the British empire. And look what we became, a pointless, miserable lame-duck nation utterly yoked to the next empire that rose after us, the USA. Now you guys are gonna be yoked to the next empire, China. Have fun with that! I'll maybe catch you on a beach in Brazil, where hopefully things will be cool. Fingers crossed.
- rhizome 15y agoThe movie "Gosford Park" is a well-covered instance of this state of affairs.
- anigbrowl 15y agoYep. Jump back 100 years, and you're in the breakdown of the British empire. You're off by several decades and two world wars. The British Empire was in full bloom in 1911, and there was little unrest in any of its colonies, never mind at home.
- johnnyg 15y agoMany have posted to this thread with complaints that boil down to "this is a slap on the wrist because they are well connected". If you were the FTC, what would you do to Facebook in this case, how would it be supported in law and what long term change for the better would your action create? Privacy is a civil good but it is a fine line to walk indeed to punish an innovator during a recession. Where's the happy medium?
- lemming 15y ago...to punish an innovator during a recession. This is not even close to a fine line. The fact that Facebook may be an innovator or the fact that we may be in a recession have nothing to do with their legal responsibilities to their users. If they have violated those responsibilities they should be punished appropriately regardless of the current economic situation, and them being an "innovator" is totally irrelevant. Should we allow innovative companies to dump toxic waste or employ racist hiring policies, for example?
- 1010100101 15y agoThe problem here is the personal information is being voluntarily given to Facebook. And the FTC can do nothing about that. As far as I can tell, most people using FB are trying to communicate with their friends (as they previously did via letter, telephone and email), not broadcast every personal detail and thought to potentially any person or organization connected to the web. Alas they are not well informed that by sending all their communications through Zuckerberg's website, this is in effect what they are doing. That lack of understanding is something the FTC can address. So to comply with the FTC's requests, FB will make more disclosures. But the problem remains. FB, whether intentionally or not, is receiving far too much private information and private conversation, and it's all being channeled over the web.
- sunchild 15y agoWrong. The FTC said very clearly that it thinks Facebook lured consumers in under false pretenses. That's punishable by criminal and civil penalties, in theory. The FTC usually settles these kind of cases, AFAIK. Sometimes there's money involved, sometimes not. Anyone who isn't in compliance with their own published privacy policy should be worried about the FTC; they can (again, in theory) do serious harm to a business – even one as big as Facebook.
- dreamdu5t 15y agoYou know... people could just take responsibility for sharing their private information. If they don't think a website "privacy policy" is enough of an assurance, it is their fault for accepting that risk. FB should not be blamed for sharing information that others freely share with FB. It's ridiculous. It's even more ridiculous to think that government regulation is somehow needed to protect privacy. How absurd. "I keep using this service and they don't do what I want! But I keep sharing my information with them." Come on. At a certain point, individuals need to accept that THEY maintain a relationship with FB as well.
- sp332 15y agoI gave my info to FB and they promised to only share it with certain people. Then they made that info publicly available. That's a breach of trust, and possibly criminal.
- brown9-2 15y agoWhile you have a point about being responsible about what information you share with Facebook, it's not that users don't like their privacy policy - it's that the FTC has found that the privacy policy Facebook has published is a lie.
- drcube 15y ago>FB should not be blamed for sharing information that others freely share with FB Your bank should not be blamed for sharing information that you freely share with your bank? Your doctor should not be blamed for sharing information that you freely share with your doctor? Law enforcement should not be blamed for sharing information that you freely share with law enforcement?
- ktrgardiner 15y ago> Obtain periodic assessments of its privacy practices by independent, third-party auditors for the next 20 years. This is assuming Facebook will be around in 20 years.
- tokenadult 15y agoThis is assuming Facebook will be around in 20 years. This binds successor corporations operating Facebook's business and thus changes the potential value of Facebook as an acquisition target (and thus as a retail investment choice when it becomes publicly traded).
- dreamdu5t 15y agoPrivacy policies aren't binding contracts or agreements. They're just stated policies. Why do people treat them like contracts?
