Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have to say, I'm really impressed with Facebook for coming out and making this their issue, instead of just waiting for the applicants and employers to slowly work it out between themselves. In hindsight, it's seems like an obviously smart move (both to impress their userbase and to remove disincentives to use Facebook), but somehow it didn't occur to me that they might join in on the fight. Good for them.


Agreed. Damn good PR move.

<sarcasm> Plus those employers shouldn't be getting their Facebook background checks for free. FB has to protect it's future revenue streams! </sarcasm>

When FB starts protecting user data from everybody, individuals, business and government, that'll be something. Might even be worth having to wade through your aunt's cats-in-clothing posts.


HOW can Facebook, or anyone else _successfully_ protect user data from government without breaking the law?


Require a confirmed court order before any amount of cooperation with authorities, including the acknowledgement that data might exist.

Assign a legal team to investigate all such orders, and proactively seek injunctions against those that overstep their authority.

Require that all government employees and contractors disclose their involvement (not publicly, obviously) and subject those individuals to enhanced scrutiny with regards to unwarranted data mining. Pursue aggressive legal action against the state for any individuals found in violation of this policy.

Of course, any of this would require Facebook or anyone else to treat its users as customers rather than products.


They can also publish statistics about law enforcement requests by political region, as Google does in its transparency report.


This would be amazing. What I'd also like to know is if LEOs have FB accounts with additional features, or if they have specialized UI where they can query user data. A whistleblower at Verizon a few years ago talked about a paid self-serve web interface they built for law enforcement to query location data because the volume of requests was too much to process manually.

Does the "secret interpretation" of the Patriot Act we keep hearing about include unfettered access to social networks?


By providing at least token resistance?

People shouldn't be getting roped in by the law because law enforcement has free reign to peruse profiles. As well, infiltrating profiles by 'social hacking' (aka asking to friend someone by having a profile with breasts on it) shouldn't be allowed by law enforcement doing fishing operations.

In other words, communications on Facebook should be considered as private communication. Monetization by anonymous advertising akin to Google's model should be the accepted quid pro quo for usage.


Sometimes pieces of government are unaware of laws they are breaking until a well-funded challenger can use the courts to educate it.


Successfully protecting user data from the government isn't an either/or zero-sum situation, it's a game of inches. They should protect it up to the point at which they are most unable, and not a minute nor filing before.


Avoid collecting potentially sensitive information in the first place, if at all possible.

Collecting and retaining the least possible amount of information about users is good security; it's just bad commercial practice. It also protects your users in case you go out of business and end up sold (or pivoting) into a non-privacy-protecting business model, like what happened with Rapleaf.


FB is indeed probably upset because employers were stupid and started asking applicants for their info directly instead of going behind their backs and asking FB for it instead (which FB would have happily given them ... for a fee, of course).

It's pretty likely FB will quietly roll out a paid background check service (which will be hyper-secretive and kept whisper-quiet) at the same time they are publicly grandstanding about this issue. In the linked article, there is a link to a second article about a US Senator who is currently crusading on this issue. He comes right out and says there will be exceptions for law enforcement, government contractors, and jobs with security clearances. Look for them to extend those exceptions until social media spying is back to being a de-facto part of applying for a job, any job. They're going to legitimize this while pretending to be fighting it.

(sounds paranoid, yes ... until it happens)


I actually expected them to do this, because it would've been to their detriment if they didn't. If asking for the employees password became a "thing", people would've started quitting Facebook, or at the very least try to make fake accounts for their employers. But even so, it's still nice to see them actually doing it.


"I have to say, I'm really impressed with Facebook for coming out and making this their issue"

I don't find it impressive or surprising. This is a major issue that would change what people would want to share. No sharing - no facebook. It's obvious that they need to do whatever they can fair, unfair, legal, fud to stop employers from requesting access to a facebook users page.

Another commenter (jerf http://news.ycombinator.com/item?id=3745916 ) brought up the issue of legal standing which I agree with. Facebook probably doesn't have legal standing (that is clear) but the mere fact they are raising the issue will stall the process and give them time to come up with a solution. And instill "carry on as usual nothing to see here" into facebook users.

They are getting out in front of the problem before it spins out of control.


Why wouldn't Facebook have legal standing? They're the ones whose servers are being accessed without authorization (employer does not have authorization to use someone else's credentials).


They are getting the credentials by asking the potential employee for them. So it's not without authorization.

Even if they wanted to build a case of coercion or duress they would need the cooperation of the employee to do this. And most importantly what is the specific harm done to facebook by this individual action? If I give you my facebook credentials and you login what damage has been done (to facebook in my specific case)?

If I was the opposing attorney I would raise the issue of whether they police and take action when people share their passwords in other cases. My guess is they have never taken action on something like this in the past.

And as far as changing their TOS what are they going to say? We forbid you from sharing your password with an employer (some might want to do this for some reason) or we forbid you to share with anyone? And if that is the case they have to police all sharing of passwords which, with hundreds of millions of users is simply not going to happen.


