Skip to content

Comment on Facebook doesn't like privacy countermeasures

Comments

This is a non-story for the reasons stated but a story for other reasons.

It's standard that widget publishers require to use their widget "as is". That's basically what Facebook is saying. Not only do you not know what any custom modifications will necessarily do but it's a completely valid argument that you want a consistent user experience with your widget.

As for user tracking, this is basically an inevitable byproduct of Facebook hosting the widget, a situation I'm sure they're not unhappy about, but this really isn't a big deal in the context of how the Web works.

The story here (IMHO) is trust. Most pages have a Google Analytics tracking script on them. Do you trust Google? I do (disclaimer: I work for Google). Protecting user data and privacy are key priorities here. It's why Google+ has relatively simple privacy controls and allows you to export your data at any time.

Do you trust Facebook? I don't. Then again, there aren't many companies I do trust. But Facebook's track record seems to be to befuddle the user and trick or opt them into sharing things wider than they understand or want.

"Most pages have a Google Analytics tracking script on them. Do you trust Google? ... Do you trust Facebook?"

I don't trust either.

I have blocked Google Analytics along with Facebook, Digg, Twitter, and a bunch of other "services".

Needless to say, I don't have an account with any of them. The "free" services they provide are of very dubious value compared to my privacy and information about my friends, interests, and online activity I'd be giving up by using them or allowing them to track me.

> But Facebook's track record seems to be to befuddle the user and trick or opt them into sharing things wider than they understand or want.

Just like Google did with Buzz

That was such a clusterfuck that for most people Google is in the same bucket as Facebook when it comes to 'caring about user privacy'

I never considered any of FB privacy curtailments to be 'clusterfucks' in the sense that they involved Buzz-level incompetence, bad planning, or lack of foresight.

To the contrary, I always felt FB knew exactly what it was doing, and was operating in a very calculated way. Three steps forward and (maybe) one step back.

Beacon?

> Facebook's track record seems to be to befuddle the user and trick or opt them into sharing things wider than they understand or want.

Are you saying that the product designers at Facebook want to design interfaces and settings that intentionally confuse users into laxer privacy settings? Turning this discussion into a rather presumptuous smear at Facebook in the face of many privacy failures by Google is rather childish.

Perhaps you're saying Google's privacy missteps were accidental, and thus tolerable. But what makes them more accidental than Facebook's? Bugs are accidental, sure, and are addressed as quickly as possible (last summer my mentor was locked in a room with a bunch of people for a week trying to fix the bugs that came up, and come up with long term solutions). As a result all privacy settings are as explicit as possible--especially with the most recent launch, the privacy settings of every single item is clear.

It is unfair to claim that Google values privacy and demonize Facebook for its privacy-related product decisions. If anything, privacy nuances are what prevented the new privacy features from launching for multiple months, as we iterated on details that an organization that cared less about privacy would have overlooked.

Here's an interesting comparison: Everything Facebook knows about me is something I or my friends entered (i.e. via tagging). In contrast, Google knows so much more about me than I told it. How did it automatically link my Quora, Twitter, etc accounts without my knowing or permission?

> Everything Facebook knows about me is something I or my friends entered (i.e. via tagging).

No. If person x is logged into facebook, they (or rather you, as it seems you work for facebook) get an indication of every page person x is browsing that has a "like" button, whether that person presses it or not. Furthermore, even if you're logged out of facebook, there's still a couple of facebook cookies identifying the computer you've logged in from.

I'm not sure I would you believe the claim that Facebook is not using any of that info right now, but I'd probably call you an outright fraud if you said that this data is never ever going to be used for anything.

Same way for Google, BTW - they've had a better track record of not abusing the data they have, but it is possibly because we haven't heard the gory details yet, and it is not going to stay that way when their profits take a dip if they ever do - they are in it for the money, and that data is worth a lot of money.

For those reasons, my firefoxen run ABP, RequestPolicy and/or Ghostery, AND I have multiple users for job / personal / porn browsing (and other measures), and multiple browsers (chromes, firefox versions) for de-panopticlicking.

> No. If person x is logged into facebook, they (or rather you, as it seems you work for facebook) get an indication of every page person x is browsing that has a "like" button, whether that person presses it or not.

OK, fair enough. I meant the stuff I or my friends see. Facebook doesn't display a list of "pages that had like buttons that orijing visited but did not like" although that would be interesting.

> OK, fair enough. I meant the stuff I or my friends see.

This is so very different from

> Everything Facebook knows about me is something I or my friends entered (i.e. via tagging).

As to be irrelevant - I don't have a single status update or biographic detail in my facebook account, and I remove tags of me from pictures -- and yet, facebook has a damn good idea of the websites I browsed before installing ghostery.

Google knows about my Twitter account because I gave them my homepage, which has semantic markup that exposes my FOAF data, linking to that account (and others). I was actually quite impressed by it...

Has Facebook (or Google) ever had a "privacy misstep" that was an error on the side of too-tight privacy?

Nobody gets outraged over privacy that's too tight — they just don't use the service. You could say that Google's longstanding reluctance to embrace social was an example of too much privacy. (I don't think that was the primary motivation, but it would look the same either way.)

Yes, but nobody knows about it.

Is that a "misstep," then? It seems to me that the logic of a too-tight misstep would be that the information simply does not get out. What would be the reason for FB (or whoever) to notice that too little of my information is getting out? I suppose the "misstep" is in the eye of the beholder. :)

> Are you saying that the product designers at Facebook want to design interfaces and settings that intentionally confuse users into laxer privacy settings?

Almost certainly, yes. Since that's how they derive revenue from users.

> Turning this discussion into a rather presumptuous smear at Facebook in the face of many privacy failures by Google is rather childish

/s/childish/factual/

Somehow, privacy UI changes at fb almost always lead to more rather than less confusion and more rather than less sharing. We could either assume the designers are incompetent or decide this is by design. Occam's razor says by design.

I would be happier if Google had a priority of not collecting user data in the first place.

(copying and extending myself from another reply in this thread, because it is actually more relevant here:)

The copyright issue is a red herring. Facebook could create an official "data:..."-url based "like" button that has the original image instead of linking to their server. It would be better for everyone involved, including facebook's bandwidth and the site's loading speed -- except that facebook would lose their tracking data.

The other thing that they would be unable to do would be to change the look of the image (because it would be _in_ the link); but I think it is a good thing that they (or a hacker) can't put a penis on every page that has a like button.

Really, the copyright thing is a PR deflection, not the real issue.

Google is by far the scarier big brother company. There is no escpaing Google and as far as I know Facebook has not to date sent teams of roving wireless sniffers in guise of map making.

This was a copyright issue about locally hosted images. Heise changed the initial image and everyone is happy.

I'm happy to hear you trust Google, but trying to warp this into a smear on Facebook (my employer) about trust is in poor taste.

So when are you guys going to back up the openness propaganda and open source something of substance other than protobuf?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.