- Silhouette 15y agoPerhaps that is so in the US; I don't know. In Europe, however, privacy policies play a significant legal role in terms of complying with privacy and data protection legislation. Facebook has its international HQ in Europe and deals with personal data about EU citizens, and is thus subject to EU rules as well as US ones.
- _delirium 15y agoContracts are a pretty gray area. In a lot of contexts, a handshake agreement or email exchange, if documented well enough, can constitute a binding, legally enforceable contract. It doesn't have to be on a paper saying OFFICIAL CONTRACT with signatures at the bottom.
- rmc 15y agoWhy aren't they contracts? When I sign up for a website, I have to enter into a contract for their Terms & Conditions, which usually includes the Privacy Policy.
- rmc 15y agoI wonder how this settlement compares to EU Data Protection Law. Is it possible FB could abide by FTC rules and still be outside EU rules? Will FB use this "We're OK by the FTC now!" as a claim to be not so bad in the EU?
- kmfrk 15y agoI think it would be too much of a mess to manage, really. Even Canadian consumer protection laws have shaped Facebook's privacy policy.
- sunchild 15y agoThere is a lot of nonsense legal interpretation in this thread. Did anyone actually read the settlement? You commit fraud if you make any intentional deception in order to benefit yourself, or to harm others. If you intentionally make public commitments that turn out to be false, and you thereby cause some harm to another person, you have committed a fraud. The FTC is empowered to enforce criminal and civil penalties for fraud on behalf of consumers. From the FTC website: "When the FTC was created in 1914, its purpose was to prevent unfair methods of competition in commerce as part of the battle to bust the trusts. Over the years, Congress passed additional laws giving the agency greater authority to police anticompetitive practices. In 1938, Congress passed a broad prohibition against unfair and deceptive acts or practices.” From the FTC's Facebook settlement statement, it's perfectly clear that the FTC believes that Facebook is guilty of committing widespread and repeated deceptions in violation of the law. The settlement itself is tantamount to saying that Facebook has had its last warning, and is on very thin ice with the FTC. Feel free to complain about whether such a "penalty" is effective. We won't really know until the next time Facebook breaks the law.
- ThePinion 15y agoOkay so question on this one. - required to prevent anyone from accessing a user's material more than 30 days after the user has deleted his or her account; Does this include people that have already deleted their account? Does this also include Government agencies and such from seeing the >30 day deleted data? I'd like to know that after permanently deleting my account all my stuff is gone, but I don't really see anywhere that says that's true. Meaning the site is still destroying my privacy even after I've decided to have nothing to do with the account.
- veyron 15y agoI am strangely reminded of that episode in 30 rock where tracy realizes he can just pay a fine to make obscene comments and do obscene things on TV ...
- egyamado 15y agoIt is our mistake we made them now they sell us as product http://news.ycombinator.com/item?id=3293936 http://news.ycombinator.com/item?id=3293936 When I created an account with HN using Google account via ClickPass, one of the screen steps before I grant access to ClickPass, Google advised me to not grant it and if I do it I can cancel it any time which it will prevent ClickPass to access to my account information and my password. This warning statement is not new; it’s there everywhere when you grant any application to use your Facebook, Twitter, Google ... etc accounts. In the mean time Google Search is nothing without us, because "we are the product", they sell (us to third parties or Governments) or use our "private information" or what they told us it’s private without approval from us. Facebook is doing same thing and that’s why their entire business model under fire in the EU. http://venturebeat.com/2011/11/28/facebook-advertising-eu/ http://venturebeat.com/2011/11/28/facebook-advertising-eu/ Do you remember what happened in 2008 with Google’s Evil EULA (http://www.theregister.co.uk/2008/09/03/google_chrome_eula_sucks/ http://www.theregister.co.uk/2008/09/03/google_chrome_eula_s...)? Now, are we "the product" still having any privacy? Are we safe? How far we can trust those businesses? Should we keep using their services; and later complain about how evil their Terms and conditions or EULA are???
- Igor_Bratnikov 15y agoso is Google for google buzz, the capability of the ftc to monitor and/or do more than a slap on the wrist is no existent the monitoring is facebook telling the ftc - we are all cool over here bro and the ftc taking them at their word