Say you let me have a copy of your house key (in case you lock yourself out or sometimes I come in to water your plants maybe watch a little TV and you are cool with both of those). Someone then asks me for the key, and I let them have a copy of it. Do they have your permission to enter your house at all? I sorta think not.

Permission to enter with a key does not necessarily transfer with possession of the key.


How do you get an analogy between a facebook password (which you pick by the way not them) and "copy of your house key"?

The analogy would be you rent a house and are given a key. And then you can give that key to someone else (like the cleaning person). You can also give the key to someone on Airbnb but that might be prohibited by other language ("you can't rent").

Your key example would be "does the employer have the right to give your password (which you gave them) to someone else". The answer to that is obviously "no" unless you told them it is ok to do.


Your Facebook user name and password is exactly like your copy of a key that lets you into their house. Your having picked the character strings used doesn't matter. You are entering their system when you use that key.

Them letting you put a bit of your furniture in their house (i.e. content you own) doesn't mean the house itself is yours. Nor does it mean that your permission to enter their system necessarily transfers to other people even given that you happen to give those other people a copy of the key.


It's probably not productive to use poor analogies here.

Accessing a computer system without authorization from the owner of that system is a crime. Facebook doesn't give authorization for employers to access their employee's accounts on their system, and explicitly forbids their users from transferring their own authorization to others.

As far as I can see, there is simply no way to construe an employer's access as authorized by the owner of the system i.e. Facebook.


"Hey Larry, here's my health insurance card. You can use it, I give you permission."

As soon as you think about this in the context of a paid service, who can grant authorization becomes very clear. The fact that Facebook is providing a free service should not change a thing. It's still their service.


Paid service? An analogy might be a paid hosting service. In that case there is no restriction on who you can give your password to to access say, your, website hosting or domain registration or similar service. Or to make changes or see what is going on there. After all, it's your content. Unless I am missing something which says facebook owns your content once you upload it.

And actually this issues has been settled (you own it):

http://www.nytimes.com/2009/02/17/technology/internet/17face...

Next, check for example the T&C for 1and1.com web hosting (randomly picked).

http://order.1and1.com/Gtc?__lf=Static&linkOrigin=&l...

"You are responsible for maintaining the confidentiality of both your password and your account and are fully responsible for all activities that occur under your password and your account."

Now while 1and1 probably has some language that restricts your ability to resell something (same as you can't resell your cable connection) allowing someone to login (like your web designer?) to view what you have is most certainly not prohibited.

So if your employer said "I want your password to your webhosting account" I don't believe the web host would have standing and/or a cause of action.


There is a difference between:

  >...(you) are fully responsible for all activities that occur under your password and your account
and Facebook's version, which goes:

  >You will not share your password, (or in the case of developers, your secret key), let anyone else access your account...
One says you're responsible for whatever happens on your account, the other explicitly says not to share your password. Kind of different, wouldn't you say?

It's worth mentioning that letting randoms into your Facebook account isn't only playing chicken with your account security, you're also playing with the security of everyone you have friended, who implicitly trust that the only person on the account is the person who's name is on it.

That is something you do not have the right to do on an ethical level, let alone a legal one.


Have you considered the possibility that Facebook and 1and1 have different terms of service?


The standard for "having standing" legally is quite low: To file a lawsuit in court, you have to be someone directly affected by the legal dispute you are suing about[1].

Is Facebook directly affected? Yes - people access their servers.

Harm, authorization etc etc can all be argued in the case, but there is no doubt at all that Facebook does have standing here.

[1] http://www.courts.ca.gov/9616.htm


Its an issue that can lead to a chain reaction. Facebook is protecting itself by protecting its users.

Employers make 'facebook background check' hiring policy -> FB users/prospective employees become more conscious of this -> User engagement drops as users are more careful about posting anything under the sun -> FB loses


Honestly, this protects them more then anybody else. If this "behavior" became norm for employers, people would begin simply deleting their Facebook accounts in droves.

Facebook is valuable, but not "that" valuable where people would sacrifice a potential job opportunity in favor of keeping their Facebook profile.

That being said, I do like that Facebook has weighed in and it favors an individuals right to privacy.


I agree. This was a damn good way of handling the situation: taking care of it head-on instead of watching from the sidelines and hoping things get better. I didn't think they would do much (except for maybe a blog post about how you shouldn't give your password to anyone or something similar), but this is totally beyond what I expected.


The cynic in me says that facebook is doing this because the employers didn't go through the proper channels (i.e. pay facebook for that kind of access) and it's a message: If you want that kind of data, you have to pay for it.

I hope this isn't the case, but facebook doesn't really have a great record when it comes to privacy.


Your cynicism is somewhat warranted, but slightly misplaced.

Facebook is doing this because not doing so would be really bad for business: i.e., it would threaten the user experience of the site. People would either quit Facebook, spend less time on it, severely tone down or alter their usage of it, or create fake profiles for work. Any or all of those things would be a big detriment to Facebook. So taking a stand on this issue is both good for business and good for PR.


The possibility of a whistleblower, I think, would be too high. It would probably destroy Facebook or close to it.


I don't think Facebook would want to sell its data so obviously just offering users' profiles to any business that comes and pays. This would be too bold of a move.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: